Chainalysis links EU-sanctioned ‘Stern’ to over $300 million in ransom payments

Chainalysis links EU-sanctioned ‘Stern’ to over $300 million in ransom payments

Coordinated U.S., EU and UK sanctions expanded from alleged Trickbot leader Vitaly Nikolayevich Kovalev to VPN, hosting and malware providers accused of enabling ransomware operations.

BTC

Fact Check
The primary Chainalysis blog post directly states that EU-sanctioned 'Stern' (Vitaly Nikolayevich Kovalev), the Trickbot/Conti administrator, had wallets that received over $300 million in ransom payments, describing him as likely the most prolific ransomware operator. It also confirms the coordinated US/EU/UK sanctions expanded from Kovalev to VPN (1VPNS), hosting (Media Land LLC), cryptor, and malware (LummaC2) providers—matching every element of the claim. The CryptoTimes secondary source independently corroborates the same $300 million figure and enabler details, citing Chainalysis.
    Reference12
Summary

Joint sanctions by the U.S., EU and UK targeted alleged hackers, cybercrime groups and infrastructure providers, broadening pressure on the ecosystem that authorities say supports ransomware. Chainalysis said EU-sanctioned Russian national Vitaly Nikolayevich Kovalev, known as “Stern,” was identified as an alleged senior TrickBot Group leader, with wallets tied to him receiving more than $300 million in ransom payments. Authorities and blockchain investigators have described him as a “CEO-like” figure within the Trickbot and Conti operations, overseeing budgets, hiring and attack planning. The group was said to have more than 100 members, pay salaries in Bitcoin and have hit more than 1,000 organizations worldwide, including Ireland’s Health Service Executive in May 2021, with an estimated $180 million acquired in 2021 alone. OFAC and EU measures also reached VPN, hosting and malware service providers, identified crypto wallet addresses across multiple blockchains and published on-chain addresses that may make it harder for sanctioned actors to move funds through exchanges and financial services.

Terms & Concepts
  • on-chain wallet addresses: Public cryptocurrency addresses recorded on a blockchain that can be tracked and screened by investigators or compliance teams.
  • infostealer: A type of malware designed to steal sensitive data such as passwords, browser data or wallet information.
  • blockchain analytics: Analysis of on-chain transactions to trace funds and link wallets to entities or activity.