Visualização de leitura

US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks

Operation Economic Outcast

The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels across multiple jurisdictions. Treasury said the campaign follows direction from President Trump and is intended to systematically target financial channels used for oil smuggling, sanctions evasion and other activities linked to Iran.

Operation Economic Outcast Expands Iran Sanctions

Under Operation Economic Outcast, the Office of Foreign Assets Control (OFAC) issued five sectoral sanctions determinations covering digital assets, technology, gold, aviation and shipping. Treasury said the measures increase its ability to sanction foreign persons operating in or providing services to these sectors of the Iranian economy. The department said Iran has increasingly used cryptocurrency for sanctions evasion, while advanced technology has been sought for weapons programs. Gold has also been used to stabilize the rial, while aviation and shipping networks have been linked to the movement of fighters, weapons, sensitive technologies, oil and other assets. The new determinations build on earlier measures covering Iran’s financial, petroleum and petrochemical sectors.

OFAC Sanctions Nearly 60 Iran-Linked Targets

OFAC also sanctioned nearly 60 entities, individuals and vessels across networks associated with nuclear and missile technology procurement, cyber operations and oil revenue generation. The action includes a procurement network spanning the Middle East and East Asia that Treasury said helped Iranian entities obtain sensitive dual-use technology through front companies, financial channels and logistics intermediaries. Treasury also targeted a malicious cyber group directed by Iran’s Ministry of Intelligence and Security (MOIS). The department said members of the group compromised and exfiltrated data from U.S. companies in critical infrastructure sectors, including energy, healthcare, defense, information technology and financial services. The designations also include Iranian cyber actors accused of network compromises and digital asset theft. Treasury said one individual illicitly gained control of a Bitcoin wallet containing more than $30,000 in 2023.

Secondary Sanctions Risk Expands

The campaign also increases secondary sanctions exposure for entities that continue conducting certain business with the Iranian regime. Treasury said countries are being given timelines to address identified Iran-related activity, while entities facilitating money laundering or sanctions evasion could face restrictions involving the U.S. financial system. OFAC also suspended several general licenses that previously authorized certain remittance payments to Iran and Iranian access to parts of the U.S. cultural and academic system.

Iran’s Shadow Fleet and Oil Networks Targeted

A major component of the measures focuses on Iran’s shadow fleet and oil revenue channels. Treasury sanctioned brokers, companies, and vessels involved in transporting Iranian crude oil and petroleum products across multiple jurisdictions. The department identified shipping networks involving the UAE, Hong Kong, China, Singapore, Switzerland, Europe, and other regions. Several UAE-based entities and individuals were designated over alleged roles in facilitating Iranian oil shipments and cryptocurrency payments. OFAC also targeted five vessels identified as blocked property, including SIFRA, G SILVER, QUANTUM HOPE, VOYAGE ELITE and TELA. Treasury said these vessels had transported Iranian LPG, petroleum products or crude oil to markets in Asia. The measures mean that property and interests in property belonging to designated or blocked persons that are in the United States or under the control of U.S. persons are blocked and must be reported to OFAC. Treasury said violations of U.S. sanctions can result in civil or criminal penalties, while certain transactions involving designated persons may also expose foreign financial institutions to secondary sanctions.

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

New Zealand Sanctions

New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreading anti-Ukraine propaganda, as well as actors from the Democratic People’s Republic of Korea (DPRK) and Iran providing support to Moscow. “Children should never be used as instruments of war,” Peters said, expressing concern over efforts to abduct and re-educate Ukrainian children through state-directed programmes.

