Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks Samiksha Jain
    The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels across multiple jurisdictions. Treasury said the campaign follows direction from Pre
     

US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks

25 de Agosto de 2026, 03:44

Operation Economic Outcast

The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels across multiple jurisdictions. Treasury said the campaign follows direction from President Trump and is intended to systematically target financial channels used for oil smuggling, sanctions evasion and other activities linked to Iran.

Operation Economic Outcast Expands Iran Sanctions

Under Operation Economic Outcast, the Office of Foreign Assets Control (OFAC) issued five sectoral sanctions determinations covering digital assets, technology, gold, aviation and shipping. Treasury said the measures increase its ability to sanction foreign persons operating in or providing services to these sectors of the Iranian economy. The department said Iran has increasingly used cryptocurrency for sanctions evasion, while advanced technology has been sought for weapons programs. Gold has also been used to stabilize the rial, while aviation and shipping networks have been linked to the movement of fighters, weapons, sensitive technologies, oil and other assets. The new determinations build on earlier measures covering Iran’s financial, petroleum and petrochemical sectors.

OFAC Sanctions Nearly 60 Iran-Linked Targets

OFAC also sanctioned nearly 60 entities, individuals and vessels across networks associated with nuclear and missile technology procurement, cyber operations and oil revenue generation. The action includes a procurement network spanning the Middle East and East Asia that Treasury said helped Iranian entities obtain sensitive dual-use technology through front companies, financial channels and logistics intermediaries. Treasury also targeted a malicious cyber group directed by Iran’s Ministry of Intelligence and Security (MOIS). The department said members of the group compromised and exfiltrated data from U.S. companies in critical infrastructure sectors, including energy, healthcare, defense, information technology and financial services. The designations also include Iranian cyber actors accused of network compromises and digital asset theft. Treasury said one individual illicitly gained control of a Bitcoin wallet containing more than $30,000 in 2023.

Secondary Sanctions Risk Expands

The campaign also increases secondary sanctions exposure for entities that continue conducting certain business with the Iranian regime. Treasury said countries are being given timelines to address identified Iran-related activity, while entities facilitating money laundering or sanctions evasion could face restrictions involving the U.S. financial system. OFAC also suspended several general licenses that previously authorized certain remittance payments to Iran and Iranian access to parts of the U.S. cultural and academic system.

Iran’s Shadow Fleet and Oil Networks Targeted

A major component of the measures focuses on Iran’s shadow fleet and oil revenue channels. Treasury sanctioned brokers, companies, and vessels involved in transporting Iranian crude oil and petroleum products across multiple jurisdictions. The department identified shipping networks involving the UAE, Hong Kong, China, Singapore, Switzerland, Europe, and other regions. Several UAE-based entities and individuals were designated over alleged roles in facilitating Iranian oil shipments and cryptocurrency payments. OFAC also targeted five vessels identified as blocked property, including SIFRA, G SILVER, QUANTUM HOPE, VOYAGE ELITE and TELA. Treasury said these vessels had transported Iranian LPG, petroleum products or crude oil to markets in Asia. The measures mean that property and interests in property belonging to designated or blocked persons that are in the United States or under the control of U.S. persons are blocked and must be reported to OFAC. Treasury said violations of U.S. sanctions can result in civil or criminal penalties, while certain transactions involving designated persons may also expose foreign financial institutions to secondary sanctions.
  • ✇Firewall Daily – The Cyber Express
  • New Zealand Targets Russian Cyber Actors With Fresh Sanctions Samiksha Jain
    New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreadi
     

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

11 de Agosto de 2026, 03:18

New Zealand Sanctions

New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreading anti-Ukraine propaganda, as well as actors from the Democratic People’s Republic of Korea (DPRK) and Iran providing support to Moscow. “Children should never be used as instruments of war,” Peters said, expressing concern over efforts to abduct and re-educate Ukrainian children through state-directed programmes.

New Zealand Sanctions Target Russian Cyber Actors

The latest Russia sanctions include several individuals previously accused by the United States and other Western governments of malicious cyber activity. Among them are Yuliya Pankratova and Denis Degtyarenko, members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR). The U.S. Treasury sanctioned both individuals in 2024 over alleged cyber operations targeting U.S. critical infrastructure. U.S. officials identified Pankratova, who uses the alias “YUliYA,” as the group’s leader, while Degtyarenko, known as “Dena,” was described as one of its primary hackers. American officials alleged that Degtyarenko was responsible for compromising an industrial control system at a U.S. energy company and had developed training materials for compromising supervisory control and data acquisition (SCADA) systems. Pankratova has also allegedly been associated with Z-Pentest, another pro-Russian hacking group accused of targeting critical infrastructure. New Zealand has also sanctioned Aleksandr Volosovik, known online as “Yalishanda.” U.S. prosecutors have accused him of helping operate Media Land, a Russian bulletproof hosting provider allegedly used by cybercriminals to target organizations including hospitals, schools and banks. In July, the U.S. Justice Department unsealed charges against Volosovik and two other Russian nationals, alleging activities that caused more than $62 million in losses to victims in the United States and other countries.

