The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned Aeza Group for supporting cybercriminal activity.
According to the OFAC, Aeza Group was designated a bulletproof hosting (BPH) service provider for its role in supporting criminals who target victims around the world. BPH service providers sell access to specialized servers and other computer infrastructures that are designed to help cybercriminals evade detection and resist law enforcement’s attempts to disrupt their activities. OFAC also designated two affiliated companies and four Aeza Group leaders as part of the BPH, and designating an Aeza Group front company in the United Kingdom.
“Cybercriminals continue to rely heavily on BPH service providers like Aeza Group to facilitate disruptive ransomware attacks, steal U.S. technology, and sell black-market drugs,” Acting Under Secretary of the Treasury for Terrorism and Financial Intelligence Bradley T. Smith said. “Treasury, in close coordination with the UK and our other international partners, remains resolved to expose the critical nodes, infrastructure, and individuals that underpin this criminal ecosystem.”
Aeza Group is headquartered in St. Petersburg, Russia and is suspected of providing services to ransomware and malware groups that have targeted the U.S. defense industrial base and technologies, among other victims. The company is also accused of hosting BianLian ransomware, RedLine infostealer panels, and BlackSprut, a Russian darknet marketplace for illicit drugs.
OFAC said Aeza Group is responsible or complicit in, or has engaged in directly or indirectly, cyber-enabled activities that are reasonably likely to result in a threat to the national security, economic health or financial stability of the United States. The actions resulted in sanctions including blocking the assets of the company and its named individual leaders.