New Zealand Sanctions Target Russian Cyber Actors

The latest Russia sanctions include several individuals previously accused by the United States and other Western governments of malicious cyber activity. Among them are Yuliya Pankratova and Denis Degtyarenko, members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR). The U.S. Treasury sanctioned both individuals in 2024 over alleged cyber operations targeting U.S. critical infrastructure. U.S. officials identified Pankratova, who uses the alias “YUliYA,” as the group’s leader, while Degtyarenko, known as “Dena,” was described as one of its primary hackers. American officials alleged that Degtyarenko was responsible for compromising an industrial control system at a U.S. energy company and had developed training materials for compromising supervisory control and data acquisition (SCADA) systems. Pankratova has also allegedly been associated with Z-Pentest, another pro-Russian hacking group accused of targeting critical infrastructure. New Zealand has also sanctioned Aleksandr Volosovik, known online as “Yalishanda.” U.S. prosecutors have accused him of helping operate Media Land, a Russian bulletproof hosting provider allegedly used by cybercriminals to target organizations including hospitals, schools and banks. In July, the U.S. Justice Department unsealed charges against Volosovik and two other Russian nationals, alleging activities that caused more than $62 million in losses to victims in the United States and other countries.

GRU-linked Official Among Sanctioned Individuals

Another individual included in the latest New Zealand sanctions against Russia is Andrey Averyanov, a senior Russian military intelligence officer who previously commanded GRU Unit 29155. Western governments have linked the unit to cyberattacks, sabotage and other covert operations. Its cyber division has been accused of targeting governments, defense organizations, think tanks and other entities in Ukraine and NATO countries. New Zealand had previously sanctioned members of the unit over alleged malicious cyber activity targeting Ukraine and other countries.

Russia Propaganda and Technology Entities Targeted

The new sanctions also target Russia’s Internet Development Institute (IRI), a Kremlin-backed organization that finances digital media and content promoting Russian state narratives. IRI director Alexey Goreslavsky has also been designated. The British government has previously said the institute was established by Russia’s presidential administration and received hundreds of millions of dollars in government funding. Its projects have included films and video games promoting narratives associated with the Kremlin. Russian information technology company LANIT has also been added to the sanctions list. The company has provided services to Russia’s Defense Ministry and sanctioned defense-industry companies, including state-owned conglomerate Rostec. LANIT had previously been sanctioned by the United States, Canada and Ukraine.

New Zealand Reaches 36th Russia Sanctions Round

The latest package represents New Zealand’s 36th round of Russia sanctions since the Russia Sanctions Act came into force in March 2022. New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. The measures generally include asset freezes and travel bans and prohibit New Zealanders from making funds or other assets available to designated individuals and entities. Peters said cyber activity can have real-world consequences, noting that cyber actors are increasingly being used to gather intelligence, enable sanctions evasion and disrupt those opposing Russia’s aggression.

US Treasury Sanctions VPN Provider Linked to Ransomware

Ransomware sanctions

The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure.

The action, coordinated with the United Kingdom, is part of broader efforts to disrupt the cybercrime ecosystem supporting ransomware operations. The Treasury said the targeted services have contributed to attacks that resulted in billions of dollars in losses across the United States.

OFAC Targets 1VPNS and Its Administrator

At the center of the ransomware sanctions is 1VPNS, a VPN provider that OFAC described as a key infrastructure supplier for ransomware operators and other cybercriminals. The Treasury also designated Dmytro Rashevskyi, the administrator of 1VPNS, for allegedly providing technological support to cyber-enabled criminal activity.

According to OFAC, VPN services have legitimate privacy and security uses but can also be misused to conceal the origin of cyberattacks, deploy malware, and manage stolen data.

The Treasury said ransomware groups used 1VPNS infrastructure during attacks against U.S. companies and institutions, including financial services firms, hospitals, municipal governments, and other organizations.

Authorities also alleged that since 2014, 1VPNS advertised its services on cybercriminal forums while claiming it did not retain user logs or cooperate with law enforcement investigations involving illegal activities conducted through its servers.

OFAC further stated that Rashevskyi used false identities, including "Maksim Sorin" and "Roman Chabanenko," to purchase infrastructure from providers that may have otherwise declined business because of abuse complaints linked to 1VPNS servers.

