See Full Document Text
Official Journal EN
of the European Union L series
2024/1390 17.5.2024
COUNCIL IMPLEMENTING REGULATION (EU) 2024/1390
of 17 May 2024
implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks
threatening the Union or its Member States
THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks
threatening the Union or its Member States (1), and in particular Article 13(1) thereof,
Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy,
Whereas:
(1) On 17 May 2019, the Council adopted Regulation (EU) 2019/796.
(2) In the light of continuing and increasing malicious behaviour in cyberspace, including behaviour directed against
third States, the reasons for including six persons and two entities in the list of natural and legal persons, entities and
bodies subject to restrictive measures set out in Annex I to Regulation (EU) 2019/796 should be updated.
(3) Annex I to Regulation (EU) 2019/796 should therefore be amended accordingly,
HAS ADOPTED THIS REGULATION:
Article 1
Annex I to Regulation (EU) 2019/796 is amended in accordance with the Annex to this Regulation.
Article 2
This Regulation shall enter into force on the day following that of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 17 May 2024.
For the Council
The President
H. LAHBIB
(1) OJ L 129 I, 17.5.2019, p. 1.
ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 1/9ANNEX
Annex I to Regulation (EU) 2019/796 (‘List of natural and legal persons, entities and bodies referred to in Article 3’) is amended as follows:
(1) in the list headed ‘A. Natural persons’, entries 3 to 8 are replaced by the following:
Name Identifying information Reasons Date of listing
‘3. Alexey Valeryevich MININ Алексей Валерьевич МИНИН Alexey Minin took part in an attempted cyber-attack with a potentially 30.7.2020
significant effect against the Organisation for the Prohibition of Chemical
Date of birth: 27.5.1972
Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant
Place of birth: Perm Oblast, Russian SFSR (now effect against third States.
Russian Federation)
As a human intelligence support officer of the Main Directorate of the
Passport number: 120017582 General Staff of the Armed Forces of the Russian Federation (GU/GRU),
Alexey Minin was part of a team of four Russian military intelligence officers
Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the
Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted
cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW,
Validity: from 17.4.2017 until 17.4.2022
which, if successful, would have compromised the security of the network
Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence
Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst)
Nationality: Russian
disrupted the attempted cyber-attack, thereby preventing serious damage to
Gender: male the OPCW.
A grand jury in the Western District of Pennsylvania (United States of
America) has indicted Alexey Minin, as an officer of the Russian Main
Intelligence Directorate (GRU), for computer hacking, wire fraud, aggravated
identity theft and money laundering.
2/9
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
EN
OJ
L,
17.5.2024Name Identifying information Reasons Date of listing
4. Aleksei Sergeyvich Алексей Сергеевич МОРЕНЕЦ Aleksei Morenets took part in an attempted cyber-attack with a potentially 30.7.2020
MORENETS significant effect against the Organisation for the Prohibition of Chemical
Date of birth: 31.7.1977
Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant
Place of birth: Murmanskaya Oblast, Russian SFSR effect against third States.
(now Russian Federation)
As a cyber-operator for the Main Directorate of the General Staff of the
Passport number: 100135556 Armed Forces of the Russian Federation (GU/GRU), Aleksei Morenets was
part of a team of four Russian military intelligence officers who attempted to
Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague,
Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at
hacking into the Wi-Fi network of the OPCW, which, if successful, would
Validity: from 17.4.2017 until 17.4.2022
have compromised the security of the network and the OPCW’s ongoing
Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security
Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted
Nationality: Russian
cyber-attack, thereby preventing serious damage to the OPCW.
Gender: male
A grand jury in the Western District of Pennsylvania (United States of
America) has indicted Aleksei Morenets, as assigned to Military Unit 26165,
for computer hacking, wire fraud, aggravated identity theft and money
laundering.
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
3/9
OJ
L,
17.5.2024
ENName Identifying information Reasons Date of listing
5. Evgenii Mikhaylovich Евгений Михайлович СЕРЕБРЯКОВ Evgenii Serebriakov took part in an attempted cyber-attack with a potentially 30.7.2020
SEREBRIAKOV significant effect against the Organisation for the Prohibition of Chemical
Date of birth: 26.7.1981
Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant
Place of birth: Kursk, Russian SFSR (now Russian effect against third States.
