US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware — Threadlinqs Intelligence
As of 2026-07-15, US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware is a high-severity threat intel threat attributed to Media Land (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1355 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Media Land · Russia · FINANCIAL
US federal prosecutors unsealed a Northern District of Ohio indictment against three Russian nationals - Aleksandr Volosovik ("Yalishanda"), Yulia Pankova, and Kirill Zatolokin - and their companies
On July 14-15, 2026, the US Department of Justice unsealed a December 2024 indictment (US District Court, Northern District of Ohio) charging Aleksandr Volosovik (alias "Yalishanda", also known online as "Downlow" and "Stas_vl"), Yulia Pankova, and Kirill Zatolokin, along with the companies Media Land LLC and ML.Cloud LLC, with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.
Media Land, operated by Volosovik from a corporate office in St. Petersburg, Russia, and its sister company ML.Cloud, owned by Pankova, provided "bulletproof hosting" (BPH) infrastructure and technical support that deliberately ignored abuse complaints and law-enforcement takedown requests, enabling criminal clients to host malware delivery infrastructure, command-and-control servers, and phishing kits. Zatolokin collected customer payments and coordinated with cyber actors on the criminal clients' behalf. Recorded Future traces attacker activity on this infrastructure back to at least 2015 - a decade of continuous bulletproof-hosting service to the cybercrime ecosystem. Brian Krebs identified Volosovik as one of the world's largest bulletproof hosting operators as early as 2019.
The indictment ties Media Land/ML.Cloud infrastructure directly to the LockBit, BlackSuit (the Royal ransomware rebrand), and Play (Playcrypt) ransomware operations, as well as to DDoS attacks against US telecommunications carriers and critical infrastructure. The indictment cites 44 unnamed victims - including banks, schools, government entities, hospitals, and media companies across 21 US states - with combined losses exceeding $62 million. Media Land's customer base also reportedly included stolen-card/carding marketplaces such as Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash (the latter dismantled by law enforcement in 2025).
A data-driven infrastructure reconstruction (Disclosing.Observer, Nov 2025) mapped Media Land's full public address space - four consecutive /24s in 45.141.84.0/24-45.141.87.0/24, plus 91.220.163.0/24, 91.240.242.0/24 (since reallocated), 194.26.29.0/24, 194.26.69.0/24, and a Netherlands-geolocated "NL Subnet" (77.221.134.0/24) run by ML Cloud Ltd, together with IPv6 ranges 2a0b:7ec0:1320::/48 and 2a0b:7ec0:533::/48 - all announced under AS206728 and AS215376. The infrastructure runs a modern virtualization/orchestration stack (VXLAN overlays, IPMI, KVM, Libvirt, Ceph, PostgreSQL/MySQL) and remains reachable through peering relationships with JSC RetnNet (Russia) and RETN Limited (UK-based ISP), illustrating how BPH providers embed themselves in legitimate transit relationships to resist disconnection.
On November 19, 2025, the US Treasury OFAC, UK FCDO, and Australian DFAT jointly sanctioned Media Land, Volosovik, and Zatolokin, along with Media Land subsidiaries Media Land Technology (MLT) and Data Center Kirishi (DC Kirishi), blocking US-person transactions and property. A further EU/UK joint cyber sanctions package followed in July 2026. Related Five Eyes/industry action has also targeted other bulletproof hosters in the same ecosystem, including Aeza Group (previously sanctioned) and Hypercore (a UK-based provider sanctioned for helping Aeza reconstitute service after its own sanctioning).
The ransomware families this infrastructure supported carry well-documented CISA #StopRansomware TTPs: Play (AA23-352A) gains initial access via valid accounts purchased on dark-web markets, exploitation of public-facing applications (FortiOS CVE-2018-13379/CVE-2020-12812; Microsoft Exchange ProxyNotShell CVE-2022-41040/CVE-2022-41082), and external remote services (RDP/VPN); BlackSuit/Royal (AA23-061A) favors phishing for initial access and uses partial/intermittent encryption to speed impact while evading detection; LockBit operates a mature RaaS affiliate model with double-extortion data theft prior to encryption. Disrupti
Target sectors: telecoms, government administration, finance, health, education, news - media, criticalinfrastructure
Target regions: united states of america, Europe, russia, netherlands
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1590, T1583, T1583, T1608, T1566, T1566, T1190, T1133, T1078, T1059