Malware Provider Also Added to Ransomware Sanctions List

The Treasury also imposed sanctions on Yegeniy Vladimirovich Silayev, a Belarusian national accused of supplying cryptors to ransomware operators.

According to OFAC, cryptors are designed to disguise malware as legitimate files, making malicious software more difficult for security products to detect or remove. Unlike traditional encryption technologies that protect user data, cryptors are intended to improve the effectiveness and stealth of malware used in cyberattacks.

The Treasury alleged that Silayev provided encryption and obfuscation services to ransomware groups targeting organizations in the United States and allied countries.

International Action Against Cybercrime Infrastructure

The sanctions were announced in coordination with the United Kingdom's Foreign, Commonwealth & Development Office, which also imposed sanctions against cybercriminals and individuals accused of enabling cybercrime.

The announcement follows a May 2026 operation by European law enforcement authorities that dismantled 1VPNS's website and supporting infrastructure with assistance from the FBI's Boston Field Office.

The FBI has also released a cybersecurity advisory detailing the tactics, techniques, and procedures associated with 1VPNS to help organizations identify and defend against ransomware attacks.

Treasury Cites Executive Orders

The designations were issued under OFAC authorities pursuant to Executive Order 13694, as amended, along with President Donald Trump's Executive Order 14390, signed in March 2026.

According to the Treasury, the order directs U.S. government agencies to strengthen protections against foreign actors involved in cybercrime, cyber-enabled fraud, extortion, and related criminal schemes targeting Americans.

What the Sanctions Mean

Under the sanctions, all property and interests belonging to the designated individuals and entity that are within the United States or controlled by U.S. persons are blocked and must be reported to OFAC.

The restrictions also extend to entities owned 50% or more by designated persons. Unless authorized by OFAC, U.S. persons are generally prohibited from engaging in transactions involving blocked individuals or organizations.

The Treasury said violations of U.S. sanctions may result in civil or criminal penalties for both U.S. and foreign persons. It also warned that financial institutions and other organizations could face sanctions exposure if they engage in prohibited transactions involving designated entities.

The latest ransomware sanctions reflect continuing efforts by U.S. authorities and international partners to target the infrastructure and services that enable ransomware operators rather than focusing solely on the attackers themselves.

Shipwrecks, Sham Papers and False Flags: Tracking the Company Behind It All

A shipwreck in India, an ammunition seizure in Senegal, and a raid on an oil tanker in Malaysia – all three incidents involve ageing vessels, operating with false papers and one recurring figure: Captain Suniel Kumar Sharma.

For over a decade, Sharma has been condemned by the governments of Dominica, Guyana, Samoa, the Federated States of Micronesia and Eswatini, as well as the UN International Maritime Organisation (IMO), for issuing fraudulent paperwork to vessels, including false flag certificates.

In a recent interview with the Financial Times, Sharma said his most prominent flag registry, the International Maritime Safety Agency of Guyana (IMSAG), was no longer operational. However, a Bellingcat investigation has found certificates issued by IMSAG as recently as December 2025. In the same interview, Sharma denied setting up any more registries. Yet Bellingcat has found evidence of a newly launched website linked to Sharma offering flag registration in Nicaragua.

In June 2020, a typhoon off the Indian coast forced the 38-year-old oil tanker, MT Basra Star (IMO 8515817), to run aground. Despite an insurance inspector’s report recommending her immediate demolition, the vessel remained for five years, rusting away on the beach, until she was finally scrapped in January this year.

The Basra Star became a local tourist attraction during the five years it lay rusting on the beach. Instagram post, December 2025.

The insurance report states Basra Star was sailing under a Samoan flag and its classification society (the company that certifies the vessel as seaworthy) was Ascent Navals.   

Two years before MT Basra Star ran aground, the Samoan government and the IMO issued a warning about a fraudulent company called Ascent Navals, and its director, Captain Suniel Kumar Sharma, for appearing to operate on behalf of Samoa, but without official authorisation.

Screenshot of part of the IMO circular warning, dated 6 June 2018.

