See Full Document Text
Official Journal EN
of the European Union L series
2026/1713 13.7.2026
COUNCIL DECISION (CFSP) 2026/1713
of 13 July 2026
amending Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks
threatening the Union or its Member States
THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on European Union and in particular Article 29 thereof,
Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy,
Whereas:
(1) On 17 May 2019 the Council adopted Decision (CFSP) 2019/797(1).
(2) As part of the sustained, tailored and coordinated Union action against persistent cyber threat actors, eight natural
persons and four entities should be added to the list of natural and legal persons, entities and bodies subject to
restrictive measures set out in the Annex to Decision (CFSP) 2019/797. Those persons and entities are responsible
for, supporting, or involved in, cyber-attacks with a significant effect which constitute an external threat to the Union
or its Member States.
(3) Decision (CFSP) 2019/797 should therefore be amended accordingly,
HAS ADOPTED THIS DECISION:
Article 1
The Annex to Decision (CFSP) 2019/797 is amended in accordance with the Annex to this Decision.
Article 2
This Decision shall enter into force on the date of its publication in the Official Journal of the European Union.
Done at Brussels, 13 July 2026.
For the Council
The President
K. KALLAS
(1) Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or
its Member States (OJ L 129 I, 17.5.2019, p. 13, ELI: http://data.europa.eu/eli/dec/2019/797/oj).
ELI: http://data.europa.eu/eli/dec/2026/1713/oj 1/13ANNEX
The Annex to Decision (CFSP) 2019/797 is amended as follows:
(1) the following entries are added under the heading ‘A. Natural persons’:
Name Identifying information Reasons Date of listing
‘20. Vitaly Nikolayevich KOVALEV Виталий Николаевич КОВАЛЕВ Vitaly Kovalev is a senior figure in the malware programs “Trickbot” and “Conti”. 13.7.2026
He is also known by the online monikers “Bentley”, “Bergen”, “Alex Konor”,
Aliases: “Bentley”, “Bergen”, “Alex Konor”,
“Benny”, “Ben” and “Stern”.
“Benny”, “Ben”, “Stern”
Conti and Trickbot were originally created and developed by Wizard Spider.
DOB: 23.6.1988
Wizard Spider has conducted ransomware campaigns in a variety of sectors,
Address: Serebristy Bulvar 34 (Serebristyy including essential services such as health and banking, has infected computers
Bul’var); krp 1; flt 528; 197341; St Petersburg, worldwide and their malware has been developed into a highly modular malware
Russian Federation suite. Campaigns by Wizard Spider, using malware such as Conti, and TrickBot,
are responsible for substantial economic damage in the European Union.
Nationality: Russian
Vitaly Kovalev is therefore responsible for, and involved in, cyber-attacks with
Gender: male a significant effect which constitute an external threat to the Union or
its Member States.
Associated entities: TrickBot, Wizard Spider,
Conti
2/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
21. Alexander Alexandrovich Александр Александрович ВОЛОСОВИК Alexander Volosovik is the owner of Media Land LLC. Since 2016, Bullet Proof 13.7.2026
VOLOSOVIK Hosting service Media Land LLC has been facilitating a wide array of malware
DOB: 30.1.1983
attacks against both the Union and globally, by offering hosting services that hide
POB: USSR user identities and resist takedowns by law enforcement. Media Land LLC enabled
large-scale ransomware operations, command-and-control services, and phishing
Nationality: Russian operations that target critical infrastructure and essential services in the Member
States, leading to significant financial losses. Operations facilitated by Media Land
Passport number: 762988138
LLC include, inter alia, LockBit, EvilCorp and BlackBasta.
Gender: male
Therefore, Media Land LLC is involved in cyber-attacks with significant effect
Associated entities: Yalishanda, LARVA-34, which constitute an external threat to the Union or its Member States. As owner
podzemniyl, Ohyeahhellno, Stas_vl, downlow of Media Land LLC, Alexander Volosovik is responsible for, and involved in, these
cyber-attacks. He is also associated to Media Land LLC.
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
3/13
OJ
L,
13.7.2026
ENName Identifying information Reasons Date of listing
22. Denis Olegovich Денис Олегович ДЕГТЯРЕНКО Denis Degtyarenko aka Dena is a Russian hacker for CARR (Cyber Army of Russia 13.7.2026
DEGTYARENKO Reborn).
