The EU Council has sanctioned nine individuals and four entities from the Russian cyber ecosystem, accused of conducting, permitting, or facilitating attacks against the European Union, member states, and international partners. Among those targeted are infrastructure providers for malware, pro-Russian hacktivist groups, individuals involved in programs such as LummaC2, Trickbot, and Conti, and actors linked to the GRU.
The European Union has sanctioned nine individuals and four entities from the Russian cyber ecosystem, accused of attacking, supporting, or facilitating cyber operations against the EU, member states, and international partners. The measures target infrastructure providers for malware attacks, pro-Russian hacktivist groups, individuals involved in the development and sale of software used for data theft, and actors linked to Russia's military intelligence services.
In short
1. The EU Council has sanctioned nine individuals and four entities from the Russian cyber ecosystem. They are accused of conducting, permitting, or facilitating cyber attacks against the EU, member states, and international partners.
2. Among the sanctioned entities is Media Land LLC, a provider of "bulletproof hosting" accused of facilitating malware, ransomware, and phishing attacks on a large scale. The attacks targeted critical infrastructure and essential services in EU member states and caused significant financial losses.
3. The EU also sanctions Z-Pentest, a pro-Russian hacktivist group that targeted critical infrastructure, especially in energy and water. The Council mentions an attack on a water company in Denmark in December 2024.
4. The measures include individuals involved in malware programs such as LummaC2, Trickbot, and Conti, used for information theft, cyber attacks, and criminal operations. The EU coordinated this round of sanctions with the United Kingdom, marking the first time that both parties simultaneously adopted sanctions through their respective cyber regimes.
5. The listed individuals and entities have their assets frozen, and EU citizens and companies are prohibited from making funds or economic resources available to them. Sanctioned individuals also face entry or transit bans on EU territory.
The sanctions demonstrate that the EU treats Russian cyber attacks as part of a broader destabilization campaign, not as isolated technical incidents. The Council states that the targeted individuals and entities form part of the Russian cyber ecosystem responsible for attacks against institutions, infrastructure, and services in the EU, Ukraine, and other partner countries.
One of the targeted entities is Media Land LLC, described by the Council as a provider of "bulletproof hosting." This type of service offers online infrastructure resistant to blocking or intervention by authorities and can allow for the hosting or distribution of malware, phishing pages, command and control servers, and other tools used in cyber attacks.
The Council states that Media Land LLC facilitated a wide range of malware attacks against EU member states and globally, generating significant financial losses. Its infrastructure would have allowed cybercriminals to conduct ransomware and phishing operations on a large scale, including against critical infrastructure and essential services in member states. The company's owner, Alexander Volosovik, is also sanctioned. The EU also lists ML.Cloud, a sister company of Media Land LLC.
Another entity is Z-Pentest, a pro-Russian hacktivist group that has targeted critical infrastructure globally, especially in the energy and water sectors. The Council mentions a cyber attack on a water company in Denmark in December 2024.
The sanctions also include Yuliya Vladimirovna Pankratova, the group's leader, and Denis Olegovich Degtyarenko, a lead hacker. Both are associated with the group Cyber Army of Russia Reborn, CARR, described as a Russian hacktivist group that has conducted sustained DDoS attack campaigns against countries supporting Ukraine since 2022.
CARR is accused of attacks against government agencies, financial institutions, media institutions, and critical infrastructure in EU member states, Ukraine, and other countries. The Council states that the group is linked to the Russian military intelligence agency, GRU.
The list also includes LLC Impuls and its owner, Evgeniy Viktorovich Bashev, a member of GRU Unit 29155. The Council states that they provided technical and material support for cyber attacks and attempted cyber attacks conducted by Unit 29155 against the EU and member states.
Unit 29155 is associated in the Council's document with other destabilizing activities. Ivan Kasyanenko, deputy commander of the GRU Special Operations Service, is sanctioned separately. The Council describes him as the organizer and main overseer of activities of Unit 29155, including operations related to Afghanistan, the Novichok attacks in 2018 against Sergei Skripal and his daughter, coordination of Russian covert activities in Europe, integration of Wagner networks in Africa, and military-technical cooperation with Iran.
The EU also targets individuals involved in malware programs used by cybercrime. Maksim Evgeniyevich Voronin and Maksim Alexsandrovich Gordienko are listed for their involvement in the development, distribution, and sale of LummaC2, malware used for information theft. Vitaly Nikolayevich Kovalev is sanctioned for participating in the development of Trickbot and Conti programs.
Trickbot and Conti are names associated with high-impact cyber operations, including attacks on public and private organizations. By including individuals involved in such tools, the EU aims to strike not only at direct attackers but also at the development, distribution, and monetization networks that enable cyber operations.
This round of sanctions was coordinated with the United Kingdom. The Council emphasizes that this is the first time the EU and the UK have simultaneously adopted sanctions through their respective cyber regimes, indicating closer coordination against Russian cyber activities.
Those listed are subject to asset freezes. Individuals and companies in the EU are not allowed to make funds or economic resources available to them. Sanctioned individuals also face entry or transit bans on the territory of the Union.
The EU uses two legal frameworks for these measures. The first is the sanctions regime against cyber attacks threatening the Union or member states, created after the activation of the "cyber diplomacy toolbox." The second is the regime regarding Russia's destabilizing actions, created in October 2024 to target individuals and entities involved in activities that undermine the fundamental values, security, stability, independence, and integrity of the EU and its member states.
For member states, the sanctions have a direct stake: critical infrastructure, essential services, public institutions, media, and the financial sector are recurring targets of Russian cyber campaigns. Through these measures, the EU seeks to increase the cost for networks that provide infrastructure, programs, expertise, and operational cover for attacks.
The EU Council adopted the sanctions on July 13, 2026. The measures target cyber attacks and destabilizing activities related to Russia and were published in the Official Journal of the European Union.
Latest News
23:08
22:19
21:39
21:28
20:59
See more news