Home Europe Council of the European Union Council Implementing Regulation (EU) 2024/1390 of 17 May 202...
Date: 17-May-2024 Category: Not Applicable State: Union Government Country: Europe

Council Implementing Regulation (EU) 2024/1390 of 17 May 2024 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Issued by Council of the European Union · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

What it means

  • Council Implementing Regulation (EU) 2024/1390 updates Annex I to Regulation (EU) 2019/796, which concerns restrictive measures against cyber-attacks threatening the Union or its Member States.
  • The regulation updates the reasons for including six persons and two entities in the list of natural and legal persons, entities and bodies subject to restrictive measures.

Key Changes

  • The regulation amends Annex I to Regulation (EU) 2019/796.
  • Entries 3 to 8 in the list of natural persons are replaced with updated information regarding Alexey Valeryevich Minin, Aleksei Sergeyvich Morenets, Evgenii Mikhaylovich Serebriakov, Oleg Mikhaylovich Sotnikov, Dmitry Sergeyevich Badin and Igor Olegovich Kostyukov. The update includes reasons for their listing and identifying information.
  • Entries 3 and 4 in the list of legal persons, entities and bodies are replaced with updated information regarding the Main Centre for Special Technologies (GTsST) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU) and the 85th Main Centre for Special Services (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). The update includes reasons for their listing and identifying information.

Impact Analysis

Stakeholders Impacted

  • Third States: The regulation acknowledges malicious cyber behavior directed against third states.

Suggested Action Items

  • Monitor Official Journal of the European Union for any further updates or amendments to the regulations.