By sailing under a false flag (Samoa False) and a fraudulent classification society (Ascent Navals), when the worst-case scenario did occur, no jurisdiction (flag state) was legally responsible for the marooned ship.

Bellingcat contacted the vessel’s owners, Shat Al Arab Marine Supply LLC, the insurance surveyors, Uday Bhogate & Associates, and Ascent Navals and its director, Suniel Kumar Sharma. None responded to requests for comment.

Nearly two years after Basra Star was shipwrecked, another ageing vessel, Eolika (IMO 8214968), was found operating under a false flag while laden with illicit cargo. At the port of Dakar, Senegalese customs officers boarded the 39-year-old cargo ship and discovered three concealed containers of ammunition, reportedly worth US$5.2 million. Eolika was flying a false Guyana flag. 

Local TV media, Jambaar report from Dakar Port, published on YouTube, January 19, 2022.

In an open letter, the IMO, together with the Guyana authorities, denounced the flag under which Eolika was sailing as false. They warned of a fraudulent company, the International Maritime Safety Agency of Guyana (IMSAG), for flagging vessels without authorisation from any flag state. Guyana’s police force said it would investigate “this rogue enterprise led by Captain Suniel Kumar”, together with Interpol.  

There is no suggestion that Sharma or IMSAG took part in the transport of illicit goods. The IMO warning was issued in response to IMSAG supplying false paperwork, which then enables vessels to operate without oversight. Flying a false flag for a registry that doesn’t exist voids any insurance, risks crew safety and threatens environmental harm, as seen with the Basra Star.  

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

But it’s not just Sharma’s companies supplying false papers. Last year, maritime experts at Windward identified 285 international tankers falsely flagged by 18 different fraudulent registries. The majority were sanctioned vessels, which typically seek out false flags to evade restrictions. However, according to Lloyd’s List Intelligence, it was Guyana’s fraudulent registry which became the first port of call for sanctioned tankers looking to hop flags.

Seized off the coast of Malaysia earlier this year, the sanctioned tanker Nora (IMO 9237539) switched to a false Guyana flag issued by IMSAG on February 1, 2025. Nora and a second sanctioned tanker, Rcelebra (IMO 9286073), were caught by the Malaysian Maritime Enforcement Agency (MMEA) engaged in an unauthorised ship-to-ship transfer.

Nora (left) and Rcelebra (right) moored together during an unauthorised ship-to-ship transfer off Penang. Source: MMEA/Facebook

Both captains and 53 members of the crew were detained. The cargo of crude oil was valued at more than RM512 million (US$130 million), according to the MMEA. 

53 crew members were arrested, according to MMEA. Source: MMEA/Facebook

However, within days, both tankers were released. Fined the maximum penalty of RM300,000 (US$76,000) for an unauthorised ship-to-ship transfer, the MMEA acted to enforce Malaysia’s environmental and maritime safety laws, but not International and UN sanctions. Asked if this was within its remit, the MMEA did not respond to our request. 

There is no indication that Sharma or IMSAG knowingly issued flags to criminal actors. But by providing false paperwork, the IMO warn that fraudulent flag registries are enabling high-risk vessels to continue operating. 

The promise of investment and the signing of an MoU

Crucial to understanding how IMSAG has continued to operate as a fraudulent registry for so long is that it was once legitimate. 

Back in 2021, Guyanan media described how IMSAG was making investments of US$35 million, creating hundreds of jobs, and constructing a state-of-the-art training facility – all presented as a way to grow Guyana’s maritime industry. 

Sharma (centre) and his wife (centre-right) pose with Guyanese officials after announcing a US$35M investment in Guyana’s maritime industry, March 2021. Source: Ministry of Public Works/Facebook.

Sharma also signed a Memorandum of Understanding (MoU) with Guyana’s Maritime Ministry. But less than six months later, Guyana quietly terminated all arrangements with Sharma and his companies.