Alias: “Dena”
CARR has been responsible for cyber-attacks against services necessary for the
DOB: 9.10.1989
maintenance of essential economic activities and critical state functions in the
POB: USSR Member States, as well as against infrastructure in Ukraine and other third
countries. CARR is linked to the Main Centre for Special Technologies (GTsST)
Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the
Russian Federation (GRU).
Gender: male
The GTsST remains active in carrying out cyber-attacks against the Union or its
Address: 130 Lenina Avenue, Novy Gorod
Member States. CARR’s targets include government agencies, financial
microdistrict, Orsk, Orenburg Region, Russian
institutions, media outlets, and critical infrastructure in the Member States and the
Federation
United States. CARR has conducted distributed denial-of-service (DDoS) attacks in
Ukraine and against governments and companies located in countries that have
supported Ukraine.
Therefore, Denis Degtyarenko, a primary hacker for CARR, is involved in
cyber-attacks with a significant effect, including attempted cyber-attacks with
a potentially significant effect, which constitute an external threat to the
Member States, as well as against third states. As a member of CARR, he is also
associated to GTsST.
4/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
23. Yuliya Vladimirovna Юлия Владимировна ПАНКРАТОВА Yuliya Pankratova is a Russian hacker who has been working for CARR (Cyber 13.7.2026
PANKRATOVA Army of Russia Reborn) and has founded, and continues to work for Z-Pentest.
Alias: “YUliYA”
CARR has been responsible for cyber attacks against services necessary for the
DOB: 6.4.1984
maintenance of essential economic activities and critical state functions in the
POB: USSR Member States, as well as against infrastructure in Ukraine and other third
countries. CARR is linked to the Main Centre for Special Technologies (GTsST)
Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the
Russian Federation (GRU). The GTsST remains active in carrying out cyber-attacks
Gender: female
against the Union or its Member States. CARR’s targets include government
Address: 130 Lenina Avenue, Novy Gorod agencies, financial institutions, media outlets, and critical infrastructure in
microdistrict, Orsk, Orenburg Region, Russian Member States and the United States. CARR has conducted distributed
Federation denial-of-service (DDoS) attacks in Ukraine and against governments and
companies located in countries that have supported Ukraine.
Z-Pentest is responsible for cyber-attacks with a significant effect against inter alia
services necessary for the maintenance of essential activities in the Member States.
Therefore, Yuliya Pankratova, a primary hacker for CARR and for Z-Pentest, is
involved in cyber-attacks with a significant effect, including attempted
cyber-attacks with a potentially significant effect, which constitute an external
threat to the Member States, as well as against third states. She is also associated to
Z-Pentest.
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
5/13
OJ
L,
13.7.2026
ENName Identifying information Reasons Date of listing
24. Maksim Evgenevich VORONIN Максим Евгеньевич ВОРОНИН Maksim Voronin aka Daugn0 is involved in the development, distribution and 13.7.2026
selling of the information stealing malware LummaC2 (aka Lumma Infostealer,
Alias: “Daugn0”
Lumma Stealer).
Nationality: allegedly Russian
LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data,
Gender: male browser credentials, crypto wallets, or system info, to deploy additional malware
on infected devices, for cryptocurrency theft and for espionage campaigns.
Cyberattacks involving LummaC2 malware are used also by financially motivated
cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and
others. LummaC2 malware has been used for cyber-attacks against critical state
functions and services necessary for the maintenance of essential social and
economic activities of the Members States. In 2024 and 2025, LummaC2 was one
of the most used tools for stealing information worldwide.
Therefore, Maksim Voronin as developer, distributor and seller of LummaC2 is
involved in and facilitates cyberattacks with a significant effect, which constitute
an external threat to the Member States.
6/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
25. Maksim Aleksandrovich Максим Александрович ГОРДИЕНКО Maksim Gordienko aka Lummaseller is involved in the development and 13.7.2026
GORDIENKO distribution of the information stealing malware LummaC2 (aka Lumma
Alias: “Lummaseller”
Infostealer, Lumma Stealer).
a.k.a. Maxim Alexandrovich
Nationality: allegedly Russian
GORDIENKO LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data,
Gender: male browser credentials, crypto wallets or system info, to deploy additional malware
on infected devices, for cryptocurrency theft and for espionage campaigns.
