Home Europe Council of the European Union Council Decision (CFSP) 2026/1713 of 13 July 2026 amending D...
Date: 2026-07-13 Category: Not Applicable State: Union Government Country: Europe

Council Decision (CFSP) 2026/1713 of 13 July 2026 amending Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Issued by Council of the European Union · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task
Official Source Record View Original Source →
See Full Document Text
Official Journal EN of the European Union L series 2026/1713 13.7.2026 COUNCIL DECISION (CFSP) 2026/1713 of 13 July 2026 amending Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on European Union and in particular Article 29 thereof, Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy, Whereas: (1) On 17 May 2019 the Council adopted Decision (CFSP) 2019/797(1). (2) As part of the sustained, tailored and coordinated Union action against persistent cyber threat actors, eight natural persons and four entities should be added to the list of natural and legal persons, entities and bodies subject to restrictive measures set out in the Annex to Decision (CFSP) 2019/797. Those persons and entities are responsible for, supporting, or involved in, cyber-attacks with a significant effect which constitute an external threat to the Union or its Member States. (3) Decision (CFSP) 2019/797 should therefore be amended accordingly, HAS ADOPTED THIS DECISION: Article 1 The Annex to Decision (CFSP) 2019/797 is amended in accordance with the Annex to this Decision. Article 2 This Decision shall enter into force on the date of its publication in the Official Journal of the European Union. Done at Brussels, 13 July 2026. For the Council The President K. KALLAS (1) Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States (OJ L 129 I, 17.5.2019, p. 13, ELI: http://data.europa.eu/eli/dec/2019/797/oj). ELI: http://data.europa.eu/eli/dec/2026/1713/oj 1/13ANNEX The Annex to Decision (CFSP) 2019/797 is amended as follows: (1) the following entries are added under the heading ‘A. Natural persons’: Name Identifying information Reasons Date of listing ‘20. Vitaly Nikolayevich KOVALEV Виталий Николаевич КОВАЛЕВ Vitaly Kovalev is a senior figure in the malware programs “Trickbot” and “Conti”. 13.7.2026 He is also known by the online monikers “Bentley”, “Bergen”, “Alex Konor”, Aliases: “Bentley”, “Bergen”, “Alex Konor”, “Benny”, “Ben” and “Stern”. “Benny”, “Ben”, “Stern” Conti and Trickbot were originally created and developed by Wizard Spider. DOB: 23.6.1988 Wizard Spider has conducted ransomware campaigns in a variety of sectors, Address: Serebristy Bulvar 34 (Serebristyy including essential services such as health and banking, has infected computers Bul’var); krp 1; flt 528; 197341; St Petersburg, worldwide and their malware has been developed into a highly modular malware Russian Federation suite. Campaigns by Wizard Spider, using malware such as Conti, and TrickBot, are responsible for substantial economic damage in the European Union. Nationality: Russian Vitaly Kovalev is therefore responsible for, and involved in, cyber-attacks with Gender: male a significant effect which constitute an external threat to the Union or its Member States. Associated entities: TrickBot, Wizard Spider, Conti 2/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 21. Alexander Alexandrovich Александр Александрович ВОЛОСОВИК Alexander Volosovik is the owner of Media Land LLC. Since 2016, Bullet Proof 13.7.2026 VOLOSOVIK Hosting service Media Land LLC has been facilitating a wide array of malware DOB: 30.1.1983 attacks against both the Union and globally, by offering hosting services that hide POB: USSR user identities and resist takedowns by law enforcement. Media Land LLC enabled large-scale ransomware operations, command-and-control services, and phishing Nationality: Russian operations that target critical infrastructure and essential services in the Member States, leading to significant financial losses. Operations facilitated by Media Land Passport number: 762988138 LLC include, inter alia, LockBit, EvilCorp and BlackBasta. Gender: male Therefore, Media Land LLC is involved in cyber-attacks with significant effect Associated entities: Yalishanda, LARVA-34, which constitute an external threat to the Union or its Member States. As owner podzemniyl, Ohyeahhellno, Stas_vl, downlow of Media Land LLC, Alexander Volosovik is responsible for, and involved in, these cyber-attacks. He is also associated to Media Land LLC. ELI: http://data.europa.eu/eli/dec/2026/1713/oj 3/13 OJ L, 13.7.2026 ENName Identifying information Reasons Date of listing 22. Denis Olegovich Денис Олегович ДЕГТЯРЕНКО Denis Degtyarenko