← Aeza Group1 decision on this page
Audit log
Every state-changing event for Aeza Group: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-31 17:05:48ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
9h37s5MrAq4B…zUyEFSjFsha256 → base58
verifying row…canonical bytes (26718 B) ▸
{"actor":"system:backfill","investigation_id":"2cb7c225-a47f-4b55-92aa-fc696b074596","kind":"publish","page_slug":"aeza-group","published_at":"2026-07-31T17:05:48.538Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Aeza Group","sections":[{"content":"Aeza Group LLC (Russian tax registration INN: 7813654490) is a hosting company incorporated in Saint Petersburg, Russia. Its origins trace to 2019 when co-founders Arseniy Penzev and Yuri Bozoyan worked together at a hosting company called MskHost. Following what Russian sources described as a 'hack' of MskHost in September 2021, the group rebranded sequentially under the names 'ЕНОТКЛАУД' (Enotcloud), then 'ПАРТНЕР' in November 2021, and finally 'АЕЗА ГРУПП' (Aeza Group) in November 2022. The company marketed itself as a legitimate provider of cybersecurity, web hosting, and IT services, while allegedly operating as a bulletproof hosting provider that knowingly ignored abuse reports and shielded criminal clients from law enforcement action. Aeza's Saint Petersburg headquarters was located in the former Wagner PMC Center. A UK-registered subsidiary, Aeza International Ltd., was used to lease IP addresses to cybercriminal clients.","heading":"Entity Overview","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0185"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"}]},{"content":"On July 1, 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Aeza Group LLC and four affiliated entities under Executive Order 13694 (as amended by E.O. 14144 and 14306), citing cyber-enabled activities threatening U.S. national security, foreign policy, and economic health. The action was coordinated with the United Kingdom's National Crime Agency (NCA). The following entities were designated: Aeza Group LLC (Russia), Aeza International Ltd. (UK), Aeza Logistic LLC (Russia), and Cloud Solutions LLC (Russia). Four individuals were also designated: CEO and 33% owner Arsenii Aleksandrovich Penzev; General Director and 33% owner Yurii Meruzhanovich Bozoyan; Technical Director Vladimir Vyacheslavovich Gast; and 33% part-owner Igor Anatolyevich Knyazev. OFAC also designated one TRON cryptocurrency address associated with the entity (TU4tDFRvcKhAZ1jdihojmBWZqvJhQCnJ4F), which Chainalysis reported had received more than $350,000 in cryptocurrency, with funds cashed out at multiple global exchanges including connections to the previously sanctioned Garantex exchange. The designation froze any U.S.-based assets of the designated parties and prohibited U.S. persons from transacting with them.","heading":"OFAC Sanctions — July 2025","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0185"},{"credibility":1,"name":"Federal Register Notice of OFAC Sanctions Action (2025-12471)","type":"regulatory","url":"https://www.federalregister.gov/documents/2025/07/03/2025-12471/notice-of-ofac-sanctions-action"},{"credibility":2,"name":"OFAC Sanctions Aeza Group for Hosting Global Bulletproof Service – Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/ofac-sanctions-aeza-group-bulletproof-hosting-crypto-payments-july-2025/"},{"credibility":2,"name":"US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations – CyberScoop","type":"news_article","url":"https://cyberscoop.com/bulletproof-hosting-provider-aezagroup-sanctions/"}]},{"content":"On November 19, 2025, OFAC, Australia's Department of Foreign Affairs and Trade (DFAT), and the UK's Foreign, Commonwealth & Development Office (FCDO) jointly announced a second round of sanctions targeting Aeza Group's sanctions evasion infrastructure. Following the July 2025 designation, Aeza leadership allegedly initiated a rebranding strategy to remove public connections between Aeza and its operational infrastructure. Three new shell companies were designated: Hypercore Ltd. (UK, AS211522, allocated July 10, 2025), to which Aeza began migrating IP ranges by July 20, 2025; Datavice MCHJ (Uzbekistan, established July 2025); and Smart Digital Ideas DOO (Serbia). Two additional individuals were designated: Maksim Vladimirovich Makarov, identified as Aeza's new director who directed the evasion strategy; and Ilya Vladislavovich Zakirov, who allegedly helped establish the new companies and payment methods. Cybersecurity researchers at Silent Push had independently detected and reported the infrastructure migration to Hypercore's AS211522 network, which already contained over 2,100 IP addresses within days of allocation.","heading":"Multilateral Sanctions — November 2025","severity":"critical","sources":[{"credibility":1,"name":"United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware – U.S. Treasury","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0319"},{"credibility":1,"name":"United