Official Gazette Notification Text
Official TranscriptOfficial Journal EN of the European Union L series 2026/1714 13.7.2026 COUNCIL IMPLEMENTING REGULATION (EU) 2026/1714 of 13 July 2026 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, Having regard to Council...
Official Journal EN of the European Union L series 2026/1714 13.7.2026 COUNCIL IMPLEMENTING REGULATION (EU) 2026/1714 of 13 July 2026 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, Having regard to Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States(1), and in particular Article 13(1) thereof, Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy,
Whereas:
(1) On 17 May 2019, the Council adopted Regulation (EU) 2019/796.
(2) As part of the sustained, tailored and coordinated Union action against persistent cyber threat actors, eight natural persons and four entities should be added to the list of natural and legal persons, entities and bodies subject to restrictive measures set out in Annex I to Regulation (EU) 2019/796. Those persons and entities are responsible for, or involved in, cyber-attacks with a significant effect which constitute an external threat to the Union or its Member States.
(3) Annex I to Regulation (EU) 2019/796 should therefore be amended accordingly,
HAS ADOPTED THIS REGULATION:
Article 1 Annex I to Regulation (EU) 2019/796 is amended in accordance with the Annex to this Regulation.
Article 2 This Regulation shall enter into force on the date of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 13 July 2026.
For the Council The President K. KALLAS
(1) OJ L 129 I, 17.5.2019, p. 1, ELI: http://data.europa.eu/eli/reg/2019/796/oj.
ELI: http://data.europa.eu/eli/reg_impl/2026/1714/oj 1/13ANNEX Annex I to Regulation (EU) 2019/796 is amended as follows:
(1) the following entries are added under the heading ‘A. Natural persons’:
Name Identifying information Reasons Date of listing ‘20. Vitaly Nikolayevich KOVALEV Виталий Николаевич КОВАЛЕВ Vitaly Kovalev is a senior figure in the malware programs “Trickbot” and “Conti”. 13.7.2026 He is also known by the online monikers “Bentley”, “Bergen”, “Alex Konor”,
Aliases: “Bentley”, “Bergen”, “Alex Konor”, “Benny”, “Ben” and “Stern”. “Benny”, “Ben”, “Stern” Conti and Trickbot were originally created and developed by Wizard Spider.
DOB: 23.6.1988 Wizard Spider has conducted ransomware campaigns in a variety of sectors,
Address: Serebristy Bulvar 34 (Serebristyy including essential services such as health and banking, has infected computers Bul’var); krp 1; flt 528; 197341; St Petersburg, worldwide and their malware has been developed into a highly modular malware Russian Federation suite. Campaigns by Wizard Spider, using malware such as Conti, and TrickBot, are responsible for substantial economic damage in the European Union.
Nationality: Russian Vitaly Kovalev is therefore responsible for, and involved in, cyber-attacks with
Gender: male a significant effect which constitute an external threat to the Union or its Member States.
Associated entities: TrickBot, Wizard Spider, Conti 2/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
21. Alexander Alexandrovich Александр Александрович ВОЛОСОВИК Alexander Volosovik is the owner of Media Land LLC. Since 2016, Bullet Proof 13.7.2026 VOLOSOVIK Hosting service Media Land LLC has been facilitating a wide array of malware
DOB: 30.1.1983 attacks against both the Union and globally, by offering hosting services that hide
POB: USSR user identities and resist takedowns by law enforcement. Media Land LLC enabled large-scale ransomware operations, command-and-control services, and phishing
Nationality: Russian operations that target critical infrastructure and essential services in the Member States, leading to significant financial losses. Operations facilitated by Media Land
Passport number: 762988138 LLC include, inter alia, LockBit, EvilCorp and BlackBasta.
Gender: male Therefore, Media Land LLC is involved in cyber-attacks with significant effect
Associated entities: Yalishanda, LARVA-34, which constitute an external threat to the Union or its Member States. As owner podzemniyl, Ohyeahhellno, Stas_vl, downlow of Media Land LLC, Alexander Volosovik is responsible for, and involved in, these cyber-attacks. He is also associated to Media Land LLC.