Screenshot of Guyana’s official notice terminating all relations with Sharma. Source: MARAD.

Whilst the MoU was in effect, IMSAG had served as Guyana’s official international ship registry. The domain imsag.org was used to register and flag vessels on its behalf. But after the MoU was terminated, instead of shutting the company down, IMSAG continued to operate without Guyana’s authorisation. A redacted version of the MoU is still live and being promoted on IMSAG’s website. 

Screenshot from imsag.org, January, 2026. The yellow box added by Bellingcat highlights the continued promotion of the MoU, which Guyana terminated in 2021.

In a recent interview with the Financial Times, Sharma confirmed he had set up a ship registry in Guyana, but said it had been “discontinued” after the authorities withdrew consent. He also said the domain imsag.org was “not operational just informative”.

Bellingcat recently downloaded 230 vessel certificates for 87 ships from imsag.org, including the sanctioned tanker recently seized by the Malaysian authorities, Nora

Nora is still broadcasting the call sign ‘8RKK9’ as shown in this certificate issued by IMSAG.

Counter to Sharma’s claims that IMSAG was no longer operational, all 230 certificates found by Bellingcat were issued well after the MoU was terminated in March 2021, including some as recently as December 2025. Of the 87 certified vessels 63 were oil tankers, with an average age of 24 years. Diana 1 (IMO 9212229), for example – a 26-year-old oil tanker last seen in Libya – was issued a certificate by IMSAG on June 26 2025. 

Screenshot of a certificate issued by IMSAG for Diana 1.

According to Equasis data, Diana 1 hopped to a false Guyana flag on July 1 2025. 

Screenshot of Equasis data for Diana 1 showing flag as Guyana False.

Neither Sharma nor IMSAG responded to our request for comment regarding our findings that IMSAG had continued issuing certificates as recently as December 2025, despite Guyana having terminated the MoU and withdrawn its authorisation.

For a full list of the 87 vessels, including certificates and details of our methods, click below to expand:

See full certificate list and methodology

The table below lists all 87 vessels and 230 certificates that Bellingcat found records for on imsag.org. Hover over each certificate for details, or click to see an archived screenshot. Each vessel’s flag history has been pulled from the maritime database Equasis to compare when the vessels switched to the Guyana flag and when they were issued a certificate from IMSAG.

Methods:

The IMSAG website allowed users to search using either a “Certificate Number” or an “Official Number.” The search returned information about a vessel, including the dates on which certificates were issued.  While these certificate numbers were not publicly disclosed, Bellingcat found a seafarer certificate via a Google search for “site:imsag.org filetype:pdf”, which locates PDFs hosted on IMSAG’s website. By changing the URL to look for ship certificates instead, imsag.org returned a vessel certificate for the oil tanker, Tranquilus.

Bellingcat then tested sequential variations of certificate and official numbers, returning 230 certificates issued by IMSAG. As not all certificate numbers were sequential, this index represents only a partial view of IMSAG’s recent activity.

Expanding Operations in Nicaragua

In Sharma’s interview with the Financial Times, he denied he was setting up any more registries and said he had left the maritime sector entirely. Yet Bellingcat has found evidence of a new registry with links to Sharma that appears to be offering flag registration in Nicaragua. 

In July 2025, the domain niataregister.com was launched, promoting the Nicaragua International Aquatica Transportation Administration (NIATA).

Screenshot www.niataregister.com 10 Feb, 2026.

The website is active. Bellingcat found a certificate issued as recently as February 2 for the sanctioned tanker and member of the shadow fleet, Al Jafzia (IMO 9171498, sanctioned under the name Chil 1).

According to maritime tracking data, on February 6, while sailing under a false Aruba flag, the Al Jafzia was detained by the Indian Coast Guard for an illicit ship-to-ship transfer of Iranian oil. On February 11, the vessel began broadcasting under a Nicaraguan flag, listing its home port as Corinto, Nicaragua’s largest port. The MMSI number can be seen in the certificate below.  