States, Australia, and United Kingdom Jointly Sanction Ransomware Infrastructure Providers – U.S. Department of State","type":"regulatory","url":"https://www.state.gov/releases/office-of-the-spokesperson/2025/11/united-states-australia-and-united-kingdom-jointly-sanction-ransomware-infrastructure-providers"},{"credibility":2,"name":"Silent Push IOFA Feed Detects Aeza Group Infrastructure Shift Following OFAC Sanctions","type":"research","url":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/"},{"credibility":2,"name":"Bulletproof Host Aeza Group Moves Infrastructure to New Autonomous System – GBHackers","type":"news_article","url":"https://gbhackers.com/bulletproof-host-aeza-group-moves-infrastructure/"}]},{"content":"According to OFAC and corroborating cybersecurity research, Aeza Group provided bulletproof hosting infrastructure to multiple named threat actor groups. BianLian ransomware operators used Aeza infrastructure for attack campaigns. RedLine infostealer panels were hosted within Aeza's network ranges. Meduza infostealer operators, who targeted U.S. defense and technology companies among other victims globally, relied on Aeza servers. Lumma infostealer operators similarly used Aeza infrastructure to target U.S. defense and technology entities. Additional malware families identified by Qurium Media Foundation within Aeza network prefixes include Aurora, SystemBC, and AsyncRat. Aeza also allegedly hosted the Doppelganger pro-Kremlin influence operation's front domains beginning in July 2022, operating from the same network ranges as the malware command-and-control servers. Aeza's primary autonomous systems identified in security research include AS210352, AS211409, and AS210644 (the latter operated through Aeza International Ltd. in the UK).","heading":"Hosted Cybercriminal Operations","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0185"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"credibility":2,"name":"US Treasury Sanctions Global Bulletproof Hosting Service Aeza Group For Enabling Cybercriminal Activity – TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/treasury-sanctions-global-bulletproof-hosting-service-aeza-group-for-enabling-cybercriminal-activity"},{"credibility":2,"name":"Russian bulletproof hosting service Aeza Group sanctioned by US for ransomware work – The Record","type":"news_article","url":"https://therecord.media/russia-bulletproof-hosting-aeza-group-us-sanctions"}]},{"content":"Aeza Group is alleged to have provided sustained technical infrastructure to BlackSprut, a Russian-language darknet marketplace that succeeded the shut-down Hydra market and facilitated illicit drug sales including fentanyl precursor chemicals and manufacturing equipment. According to OFAC and the Qurium Media Foundation, Aeza protected BlackSprut from Denial-of-Service attacks for approximately two years. CEO Arsenii Penzev and General Director Yurii Bozoyan allegedly began providing BlackSprut with services in 2023. Technical Director Vladimir Gast was identified by OFAC as specifically responsible for overseeing the technical details of placing BlackSprut on Aeza Group's infrastructure. Russian investigative accounts indicate the investigation was triggered after an undercover officer purchased 4.19 grams of mephedrone through the marketplace. BlackSprut operated through approximately 16 front-end domains (including bs2best[.]at and bs2c[.]io) across IP addresses primarily within Aeza's AS210352 and AS211409 networks.","heading":"BlackSprut Darknet Marketplace","severity":"critical","sources":[{"credibility":1,"name":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0185"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"credibility":2,"name":"Russian Hosting Provider Aeza Group Sanctioned for Aiding Hackers and Darknet Drug Markets – SlowMist","type":"research","url":"https://slowmist.medium.com/russian-hosting-provider-aeza-group-sanctioned-for-aiding-hackers-and-darknet-drug-markets-b545b5919a88"}]},{"content":"In early April 2025, Russian law enforcement — including the Federal Security Service (FSB) — conducted a raid on Aeza Group's Saint Petersburg headquarters. The following individuals were arrested: co-founders Arseniy Penzev and Yuri Bozoyan, along with employees Maxim Orel, Tatyana Zubova, Georgy Lavrukhin, and Technical Director Vladimir Gasta. Penzev and Bozoyan were charged under Articles 210 and 228.1 of the Russian Criminal Code for participation in an organized criminal group and large-scale drug trafficking. Russian media described the pair as having provided the 'technical base' for BlackSprut's operations. Following the arrests, part-owner Igor Knyazev assumed operational control of the entity, and security researchers noted that Aeza's services continued operating with, according to reports, 'no significant changes.' The Russian arrests were notable given Russia's