On July 13, 2026, the United States, the European Union, and the United Kingdom announced one of the largest coordinated cyber enforcement actions to date, sanctioning a broad network of nation-state hackers, cybercriminals, and their enablers. The headline designation came from the EU, which named Vitaly Nikolayevich Kovalev — better known by the handle “Stern” — as the administrator of the Trickbot and Conti ransomware syndicate. Wallets tied to Stern have received more than $300 million in ransom payments, a sum that could make him the single most prolific ransomware operator ever identified Chainalysis: “Stern” Ransomware Operator Sanctioned by EU.
Who “Stern” actually is
Kovalev is a Russian national who operated under multiple aliases, the most prominent being “Stern.” According to the EU designation, he is a senior figure in the Trickbot Group, the criminal network behind some of the most destructive malware families in recent memory, including Ryuk and Conti and their many offshoots. Blockchain tracing shows Stern transacted with a long list of ransomware strains — Ryuk, Conti, Diavol, Karakurt, Royal, 3am, Quantum, and Bitpaymer — underscoring how central he was to the group’s money flow.
The $300 million figure represents only Stern’s personal cut. Trickbot’s total haul across years of campaigns is substantially larger, and the group’s attacks repeatedly hit essential services such as healthcare and banking. The so-called Conti Leaks painted Stern as a “CEO-like” figure with discretion over the syndicate’s budget, procurement, hiring, and even attack planning — not merely a peripheral admin.
The wider sweep targets the ecosystem
Stern was not the only name in the action. The US Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and cryptor provider Yevgeniy Silayev for enabling ransomware attacks. The EU simultaneously designated individuals and entities linked to the LummaC2 infostealer, the bullet-proof hosting provider Media Land LLC, Russian GRU Unit 29155, and pro-Russia hacktivist groups CARR and Z-Pentest. The institutional sanctions themselves are documented by the EU Council’s cyber-attacks sanctions framework and OFAC’s cyber-related sanctions program, which together impose asset freezes and travel bans on the designated parties EU Council cyber sanctions policy OFAC recent actions.
Stern’s designation also extends a longer campaign against Trickbot. He was first sanctioned by OFAC and the UK’s Office of Financial Sanctions Implementation (OFSI) on February 9, 2023, but the EU was the first body to attach the “Stern” moniker as an identifier. His listing follows the UK and US designations of 7 and then 11 Trickbot members in 2023, bringing the total number of sanctioned Trickbot actors to 19.
Why this matters for crypto and cybercrime
Ransomware remains one of the most damaging uses of cryptocurrency, and tracing on-chain flows is now a core part of how investigators attribute and disrupt these groups. The joint US-UK-EU action shows a maturing playbook: rather than chasing only the malware, regulators are sanctioning the administrators, the infrastructure providers, and the money-moving services that keep the business running. Asset freezes make it harder for designated operators to cash out or move funds through compliant exchanges.
For businesses, the takeaway is operational as much as geopolitical. The same blockchain-intelligence methods used in these investigations are increasingly bundled into compliance tooling that banks, exchanges, and crypto platforms use to screen wallets and freeze suspicious flows before they reach the broader ecosystem.
Bottom line: The EU’s July 2026 sanction of Vitaly Kovalev (“Stern”) puts a face and a $300 million figure on one of ransomware’s most consequential operators, and the coordinated sweep against VPNs, cryptors, infostealers, and bullet-proof hosting signals that future enforcement will target the entire support chain — not just the malware itself.
