Community intelligence
Verified context on blocklisted addresses comes from the community. Earn a star for every submission an admin verifies - submit intel from any event page.
- @sherlock-botsanctionsirancyberAug 25, 2026, 21:22:54 UTCKeyvan Fayyaz Gareh BLAGHThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (TRX) associated with Keyvan Fayyaz Gareh BLAGH, designated for malicious cyber-enabled activities (CYBER program). Exact address match against the published list. Keyvan Fayyaz Gareh Blagh is an Iranian cyber actor sanctioned under CYBER4 for conducting computer network exploitations on behalf of Iran’s MOIS, including digital asset theft.TP3kVt…NgB6
- @sherlock-botsanctionscyberiranAug 25, 2026, 20:08:37 UTCBehzad MESRIThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (TRX) associated with Behzad MESRI, designated for malicious cyber-enabled activities (CYBER program). Exact address match against the published list. Behzad Mesri is an Iran-based cyber actor designated for malicious cyber campaigns, including targeting U.S. personnel and extortion of a U.S. media company.TAbbVa…inQh
- OfficialiransanctionscyberAug 25, 2026, 12:51:34 UTCBehzad Mezri (a.k.a. "Skote Vahshat")Since at least summer 2023, Mojtaba Ghal’eh-Kuhi and Behzad Mesri have led a group of Iranian malicious cyber actors that includes Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Arman Kahzadian. This group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran’s MOIS.0xF45E…Be91
- @sherlock-botsanctionscyberiranAug 25, 2026, 05:20:44 UTCArman KAHZADIANThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (ETH) associated with Arman KAHZADIAN, designated for malicious cyber-enabled activities (CYBER program). Exact address match against the published list. Arman Kahzadian is an Iranian cyber actor sanctioned under CYBER4 for conducting computer network exploitations and digital asset theft on behalf of Iran’s MOIS, including hacking U.S. universities and companies.0xef85…cE2a
- @sherlock-botsanctionsirancyberAug 25, 2026, 05:20:43 UTCMojtaba GHAL'EH-KUHIThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (ETH) associated with Mojtaba GHAL'EH-KUHI, designated for malicious cyber-enabled activities (CYBER program). Exact address match against the published list. Mojtaba GHAL'EH-KUHI is an Iranian cyber actor designated under CYBER4 for operating on behalf of Iran's Ministry of Intelligence (MOIS).0x1b85…1E6e
- @sherlock-botsanctionsirancyberAug 25, 2026, 05:18:57 UTCAlmpertos TSORISThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (USDT) associated with Almpertos TSORIS, designated under the Iran sanctions program. Exact address match against the published list. Greek national Almpertos "Alberto" Tsoris was sanctioned under E.O. 13902 for coordinating with Iranian actors to provide bunkering services to vessels carrying Iranian crude oil.TJCBpx…SA36
- @sherlock-botsanctionscybermoney-launderingAug 22, 2026, 11:49:02 UTCTornado.CashThis address is the governance proxy contract for Tornado.Cash, a sanctioned mixing service used to obfuscate cryptocurrency transactions and facilitate illicit finance, per OFAC designation under the Cyber-related Sanctions Regulations.0x5efd…A1Ce
- @sherlock-botsanctionsmoney-launderingcyberAug 22, 2026, 11:48:54 UTCTornado CashThis address is linked to the Tornado Cash mixer, a sanctioned virtual currency mixer used to facilitate money laundering, per OFAC designations and public listings.0xffba…9fba
- @sherlock-botsanctionsnorth-koreacybercourt-orderJul 17, 2026, 12:07:59 UTCLazarus GroupPer a court filing, this address is frozen by Circle and attributed to the Lazarus Group, a North Korean state-sponsored hacking group.0xDa2e…0c2c
- @sherlock-botsanctionscyberrussiaJul 15, 2026, 05:13:50 UTCDmytro RASHEVSKYIThis address is listed on the OFAC SDN List as a sanctioned digital-currency address (SOL) associated with Dmytro RASHEVSKYI, designated for malicious cyber-enabled activities (CYBER program). Exact address match against the published list. Dmytro Rashevskyi is the administrator of First VPN Service (1VPNS), sanctioned for providing VPN services to ransomware groups, enabling attacks against Americans.Fc1EwQ…cJdH
Most-reported categories
- sanctions11,763 events
- terrorism4,337 events
- iran3,026 events
- money-laundering2,886 events
- court-order2,512 events
- north-korea2,393 events
- fraud1,329 events
- russia1,083 events
- darknet-market1,060 events
- cyber886 events
- drugs-trafficking712 events
- scam406 events
- ransomware301 events
- theft204 events
- exchange-hack187 events
- kidnapping8 events
- phishing-drainer2 events
Each category counts the distinct blocklisting events that carry verified intel in it (a category counts once per event).
Top contributors
- 1@sherlock-bot1844
- 2@satoshi1