Cyberattacks involving LummaC2 malware are used also by financially motivated
cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and
others. LummaC2 malware has been used for cyber-attacks against critical state
functions and services necessary for the maintenance of essential social and
economic activities of the Member States. In 2024 and 2025 LummaC2 was one
of the most used tools for stealing information worldwide.
Therefore, Maksim Gordienko as developer, distributor and seller of LummaC2 is
involved in and facilitates cyberattacks with a significant effect, which constitute
an external threat to the Member States.
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
7/13
OJ
L,
13.7.2026
ENName Identifying information Reasons Date of listing
26. Evgeniy Viktorovich BASHEV Евгений Викторович БАШЕВ Evgeniy Bashev is a member of Russian Military Intelligence Agency GRU, Unit 13.7.2026
29155. Within the unit he supports and facilitates cyber-attacks with a significant
DOB: 25.1.1980
effect against the Member States, inter alia via controlling the server “Aegon”, used
POB: USSR for hacking operations. In particular, he provides technical and material support
to the cyber-attacks of the GRU Unit 29155 through his company “Impuls” LLC,
Nationality: Russian which facilitated operational cover, infrastructure, and payments, and managed
technical assets, including servers, that are used for the cyber-attacks. He also
Gender: male
coordinated cooperation between GRU structures and external hacker networks.
Associated individuals: Denis Igorevich The cyber-attacks he facilitated targeted critical state functions systems and
Denisenko, Yuriy Fedorovich Denisov, Dmitriy services necessary for the maintenance of essential social or economic activities in
Yuryevich Goloshubov, Nikolay Alexandrovich the Member States, notably in the transport sector. Via the WhisperGate
Korchagin campaign, GRU Unit 29155 also targeted critical infrastructure of Ukraine.
Associated entities: GRU Unit 29155, “Impuls” Therefore, Evgeniy Bashev provides technical and material support for, or is
LLC otherwise involved in, cyber-attacks with a significant effect, including attempted
cyber-attacks with a potentially significant effect, which constitute an external
threat to the Member States, as well as cyber-attacks with a significant effect
against a third country.
As owner and General Director, he is associated with the company “Impuls” LLC.
As a Member of GRU Unit 29155, he is also associated with that entity.
8/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
27. Roman Alexandrovich PUNTUS Роман Александрович ПУНТУС Roman Puntus is a member of the Russian Military Intelligence Agency GRU, Unit 13.7.2026’
29155. Within the unit, he holds a leading role in the organisation and
POB: Russian Federation
coordination of cyber-attacks with a significant effect against the Member States.
Nationality: Russian He also supports the development of the unit’s internal cyber capability, including
the recruitment and supervision of personnel such as hackers and programmers.
Gender: male By establishing the front company “Aegeon-Impulse,” he facilitated logistical and
financial aspects of cyber operations. Under his coordination, the unit conducted
Associated individuals: Denis Igorevich
cyber-attacks targeting critical state functions systems and services necessary for
Denisenko, Yuriy Fedorovich Denisov, Dmitriy
the maintenance of essential social or economic activities in the Member States,
Yuryevich Goloshubov, Nikolay Alexandrovich
notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155
Korchagin, Evgeniy Viktorovich Bashev
also targeted critical infrastructure of Ukraine.
Associated entities: GRU Unit 29155
Therefore, Roman Puntus is responsible for, or is otherwise involved in,
cyber-attacks with a significant effect, including attempted cyber-attacks with
a potentially significant effect, which constitute an external threat to
the Member States, as well as cyber-attacks with a significant effect against a third
country.
As a Member of GRU Unit 29155, he is also associated with that entity.
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
9/13
OJ
L,
13.7.2026
EN(2) the following entries are added under the heading ‘B. Legal persons, entities and bodies’:
Name Identifying information Reasons Date of listing
‘8. Media Land LLC Address: Tsvetnochnaya st., 16 Litera P, Room Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating 13.7.2026
27, Moskovskaya Zastava Municipal District a wide array of malware attacks against the Member States and globally, by
offering hosting services that hide user identities and resist takedowns by law
St Petersburg, 196006, Russian Federation
enforcement, leading to significant financial losses. Media Land LLC enabled
Type of entity: Limited Liability Company large-scale ransomware operations, command-and-control services, and phishing
operations that target critical infrastructure and essential services among the
Place of registration: St Petersburg Member States. Operations facilitated by Media Land LLC include, inter alia,
LockBit, EvilCorp and BlackBasta.
