The European Union has imposed sanctions on Russian national Vitaly Nikolayevich Kovalev, identifying him by name as the operator known as “Stern” and linking him to the Trickbot ransomware network and its Conti offshoot. The move was coordinated with the United States and the United Kingdom and forms part of a broader action against cybercrime actors and the online services that support them.

Leadership role in Trickbot

According to the sanctions action described in the source report, Kovalev acted as a CEO-like figure inside Trickbot. He allegedly oversaw budgeting, recruitment and attack planning for an operation said to involve more than 100 members. The group reportedly maintained offices and paid salaries in Bitcoin, indicating a structured organization rather than a loose criminal collective.

The EU’s step is notable because it explicitly connects Kovalev with the “Stern” alias in a sanctions listing. That attribution ties a real-world identity to a handle long associated with major ransomware activity.

Scale of the alleged operation

The group was described as targeting hospitals, banks and more than 1,000 organizations worldwide. Named victims in the source material included Ireland’s Health Service Executive and jeweler Graff, alongside numerous other healthcare and financial institutions.

The source article said the syndicate collected an estimated $180 million in 2021 alone. It also reported that Kovalev’s wallets moved funds associated with several ransomware strains beyond Trickbot and Conti, including Ryuk, Diavol, Karakurt, Royal, Quantum and Bitpaymer. His personal share was said to exceed $300 million.

Crypto wallets published

Following the sanctions, authorities published on-chain wallet addresses linked to Kovalev. The purpose, according to the report, is to make it more difficult for him to move funds through crypto exchanges and other financial services.

That step adds a practical enforcement layer to the designation. Rather than only naming an individual, it gives exchanges and service providers specific blockchain identifiers they can monitor or block under applicable sanctions controls.

Wider cybercrime crackdown

The action was not limited to Kovalev. The sanctions also targeted First VPN Service, or 1VPNS, and its administrator Dmytro Rashevskyi, who were accused of helping criminals conceal internet traffic and locations. In addition, the report said the EU moved against LummaC2 infostealer developers Maksim Voronin and Maksim Gordienko, as well as other entities linked to cybercrime networks.

The coordinated nature of the measures reflects an effort to go beyond ransomware operators themselves and reach the infrastructure and service providers that allegedly help such groups function.

Kovalev is believed to be in Russia, according to the source article, which noted that Russia does not extradite its own nationals. That means the sanctions may be more significant as a tool for financial isolation and attribution than as a direct route to arrest. By naming Kovalev as “Stern” and publishing wallet data, the EU, alongside the US and UK, has taken a more detailed public step against one of the figures accused of leading a large ransomware enterprise.

Source: Cryptopolitan