general tolerance of cybercriminal activity directed at Western targets; analysts have noted the charges were specifically tied to the domestic drug trafficking operation rather than to the foreign-targeted cyberattacks.","heading":"Arrests of Leadership by Russian Authorities","severity":"high","sources":[{"credibility":2,"name":"Russia arrests CEO of tech company linked to Doppelganger disinformation campaign – The Record","type":"news_article","url":"https://therecord.media/doppelganger-ceo-arrests-russia-tech"},{"credibility":2,"name":"Russia arrests executives of company linked to Doppelganger disinformation group – InCyber News","type":"news_article","url":"https://incyber.org/en/article/russia-arrests-executives-of-company-linked-to-doppelganger-disinformation-group/"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"credibility":2,"name":"US Sanctions Russian Tech Firm for Aiding Cybercrime – OCCRP","type":"news_article","url":"https://www.occrp.org/en/news/us-sanctions-russian-tech-firm-for-aiding-cybercrime"}]},{"content":"Aeza Group allegedly hosted infrastructure for the Doppelganger disinformation campaign, a Russian state-aligned influence operation active since at least May 2022. The Doppelganger operation published fake articles mimicking major Western media outlets — including Germany's Der Spiegel and Britain's The Guardian — to amplify pro-Russian narratives and sow division in Western societies. Qurium Media Foundation identified Aeza as hosting early Doppelganger front domains beginning in July 2022, operating within the same network ranges as Aeza-hosted malware command-and-control servers. OFAC's July 2025 sanctions against Aeza Group referenced ties to the Doppelganger network. Researchers noted the co-location of disinformation infrastructure with criminal malware hosting as illustrative of Aeza's permissive, multi-use model for its clients.","heading":"Doppelganger Disinformation Infrastructure","severity":"high","sources":[{"credibility":2,"name":"U.S. sanctions AEZA Group for supporting pro-Kremlin disinformation network Doppelganger – The Insider","type":"news_article","url":"https://theins.press/en/news/282709"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"credibility":2,"name":"Doppelganger (disinformation campaign) – Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/Doppelganger_(disinformation_campaign)"}]},{"content":"OFAC's July 2025 designation included one TRON-network cryptocurrency address (TU4tDFRvcKhAZ1jdihojmBWZqvJhQCnJ4F) associated with Aeza Group's payment operations. Chainalysis analysis found the address received more than $350,000 in cryptocurrency. The wallet functioned as an administrative account: it handled cash-outs from Aeza's payment processor, forwarded funds to various global exchanges, and received direct payments for services. Connections were identified between this address and Garantex, a Russia-based cryptocurrency exchange that was itself sanctioned by OFAC in 2022 for facilitating transactions for ransomware operators and darknet markets. Aeza accepted cryptocurrency payments for its hosting services, providing a degree of anonymity to clients. This use of cryptocurrency to receive payments from cybercriminal clients and to route proceeds through sanctioned exchanges constitutes significant blockchain-layer risk for any counterparty.","heading":"Cryptocurrency Payments and Blockchain Exposure","severity":"critical","sources":[{"credibility":2,"name":"OFAC Sanctions Aeza Group for Hosting Global Bulletproof Service – Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/ofac-sanctions-aeza-group-bulletproof-hosting-crypto-payments-july-2025/"},{"credibility":2,"name":"U.S. Treasury Sanctions Crypto Wallet Tied to Russian Bulletproof Host Aeza Group – Crypto Daily","type":"news_article","url":"https://cryptodaily.co.uk/2025/07/us-treasury-sanctions-crypto-wallet-tied-to-russian-bulletproof-host-aeza-group"},{"credibility":2,"name":"US Treasury Sanctions Global Bulletproof Hosting Service Aeza Group For Enabling Cybercriminal Activity – TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/treasury-sanctions-global-bulletproof-hosting-service-aeza-group-for-enabling-cybercriminal-activity"}]},{"content":"Following the July 1, 2025 OFAC designation, Aeza Group allegedly continued operating and undertook active measures to evade sanctions. Within ten days of the initial designation, Hypercore Ltd. was registered in the UK and assigned autonomous system number AS211522. By July 20, 2025, security researchers at Silent Push detected IP ranges migrating from Aeza's original AS210644 to AS211522, which had already accumulated over 2,100 IP addresses. Two additional entities — Datavice MCHJ (Uzbekistan) and Smart Digital Ideas DOO (Serbia) — were also established in July 2025 as alleged front companies for Aeza's infrastructure. New director Maksim Vladimirovich Makarov and associate Ilya Vladislavovich Zakirov