CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Operation Saffron

incident · incident:operation-saffron-first-vpn-takedown-33-servers-27-countri

First criminal VPN anonymisation service (First VPN Service / 1VPNS) dismantled (33 servers, 27 countries); Switzerland participated in the JIT; Phobos RaaS link confirmed. Administrator Dmytro Rashevskyi and Belarusian cryptor seller Yegeniy Silayev sanctioned by US Treasury OFAC and the UK FCDO on 2026-07-13.

Aliases: First VPN Service, 1VPNS

Coverage
1
first 2026-05-22 → last 2026-05-22
Latest activity
2026-07-14
Operation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe, switzerland, us
Sources cited
6
6 hosts

Defender insights

What each entry about Operation Saffron tells a defender to do, newest first.

2026-05-22HIGHOperation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link

Story timeline

  1. 2026-05-22Operation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed
    active-threatsOperation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • StealthObfuscated Files or Information: Software Packing
  • Command and ControlProxy: External Proxy

Stealth TA0005

T1027.002Obfuscated Files or Information: Software Packing×1

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.

Evidence: 2026-05-22/operation-saffron-dismantles-first-vpn-33-servers-seized-use · ATT&CK page ↗

Command and Control TA0011

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-05-22/operation-saffron-dismantles-first-vpn-33-servers-seized-use · ATT&CK page ↗

Entries about Operation Saffron (1)

2026-05-22 · view entry permalink →

HIGHupdated

Operation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed

A coordinated international law enforcement action on 2026-05-19–20 took down First VPN, a Russian-language criminal anonymisation service established in 2014 and systematically marketed on cybercrime forums as a no-log, law-enforcement-resistant tool (Eurojust, 2026-05-21). Europol stated the service "appeared in almost every major cybercrime investigation the agency supported" (BleepingComputer, 2026-05-21). Led by French and Dutch investigators through a Eurojust joint investigation team established in November 2023, the operation seized more than 33 servers distributed across 27 countries (server-host count); 16 nations participated through Europol's Joint Cybercrime Action Taskforce; 7 nations sat on the Eurojust-led JIT, including Switzerland, France, Netherlands, Luxembourg, Romania, Ukraine, and the UK, signalling fedpol/GovCERT.ch operational involvement. Law enforcement arrested the administrator in Ukraine, captured the full user database (over 5,000 accounts) and cryptographic connection records, and generated 83 intelligence packages covering 506 users distributed to partner agencies; Help Net Security reporting confirms the captured data links to the Phobos ransomware-as-a-service operation and broader ransomware, fraud, and data theft investigations (Help Net Security, 2026-05-21). The primary domains (1vpns.com, 1vpns.net, 1vpns.org) and associated .onion mirrors were seized. Historical network flows to those domains in proxy or firewall logs now constitute potential investigative leads flowing through Europol sharing channels; Phobos affiliates have repeatedly targeted EU public-sector and healthcare organisations.

OFAC is designating two individuals and one entity enabling ransomware actors' and other cybercriminals' malign activities, notably ransomware attacks against Americans.

cryptors are built specifically to make malware stealthier and more effective by disguising it as harmless files

US Department of the Treasury (OFAC) 2026-07-13

This takedown was conducted by France's Direction Régionale de la Police Judiciaire Brigade de Lutte Contre la Cybercriminalité (BL2C), and the Dutch National Police, National High Tech Crime Unit (NHTC), with assistance from Ukraine, the United Kingdom, Switzerland, and Luxembourg.

FBI Boston Field Office 2026-06-09
Updaterun 2026-07-14T0409Z-intelevidenceregionssectorssourcestechniquesbody

The May 2026 Operation Saffron takedown of First VPN Service (1VPNS) (the Russian-language, no-log criminal anonymisation service in which Switzerland sat on the Eurojust joint investigation team) has now drawn coordinated sanctions. On 2026-07-13 the US Treasury's Office of Foreign Assets Control, in an action coordinated with the UK's Foreign, Commonwealth & Development Office, designated 1VPNS and its administrator Dmytro Rashevskyi (who used false identities including "Maksim Sorin" and "Roman Chabanenko" to buy infrastructure from providers that would otherwise have refused him), and separately a Belarusian national, Yegeniy Silayev, who sells "cryptors" (US Treasury, 2026-07-13). Treasury frames cryptors as tools "built specifically to make malware stealthier and more effective by disguising it as harmless files" (US Treasury, 2026-07-13), designating the obfuscation-service vendor as a distinct enabling layer beneath the ransomware payload and the affiliate, not just the anonymisation infrastructure. The designations were made under Executive Order 13694 as amended; the FBI confirms the underlying takedown was led by France's BL2C and the Dutch NHTC "with assistance from Ukraine, the United Kingdom, Switzerland, and Luxembourg," and that at least 25 ransomware groups, including Avaddon, used the service for reconnaissance and intrusions (FBI Boston, 2026-06-09).

Treasury describes the concrete abuse pattern: ransomware groups purchased 1VPNS infrastructure and used it "to hide the origins of their attacks, deploy malware, and manage exfiltrated data", an external commercial VPN used as an anonymising relay in front of the operators' own reconnaissance, delivery and exfiltration traffic (US Treasury, 2026-07-13).

threat22 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • bleepingcomputer.com1 (17%)
  • eurojust.europa.eu1 (17%)
  • fbi.gov1 (17%)
  • helpnetsecurity.com1 (17%)
  • home.treasury.gov1 (17%)
  • ofac.treasury.gov1 (17%)