Key Entities Referenced

Council Regulation (EU) 2019/796: Regulation concerning restrictive measures against cyber-attacks threatening the Union or its Member States. Alexey Valeryevich Minin: A Russian national involved in attempted cyber-attacks against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. Human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Aleksei Sergeyvich Morenets: A Russian national involved in attempted cyber-attacks against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. Cyber-operator for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Evgenii Mikhaylovich Serebriakov: A Russian national involved in attempted cyber-attacks against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. Leader of 'Sandworm', an actor and hacking group affiliated with Unit 74455 of the Russian Main Intelligence Directorate. Oleg Mikhaylovich Sotnikov: A Russian national involved in attempted cyber-attacks against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. Human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Dmitry Sergeyevich Badin: A Russian national involved in a cyber-attack against the German federal parliament (Deutscher Bundestag) and cyber-attacks against third states. Military intelligence officer of the 85th Main Centre for Special Services (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Igor Olegovich Kostyukov: The current Head of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Responsible for cyber-attacks carried out by the 85th Main Centre for Special Services (GTsSS). Main Centre for Special Technologies (GTsST) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU): Involved in cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and in cyber-attacks with a significant effect against third States. 85th Main Centre for Special Services (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU): Involved in cyber-attacks with a significant effect constituting an external threat to the Union or its Member States and in cyber-attacks with a significant effect against third States. Organisation for the Prohibition of Chemical Weapons (OPCW): An international organization whose Wi-Fi network was targeted in an attempted cyber-attack. German federal parliament (Deutscher Bundestag): Target of a cyber-attack in April and May 2015.
Official Source Record View Original Source →
See Full Document Text
Official Journal EN of the European Union L series 2024/1390 17.5.2024 COUNCIL IMPLEMENTING REGULATION (EU) 2024/1390 of 17 May 2024 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, Having regard to Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States (1), and in particular Article 13(1) thereof, Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy, Whereas: (1) On 17 May 2019, the Council adopted Regulation (EU) 2019/796. (2) In the light of continuing and increasing malicious behaviour in cyberspace, including behaviour directed against third States, the reasons for including six persons and two entities in the list of natural and legal persons, entities and bodies subject to restrictive measures set out in Annex I to Regulation (EU) 2019/796 should be updated. (3) Annex I to Regulation (EU) 2019/796 should therefore be amended accordingly, HAS ADOPTED THIS REGULATION: Article 1 Annex I to Regulation (EU) 2019/796 is amended in accordance with the Annex to this Regulation. Article 2 This Regulation shall enter into force on the day following that of its publication in the Official Journal of the European Union. This Regulation shall be binding in its entirety and directly applicable in all Member States. Done at Brussels, 17 May 2024. For the Council The President H. LAHBIB (1) OJ L 129 I, 17.5.2019, p. 1. ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 1/9ANNEX Annex I to Regulation (EU) 2019/796 (‘List of natural and legal persons, entities and bodies referred to in Article 3’) is amended as follows: (1) in the list headed ‘A. Natural persons’, entries 3 to 8 are replaced by the following: Name Identifying information Reasons Date of listing ‘3. Alexey Valeryevich MININ Алексей Валерьевич МИНИН Alexey Minin took part in an attempted cyber-attack with a potentially 30.7.2020 significant effect against the Organisation for the Prohibition of Chemical Date of birth: 27.5.1972 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Perm Oblast, Russian SFSR (now effect against third States. Russian Federation) As a human intelligence support officer of the Main Directorate of the Passport number: 120017582 General Staff of the Armed Forces of the Russian Federation (GU/GRU), Alexey Minin was part of a team of four Russian military intelligence officers Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, Validity: from 17.4.2017 until 17.4.2022 which, if successful, would have compromised the security of the network Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) Nationality: Russian disrupted the attempted cyber-attack, thereby preventing serious damage to Gender: male the OPCW. A grand jury in the Western District of Pennsylvania (United States of America) has indicted Alexey Minin, as an officer of the Russian Main Intelligence Directorate (GRU), for computer hacking, wire fraud, aggravated identity theft and money laundering. 2/9 ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 4. Aleksei Sergeyvich Алексей Сергеевич МОРЕНЕЦ Aleksei Morenets took part in an attempted cyber-attack with a potentially 30.7.2020 MORENETS significant effect against the Organisation for the Prohibition of Chemical Date of birth: 31.7.1977 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Murmanskaya Oblast, Russian SFSR effect against third States. (now Russian Federation) As a cyber-operator for the Main Directorate of the General Staff of the Passport number: 100135556 Armed Forces of the Russian Federation (GU/GRU), Aleksei Morenets was part of a team of four Russian military intelligence officers who attempted to Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would Validity: from 17.4.2017 until 17.4.2022 have compromised the security of the network and the OPCW’s ongoing Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted Nationality: Russian cyber-attack, thereby preventing serious damage to the OPCW. Gender: male A grand jury in the Western District of Pennsylvania (United States of America) has indicted Aleksei Morenets, as assigned to Military Unit 26165, for computer hacking, wire fraud, aggravated identity theft and money laundering. ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 3/9 OJ L, 17.5.2024 ENName Identifying information Reasons Date of listing 5. Evgenii Mikhaylovich Евгений Михайлович СЕРЕБРЯКОВ Evgenii Serebriakov took part in an attempted cyber-attack with a potentially 30.7.2020 SEREBRIAKOV significant effect against the Organisation for the Prohibition of Chemical Date of birth: 26.7.1981 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Kursk, Russian SFSR (now Russian effect against third States. Federation) As a cyber-operator for the Main Directorate of the General Staff of the Passport number: 100135555 Armed Forces of the Russian Federation (GU/GRU), Evgenii Serebriakov was part of a team of four Russian military intelligence officers who attempted to Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would Validity: from 17.4.2017 until 17.4.2022 have compromised the security of the network and the OPCW’s ongoing Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted Nationality: Russian cyber-attack, thereby preventing serious damage to the OPCW. Gender: male Since spring 2022, Evgenii Serebriakov is leading “Sandworm” (a.k.a. “Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and “Telebots”), an actor and hacking group affiliated with Unit 74455 of the Russian Main Intelligence Directorate. Sandworm has carried out cyber-attacks on Ukraine, including Ukrainian government agencies, following Russia’s war of aggression against Ukraine. 