were identified as the primary architects of this evasion strategy. These entities were all designated in the November 2025 multilateral sanctions action. Investigative reporting by VSquare.org noted that Aeza continued registering new domains daily even while operating under sanctions, and that its infrastructure remained partly accessible within the European Union.","heading":"Sanctions Evasion and Continued Operations","severity":"critical","sources":[{"credibility":1,"name":"United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware – U.S. Treasury","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0319"},{"credibility":2,"name":"Bulletproof Host Aeza Group Moves Infrastructure to New Autonomous System – GBHackers","type":"news_article","url":"https://gbhackers.com/bulletproof-host-aeza-group-moves-infrastructure/"},{"credibility":2,"name":"From Darknet to Disinfo: How a Bulletproof Russian Host Evades EU Sanctions – VSquare.org","type":"news_article","url":"https://vsquare.org/sanctions-west-prosecuted-in-russia-aeza-still-working-in-the-eu-doppelganger/"},{"credibility":2,"name":"Silent Push IOFA Feed Detects Aeza Group Infrastructure Shift Following OFAC Sanctions","type":"research","url":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/"}]}],"sources_used":[{"credibility":1,"name":"Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0185"},{"credibility":1,"name":"United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sb0319"},{"credibility":1,"name":"United States, Australia, and United Kingdom Jointly Sanction Ransomware Infrastructure Providers – U.S. Department of State","type":"regulatory","url":"https://www.state.gov/releases/office-of-the-spokesperson/2025/11/united-states-australia-and-united-kingdom-jointly-sanction-ransomware-infrastructure-providers"},{"credibility":1,"name":"Federal Register Notice of OFAC Sanctions Action (2025-12471)","type":"regulatory","url":"https://www.federalregister.gov/documents/2025/07/03/2025-12471/notice-of-ofac-sanctions-action"},{"credibility":2,"name":"Disinformation, Malware and Drugs: Aeza's cyber crime portfolio – Qurium Media Foundation","type":"research","url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"credibility":2,"name":"OFAC Sanctions Aeza Group for Hosting Global Bulletproof Service – Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/ofac-sanctions-aeza-group-bulletproof-hosting-crypto-payments-july-2025/"},{"credibility":2,"name":"US Treasury Sanctions Global Bulletproof Hosting Service Aeza Group For Enabling Cybercriminal Activity – TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/treasury-sanctions-global-bulletproof-hosting-service-aeza-group-for-enabling-cybercriminal-activity"},{"credibility":2,"name":"Russian bulletproof hosting service Aeza Group sanctioned by US for ransomware work – The Record","type":"news_article","url":"https://therecord.media/russia-bulletproof-hosting-aeza-group-us-sanctions"},{"credibility":2,"name":"US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations – CyberScoop","type":"news_article","url":"https://cyberscoop.com/bulletproof-hosting-provider-aezagroup-sanctions/"},{"credibility":2,"name":"Russia arrests CEO of tech company linked to Doppelganger disinformation campaign – The Record","type":"news_article","url":"https://therecord.media/doppelganger-ceo-arrests-russia-tech"},{"credibility":2,"name":"US Sanctions Russian Tech Firm for Aiding Cybercrime – OCCRP","type":"news_article","url":"https://www.occrp.org/en/news/us-sanctions-russian-tech-firm-for-aiding-cybercrime"},{"credibility":2,"name":"Silent Push IOFA Feed Detects Aeza Group Infrastructure Shift Following OFAC Sanctions","type":"research","url":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/"},{"credibility":2,"name":"Bulletproof Host Aeza Group Moves Infrastructure to New Autonomous System – GBHackers","type":"news_article","url":"https://gbhackers.com/bulletproof-host-aeza-group-moves-infrastructure/"},{"credibility":2,"name":"From Darknet to Disinfo: How a Bulletproof Russian Host Evades EU Sanctions – VSquare.org","type":"news_article","url":"https://vsquare.org/sanctions-west-prosecuted-in-russia-aeza-still-working-in-the-eu-doppelganger/"},{"credibility":2,"name":"U.S. sanctions AEZA Group for supporting pro-Kremlin disinformation network Doppelganger – The Insider","type":"news_article","url":"https://theins.press/en/news/282709"},{"credibility":2,"name":"Aeza Group sanctioned for hosting ransomware, infostealer servers – BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/aeza-group-sanctioned-for-hosting-ransomware-infostealer-servers/"},{"credibility":2,"name":"U.S. Treasury Sanctions Crypto Wallet Tied to Russian Bulletproof Host Aeza Group – Crypto Daily","type":"news_article","url":"https://cryptodaily.co.uk/2025/07/us-treasury-sanctions-crypto-wallet-tied-to-russian-bulletproof-host-aeza-group"},{"credibility":2,"name":"Russia arrests executives of