The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has implemented sanctions against Aeza Group, a Russian-based bulletproof hosting (BPH) provider notorious for aiding cybercriminals worldwide. These BPH services are tailored to withstand takedown efforts and evade law enforcement, thus enabling various unlawful online activities.
In a decisive move against cybercrime, the U.S. Treasury has targeted Aeza Group for its involvement in supporting nefarious actors. The sanctions have also extended to two related companies and four key leaders within the group. Aeza Group’s infrastructure has been crucial for ransomware groups such as BianLian and malware operations like Meduza and Lumma. These groups have carried out attacks against the U.S. defense sector and technology firms globally, often stealing sensitive credentials and personal information to sell on darknet markets.
Moreover, Aeza Group hosted BlackSprut, a significant Russian darknet marketplace dealing with illegal drugs. The Treasury highlighted the role of such platforms in trafficking fentanyl and other narcotics into the U.S. Cybercriminals continue to depend heavily on BPH providers like Aeza Group for orchestrating ransomware attacks, stealing U.S. technology, and distributing drugs on the black market.
This initiative, coordinated with the United Kingdom’s National Crime Agency, effectively freezes all properties and interests of Aeza Group and its leadership in the United States. It also prohibits U.S. individuals and entities from conducting business with them. Among those designated are CEO Arsenii Penzev and General Director Yurii Bozoyan, both of whom have been detained by Russian authorities due to their roles in the BlackSprut marketplace.