4/9 ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 6. Oleg Mikhaylovich Олег Михайлович СОТНИКОВ Oleg Sotnikov took part in an attempted cyber-attack with a potentially 30.7.2020 SOTNIKOV significant effect against the Organisation for the Prohibition of Chemical Date of birth: 24.8.1972 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Ulyanovsk, Russian SFSR (now effect against third States. Russian Federation) As a human intelligence support officer of the Main Directorate of the Passport number: 120018866 General Staff of the Armed Forces of the Russian Federation (GU/GRU), Oleg Sotnikov was part of a team of four Russian military intelligence officers Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, Validity: from 17.4.2017 until 17.4.2022 which, if successful, would have compromised the security of the network Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) Nationality: Russian disrupted the attempted cyber-attack, thereby preventing serious damage to Gender: male the OPCW. A grand jury in the Western District of Pennsylvania has indicted Oleg Sotnikov, as an officer of the Russian Main Intelligence Directorate (GRU), for computer hacking, wire fraud, aggravated identity theft and money laundering. ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 5/9 OJ L, 17.5.2024 ENName Identifying information Reasons Date of listing 7. Dmitry Sergeyevich BADIN Дмитрий Сергеевич БАДИН Dmitry Badin took part in a cyber-attack with a significant effect against the 22.10.2020 German federal parliament (Deutscher Bundestag) and in cyber-attacks with Date of birth: 15.11.1990 a significant effect against third States. Place of birth: Kursk, Russian SFSR (now Russian As a military intelligence officer of the 85th Main Centre for Special Services Federation) (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of Nationality: Russian the Russian Federation (GU/GRU), Dmitry Badin was part of a team of Russian military intelligence officers who conducted a cyber-attack against Gender: male the German federal parliament in April and May 2015. That cyber-attack targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and the email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. A grand jury in the Western District of Pennsylvania (United States of America) has indicted Dmitry Badin, as assigned to Military Unit 26165, for computer hacking, wire fraud, aggravated identity theft and money laundering. 6/9 ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 8. Igor Olegovich Игорь Олегович КОСТЮКОВ Igor Kostyukov is the current Head of the Main Directorate of the General 22.10.2020’; KOSTYUKOV Staff of the Armed Forces of the Russian Federation (GU/GRU), where he Date of birth: 21.2.1961 previously served as First Deputy Head. One of the units under his Nationality: Russian command is the 85th Main Centre for Special Services (GTsSS) (a.k.a. “Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn Storm” Gender: male and “Strontium”). In this capacity, Igor Kostyukov is responsible for cyber-attacks carried out by the GTsSS, including those with a significant effect constituting an external threat to the Union or its Member States. In particular, military intelligence officers of the GTsSS took part in the cyber-attack against the German federal parliament (Deutscher Bundestag) in April and May 2015 and the attempted cyber-attack aimed at hacking into the Wi-Fi network of the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands in April 2018. The cyber-attack against the German federal parliament targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 7/9 OJ L, 17.5.2024 EN(2) in the list headed ‘B. Legal persons, entities and bodies’, entries 3 and 4 are replaced by the following: Name Identifying information Reasons Date of listing ‘3. Main Centre for Special Address: 22 Kirova Street, Moscow, Russian The Main Centre for Special Technologies (GTsST) of the Main Directorate of 30.7.2020 Technologies (GTsST) of the Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Main Directorate of the also known by its field post number 74455, is involved in cyber-attacks with General Staff of the Armed a significant effect originating from outside the Union and constituting an Forces of the Russian external threat to the Union or its Member States and in cyber-attacks with Federation (GU/GRU) a significant effect against third States, including the cyber-attacks publicly known as “NotPetya” or “EternalPetya” in June 2017 and the cyber-attacks directed at a Ukrainian power grid in the winter of 2015 and 2016. “NotPetya” or “EternalPetya” rendered data inaccessible in a number of companies in the Union, wider Europe and worldwide, by targeting computers with ransomware and blocking access to data, resulting amongst others in significant economic loss. The cyber-attack on a Ukrainian power grid resulted in parts of it being switched off during winter. The actor publicly known as “Sandworm” (a.k.a. “Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and “Telebots”), which is also behind the attack on the Ukrainian power grid, carried out “NotPetya” or “EternalPetya”. Sandworm has carried out cyber-attacks against Ukraine, including Ukrainian government agencies and Ukrainian critical infrastructure, following Russia’s war of aggression against Ukraine. Those cyber-attacks include spear-phishing campaigns, malware and ransomware attacks. The Main Centre for Special Technologies of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation has an active role in the cyber-activities undertaken by Sandworm and can be linked to Sandworm. 8/9 ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 4. 85th Main Centre for Special Address: Komsomol’skiy Prospekt, 20, Moscow, The 85th Main Centre for Special Services (GTsSS) of the Main Directorate of 22.10.2020’. Services (GTsSS) of the Main 119146, Russian Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU) Directorate of the General (a.k.a. “Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn Staff of the Armed Forces of Storm” and “Strontium”) is involved in cyber-attacks with a significant effect the Russian Federation constituting an external threat to the Union or its Member States and in (GU/GRU) cyber-attacks with a significant effect against third States. In particular, military intelligence officers of the GTsSS took part in the cyber-attack against the German federal parliament (Deutscher Bundestag) in April and May 2015 and the attempted cyber-attack aimed at hacking into the Wi-Fi network of the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands in April 2018. The cyber-attack against the German federal parliament targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. Following Russia’s war of aggression against Ukraine, cyber-attacks by the GTsSS (spear-phishing and malware-based attacks) were carried out against Ukraine. ELI: http://data.europa.eu/eli/reg_impl/2024/1390/oj 9/9 OJ L, 17.5.2024 EN

Continue your research