Recent Posts

Russian Cyber-Attacks and Destabilising Activities: Council Sanctions Nine Individuals and Four Entities

Brussels: The Council today decided to impose restrictive measures on nine Russian individuals and four entities forming part of Russia's cyber ecosystem, responsible for and involved in carrying out, enabling, and facilitating cyber-attacks against the EU, its member states, and international partners.

According to European Union, the sanctions target Media Land LLC, a Bullet Proof Hosting service provider, and its owner Alexander Volosovik, which have been linked to facilitating extensive malware attacks globally. These cyber activities include large-scale ransomware and phishing operations, significantly impacting critical infrastructure and essential services within EU member states. The Council also sanctioned ML.Cloud, Media Land LLC's sister company, for its involvement in similar activities.

Z-Pentest, a pro-Russia hacktivist group known for targeting critical infrastructure sectors like energy and water, is also under sanctions. The group conducted a cyber-attack on a Danish water utility in December 2024. Sanctions were extended to the group's leader, Yuliya Vladimirovna Pankratova, and a primary hacker, Denis Olegovich Degtyarenko, both linked to the Russian hacktivist group CARR (Cyber Army of Russia Reborn). CARR has executed numerous DDoS attacks on countries supporting Ukraine, targeting government agencies, financial institutions, media outlets, and critical infrastructure. LLC Impuls and its owner, Evgeniy Viktorovich Bashev, associated with the Russian Military Intelligence Agency GRU Unit 29155, are also sanctioned for supporting cyber-attacks against the EU and its member states.

Additionally, sanctions include individuals Maksim Evgeniyevich Voronin, Maksim Alexsandrovich Gordienko, and Vitaly Nikolayevich Kovalev. Voronin and Gordienko are connected to the LummaC2 malware, while Kovalev has been involved in developing malware programs Trickbot and Conti. These sanctions are coordinated with the United Kingdom, marking a first-time simultaneous action under EU and UK cyber sanctions regimes, highlighting a joint effort to counter Russian cyber threats.

In terms of destabilising activities, the Council has imposed measures on Ivan Kasyanenko, deputy commander of the GRU's Special Operations Service (SSD), for organizing and supervising Unit 29155's operations linked to Afghanistan and the 2018 Novichok poisonings. He is also connected to Russian covert operations in Europe, Wagner Group networks in Africa, and military cooperation with Iran. Unit 29155 is implicated in cyber-attacks against EU member states and partners, including Ukraine.

The individuals and entities listed are subject to an asset freeze, and EU citizens and companies are prohibited from providing them with funds or economic resources. Additionally, the sanctioned individuals face travel bans preventing entry or transit through EU territories.