GRU-linked Official Among Sanctioned Individuals

Another individual included in the latest New Zealand sanctions against Russia is Andrey Averyanov, a senior Russian military intelligence officer who previously commanded GRU Unit 29155. Western governments have linked the unit to cyberattacks, sabotage and other covert operations. Its cyber division has been accused of targeting governments, defense organizations, think tanks and other entities in Ukraine and NATO countries. New Zealand had previously sanctioned members of the unit over alleged malicious cyber activity targeting Ukraine and other countries.

Russia Propaganda and Technology Entities Targeted

The new sanctions also target Russia’s Internet Development Institute (IRI), a Kremlin-backed organization that finances digital media and content promoting Russian state narratives. IRI director Alexey Goreslavsky has also been designated. The British government has previously said the institute was established by Russia’s presidential administration and received hundreds of millions of dollars in government funding. Its projects have included films and video games promoting narratives associated with the Kremlin. Russian information technology company LANIT has also been added to the sanctions list. The company has provided services to Russia’s Defense Ministry and sanctioned defense-industry companies, including state-owned conglomerate Rostec. LANIT had previously been sanctioned by the United States, Canada and Ukraine.

New Zealand Reaches 36th Russia Sanctions Round

The latest package represents New Zealand’s 36th round of Russia sanctions since the Russia Sanctions Act came into force in March 2022. New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. The measures generally include asset freezes and travel bans and prohibit New Zealanders from making funds or other assets available to designated individuals and entities. Peters said cyber activity can have real-world consequences, noting that cyber actors are increasingly being used to gather intelligence, enable sanctions evasion and disrupt those opposing Russia’s aggression.
  • ✇Firewall Daily – The Cyber Express
  • US Treasury Sanctions VPN Provider Linked to Ransomware Samiksha Jain
    The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure. The act
     

US Treasury Sanctions VPN Provider Linked to Ransomware

Ransomware sanctions

The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure.

The action, coordinated with the United Kingdom, is part of broader efforts to disrupt the cybercrime ecosystem supporting ransomware operations. The Treasury said the targeted services have contributed to attacks that resulted in billions of dollars in losses across the United States.

OFAC Targets 1VPNS and Its Administrator

At the center of the ransomware sanctions is 1VPNS, a VPN provider that OFAC described as a key infrastructure supplier for ransomware operators and other cybercriminals. The Treasury also designated Dmytro Rashevskyi, the administrator of 1VPNS, for allegedly providing technological support to cyber-enabled criminal activity.

According to OFAC, VPN services have legitimate privacy and security uses but can also be misused to conceal the origin of cyberattacks, deploy malware, and manage stolen data.

The Treasury said ransomware groups used 1VPNS infrastructure during attacks against U.S. companies and institutions, including financial services firms, hospitals, municipal governments, and other organizations.

Authorities also alleged that since 2014, 1VPNS advertised its services on cybercriminal forums while claiming it did not retain user logs or cooperate with law enforcement investigations involving illegal activities conducted through its servers.

OFAC further stated that Rashevskyi used false identities, including "Maksim Sorin" and "Roman Chabanenko," to purchase infrastructure from providers that may have otherwise declined business because of abuse complaints linked to 1VPNS servers.

Malware Provider Also Added to Ransomware Sanctions List

The Treasury also imposed sanctions on Yegeniy Vladimirovich Silayev, a Belarusian national accused of supplying cryptors to ransomware operators.

According to OFAC, cryptors are designed to disguise malware as legitimate files, making malicious software more difficult for security products to detect or remove. Unlike traditional encryption technologies that protect user data, cryptors are intended to improve the effectiveness and stealth of malware used in cyberattacks.

The Treasury alleged that Silayev provided encryption and obfuscation services to ransomware groups targeting organizations in the United States and allied countries.

International Action Against Cybercrime Infrastructure

The sanctions were announced in coordination with the United Kingdom's Foreign, Commonwealth & Development Office, which also imposed sanctions against cybercriminals and individuals accused of enabling cybercrime.

The announcement follows a May 2026 operation by European law enforcement authorities that dismantled 1VPNS's website and supporting infrastructure with assistance from the FBI's Boston Field Office.

The FBI has also released a cybersecurity advisory detailing the tactics, techniques, and procedures associated with 1VPNS to help organizations identify and defend against ransomware attacks.

Treasury Cites Executive Orders

The designations were issued under OFAC authorities pursuant to Executive Order 13694, as amended, along with President Donald Trump's Executive Order 14390, signed in March 2026.

According to the Treasury, the order directs U.S. government agencies to strengthen protections against foreign actors involved in cybercrime, cyber-enabled fraud, extortion, and related criminal schemes targeting Americans.

What the Sanctions Mean

Under the sanctions, all property and interests belonging to the designated individuals and entity that are within the United States or controlled by U.S. persons are blocked and must be reported to OFAC.

The restrictions also extend to entities owned 50% or more by designated persons. Unless authorized by OFAC, U.S. persons are generally prohibited from engaging in transactions involving blocked individuals or organizations.

The Treasury said violations of U.S. sanctions may result in civil or criminal penalties for both U.S. and foreign persons. It also warned that financial institutions and other organizations could face sanctions exposure if they engage in prohibited transactions involving designated entities.

The latest ransomware sanctions reflect continuing efforts by U.S. authorities and international partners to target the infrastructure and services that enable ransomware operators rather than focusing solely on the attackers themselves.

❌
❌