"Stern" Sanctioned: What the Trickbot Enforcement Action Means for Crypto Accounting and AML Compliance
On 13 July 2026, the United States Office of Foreign Assets Control (OFAC), the UK Office of Financial Sanctions Implementation (OFSI), and the European Union announced one of the largest coordinated cyber-sanctions actions on record. The primary target: Vitaly Nikolayevich Kovalev, alias "Stern," identified as the administrator of the Trickbot criminal syndicate and widely described as potentially the single most prolific ransomware operator ever designated. For accounting firms, auditors, and CFOs running crypto accounting software or managing crypto-exposed client portfolios, the implications are immediate and practical.
Who Was Designated and Why It Matters
The action is notable both for its breadth and for its layered, cross-jurisdictional coordination. Understanding the specific designations is the first step toward understanding the compliance obligations that flow from them.
Vitaly Kovalev, alias "Stern"
Kovalev is a Russian national and senior figure within the Trickbot group, the criminal syndicate behind Ryuk, Conti, Diavol, Karakurt, Royal, 3AM, Quantum, and Bitpaymer ransomware strains. He was first designated by OFAC and OFSI in February 2023, but the EU's July 2026 action is the first time any sanctioning authority formally included "Stern" as an alias in the designation, providing a critical link for blockchain analysts and compliance teams.
Wallets associated with Kovalev have received more than $300 million in ransom payments. Crucially, that figure represents only his personal share of Trickbot proceeds, not the syndicate's total haul, which is substantially larger. Blockchain analysis of Kovalev's on-chain activity shows he transacted with multiple ransomware strains simultaneously and also directed payments to team members for infrastructure upkeep, vendor services, and operational procurement. Leaked internal Conti communications, widely known as the "Conti Leaks," confirm that Stern functioned as a CEO-level figure: controlling the syndicate's budget, overseeing hiring, and approving attack planning.
OFAC Designations: 1VPNS, Rashevskyi, and Silayev
In a parallel action, OFAC designated First VPN Service (1VPNS), a VPN provider whose principal client base includes ransomware actors. Its administrator, Dmytro Rashevskyi, and a cryptor provider, Yevgeniy Vladimirovich Silayev, were designated alongside the service. OFAC published cryptocurrency wallet addresses linked to both 1VPNS and Rashevskyi spanning eight blockchains: Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. The designation followed a takedown of 1VPNS's website and infrastructure by European law enforcement, with support from the FBI's Boston Field Office.
EU Designations: LummaC2, Media Land LLC, GRU Unit 29155, and Hacktivist Groups
The EU's action extended beyond Kovalev to cover a wider ecosystem of ransomware enablers. LummaC2 infostealer developers Maksim Voronin and Maksim Gordienko were designated. Their Malware-as-a-Service platform was among the most widely deployed infostealer tools globally in 2024 and 2025, capable of harvesting browser credentials, crypto wallet data, and system information. LummaC2 had already been disrupted in a coordinated effort by the US Department of Justice, Europol's European Cybercrime Centre, and Japan's Cybercrime Control Center beginning in May 2025.
Media Land LLC, a Russian bullet-proof hosting provider, was also designated. Operating since 2016, it has provided infrastructure to LockBit, EvilCorp, and BlackBasta ransomware groups by offering hosting services specifically designed to resist law enforcement takedowns. Its owner, Alexander Volosovik, was named individually. Media Land had already appeared on OFAC's list in November 2025.
Russian state-linked actors also feature in the EU designations, including members of GRU Unit 29155. Evgeniy Bashev, identified as a GRU Unit 29155 member, is specifically named for facilitating infrastructure payments and coordinating collaboration between GRU and external hacker networks. Bashev's activities include supporting the WhisperGate malware campaign targeting Ukrainian critical infrastructure, which included an extortion demand issued in cryptocurrency. The Cyber Army of Russia Reborn (CARR), previously designated by OFAC in 2024, and Z-Pentest, a pro-Russia hacktivist group linked to CARR that targeted critical infrastructure in the energy and water sectors including a Danish water utility in December 2024, also received EU designations.
Sanctions Screening Obligations: What Firms Must Do Now
Every new OFAC, OFSI, or EU designation creates an immediate obligation to screen client activity and on-chain transaction history against the updated lists. The multi-chain nature of the 1VPNS-related designations, covering eight different blockchains, raises the screening burden well above what a single-chain check would require.
Immediate Steps for Accounting Firms and Auditors
Firms providing crypto accounting or bookkeeping services should treat 14 July 2026 as the effective date for updating their sanctions watchlists. The following actions are time-sensitive.
First, load the newly published wallet addresses from the OFAC Specially Designated Nationals (SDN) list and the EU's consolidated sanctions list into your transaction monitoring or digital asset accounting software. The OFAC listing for 1VPNS and Rashevskyi includes addresses across Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana, so any firm whose clients transact on those chains must run a retrospective screen.
Second, review any clients operating in industries historically targeted by Trickbot-affiliated ransomware strains: healthcare, financial services, and critical infrastructure. Where those clients have made or received cryptocurrency payments, consider whether any counterparty addresses require additional due diligence under existing AML policies.
Third, document your firm's screening response. Regulators in all three jurisdictions expect a demonstrable, timely compliance process. A dated log showing when designations were ingested and which client accounts were screened will be material if a regulatory inquiry arises.
CFO-Level Considerations
CFOs at companies holding cryptocurrency on the balance sheet, or managing treasury operations that include digital assets, face two distinct risks from this action. The first is direct exposure: any counterparty wallet that has transacted with a designated address can trigger secondary screening obligations. The second is reputational: auditors are increasingly asking for evidence of sanctions-screening controls as part of crypto asset disclosures, and the absence of documented procedures will attract scrutiny.