Screenshot of a vessel certificate issued for Al Jafzia, February, 2026.

Despite multiple requests, the Nicaraguan authorities did not respond to our questions as to whether they had heard of NIATA or had any official partnership with the company. 

According to the IMO’s GISIS database, Nicaragua has not approved any organisation to issue flags on its behalf. The IMO also confirmed directly to Bellingcat that Nicaragua had provided no further information beyond what was visible in GISIS at the time of publication.

Screenshot of IMO GISIS database, January 2026.

Bellingcat downloaded all publicly available forms from NIATA’s website. Analysing document metadata revealed the creator of the documents as ‘Oceaniek Technologies’.

Screenshots: (left) form downloaded from the NIATA website, December 2025; (right) form metadata showing author as Oceaniek Technologies.

Navigating to the Oceaniek Technologies homepage (shown below), under the headline ‘Our Products’ 11 companies were promoted in a looping carousel up until August of last year. It now features only five, spanning a wide range of industries, including a cricket league, a hospital and streaming services.

Top – Oceanik Technologies homepage. Bottom – four of the 11 companies promoted up until August of last year.  Shown left to right: IMSAG, a cricket league, streaming services, and a hospital. Screenshots captured August, 2025.

The managing director of Oceanik Technologies, according to his own LinkedIn, is Suniel Sharma. Sharma has also been photographed by local Indian media, cited as the “MD of Oceanik Technologies”.

Screenshot of Sharma’s LinkedIn profile from December 19 2025.

Also among the 11 companies promoted up until August of last year were the Nautilus Times and Nautilus Register.

Screenshots taken August, 2025.

Promoting vessel classification services, Nautilus Register, appears as an entity of interest in OpenSanctions due to its ties with several sanctioned vessels, including members of the shadow fleet. Sharma’s own LinkedIn lists him as the Director General of the Nautilus Register. 

Screenshot of Sharma’s LinkedIn profile, dated 19 Dec.

Bellingcat confirmed nautilusregister.net is still active, issuing classification certificates as recently as January 2026 (shown below). The IMO told Bellingcat that Nautilus Register is not listed as a recognised organisation in their database, GISIS.

Certificate issued January 13 2026, via nautilusregister.net. Metadata contained within the PDF listed Sharma as the author.

A search for the second company, Nautilus Times, led to a website offering dozens of training courses, from cadetship to firefighting, as well as competency training.

Competency training is a requirement for all seafarers. Crew members may attend a course in any jurisdiction, but it’s then up to the flag state (the country in which the vessel is registered) as to whether that training is recognised.

According to the Nautilus Times website, a crew member can enrol in any one of six jurisdictions, as shown below, including Guyana and Nicaragua.

Screenshot of the Nautilus Times website offering competency training fees for six jurisdictions, highlighted by a yellow box. Annotations by Bellingcat.

After contacting all six jurisdictions, the official Maritime Administration Department (MARAD) of Guyana confirmed that Nautilus Times was not authorised to issue certificates to seafarers on their behalf. They reiterated that they had no relationship with Nautilus Times or Sharma. St Maarten has previously said that it does not have an international flag registry and therefore does not issue competency certificates. No other jurisdictions replied to our request. 

Bellingcat contacted both the Nautilus Times and Sharma to ask why the site was advertising courses on behalf of Guyana and St Maarten without their authorisation. Neither replied to our request for comment.

Finally, two more companies embedded in the carousel on Oceaniek Technologies’ homepage,  but deleted after August 2025, were the MSTA Registry and Aruba Maritime.

Screenshots of two of the 11 companies promoted in a carousel embedded on Oceanik Technologies’ homepage. Captured August 2025.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

The MSTA Registry was cited in a warning issued by St Maarten and the IMO in May 2025 for issuing false flags to vessels under the guise of St. Maarten. Aruba Maritime was sanctioned by the European Union in October 2025 for fraudulently issuing oil tankers with false Aruba flags. 