Federation)
As a cyber-operator for the Main Directorate of the General Staff of the
Passport number: 100135555 Armed Forces of the Russian Federation (GU/GRU), Evgenii Serebriakov was
part of a team of four Russian military intelligence officers who attempted to
Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague,
Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at
hacking into the Wi-Fi network of the OPCW, which, if successful, would
Validity: from 17.4.2017 until 17.4.2022
have compromised the security of the network and the OPCW’s ongoing
Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security
Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted
Nationality: Russian
cyber-attack, thereby preventing serious damage to the OPCW.
Gender: male
Since spring 2022, Evgenii Serebriakov is leading “Sandworm” (a.k.a.
“Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”,
“Olympic Destroyer” and “Telebots”), an actor and hacking group affiliated
with Unit 74455 of the Russian Main Intelligence Directorate. Sandworm
has carried out cyber-attacks on Ukraine, including Ukrainian government
agencies, following Russia’s war of aggression against Ukraine.
4/9
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
EN
OJ
L,
17.5.2024Name Identifying information Reasons Date of listing
6. Oleg Mikhaylovich Олег Михайлович СОТНИКОВ Oleg Sotnikov took part in an attempted cyber-attack with a potentially 30.7.2020
SOTNIKOV significant effect against the Organisation for the Prohibition of Chemical
Date of birth: 24.8.1972
Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant
Place of birth: Ulyanovsk, Russian SFSR (now effect against third States.
Russian Federation)
As a human intelligence support officer of the Main Directorate of the
Passport number: 120018866 General Staff of the Armed Forces of the Russian Federation (GU/GRU), Oleg
Sotnikov was part of a team of four Russian military intelligence officers
Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the
Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted
cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW,
Validity: from 17.4.2017 until 17.4.2022
which, if successful, would have compromised the security of the network
Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence
Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst)
Nationality: Russian
disrupted the attempted cyber-attack, thereby preventing serious damage to
Gender: male the OPCW.
A grand jury in the Western District of Pennsylvania has indicted Oleg
Sotnikov, as an officer of the Russian Main Intelligence Directorate (GRU),
for computer hacking, wire fraud, aggravated identity theft and money
laundering.
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
5/9
OJ
L,
17.5.2024
ENName Identifying information Reasons Date of listing
7. Dmitry Sergeyevich BADIN Дмитрий Сергеевич БАДИН Dmitry Badin took part in a cyber-attack with a significant effect against the 22.10.2020
German federal parliament (Deutscher Bundestag) and in cyber-attacks with
Date of birth: 15.11.1990
a significant effect against third States.
Place of birth: Kursk, Russian SFSR (now Russian
As a military intelligence officer of the 85th Main Centre for Special Services
Federation)
(GTsSS) of the Main Directorate of the General Staff of the Armed Forces of
Nationality: Russian the Russian Federation (GU/GRU), Dmitry Badin was part of a team of
Russian military intelligence officers who conducted a cyber-attack against
Gender: male the German federal parliament in April and May 2015. That cyber-attack
targeted the parliament’s information system and affected its operation for
several days. A significant amount of data was stolen and the email accounts
of several MPs, as well as of former Chancellor Angela Merkel, were affected.
A grand jury in the Western District of Pennsylvania (United States of
America) has indicted Dmitry Badin, as assigned to Military Unit 26165, for
computer hacking, wire fraud, aggravated identity theft and money
laundering.
6/9
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
EN
OJ
L,
17.5.2024Name Identifying information Reasons Date of listing
8. Igor Olegovich Игорь Олегович КОСТЮКОВ Igor Kostyukov is the current Head of the Main Directorate of the General 22.10.2020’;
KOSTYUKOV Staff of the Armed Forces of the Russian Federation (GU/GRU), where he
Date of birth: 21.2.1961
previously served as First Deputy Head. One of the units under his
Nationality: Russian command is the 85th Main Centre for Special Services (GTsSS) (a.k.a.
“Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn Storm”
Gender: male and “Strontium”).
In this capacity, Igor Kostyukov is responsible for cyber-attacks carried out
by the GTsSS, including those with a significant effect constituting an
external threat to the Union or its Member States.
In particular, military intelligence officers of the GTsSS took part in the
cyber-attack against the German federal parliament (Deutscher Bundestag) in
April and May 2015 and the attempted cyber-attack aimed at hacking into
the Wi-Fi network of the Organisation for the Prohibition of Chemical
Weapons (OPCW) in the Netherlands in April 2018.
The cyber-attack against the German federal parliament targeted the
parliament’s information system and affected its operation for several days.
A significant amount of data was stolen and email accounts of several MPs,
as well as of former Chancellor Angela Merkel, were affected.
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
7/9
OJ
L,
17.5.2024
EN(2) in the list headed ‘B. Legal persons, entities and bodies’, entries 3 and 4 are replaced by the following:
Name Identifying information Reasons Date of listing
‘3. Main Centre for Special Address: 22 Kirova Street, Moscow, Russian The Main Centre for Special Technologies (GTsST) of the Main Directorate of 30.7.2020
Technologies (GTsST) of the Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU),
Main Directorate of the also known by its field post number 74455, is involved in cyber-attacks with
General Staff of the Armed a significant effect originating from outside the Union and constituting an
Forces of the Russian external threat to the Union or its Member States and in cyber-attacks with
Federation (GU/GRU) a significant effect against third States, including the cyber-attacks publicly
known as “NotPetya” or “EternalPetya” in June 2017 and the cyber-attacks
directed at a Ukrainian power grid in the winter of 2015 and 2016.
“NotPetya” or “EternalPetya” rendered data inaccessible in a number of
companies in the Union, wider Europe and worldwide, by targeting
computers with ransomware and blocking access to data, resulting amongst
others in significant economic loss. The cyber-attack on a Ukrainian power
grid resulted in parts of it being switched off during winter.
The actor publicly known as “Sandworm” (a.k.a. “Sandworm Team”,
“BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and
“Telebots”), which is also behind the attack on the Ukrainian power grid,
carried out “NotPetya” or “EternalPetya”. Sandworm has carried out
cyber-attacks against Ukraine, including Ukrainian government agencies
and Ukrainian critical infrastructure, following Russia’s war of aggression
against Ukraine. Those cyber-attacks include spear-phishing campaigns,
malware and ransomware attacks.
The Main Centre for Special Technologies of the Main Directorate of the
General Staff of the Armed Forces of the Russian Federation has an active
role in the cyber-activities undertaken by Sandworm and can be linked to
Sandworm.
8/9
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
EN
OJ
L,
17.5.2024Name Identifying information Reasons Date of listing
4. 85th Main Centre for Special Address: Komsomol’skiy Prospekt, 20, Moscow, The 85th Main Centre for Special Services (GTsSS) of the Main Directorate of 22.10.2020’.
Services (GTsSS) of the Main 119146, Russian Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU)
Directorate of the General (a.k.a. “Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn
Staff of the Armed Forces of Storm” and “Strontium”) is involved in cyber-attacks with a significant effect
the Russian Federation constituting an external threat to the Union or its Member States and in
(GU/GRU) cyber-attacks with a significant effect against third States.
In particular, military intelligence officers of the GTsSS took part in the
cyber-attack against the German federal parliament (Deutscher Bundestag) in
April and May 2015 and the attempted cyber-attack aimed at hacking into
the Wi-Fi network of the Organisation for the Prohibition of Chemical
Weapons (OPCW) in the Netherlands in April 2018.
The cyber-attack against the German federal parliament targeted the
parliament’s information system and affected its operation for several days.
A significant amount of data was stolen and email accounts of several MPs,
as well as of former Chancellor Angela Merkel, were affected.
Following Russia’s war of aggression against Ukraine, cyber-attacks by the
GTsSS (spear-phishing and malware-based attacks) were carried out against
Ukraine.
ELI:
http://data.europa.eu/eli/reg_impl/2024/1390/oj
9/9
OJ
L,
17.5.2024
EN