company linked to Doppelganger disinformation group – InCyber News","type":"news_article","url":"https://incyber.org/en/article/russia-arrests-executives-of-company-linked-to-doppelganger-disinformation-group/"},{"credibility":2,"name":"Russian Hosting Provider Aeza Group Sanctioned for Aiding Hackers and Darknet Drug Markets – SlowMist","type":"research","url":"https://slowmist.medium.com/russian-hosting-provider-aeza-group-sanctioned-for-aiding-hackers-and-darknet-drug-markets-b545b5919a88"},{"credibility":2,"name":"US cracks down on Russian bulletproof hosting services enabling cybercrime – Elliptic","type":"research","url":"https://www.elliptic.co/blog/us-cracks-down-on-russian-bulletproof-hosting-services"}],"summary":"Aeza Group LLC is a Russia-based bulletproof hosting (BPH) provider headquartered in Saint Petersburg, sanctioned by the U.S. Treasury's OFAC on July 1, 2025 for knowingly providing server infrastructure to ransomware operators, infostealer campaigns, and the BlackSprut darknet drug marketplace. Its founders were arrested by Russian authorities in April 2025 on drug trafficking and organized crime charges, and a second round of multilateral sanctions by the U.S., UK, and Australia in November 2025 targeted the shell companies Aeza established to evade the initial designation.","timeline":[{"date":"2019-01-01","event":"Arseniy Penzev and Yuri Bozoyan begin working together at Russian hosting company MskHost, laying the groundwork for their future operations.","source":"Qurium Media Foundation","source_url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"date":"2021-09-01","event":"MskHost is reported to have been 'hacked'; the founders subsequently rebrand and establish new hosting operations under the name Enotcloud.","source":"Qurium Media Foundation","source_url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"date":"2021-11-01","event":"Entity rebrands to 'ПАРТНЕР' (Partner), continuing hosting operations.","source":"Qurium Media Foundation","source_url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"date":"2022-07-01","event":"Aeza network infrastructure begins hosting early front domains for the Doppelganger pro-Kremlin disinformation campaign, co-located with malware C2 servers.","source":"Qurium Media Foundation","source_url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"date":"2022-11-01","event":"Entity formally rebrands to 'АЕЗА ГРУПП' (Aeza Group LLC), the name under which it will be sanctioned.","source":"Qurium Media Foundation","source_url":"https://www.qurium.org/alerts/aeza-blacksprut-and-disinformation/"},{"date":"2023-01-01","event":"CEO Arsenii Penzev and General Director Yurii Bozoyan allegedly begin providing technical infrastructure services to the BlackSprut darknet drug marketplace.","source":"U.S. Treasury OFAC","source_url":"https://home.treasury.gov/news/press-releases/sb0185"},{"date":"2025-04-01","event":"Russian FSB and law enforcement raid Aeza Group's Saint Petersburg headquarters. Co-founders Penzev and Bozoyan, along with four other employees, are arrested on charges of participation in an organized criminal group and large-scale drug trafficking related to BlackSprut.","source":"The Record from Recorded Future News","source_url":"https://therecord.media/doppelganger-ceo-arrests-russia-tech"},{"date":"2025-07-01","event":"OFAC designates Aeza Group LLC, Aeza International Ltd. (UK), Aeza Logistic LLC, Cloud Solutions LLC, and four individuals (Penzev, Bozoyan, Gast, Knyazev) under Executive Order 13694. One TRON cryptocurrency address (TU4tDFRvcKhAZ1jdihojmBWZqvJhQCnJ4F) is also designated. Action coordinated with the UK's National Crime Agency.","source":"U.S. Department of the Treasury","source_url":"https://home.treasury.gov/news/press-releases/sb0185"},{"date":"2025-07-10","event":"Hypercore Ltd. is registered in the UK and assigned autonomous system AS211522, alleged to be a front company established to migrate Aeza's IP infrastructure and evade the July 1 sanctions.","source":"Silent Push","source_url":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/"},{"date":"2025-07-20","event":"Security researchers at Silent Push detect mass migration of Aeza Group IP ranges from AS210644 to Hypercore's AS211522, with over 2,100 IP addresses already present in the new autonomous system.","source":"Silent Push","source_url":"https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/"},{"date":"2025-11-19","event":"OFAC, Australia's DFAT, and the UK's FCDO jointly sanction Aeza Group's evasion infrastructure: Hypercore Ltd. (UK), Datavice MCHJ (Uzbekistan), Smart Digital Ideas DOO (Serbia), and two additional individuals — Maksim Makarov and Ilya Zakirov.","source":"U.S. Department of the Treasury","source_url":"https://home.treasury.gov/news/press-releases/sb0319"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 14774a76-ba2a-40f5-8190-8214bb72db15
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.