Date of registration: 19.10.2015
Therefore, Media Land LLC is involved in cyber-attacks with a significant effect,
Registration number: 1152536009900
which constitute an external threat to the Member States.
Principal place of business: St Petersburg,
Russian Federation
Associated entity: ML.Cloud
10/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
9. ML.Cloud Address: Brivibas iela 52, Riga, LV-1011, ML.Cloud is the sister company of Media Land LLC, and provides the technical 13.7.2026
Latvija; Russian Federation, Kazan, infrastructure for Media Land LLC.
Peterburgskaya st. 52
Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating
Place of registration: Riga a wide array of malware attacks against the Member States and globally, by
offering hosting services that hide user identities and resist takedowns by law
Associated individual: Alexander Volosovik
enforcement, leading to significant financial losses. Media Land LLC enabled
Other associated entities: Media Land LLC large-scale ransomware operations, command-and-control services, and phishing
operations that target critical infrastructure and essential services among the
Member States. Operations facilitated by Media Land LLC include, inter alia,
LockBit, EvilCorp and BlackBasta.
Therefore, Media Land LLC is involved in cyber- attacks that constitute an external
threat with significant effect to EU Member States.
Therefore, ML. Cloud provides technical support for cyber-attacks with
a significant effect, which constitute an external threat to the Member States.
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
11/13
OJ
L,
13.7.2026
ENName Identifying information Reasons Date of listing
10. “Impuls” LLC Общество с ограниченной ответственностью “Impuls” LLC is a Russian company owned by Evgeniy Viktorovich Bashev, 13.7.2026
“Импульс” a member of Russian Military Intelligence Agency GRU, Unit 29155. The
company provides technical and material support to cyber-attacks and attempted
Address: 344015, Russian Federation, Rostov
cyber-attacks conducted by GRU Unit 29155. In particular, “Impuls” LLC serves as
Region, Rostov-on-Don, ul. Eremenko, d. 56,
an operational intermediary enabling hacking-related activities to be carried out
k. 6, apt. 88
through a company formally unconnected to the Russian State. It facilitated
Type of entity: Limited Liability Company operational cover, infrastructure and payments for cyber-attacks, and was
connected to technical assets, including servers used in support of hacking
Place of registration: Interdistrict Inspectorate activities. In particular, “Impuls” LLC enabled cooperation between GRU
of the Federal Tax Service No. 26 for the Rostov structures and external hacker networks. The cyber operations facilitated by
Region, 344019, Rostov-on-Don, ul. “Impuls” LLC target critical state functions and services necessary for the
Myasnikova, d. 52/32, Russian Federation maintenance of essential social and economic activities in the Member States,
notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155
Date of registration: 27.9.2010
also targeted critical infrastructure of Ukraine.
Registration number: INN (ИНН):
Therefore, “Impuls” LLC provides technical and material support for, or is
6168033776; OGRN (ОГРН):
otherwise involved in, cyber-attacks with a significant effect, which constitute an
1106194004850
external threat to the Member States, as well as cyber-attacks with a significant
Principal place of business: Russian Federation effect against a third country.
Associated individuals: Evgeniy Bashev
Associated entities: GRU Unit 29155
12/13
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
EN
OJ
L,
13.7.2026Name Identifying information Reasons Date of listing
11. Z-Pentest Aliases: “Z-Pentest Alliance”, “Z-Alliance” Z-Pentest is a pro-Russia hacktivist group, composed of members from CARR 13.7.2026’
(Cyber Army of Russia Reborn) and NoName057, globally targeting critical
Principal place of business: Russian Federation
infrastructure, especially the energy and water sector.
Associated individuals: Yuliya Pankratova
Notably, the group attacked a Danish water utility in December 2024.
Associated entities: Cyber Army of
Therefore, Z-Pentest is responsible for cyber-attacks with a significant effect,
Russia/CARR
which constitute an external threat to the Member States.
X.com account: ZPentest (Account suspended)
Telegram account: Zpentestalliance
ELI:
http://data.europa.eu/eli/dec/2026/1713/oj
13/13
OJ
L,
13.7.2026
EN