Threat reportThreat IntelligenceTL-2026-1355
US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware
US Indicts Alleged Operators of Media Land Bulletproof (TL-2026-1355), also tracked as Media Land bulletproof hosting indictment, is a high-severity tracked intrusion set, first published 2026-07-15. It is attributed to Media Land (Russia) with high confidence, affects N/A - infrastructure/hosting provider Media Land LLC / ML.Cloud LLC, maps to 22 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 2Media Land
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-1355
- Threat ID
- TL-2026-1355
- Also known as
- Media Land bulletproof hosting indictment, US v. Volosovik et al.
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- Media Land, ML.Cloud Bulletproof Hosting Network
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- telecoms, government administration, finance, health, education, news - media, criticalinfrastructure
- Target regions
- united states of america, Europe, russia, netherlands
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in US Indicts Alleged Operators of Media Land Bulletproof
Malware and tooling: LockBit, Playcrypt - S1162, black suit
How US Indicts Alleged Operators of Media Land Bulletproof works
US federal prosecutors unsealed a Northern District of Ohio indictment against three Russian nationals - Aleksandr Volosovik ("Yalishanda"), Yulia Pankova, and Kirill Zatolokin - and their companies Media Land LLC and ML.Cloud LLC for operating bulletproof hosting infrastructure that enabled LockBit, BlackSuit, and Play ransomware operations and DDoS attacks against US telecommunications and critical infrastructure, causing over $62 million in losses to 44 identified victims. The action follows November 2025 US/UK/Australia OFAC sanctions and a July 2026 EU/UK joint sanctions package, with the State Department offering up to $10 million via Rewards for Justice for information on the defendants' foreign-government ties.
On July 14-15, 2026, the US Department of Justice unsealed a December 2024 indictment (US District Court, Northern District of Ohio) charging Aleksandr Volosovik (alias "Yalishanda", also known online as "Downlow" and "Stas_vl"), Yulia Pankova, and Kirill Zatolokin, along with the companies Media Land LLC and ML.Cloud LLC, with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.
Media Land, operated by Volosovik from a corporate office in St. Petersburg, Russia, and its sister company ML.Cloud, owned by Pankova, provided "bulletproof hosting" (BPH) infrastructure and technical support that deliberately ignored abuse complaints and law-enforcement takedown requests, enabling criminal clients to host malware delivery infrastructure, command-and-control servers, and phishing kits. Zatolokin collected customer payments and coordinated with cyber actors on the criminal clients' behalf. Recorded Future traces attacker activity on this infrastructure back to at least 2015 - a decade of continuous bulletproof-hosting service to the cybercrime ecosystem. Brian Krebs identified Volosovik as one of the world's largest bulletproof hosting operators as early as 2019.
The indictment ties Media Land/ML.Cloud infrastructure directly to the LockBit, BlackSuit (the Royal ransomware rebrand), and Play (Playcrypt) ransomware operations, as well as to DDoS attacks against US telecommunications carriers and critical infrastructure. The indictment cites 44 unnamed victims - including banks, schools, government entities, hospitals, and media companies across 21 US states - with combined losses exceeding $62 million. Media Land's customer base also reportedly included stolen-card/carding marketplaces such as Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash (the latter dismantled by law enforcement in 2025).
A data-driven infrastructure reconstruction (Disclosing.Observer, Nov 2025) mapped Media Land's full public address space - four consecutive /24s in 45.141.84.0/24-45.141.87.0/24, plus 91.220.163.0/24, 91.240.242.0/24 (since reallocated), 194.26.29.0/24, 194.26.69.0/24, and a Netherlands-geolocated "NL Subnet" (77.221.134.0/24) run by ML Cloud Ltd, together with IPv6 ranges 2a0b:7ec0:1320::/48 and 2a0b:7ec0:533::/48 - all announced under AS206728 and AS215376. The infrastructure runs a modern virtualization/orchestration stack (VXLAN overlays, IPMI, KVM, Libvirt, Ceph, PostgreSQL/MySQL) and remains reachable through peering relationships with JSC RetnNet (Russia) and RETN Limited (UK-based ISP), illustrating how BPH providers embed themselves in legitimate transit relationships to resist disconnection.
On November 19, 2025, the US Treasury OFAC, UK FCDO, and Australian DFAT jointly sanctioned Media Land, Volosovik, and Zatolokin, along with Media Land subsidiaries Media Land Technology (MLT) and Data Center Kirishi (DC Kirishi), blocking US-person transactions and property. A further EU/UK joint cyber sanctions package followed in July 2026. Related Five Eyes/industry action has also targeted other bulletproof hosters in the same ecosystem, including Aeza Group (previously sanctioned) and Hypercore (a UK-based provider sanctioned for helping Aeza reconstitute service after its own sanctioning).
The ransomware families this infrastructure supported carry well-documented CISA #StopRansomware TTPs: Play (AA23-352A) gains initial access via valid accounts purchased on dark-web markets, exploitation of public-facing applications (FortiOS CVE-2018-13379/CVE-2020-12812; Microsoft Exchange ProxyNotShell CVE-2022-41040/CVE-2022-41082), and external remote services (RDP/VPN); BlackSuit/Royal (AA23-061A) favors phishing for initial access and uses partial/intermittent encryption to speed impact while evading detection; LockBit operates a mature RaaS affiliate model with double-extortion data theft prior to encryption. Disrupting the bulletproof-hosting layer that fronts these operations - rather than only the ransomware payloads - is treated by CISA/FBI/Treasury as a force-multiplying mitigation because a single BPH provider services many otherwise-unrelated criminal groups simultaneously.