Neither Oceaniek Technologies nor Sharma responded to our request for comment regarding the nature of these companies’ connection to Oceaniek Technologies. 

As sanction enforcements continue to expand, so too will the number of vessels seeking illegitimate paperwork from fraudulent registries such as IMSAG. Despite criminal charges being filed, warnings being issued, and investigations being published, Sharma’s operation continues – now seemingly having expanded into Nicaragua and with the apparent formation of a larger network, Oceaniek Technologies. 


Merel Zoet and Claire Press contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work depends on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Shipwrecks, Sham Papers and False Flags: Tracking the Company Behind It All appeared first on bellingcat.

Tracking Adversaries: EvilCorp, the RansomHub affiliate

 


Introduction

This blog is part of a cyber threat intelligence (CTI) blog series called Tracking Adversaries that investigates prominent or new threat groups.

The focus of this blog is EvilCorp, a sanctioned Russia-based cybercriminal enterprise known for launching ransomware attacks, and RansomHub, a prominent ransomware as a service (RaaS) operation run by Russian-speaking cybercriminals.

These two threat groups have been linked together through cooperation on intrusions and IOCs and TTPs shared by multiple CTI sources. The implication of this link is critical due to RansomHub being the most active ransomware gang and is working with a well-known sanctioned affiliate.

Who is RansomHub?

Active since February 2024, RansomHub is a RaaS operation formerly known as Cyclops and Knight and is run by Russian-speaking adversaries. It is currently used by more and more cybercriminals that are ex-affiliates of other RaaS operations. This includes the ALPHV/BlackCat RaaS and the LockBit RaaS, which have since shutdown or disappeared. This has made the RansomHub RaaS one of the most widespread ransomware families as of early 2025.

Due to having a high number of affiliates, the tools and TTPs observed before the final RansomHub payload is deployed can vary significantly. Each affiliate may have their own set of tools and TTPs to achieve the final objectives of data exfiltration and ransomware deployment.

Who is EvilCorp?

Evil Corp is an international cybercrime network sanctioned for orchestrating large-scale financial cyberattacks led by Maksim Yakubets. EvilCorp’s operations have evolved over time, expanding from Dridex banking trojan campaigns into developing ransomware like BitPaymer, WastedLocker, Hades, PhoenixLocker, and MacawLocker.

Notably, Aleksandr Ryzhenkov, was identified by the National Crime Agency (NCA) as a high-ranking member of EvilCorp and also LockBit affiliate. Ryzhenkov became a LockBit affiliate around 2022, contributing to over 60 LockBit ransomware builds and attempting to extort more than $100 million from victims. This discovery aligns with Mandiant’s previous reporting on EvilCorp shifting to LockBit as well.

The NCA also found that EvilCorp maintains close ties with Russian intelligence agencies through Yakubets' father-in-law, Eduard Bendersky, a former FSB officer, who is suspected of using his influence to shield the group from prosecution in Russia.

One of the TTPs that makes EvilCorp standout from the rest of the RaaS affiliates is their own affiliation to the SocGholish JavaScript malware (aka FAKEUPDATES). If ransomware deployment takes place following a SocGholish infection, then the attackers responsible for the attack will be affiliated with EvilCorp.

Reported Connections Between EvilCorp and RansomHub

On 15 July 2024, Microsoft shared a post on X stating that RansomHub was observed being deployed in post-compromise activity by Manatee Tempest (which is Microsoft’s name for EvilCorp) following initial access via SocGholish (aka FakeUpdates) infections (which Microsoft tracks as Mustard Tempest).

A screenshot of a computer

AI-generated content may be incorrect.

On 15 January 2025, Guidepoint wrote a blog on a new Python backdoor used by an affiliate of RansomHub. Notably, the new Python backdoor was delivered by SocGholish. Therefore, this Python backdoor is another potential artifact worth monitoring for its connection to known EvilCorp-related malware.

