An international operation this week led by France and the Netherlands has taken down a VPN service that was used widely by cybercriminals called First VPN.

The VPN service has been active for more than a decade and is specifically designed for ransomware operators, fraud groups, and other cybercriminals trying to hide malicious activity from law enforcement (among other purposes). First VPN maintained exit nodes in 27 countries, and was used in attacks linked back to at least 25 types of ransomware (including Avaddon ransomware). Its infrastructure was also linked to scanning, botnets, denial of service attacks, scams, and hacking.

“For years, the service, known as ‘First VPN’, was promoted on Russian-speaking cybercrime forums as a trusted tool for remaining beyond the reach of law enforcement,” according to Europol on Thursday. “It offered users anonymous payments, hidden infrastructure, and services designed specifically for criminal use.”

First VPN offered subscription durations ranging from one day to one year, with users paying for the service in cryptocurrency.

Credit: Europol

The law enforcement crackdown disrupted First VPN’s infrastructure, and authorities dismantled 33 servers linked to the criminal service. Additionally, several domain names were shut down, including 1vpns[.]com, 1vpns[.]net, and 1vpns[.]org. The U.S. supported the disruption, and on Thursday the FBI released several Indicators of Compromise (IoCs) linked to First VPN. According to the FBI, there were three US-based exit nodes:  92.223.66[.]103, 5.181.234[.]59, and 92.38.148[.]58. 

Indicators from FBI. Credit: FBI Flash Report

Europol said that the takedown occurred after an investigation that was launched all the way back in 2021. 

“Working with Europol’s European Cybercrime Centre, investigators gained access to the service, obtained its user database and identified VPN connections used by cybercriminals seeking to conceal their activities,” according to Europol. “The gathered intelligence exposed thousands of users linked to the cybercrime ecosystem and generated operational leads connected to ransomware attacks, fraud schemes, and other serious offences worldwide.”

The bigger takeaway here, though, is that law enforcement is increasingly targeting the “infrastructure layer” of cybercrime, rather than ransomware operators themselves. This is an effort to hit cybercriminals across all aspects of their operations, including attempts to stay anonymous and hidden during attacks. Other recent takedowns have included ones targeting bulletproof hosting providers, residential proxy networks, and more.