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 3/13 OJ L,
13.7.2026 ENName Identifying information Reasons Date of listing
22. Denis Olegovich Денис Олегович ДЕГТЯРЕНКО Denis Degtyarenko aka Dena is a Russian hacker for CARR (Cyber Army of Russia 13.7.2026 DEGTYARENKO Reborn).
Alias: “Dena” CARR has been responsible for cyber-attacks against services necessary for the
DOB: 9.10.1989 maintenance of essential economic activities and critical state functions in the
POB: USSR Member States, as well as against infrastructure in Ukraine and other third countries. CARR is linked to the Main Centre for Special Technologies (GTsST)
Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).
Gender: male The GTsST remains active in carrying out cyber-attacks against the Union or its
Address: 130 Lenina Avenue, Novy Gorod Member States. CARR’s targets include government agencies, financial microdistrict, Orsk, Orenburg Region, Russian institutions, media outlets, and critical infrastructure in the Member States and the Federation United States. CARR has conducted distributed denial-of-service (DDoS) attacks in Ukraine and against governments and companies located in countries that have supported Ukraine.
Therefore, Denis Degtyarenko, a primary hacker for CARR, is involved in cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as against third states. As a member of CARR, he is also associated to GTsST.
4/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
23. Yuliya Vladimirovna Юлия Владимировна ПАНКРАТОВА Yuliya Pankratova is a Russian hacker who has been working for CARR (Cyber 13.7.2026 PANKRATOVA Army of Russia Reborn) and has founded, and continues to work for Z-Pentest.
Alias: “YUliYA” CARR has been responsible for cyber attacks against services necessary for the
DOB: 6.4.1984 maintenance of essential economic activities and critical state functions in the
POB: USSR Member States, as well as against infrastructure in Ukraine and other third countries. CARR is linked to the Main Centre for Special Technologies (GTsST)
Nationality: Russian within the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). The GTsST remains active in carrying out cyber-attacks
Gender: female against the Union or its Member States. CARR’s targets include government
Address: 130 Lenina Avenue, Novy Gorod agencies, financial institutions, media outlets, and critical infrastructure in microdistrict, Orsk, Orenburg Region, Russian Member States and the United States. CARR has conducted distributed Federation denial-of-service (DDoS) attacks in Ukraine and against governments and companies located in countries that have supported Ukraine.
Z-Pentest is responsible for cyber-attacks with a significant effect against inter alia services necessary for the maintenance of essential activities in the Member States.
Therefore, Yuliya Pankratova, a primary hacker for CARR and for Z-Pentest, is involved in cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as against third states. She is also associated to Z-Pentest.
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 5/13 OJ L,
13.7.2026 ENName Identifying information Reasons Date of listing
24. Maksim Evgenevich VORONIN Максим Евгеньевич ВОРОНИН Maksim Voronin aka Daugn0 is involved in the development, distribution and 13.7.2026 selling of the information stealing malware LummaC2 (aka Lumma Infostealer,
Alias: “Daugn0” Lumma Stealer).
Nationality: allegedly Russian LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data,
Gender: male browser credentials, crypto wallets, or system info, to deploy additional malware on infected devices, for cryptocurrency theft and for espionage campaigns.
Cyberattacks involving LummaC2 malware are used also by financially motivated cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and others. LummaC2 malware has been used for cyber-attacks against critical state functions and services necessary for the maintenance of essential social and economic activities of the Members States. In 2024 and 2025, LummaC2 was one of the most used tools for stealing information worldwide.
Therefore, Maksim Voronin as developer, distributor and seller of LummaC2 is involved in and facilitates cyberattacks with a significant effect, which constitute an external threat to the Member States.
6/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
25. Maksim Aleksandrovich Максим Александрович ГОРДИЕНКО Maksim Gordienko aka Lummaseller is involved in the development and 13.7.2026 GORDIENKO distribution of the information stealing malware LummaC2 (aka Lumma
Alias: “Lummaseller” Infostealer, Lumma Stealer). a.k.a. Maxim Alexandrovich
Nationality: allegedly Russian GORDIENKO LummaC2 is a Malware-as-a-Service (MaaS) platform, used to steal sensitive data,
Gender: male browser credentials, crypto wallets or system info, to deploy additional malware on infected devices, for cryptocurrency theft and for espionage campaigns.