aka Dena is a Russian hacker for CARR (Cyber Army of Russia 13.7.2026 DEGTYARENKO Reborn). Alias: “Dena” CARR has been responsible for cyber-attacks against services necessary for the DOB: 9.10.1989 maintenance of essential economic activities and critical state functions in the POB: USSR Member States, as well as against infrastructure in Ukraine and other third countries. CARR is linked to the Main Centre for Special Technologies (GTsST) Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). Gender: male The GTsST remains active in carrying out cyber-attacks against the Union or its Address: 130 Lenina Avenue, Novy Gorod Member States. CARR’s targets include government agencies, financial microdistrict, Orsk, Orenburg Region, Russian institutions, media outlets, and critical infrastructure in the Member States and the Federation United States. CARR has conducted distributed denial-of-service (DDoS) attacks in Ukraine and against governments and companies located in countries that have supported Ukraine. Therefore, Denis Degtyarenko, a primary hacker for CARR, is involved in cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as against third states. As a member of CARR, he is also associated to GTsST. 4/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 23. Yuliya Vladimirovna Юлия Владимировна ПАНКРАТОВА Yuliya Pankratova is a Russian hacker who has been working for CARR (Cyber 13.7.2026 PANKRATOVA Army of Russia Reborn) and has founded, and continues to work for Z-Pentest. Alias: “YUliYA” CARR has been responsible for cyber attacks against services necessary for the DOB: 6.4.1984 maintenance of essential economic activities and critical state functions in the POB: USSR Member States, as well as against infrastructure in Ukraine and other third countries. CARR is linked to the Main Centre for Special Technologies (GTsST) Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). The GTsST remains active in carrying out cyber-attacks Gender: female against the Union or its Member States. CARR’s targets include government Address: 130 Lenina Avenue, Novy Gorod agencies, financial institutions, media outlets, and critical infrastructure in microdistrict, Orsk, Orenburg Region, Russian Member States and the United States. CARR has conducted distributed Federation denial-of-service (DDoS) attacks in Ukraine and against governments and companies located in countries that have supported Ukraine. Z-Pentest is responsible for cyber-attacks with a significant effect against inter alia services necessary for the maintenance of essential activities in the Member States. Therefore, Yuliya Pankratova, a primary hacker for CARR and for Z-Pentest, is involved in cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as against third states. She is also associated to Z-Pentest. ELI: http://data.europa.eu/eli/dec/2026/1713/oj 5/13 OJ L, 13.7.2026 ENName Identifying information Reasons Date of listing 24. Maksim Evgenevich VORONIN Максим Евгеньевич ВОРОНИН Maksim Voronin aka Daugn0 is involved in the development, distribution and 13.7.2026 selling of the information stealing malware LummaC2 (aka Lumma Infostealer, Alias: “Daugn0” Lumma Stealer). Nationality: allegedly Russian LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data, Gender: male browser credentials, crypto wallets, or system info, to deploy additional malware on infected devices, for cryptocurrency theft and for espionage campaigns. Cyberattacks involving LummaC2 malware are used also by financially motivated cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and others. LummaC2 malware has been used for cyber-attacks against critical state functions and services necessary for the maintenance of essential social and economic activities of the Members States. In 2024 and 2025, LummaC2 was one of the most used tools for stealing information worldwide. Therefore, Maksim Voronin as developer, distributor and seller of LummaC2 is involved in and facilitates cyberattacks with a significant effect, which constitute an external threat to the Member States. 