The next day, on 16 January 2025, Google shared a report on EvilCorp (which Google tracks as UNC2165) that disclosed numerous tools and malware families they have been using to deliver RansomHub, including a Python backdoor dubbed VIPERTUNNEL (see the image below). The presence of a Python backdoor following a SocGholish infection is notable TTP that overlaps with the Guidepoint blog on RansomHub.

On 14 March 2025, Trend Micro disclosed further details that also confirmed the SocGholish malware is leading to the deployment of RansomHub ransomware. The operators of SocGholish are tracked as Water Scylla by Trend Micro. The operators distribute SocGholish via the Keitaro Traffic Direction System (TDS), a legitimate service used for marketing campaigns. Trend Micro also observed SocGholish dropping the same custom Python backdoor (aka VIPERTUNNEL) as well.

So What?

EvilCorp has been under US sanctions since 2019, making it illegal for affected organisations to pay ransoms to them without facing potential fines from the US Treasury’s Office of Foreign Assets Control (OFAC). Despite these sanctions, EvilCorp has continued its cybercriminal activities by adapting its tactics to include rebranding their ransomware and becoming an affiliate of RaaS operations, such as LockBit and RansomHub. 

The key indicator of EvilCorp's involvement in ransomware attacks continues to be the use of the SocGholish malware, which employs drive-by downloads masquerading as web browser software updates to gain initial access to systems.

EvilCorp’s affiliation with RansomHub raises the possibilities that RansomHub may soon face sanctions similar to those imposed on EvilCorp. Consequently, any victim that pays a ransom to RansomHub could become significantly riskier for cyber insurance organisations, incident responders, and ransomware negotiators, as they may inadvertently violate sanctions and face legal repercussions.

Given EvilCorp's prominence as a target for international law enforcement, its association with RansomHub is likely to draw increased scrutiny. This could result in RansomHub becoming the focus of future law enforcement actions, including potential takedowns and additional sanctions, further complicating the landscape for entities involved in ransomware response and mitigation.

There is also the increased likelihood that RansomHub will now rebrand. As we saw in the BlackBasta Leaks, ransomware groups pay close attention to the news, CTI reports, and even posts on X and even blogs by researchers. This association to EvilCorp and threat of sanctions is an issue for ransomware groups as it impacts their business model and makes earning harder. Therefore, by linking the two entities together CTI analysts can impose cost on these cybercriminals.

References:

  1. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a
  2. https://www.bankinfosecurity.com/blogs/ransomhub-hits-powered-by-ex-affiliates-lockbit-blackcat-p-3703
  3. https://www.ransomware.live/group/ransomhub#ttps
  4. https://home.treasury.gov/news/press-releases/sm845
  5. https://web.archive.org/web/20200213115628/https:/www.nationalcrimeagency.gov.uk/news/international-law-enforcement-operation-exposes-the-world-s-most-harmful-cyber-crime-group
  6. https://www.crowdstrike.com/en-us/blog/hades-ransomware-successor-to-indrik-spiders-wastedlocker/
  7. https://web.archive.org/web/20241004104429/https:/www.nationalcrimeagency.gov.uk/news/further-evil-corp-cyber-criminals-exposed-one-unmasked-as-lockbit-affiliate
  8. https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/#DEV-0206-DEV-0243
  9. https://malpedia.caad.fkie.fraunhofer.de/details/js.fakeupdates
  10. https://x.com/msftsecintel/status/1812932754947911780
  11. https://www.microsoft.com/en-gb/security/security-insider/manatee-tempest
  12. https://www.guidepointsecurity.com/blog/ransomhub-affiliate-leverage-python-based-backdoor/
  13. https://services.google.com/fh/files/misc/threat_horizons_report_h1_2025.pdf
  14. https://www.trendmicro.com/en_us/research/25/c/socgholishs-intrusion-techniques-facilitate-distribution-of-rans.html
  15. https://blog.bushidotoken.net/2025/02/blackbasta-leaks-lessons-from-ascension.html


❌