MITRE ATT&CK techniques used in TL-2026-1355
Credential Access
Collection
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Discovery
T1082 System Information Discovery
Persistence
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1498 Network Denial of Service
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Reconnaissance
Affected products and versions in US Indicts Alleged Operators of Media Land Bulletproof
- N/A - infrastructure/hosting provider — Media Land LLC / ML.Cloud LLC bulletproof hosting services
Vulnerable versions: all customer-facing hosting/VPS/dedicated server offerings
Fixed in: N/A - law-enforcement/sanctions disruption, not a software patch
Remediation for US Indicts Alleged Operators of Media Land Bulletproof
Patches
- Patch FortiOS against CVE-2018-13379 and CVE-2020-12812 (Play ransomware initial-access vector)
- Patch Microsoft Exchange against ProxyNotShell CVE-2022-41040 and CVE-2022-41082 (Play ransomware initial-access vector)
Immediate actions
- Block/null-route Media Land IP ranges at perimeter and upstream: 45.141.84.0/24-45.141.87.0/24, 91.220.163.0/24, 91.240.242.0/24, 194.26.29.0/24, 194.26.69.0/24, 77.221.134.0/24, and IPv6 2a0b:7ec0:1320::/48, 2a0b:7ec0:533::/48
- Filter/monitor traffic to and from AS206728 and AS215376 at network edge and via BGP route filtering where feasible
- Alert on any DNS resolution, TLS SNI, or netflow records touching JSC RetnNet or RETN Limited peering ranges associated with Media Land customers
- Review historical logs for connections to known carding-marketplace domains formerly hosted via Media Land (Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, Bidencash)
Workarounds
- Enforce MFA on all externally facing RDP/VPN services to blunt valid-account and external-remote-services initial access used by Play affiliates
- Disable or restrict direct internet exposure of management interfaces (IPMI/KVM-style out-of-band access) mirroring the orchestration stack observed in the Media Land infrastructure reconstruction
Longer-term hardening
- Adopt curated bulletproof-hosting ASN/IP threat-list feeds and automate periodic review as BPH providers rotate address space
- Coordinate with upstream ISPs/peers on abuse reporting and consider peering-level pressure against providers (e.g., RETN) that continue transiting BPH traffic
- Deploy EDR/network detection tuned to LockBit, BlackSuit, and Play TTPs (per CISA AA23-061A / AA23-352A) rather than relying solely on IOC blocklists, since infrastructure and affiliates rotate frequently
- Participate in Five Eyes / industry bulletproof-hosting intelligence sharing to track successor infrastructure as Media Land assets are seized or reallocated
Timeline of US Indicts Alleged Operators of Media Land Bulletproof
- Recorded Future traces attacker use of Media Land bulletproof hosting infrastructure back to at least 2015, marking roughly a decade of continuous cybercrime-enabling service.
- Journalist Brian Krebs publicly identifies Aleksandr Volosovik ("Yalishanda") as one of the world's largest bulletproof hosting operators.
- US federal grand jury in the Northern District of Ohio files a sealed indictment against Volosovik, Pankova, and Zatolokin along with Media Land LLC and ML.Cloud LLC.
- US Treasury OFAC, UK FCDO, and Australian DFAT jointly sanction Media Land, Volosovik, Zatolokin, and subsidiaries Media Land Technology (MLT) and Data Center Kirishi (DC Kirishi).
- Disclosing.Observer publishes a data-driven reconstruction of Media Land's full public IP/ASN footprint from leaked operational data.
- Law enforcement dismantles the Bidencash carding marketplace, one of the criminal customers reportedly hosted via Media Land infrastructure.
- The EU and UK issue a further joint cyber sanctions package covering the Media Land bulletproof-hosting ecosystem.
- DOJ unseals the indictment in the Northern District of Ohio, publicly charging Volosovik, Pankova, and Zatolokin; State Department announces up to $10 million Rewards for Justice offer.
- BleepingComputer and other outlets report on the unsealed indictment, summarizing the $62M+ in victim losses and ties to LockBit, BlackSuit, and Play ransomware.
Sources cited for US Indicts Alleged Operators of Media Land Bulletproof
- US charges alleged operators of Russian bulletproof hosting service
- Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses
- Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims (N.D. Ohio)
- US unseals indictment against alleged operators of Russian bulletproof hosting service
- US indicts Russians alleged to be at center of major cybercrime network
- United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware
- Cyber-related Designations; CAATSA - Russia-related Designations (OFAC Recent Actions)
- Notice of OFAC Sanctions Action (Federal Register)
- Five Eyes just made life harder for bulletproof hosting providers
- The Anatomy of a Bulletproof Hoster: A Data-Driven Reconstruction of Media Land
- Russian bulletproof hosting provider sanctioned over ransomware ties
- US cracks down on Russian bulletproof hosting services enabling cybercrime
- #StopRansomware: BlackSuit (Royal) Ransomware (AA23-061A)
- #StopRansomware: Play Ransomware (AA23-352A)
- Russian fraudsters siphoned $63 million from Americans and global citizens: DOJ
Detection coverage for TL-2026-1355
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1355 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.