AntiMalwareJuly 24, 2026🇷🇺Translated from Russian

EU Imposes 21st Sanctions Package Targeting 94 Russian Banks Including Ozon Bank, Yandex Bank and WB Bank

The European Union has approved its 21st sanctions package against Russia, imposing restrictions on 94 banks, the Moscow Exchange, and multiple payment organizations.

Effective 23 July, the measures target Rosselkhozbank, Dom.rf, MTS Bank, Ak Bars, Uralsib, Zenit, Absolut Bank, WB Bank, Ozon Bank, Tochka, Yandex Bank, Post Bank, and other institutions. The list also includes the non-profit organization Mobile Card and the settlement non-bank credit organization Payment Center.

Personal sanctions were applied to Bank of Russia Deputy Chairman Sergey Belov, Russian Railways CEO Oleg Belozerov, and additional individuals. Beyond the financial sector, the package addresses energy, trade, and cryptocurrency activities.

The Moscow Exchange stated that trading and settlements will proceed without changes. Ozon Bank, Tochka, and broker Finam (not included in the sanctions) assured clients that services and payments continue in normal mode.

AFK Sistema described the EU decision as unlawful and pledged to manage the restrictions. Initial operational impacts have already emerged: the Golden Crown payment system halted transfers to Georgia and several other countries after support confirmed that certain routes are temporarily unavailable.

Another potential consequence is the removal of banking applications from App Store and Google Play, following previous precedent with sanctioned Russian banks and VK. Owners of affected banks are advised to retain currently installed applications.

The Russian mission to the EU warned of an adequate response to the new measures.

Related articles

AntiMalwarePolicy & Regulation

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank announced it will cease servicing currency and multicurrency Visa cards starting September 1, 2026, including those whose validity was previously extended until 2030. The bank notified customers via SMS and advised them to close affected cards in advance through the Sberbank Online app or at a branch to avoid access issues with their funds. This decision aligns with ongoing sanctions against Russia, import substitution policies, and the gradual removal of Visa and Mastercard from the Russian market. Central Bank officials, including Elvira Nabiullina and Alla Bakina, have confirmed that international payment systems must exit Russia, with the share of Visa and Mastercard already reduced to less than 17 percent. The National System of Payment Cards continues to incur costs supporting legacy cards while promoting domestic alternatives such as Mir. Customers are encouraged to transfer remaining balances to other accounts to maintain uninterrupted access to their money.

AntiMalwarePolicy & Regulation

.RU and .РФ Registries Stop Disclosing Legal Entity Domain Owners in WHOIS

The domain registries for .RU and .РФ have ceased displaying detailed information about administrators that are legal entities. Previously the WHOIS service revealed the full name of the organization along with its INN tax identification number, but the records now show only the generic term Organization. The change was first noticed on 22 July by Habr user @ifap, who observed that domains previously linked to government bodies such as the Federal Protective Service no longer reveal the actual administrator. Support staff at the Coordination Center attributed the disappearance of data to unspecified technical issues and described the outage as temporary, without providing any timeline or details on the root cause. Observers note that the reduced transparency turns routine owner identification into a lengthy investigation, especially for less prominent domains. One unconfirmed theory suggests the registry is being reconfigured to meet new authentication requirements for domain administrators. It remains unclear whether the previous level of disclosure will be restored or whether the current limited view will become permanent.

HabrPolicy & Regulation

Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments

The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.

AntiMalwarePolicy & Regulation

Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations

The Supreme Court of the Russian Federation has officially recognized the hacker groups Silent Crow and Cyberpartisans BY as extremist organizations and banned their activities in Russia. The closed-door ruling, issued at the request of the General Prosecutor's Office, accuses both groups of conducting joint cyberattacks against Russian and Belarusian critical information infrastructure with the aim of destabilizing the political situation and achieving an unconstitutional change of government. Cyberpartisans BY are described as part of the Belarusian association Supratsiv, which allegedly seeks a violent overthrow of the constitutional order, and are linked to the banned Polk named after Kastus Kalinouski as well as Ukrainian military information-psychological operations units. Silent Crow, previously known as CyberWar and Cyber LegionsUA, is portrayed as a pro-Ukrainian collective of politically motivated hacktivists whose primary objective is to damage Russian state bodies, companies, and critical infrastructure. Both groups are held responsible for attacks on Aeroflot IT systems, Rostelecom databases, Rosreestr servers, and the Belarusian Railway infrastructure. Participation in or support for these organizations now carries legal liability under Russian law.