6/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 25. Maksim Aleksandrovich Максим Александрович ГОРДИЕНКО Maksim Gordienko aka Lummaseller is involved in the development and 13.7.2026 GORDIENKO distribution of the information stealing malware LummaC2 (aka Lumma Alias: “Lummaseller” Infostealer, Lumma Stealer). a.k.a. Maxim Alexandrovich Nationality: allegedly Russian GORDIENKO LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data, Gender: male browser credentials, crypto wallets or system info, to deploy additional malware on infected devices, for cryptocurrency theft and for espionage campaigns. Cyberattacks involving LummaC2 malware are used also by financially motivated cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and others. LummaC2 malware has been used for cyber-attacks against critical state functions and services necessary for the maintenance of essential social and economic activities of the Member States. In 2024 and 2025 LummaC2 was one of the most used tools for stealing information worldwide. Therefore, Maksim Gordienko as developer, distributor and seller of LummaC2 is involved in and facilitates cyberattacks with a significant effect, which constitute an external threat to the Member States. ELI: http://data.europa.eu/eli/dec/2026/1713/oj 7/13 OJ L, 13.7.2026 ENName Identifying information Reasons Date of listing 26. Evgeniy Viktorovich BASHEV Евгений Викторович БАШЕВ Evgeniy Bashev is a member of Russian Military Intelligence Agency GRU, Unit 13.7.2026 29155. Within the unit he supports and facilitates cyber-attacks with a significant DOB: 25.1.1980 effect against the Member States, inter alia via controlling the server “Aegon”, used POB: USSR for hacking operations. In particular, he provides technical and material support to the cyber-attacks of the GRU Unit 29155 through his company “Impuls” LLC, Nationality: Russian which facilitated operational cover, infrastructure, and payments, and managed technical assets, including servers, that are used for the cyber-attacks. He also Gender: male coordinated cooperation between GRU structures and external hacker networks. Associated individuals: Denis Igorevich The cyber-attacks he facilitated targeted critical state functions systems and Denisenko, Yuriy Fedorovich Denisov, Dmitriy services necessary for the maintenance of essential social or economic activities in Yuryevich Goloshubov, Nikolay Alexandrovich the Member States, notably in the transport sector. Via the WhisperGate Korchagin campaign, GRU Unit 29155 also targeted critical infrastructure of Ukraine. Associated entities: GRU Unit 29155, “Impuls” Therefore, Evgeniy Bashev provides technical and material support for, or is LLC otherwise involved in, cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as cyber-attacks with a significant effect against a third country. As owner and General Director, he is associated with the company “Impuls” LLC. As a Member of GRU Unit 29155, he is also associated with that entity. 8/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 27. Roman Alexandrovich PUNTUS Роман Александрович ПУНТУС Roman Puntus is a member of the Russian Military Intelligence Agency GRU, Unit 13.7.2026’ 29155. Within the unit, he holds a leading role in the organisation and POB: Russian Federation coordination of cyber-attacks with a significant effect against the Member States. Nationality: Russian He also supports the development of the unit’s internal cyber capability, including the recruitment and supervision of personnel such as hackers and programmers. Gender: male By establishing the front company “Aegeon-Impulse,” he facilitated logistical and financial aspects of cyber operations. Under his coordination, the unit conducted Associated individuals: Denis Igorevich cyber-attacks targeting critical state functions systems and services necessary for Denisenko, Yuriy Fedorovich Denisov, Dmitriy the maintenance of essential social or economic activities in the Member States, Yuryevich Goloshubov, Nikolay Alexandrovich notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155 Korchagin, Evgeniy Viktorovich Bashev also targeted critical infrastructure of Ukraine. Associated entities: GRU Unit 29155 Therefore, Roman Puntus is responsible for, or is otherwise involved in, cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as cyber-attacks with a significant effect against a third country. As a Member of GRU Unit 29155, he is also associated with that entity. ELI: http://data.europa.eu/eli/dec/2026/1713/oj 9/13 OJ L, 13.7.2026 EN(2) the following entries are added under the heading ‘B. Legal persons, entities and bodies’: Name Identifying information Reasons Date of listing ‘8. Media Land LLC Address: Tsvetnochnaya st., 16 Litera P, Room Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating 13.7.2026 27, Moskovskaya Zastava Municipal District a wide array of malware attacks against the Member States and globally, by offering hosting services that hide user identities and resist takedowns by law St Petersburg, 196006, Russian Federation enforcement, leading to significant financial losses. Media Land LLC enabled Type of entity: Limited Liability Company large-scale ransomware operations, command-and-control services, and phishing operations that target critical