My bookmarksSign up free

Council Implementing Regulation (EU) 2020/1125 of 30 July 2020 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Council Implementing Regulation (EU) 2020/1125 of 30 July 2020 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Implementing Regulation (EU) 2020/1125 · Regulation · 3 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Article 1

Annex I to Regulation (EU) 2019/796 is amended in accordance with the Annex to this Regulation.

Article 2

This Regulation shall enter into force on the date of its publication in the Official Journal of the European Union .

Supplementary provisions

ANNEXSupplementary provisions

ANNEX The following persons and entities or bodies are added to the list of natural and legal persons, entities and bodies set out in Annex I to Regulation (EU) 2019/796: ‘A.   Natural persons   Name Identifying information Reasons Date of listing 1. GAO Qiang Place of birth: Shandong Province, China Address: Room 1102, Guanfu Mansion, 46 Xinkai Road, Hedong District, Tianjin, China Nationality: Chinese Gender: male Gao Qiang is involved in “Operation Cloud Hopper”, a series of cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and of cyber-attacks with a significant effect against third States. “Operation Cloud Hopper” targeted information systems of multinational companies in six continents, including companies located in the Union, and gained unauthorised access to commercially sensitive data, resulting in significant economic loss. 30.7.2020 The actor publicly known as “APT10” (“Advanced Persistent Threat 10”) (a.k.a. “Red Apollo”, “CVNX”, “Stone Panda”, “MenuPass” and “Potassium”) carried out “Operation Cloud Hopper”. Gao Qiang can be linked to APT10, including through his association with APT10 command and control infrastructure. Moreover, Huaying Haitai, an entity designated for providing support to and facilitating “Operation Cloud Hopper”, employed Gao Qiang. He has links with Zhang Shilong, who is also designated in connection with “Operation Cloud Hopper”. Gao Qiang is therefore associated with both Huaying Haitai and Zhang Shilong. 2. ZHANG Shilong Address: Hedong, Yuyang Road No 121, Tianjin, China Nationality: Chinese Gender: male Zhang Shilong is involved in “Operation Cloud Hopper”, a series of cyber‐attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and of cyber‐attacks with a significant effect against third States. “Operation Cloud Hopper” has targeted information systems of multinational companies in six continents, including companies located in the Union, and gained unauthorised access to commercially sensitive data, resulting in significant economic loss. The actor publicly known as “APT10” (“Advanced Persistent Threat 10”) (a.k.a. “Red Apollo”, “CVNX”, “Stone Panda”, “MenuPass” and “Potassium”) carried out “Operation Cloud Hopper”. 30.7.2020 Zhang Shilong can be linked to APT10, including through the malware he developed and tested in connection with the cyber-attacks carried out by APT10. Moreover, Huaying Haitai, an entity designated for providing support to and facilitating “Operation Cloud Hopper”, employed Zhang Shilong. He has links with Gao Qiang, who is also designated in connection with “Operation Cloud Hopper”. Zhang Shilong is therefore associated with both Huaying Haitai and Gao Qiang. 3. Alexey Valeryevich MININ Алексей Валерьевич МИНИН Date of birth: 27 May 1972 Place of birth: Perm Oblast, Russian SFSR (now Russian Federation) Passport number: 120017582 Issued by: Ministry of Foreign Affairs of the Russian Federation Validity: from 17 April 2017 until 17 April 2022 Location: Moscow, Russian Federation Nationality: Russian Gender: male Alexey Minin took part in an attempted cyber-attack with a potentially significant effect against the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands. As a human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Alexey Minin was part of a team of four Russian military intelligence officers who attempted to gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would have compromised the security of the network and the OPCW's ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (DISS) (Militaire Inlichtingen- en Veiligheidsdienst – MIVD) disrupted the attempted cyber-attack, thereby preventing serious damage to the OPCW. 30.7.2020 4. Aleksei Sergeyvich MORENETS Алексей Сергеевич МОРЕНЕЦ Date of birth: 31 July 1977 Place of birth: Murmanskaya Oblast, Russian SFSR (now Russian Federation) Passport number: 100135556 Issued by: Ministry of Foreign Affairs of the Russian Federation Validity: from 17 April 2017 until 17 April 2022 Location: Moscow, Russian Federation Nationality: Russian Gender: male Aleksei Morenets took part in an attempted cyber-attack with a potentially significant effect against the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands. As a cyber-operator for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Aleksei Morenets was part of a team of four Russian military intelligence officers who attempted to gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would have compromised the security of the network and the OPCW's ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (DISS) (Militaire Inlichtingen- en Veiligheidsdienst – MIVD) disrupted the attempted cyber-attack, thereby preventing serious damage to the OPCW. 30.7.2020 5. Evgenii Mikhaylovich SEREBRIAKOV Евгений Михайлович СЕРЕБРЯКОВ Date of birth: 26 July 1981 Place of birth: Kursk, Russian SFSR (now Russian Federation) Passport number: 100135555 Issued by: Ministry of Foreign