The U.S. Treasury imposed sweeping sanctions on Russia over malicious cyber activity, including measures against six Russian technology-sector entities accused of supporting the FSB, GRU, and SVR. Treasury said the action responded to a broader pattern of Russian operations, citing the SolarWinds compromise, NotPetya, Olympic Destroyer, election interference, attacks on Ukraine and Georgia, and support for criminal groups such as Evil Corp. The sanctions block property and interests in property of designated entities under U.S. jurisdiction and broadly prohibit U.S. persons from transacting with those parties, alongside new restrictions on certain Russian sovereign debt activity.
Separate reporting highlighted questionable security practices in the FSB’s own online communications system, which required visitors to download a Windows executable to submit encrypted messages. Researchers found the per-download program was flagged by about 20 antivirus engines and exhibited behaviors such as self-deletion, log erasure, dynamic builds, and use of GOST cryptography, though independent analysis said it did not appear to be outright malware. KrebsOnSecurity also found the FSB site relied on HTTP rather than HTTPS, and testing showed the tool contacted an IP address assigned to the FSB before enabling access to a contact form, underscoring operational concerns around Russian state security technology.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
On April 15, 2021, the U.S. Department of the Treasury announced sanctions under a new Executive Order targeting harmful activities by the Russian government, including malicious cyber operations. Treasury said the FSB cultivates and co-opts criminal hackers such as Evil Corp to enable ransomware attacks and phishing campaigns.
The FSB recently launched a Tor-accessible website that allows users to make contact without downloading the disputed Windows executable. This provided an alternative to the software-based secure contact workflow described in the reporting.
KrebsOnSecurity installed the FSB software in an isolated environment and observed it connecting to an IP address assigned to the FSB before enabling access to a secure contact form. Krebs then used the form to ask the FSB about the antivirus detections but received no reply.
Lance James of Unit221B analyzed the FSB software and concluded it did not appear to exhibit outright trojan behavior, though it used one-time executables, self-deletion, GOST cryptography, and log-erasing routines that could resemble ransomware-like behavior to antivirus engines. He also created a benign GOST-based test program that was flagged by multiple antivirus products, supporting the possibility of false positives.
Vladislav "BadB" Horohorin published a blog post warning that the FSB's required "random number generation" client for secure website communications was flagged as malicious by about 20 antivirus and security products. His post prompted further scrutiny of the software's behavior and detections on VirusTotal.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcehome.treasury.gov
Open sourcehome.treasury.gov
Open sourcewashingtonpost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.