Cyberattacks involving LummaC2 malware are used also by financially motivated cyber threat actors like Storm-113, Storm-1607, Storm-1674, Octo Tempest and others. LummaC2 malware has been used for cyber-attacks against critical state functions and services necessary for the maintenance of essential social and economic activities of the Member States. In 2024 and 2025 LummaC2 was one of the most used tools for stealing information worldwide.
Therefore, Maksim Gordienko as developer, distributor and seller of LummaC2 is involved in and facilitates cyberattacks with a significant effect, which constitute an external threat to the Member States.
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 7/13 OJ L,
13.7.2026 ENName Identifying information Reasons Date of listing
26. Evgeniy Viktorovich BASHEV Евгений Викторович БАШЕВ Evgeniy Bashev is a member of Russian Military Intelligence Agency GRU, Unit 13.7.2026
29155. Within the unit he supports and facilitates cyber-attacks with a significant
DOB: 25.1.1980 effect against the Member States, inter alia via controlling the server “Aegon”, used
POB: USSR for hacking operations. In particular, he provides technical and material support to the cyber-attacks of the GRU Unit 29155 through his company “Impuls” LLC,
Nationality: Russian which facilitated operational cover, infrastructure, and payments, and managed technical assets, including servers, that are used for the cyber-attacks. He also
Gender: male coordinated cooperation between GRU structures and external hacker networks.
Associated individuals: Denis Igorevich The cyber-attacks he facilitated targeted critical state functions systems and Denisenko, Yuriy Fedorovich Denisov, Dmitriy services necessary for the maintenance of essential social or economic activities in Yuryevich Goloshubov, Nikolay Alexandrovich the Member States, notably in the transport sector. Via the WhisperGate Korchagin campaign, GRU Unit 29155 also targeted critical infrastructure of Ukraine.
Associated entities: GRU Unit 29155, “Impuls” Therefore, Evgeniy Bashev provides technical and material support for, or is LLC otherwise involved in, cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as cyber-attacks with a significant effect against a third country.
As owner and General Director, he is associated with the company “Impuls” LLC.
As a Member of GRU Unit 29155, he is also associated with that entity.
8/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
27. Roman Alexandrovich PUNTUS Роман Александрович ПУНТУС Roman Puntus is a member of the Russian Military Intelligence Agency GRU, Unit 13.7.2026’;
29155. Within the unit, he holds a leading role in the organisation and
POB: Russian Federation coordination of cyber-attacks with a significant effect against the Member States.
Nationality: Russian He also supports the development of the unit’s internal cyber capability, including the recruitment and supervision of personnel such as hackers and programmers.
Gender: male By establishing the front company “Aegeon-Impulse,” he facilitated logistical and financial aspects of cyber operations. Under his coordination, the unit conducted
Associated individuals: Denis Igorevich cyber-attacks targeting critical state functions systems and services necessary for Denisenko, Yuriy Fedorovich Denisov, Dmitriy the maintenance of essential social or economic activities in the Member States, Yuryevich Goloshubov, Nikolay Alexandrovich notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155 Korchagin, Evgeniy Viktorovich Bashev also targeted critical infrastructure of Ukraine.
Associated entities: GRU Unit 29155 Therefore, Roman Puntus is responsible for, or is otherwise involved in, cyber-attacks with a significant effect, including attempted cyber-attacks with a potentially significant effect, which constitute an external threat to the Member States, as well as cyber-attacks with a significant effect against a third country.
As a Member of GRU Unit 29155, he is also associated with that entity.
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 9/13 OJ L,
13.7.2026 EN(2) the following entries are added under the heading ‘B. Legal persons, entities and bodies’:
Name Identifying information Reasons Date of listing ‘8. Media Land LLC Address: Tsvetnochnaya st., 16 Litera P, Room Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating 13.7.2026 27, Moskovskaya Zastava Municipal District a wide array of malware attacks against the Member States and globally, by offering hosting services that hide user identities and resist takedowns by law St Petersburg, 196006, Russian Federation enforcement, leading to significant financial losses. Media Land LLC enabled
Type of entity: Limited Liability Company large-scale ransomware operations, command-and-control services, and phishing operations that target critical infrastructure and essential services among the
Place of registration: St Petersburg Member States. Operations facilitated by Media Land LLC include, inter alia, LockBit, EvilCorp and BlackBasta.