Affairs of the Russian Federation Validity: from 17 April 2017 until 17 April 2022 Location: Moscow, Russian Federation Nationality: Russian Gender: male Evgenii Serebriakov took part in an attempted cyber-attack with a potentially significant effect against the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands. As a cyber-operator for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Evgenii Serebriakov was part of a team of four Russian military intelligence officers who attempted to gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would have compromised the security of the network and the OPCW's ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (DISS) (Militaire Inlichtingen- en Veiligheidsdienst – MIVD) disrupted the attempted cyber-attack, thereby preventing serious damage to the OPCW. 30.7.2020 6. Oleg Mikhaylovich SOTNIKOV Олег Михайлович СОТНИКОВ Date of birth: 24 August 1972 Place of birth: Ulyanovsk, Russian SFSR (now Russian Federation) Passport number: 120018866 Issued by: Ministry of Foreign Affairs of the Russian Federation Validity: from 17 April 2017 until 17 April 2022 Location: Moscow, Russian Federation Nationality: Russian Gender: male Oleg Sotnikov took part in an attempted cyber-attack with a potentially significant effect against the Organisation for the Prohibition of Chemical Weapons (OPCW), in the Netherlands. As a human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Oleg Sotnikov was part of a team of four Russian military intelligence officers who attempted to gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would have compromised the security of the network and the OPCW's ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (DISS) (Militaire Inlichtingen- en Veiligheidsdienst – MIVD) disrupted the attempted cyber-attack, thereby preventing serious damage to the OPCW. 30.7.2020 B.   Legal persons, entities and bodies   Name Identifying information Reasons Date of listing 1. Tianjin Huaying Haitai Science and Technology Development Co. Ltd (Huaying Haitai) a.k.a.: Haitai Technology Development Co. Ltd Location: Tianjin, China Huaying Haitai provided financial, technical or material support for and facilitated “Operation Cloud Hopper”, a series of cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and of cyber-attacks with a significant effect against third States. “Operation Cloud Hopper” has targeted information systems of multinational companies in six continents, including companies located in the Union, and gained unauthorised access to commercially sensitive data, resulting in significant economic loss. The actor publicly known as “APT10” (“Advanced Persistent Threat 10”) (a.k.a. “Red Apollo”, “CVNX”, “Stone Panda”, “MenuPass” and “Potassium”) carried out “Operation Cloud Hopper”. Huaying Haitai can be linked to APT10. Moreover, Huaying Haitai employed Gao Qiang and Zhang Shilong, who are both designated in connection with “Operation Cloud Hopper”. Huaying Haitai is therefore associated with Gao Qiang and Zhang Shilong. 30.7.2020 2. Chosun Expo a.k.a.: Chosen Expo; Korea Export Joint Venture Location: DPRK Chosun Expo provided financial, technical or material support for and facilitated a series of cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and of cyber-attacks with a significant effect against third States, including the cyber-attacks publicly known as “WannaCry” and cyber-attacks against the Polish Financial Supervision Authority and Sony Pictures Entertainment, as well as cyber-theft from the Bangladesh Bank and attempted cyber-theft from the Vietnam Tien Phong Bank. “WannaCry” disrupted information systems around the world by targeting information systems with ransomware and blocking access to data. It affected information systems of companies in the Union, including information systems relating to services necessary for the maintenance of essential services and economic activities within Member States. The actor publicly known as “APT38” (“Advanced Persistent Threat 38”) or the “Lazarus Group” carried out “WannaCry”. Chosun Expo can be linked to APT38 / the Lazarus Group, including through the accounts used for the cyber-attacks. 30.7.2020 3. Main Centre for Special Technologies (GTsST) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU) Address: 22 Kirova Street, Moscow, Russian Federation The Main Centre for Special Technologies (GTsST) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU), also known by its field post number 74455, is responsible for cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and for cyber-attacks with a significant effect against third States, including the cyber-attacks publicly known as “NotPetya” or “EternalPetya” in June 2017 and the cyber-attacks directed at an Ukrainian power grid in the winter of 2015 and 2016. “NotPetya” or “EternalPetya” rendered data inaccessible in a number of companies in the Union, wider Europe and worldwide, by targeting computers with ransomware and blocking access to data, resulting amongst others in significant economic loss. The cyber-attack on a Ukrainian power grid resulted in parts of it being switched off during winter. 30.7.2020’ The actor publicly known as “Sandworm” (a.k.a. “Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and “Telebots”), which is also behind the attack on the Ukrainian power grid, carried out “NotPetya” or “EternalPetya”. The Main Centre for Special Technologies of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation has an active role in the cyber‐activities undertaken by Sandworm and can be linked to Sandworm.