CFOs should also note the breadth of the LummaC2 designation. The malware was designed specifically to harvest crypto wallet credentials and private key data. Any organisation that suffered a LummaC2 infection in 2024 or 2025, whether it knew it at the time or not, should assess whether compromised wallet access has created an unrecognised liability or a chain of title issue over digital assets still on the balance sheet.
AML and Accounting Implications of the Enforcement Pattern
This action illustrates a deliberate shift in how enforcement authorities approach ransomware. Rather than targeting operators alone, the designations now systematically reach the enabling layer: VPN providers, cryptor developers, bullet-proof hosting companies, and malware-as-a-service platforms. From an AML risk-assessment perspective, this means the population of entities that can create indirect sanctions exposure for a legitimate business is growing.
Implications for Crypto Bookkeeping and Audit
For firms using crypto bookkeeping software to reconcile client transactions, the multi-chain wallet disclosures in this action present a practical challenge. Addresses across eight different networks are now live on the SDN list. Any reconciliation tool that does not ingest OFAC data in near-real time, or that lacks multi-chain address screening, creates a gap that could leave a firm unable to demonstrate adequate controls.
From a financial statements perspective, if a client's digital asset holdings are traced to a sanctioned counterparty, the assets may need to be reclassified. Under both US GAAP (ASC 350-60, the FASB fair-value model for crypto assets) and IFRS (IAS 38 or IAS 32 depending on classification), an asset subject to a legal freeze or seizure risk is not straightforwardly measurable at fair value. Auditors should flag this scenario in their risk assessment procedures for any client with material crypto holdings.
The ransomware payments received by Kovalev, which exceeded $300 million to his wallets alone, also raise a practical question for any firm whose client may have paid a ransom in cryptocurrency: OFAC's guidance on ransomware payments makes clear that paying a designated entity, even unknowingly, can constitute a sanctions violation. Firms advising clients who experienced ransomware incidents should revisit those engagements in light of the confirmed identity of Stern as Kovalev, now formally named across all three major sanctions regimes.
Understanding how the MiCA transitional period affects CASP compliance obligations is increasingly relevant here, as EU-regulated crypto asset service providers must now integrate these designations into their transaction monitoring frameworks under both MiCA and the EU AML Directive. Similarly, the pattern of cross-jurisdictional crypto sanctions is consistent with the enforcement trajectory we covered when examining US Treasury sanctions on Bitcoin payments for Hormuz passage and what firms must do: OFAC is expanding the range of on-chain activities it treats as SDN-adjacent, and firms need screening infrastructure that keeps pace.
The Strategic Signal: Enablers Are Now Primary Targets
The inclusion of 1VPNS, Media Land LLC, and LummaC2 developers alongside the Trickbot operator himself sends a clear message to compliance professionals. Sanctions authorities are no longer content to designate only the individuals who receive ransom payments. They are systematically mapping and designating the commercial infrastructure that makes large-scale ransomware operations viable: the VPNs, the hosting providers, the obfuscation tools, and the malware distribution platforms.
For accounting firms and CFOs, this means the perimeter of sanctions risk in a crypto-exposed client base is wider than the client's own wallet addresses. Any vendor, counterparty, or payment processor in the client's ecosystem that intersects with these designated entities creates a potential exposure. Risk assessments that were adequate six months ago may need to be updated now that the enabling layer of the ransomware economy has formal SDN status across all three major Western sanctions regimes.
Frequently Asked Questions
Does the EU designation of "Stern" change anything if OFAC already designated Kovalev in 2023?
Yes. The EU designation formally introduces the alias "Stern" as an identifier linked to Kovalev for the first time across any sanctions regime. This matters for screening systems that match on aliases as well as legal names: firms operating under EU jurisdiction now have an explicit obligation to screen for this alias, and blockchain analysts can use the EU's on-chain address data to enrich their existing monitoring.
Which blockchains are covered by the 1VPNS-related OFAC wallet designations?
OFAC published addresses across eight networks: Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. Firms whose clients transact on any of these chains should run an immediate retrospective screen against the newly published addresses.
If a client paid a ransom in crypto before Kovalev was identified as Stern, is there still a sanctions risk?
Potentially. OFAC's enforcement posture on ransomware payments has consistently held that paying a designated entity, even without knowledge of their designated status, can constitute a violation. The formal identification of Kovalev as Stern means firms advising on historical ransomware incidents should reassess those cases. Legal counsel with OFAC expertise should be involved in any such review.
How should auditors treat crypto assets that may have passed through a sanctioned address?
Where an auditor identifies that a client's digital asset holdings are linked, even indirectly, to a sanctioned counterparty, those assets may carry a legal freeze or seizure risk. That risk affects fair-value measurement under ASC 350-60 and IFRS frameworks. Auditors should document the assessment, consider whether disclosure is required, and evaluate whether the asset should be reclassified pending legal clarification.
Does this action create new obligations for EU-regulated CASPs under MiCA?
MiCA does not itself create sanctions obligations, but CASPs authorised under MiCA are subject to the EU AML Directive and the EU Funds Transfer Regulation, both of which require screening against the EU consolidated sanctions list. The new designations must be ingested into transaction monitoring systems promptly. CASPs that cannot demonstrate timely integration of updated sanctions lists face supervisory risk during MiCA compliance reviews. See our coverage of how the MiCA transitional period affects CASP compliance obligations for the broader framework.
Source: Chainalysis