Date of registration: 19.10.2015 Therefore, Media Land LLC is involved in cyber-attacks with a significant effect,
Registration number: 1152536009900 which constitute an external threat to the Member States.
Principal place of business: St Petersburg, Russian Federation
Associated entity: ML.Cloud 10/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
9. ML.Cloud Address: Brivibas iela 52, Riga, LV-1011, ML.Cloud is the sister company of Media Land LLC, and provides the technical 13.7.2026 Latvija; Russian Federation, Kazan, infrastructure for Media Land LLC.
Peterburgskaya st. 52 Since 2016, Bullet Proof Hosting service Media Land LLC has been facilitating
Place of registration: Riga a wide array of malware attacks against the Member States and globally, by offering hosting services that hide user identities and resist takedowns by law
Associated individual: Alexander Volosovik enforcement, leading to significant financial losses. Media Land LLC enabled
Other associated entities: Media Land LLC large-scale ransomware operations, command-and-control services, and phishing operations that target critical infrastructure and essential services among the Member States. Operations facilitated by Media Land LLC include, inter alia, LockBit, EvilCorp and BlackBasta.
Therefore, Media Land LLC is involved in cyber- attacks that constitute an external threat with significant effect to EU Member States.
Therefore, ML. Cloud provides technical support for cyber-attacks with a significant effect, which constitute an external threat to the Member States.
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 11/13 OJ L,
13.7.2026 ENName Identifying information Reasons Date of listing
10. “Impuls” LLC Общество с ограниченной ответственностью “Impuls” LLC is a Russian company owned by Evgeniy Viktorovich Bashev, 13.7.2026 “Импульс” a member of Russian Military Intelligence Agency GRU, Unit 29155. The company provides technical and material support to cyber-attacks and attempted
Address: 344015, Russian Federation, Rostov cyber-attacks conducted by GRU Unit 29155. In particular, “Impuls” LLC serves as Region, Rostov-on-Don, ul. Eremenko, d. 56, an operational intermediary enabling hacking-related activities to be carried out k. 6, apt. 88 through a company formally unconnected to the Russian State. It facilitated
Type of entity: Limited Liability Company operational cover, infrastructure and payments for cyber-attacks, and was connected to technical assets, including servers used in support of hacking
Place of registration: Interdistrict Inspectorate activities. In particular, “Impuls” LLC enabled cooperation between GRU of the Federal Tax Service No. 26 for the Rostov structures and external hacker networks. The cyber operations facilitated by Region, 344019, Rostov-on-Don, ul. “Impuls” LLC target critical state functions and services necessary for the Myasnikova, d. 52/32, Russian Federation maintenance of essential social and economic activities in the Member States, notably in the transport sector. Via the WhisperGate campaign, GRU Unit 29155
Date of registration: 27.9.2010 also targeted critical infrastructure of Ukraine.
Registration number: INN (ИНН):
Therefore, “Impuls” LLC provides technical and material support for, or is 6168033776; OGRN (ОГРН): otherwise involved in, cyber-attacks with a significant effect, which constitute an 1106194004850 external threat to the Member States, as well as cyber-attacks with a significant
Principal place of business: Russian Federation effect against a third country.
Associated individuals: Evgeniy Bashev
Associated entities: GRU Unit 29155 12/13
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj EN OJ L,
13.7.2026Name Identifying information Reasons Date of listing
11. Z-Pentest Aliases: “Z-Pentest Alliance”, “Z-Alliance” Z-Pentest is a pro-Russia hacktivist group, composed of members from CARR 13.7.2026’. (Cyber Army of Russia Reborn) and NoName057, globally targeting critical
Principal place of business: Russian Federation infrastructure, especially the energy and water sector.
Associated individuals: Yuliya Pankratova Notably, the group attacked a Danish water utility in December 2024.
Associated entities: Cyber Army of Russia Therefore, Z-Pentest is responsible for cyber-attacks with a significant effect, Reborn/CARR which constitute an external threat to the Member States.
X.com account: ZPentest (Account suspended)
Telegram account: Zpentestalliance
ELI:
http://data.europa.eu/eli/reg_impl/2026/1714/oj 13/13 OJ L,
13.7.2026 EN