Other acts of the same type
Commission Implementing Regulation (EU) 2025/2606 of 18 December 2025 setting out the format of Member State reports on the implementation of Directive 2009/33/EC of the European Parliament and of the CouncilCouncil Regulation (EU) 2025/2618 of 18 December 2025 amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in UkraineCommission Implementing Regulation (EU) 2025/2629 of 18 December 2025 amending Annexes I and II to Implementing Regulation (EU) 2023/594 laying down special control measures for African swine fever and repealing Commission Implementing Decision (EU) 2025/2489 concerning certain interim emergency measures relating to African swine fever in SpainCommission Implementing Regulation (EU) 2025/2639 of 18 December 2025 amending Annexes V and XIV to Implementing Regulation (EU) 2021/404 as regards the entries for Canada, the United Kingdom and the United States in the lists of third countries, territories, or zones thereof authorised for the entry into the Union of consignments of poultry and germinal products of poultry, and of fresh meat of poultry and game birdsCommission Implementing Regulation (EU) 2025/2553 of 17 December 2025 amending Implementing Regulation (EU) 2020/1147 as regards administrative changes to the Union authorisation for the single biocidal product ClearKlens product based on IPACommission Implementing Regulation (EU) 2025/2556 of 17 December 2025 concerning the authorisation of a preparation of endo-1,4-beta-xylanase produced with Komagataella phaffii DSM 25376 and endo-1,3(4)-beta-glucanase produced with Komagataella phaffii DSM 26469 as a feed additive for chickens for laying or breeding, turkeys for breeding, minor poultry species for fattening and minor poultry species for laying or breeding (holder of authorisation: Kaesler Nutrition GmbH) and amending Implementing Regulation (EU) 2018/1090 as regards the terms of the authorisation of the preparation of endo-1,4-beta-xylanase produced with Komagataella phaffii DSM 25376 and endo-1,3(4)-beta-glucanase produced with Komagataella phaffii DSM 26469 as a feed additive for chickens for fattening and chickens reared for layingCommission Implementing Regulation (EU) 2025/2592 of 17 December 2025 for the application of Regulation (EU) 2015/2120 of the European Parliament and of the Council as regards fair use, based on typical usage patterns, and anti-fraud measures for intra-EU communicationsCommission Implementing Regulation (EU) 2025/2615 of 17 December 2025 amending Annex II to Implementing Regulation (EU) 2021/403 as regards the model animal health certificate and the model declaration for the re-entry into the Union of registered horses for competitionCommission Delegated Regulation (EU) 2026/55 of 17 December 2025 amending Regulation (EU) 2017/852 of the European Parliament and of the Council as regards mercury-added products subject to manufacturing, import and export prohibitionsRegulation (EU) 2025/2005 of the European Parliament and of the Council of 16 December 2025 amending Regulations (EU) 2015/1017, (EU) 2021/523, (EU) 2021/695 and (EU) 2021/1153 as regards increasing the efficiency of the EU guarantee under Regulation (EU) 2021/523 and simplifying reporting requirementsRegulation (EU) 2025/2014 of the European Parliament and of the Council of 16 December 2025 amending Regulation (EU) 2024/823 on exceptional trade measures for countries and territories participating in or linked to the Stabilisation and Association ProcessCommission Implementing Regulation (EU) 2025/2526 of 16 December 2025 amending Implementing Regulation (EU) 2023/2713 to correct the designation of an EU reference laboratory and to designate European Union reference laboratories for in vitro diagnostic medical devices intended for detection or quantification of markers of parasite infection and detection of blood grouping markers

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

Contents

What to look at next