infrastructure and essential services among the Place of registration: St Petersburg Member States. Operations facilitated by Media Land LLC include, inter alia, LockBit, EvilCorp and BlackBasta. Date of registration: 19.10.2015 Therefore, Media Land LLC is involved in cyber-attacks with a significant effect, Registration number: 1152536009900 which constitute an external threat to the Member States. Principal place of business: St Petersburg, Russian Federation Associated entity: ML.Cloud 10/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 9. ML.Cloud Address: Brivibas iela 52, Riga, LV-1011, ML.Cloud is the sister company of Media Land LLC, and provides the technical 13.7.2026 Latvija; Russian Federation, Kazan, infrastructure for Media Land LLC. Peterburgskaya st. 52 Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating Place of registration: Riga a wide array of malware attacks against the Member States and globally, by offering hosting services that hide user identities and resist takedowns by law Associated individual: Alexander Volosovik enforcement, leading to significant financial losses. Media Land LLC enabled Other associated entities: Media Land LLC large-scale ransomware operations, command-and-control services, and phishing operations that target critical infrastructure and essential services among the Member States. Operations facilitated by Media Land LLC include, inter alia, LockBit, EvilCorp and BlackBasta. Therefore, Media Land LLC is involved in cyber- attacks that constitute an external threat with significant effect to EU Member States. Therefore, ML. Cloud provides technical support for cyber-attacks with a significant effect, which constitute an external threat to the Member States. ELI: http://data.europa.eu/eli/dec/2026/1713/oj 11/13 OJ L, 13.7.2026 ENName Identifying information Reasons Date of listing 10. “Impuls” LLC Общество с ограниченной ответственностью “Impuls” LLC is a Russian company owned by Evgeniy Viktorovich Bashev, 13.7.2026 “Импульс” a member of Russian Military Intelligence Agency GRU, Unit 29155. The company provides technical and material support to cyber-attacks and attempted Address: 344015, Russian Federation, Rostov cyber-attacks conducted by GRU Unit 29155. In particular, “Impuls” LLC serves as Region, Rostov-on-Don, ul. Eremenko, d. 56, an operational intermediary enabling hacking-related activities to be carried out k. 6, apt. 88 through a company formally unconnected to the Russian State. It facilitated Type of entity: Limited Liability Company operational cover, infrastructure and payments for cyber-attacks, and was connected to technical assets, including servers used in support of hacking Place of registration: Interdistrict Inspectorate activities. In particular, “Impuls” LLC enabled cooperation between GRU of the Federal Tax Service No. 26 for the Rostov structures and external hacker networks. The cyber operations facilitated by Region, 344019, Rostov-on-Don, ul. “Impuls” LLC target critical state functions and services necessary for the Myasnikova, d. 52/32, Russian Federation maintenance of essential social and economic activities in the Member States, notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155 Date of registration: 27.9.2010 also targeted critical infrastructure of Ukraine. Registration number: INN (ИНН): Therefore, “Impuls” LLC provides technical and material support for, or is 6168033776; OGRN (ОГРН): otherwise involved in, cyber-attacks with a significant effect, which constitute an 1106194004850 external threat to the Member States, as well as cyber-attacks with a significant Principal place of business: Russian Federation effect against a third country. Associated individuals: Evgeniy Bashev Associated entities: GRU Unit 29155 12/13 ELI: http://data.europa.eu/eli/dec/2026/1713/oj EN OJ L, 13.7.2026Name Identifying information Reasons Date of listing 11. Z-Pentest Aliases: “Z-Pentest Alliance”, “Z-Alliance” Z-Pentest is a pro-Russia hacktivist group, composed of members from CARR 13.7.2026’ (Cyber Army of Russia Reborn) and NoName057, globally targeting critical Principal place of business: Russian Federation infrastructure, especially the energy and water sector. Associated individuals: Yuliya Pankratova Notably, the group attacked a Danish water utility in December 2024. Associated entities: Cyber Army of Therefore, Z-Pentest is responsible for cyber-attacks with a significant effect, Russia/CARR which constitute an external threat to the Member States. X.com account: ZPentest (Account suspended) Telegram account: Zpentestalliance ELI: http://data.europa.eu/eli/dec/2026/1713/oj 13/13 OJ L, 13.7.2026 EN

Continue your research