# US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware

> US federal prosecutors unsealed a Northern District of Ohio indictment against three Russian nationals - Aleksandr Volosovik ("Yalishanda"), Yulia Pankova, and Kirill Zatolokin - and their companies Media Land LLC and ML.Cloud LLC for operating bulletproof hosting infrastructure that enabled LockBit, BlackSuit, and Play ransomware operations and DDoS attacks against US telecommunications and critical infrastructure, causing over $62 million in losses to 44 identified victims. The action follows November 2025 US/UK/Australia OFAC sanctions and a July 2026 EU/UK joint sanctions package, with the State Department offering up to $10 million via Rewards for Justice for information on the defendants' foreign-government ties.

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1355
- **ID:** TL-2026-1355
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** Media Land (Russia)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 14-15, 2026, the US Department of Justice unsealed a December 2024 indictment (US District Court, Northern District of Ohio) charging Aleksandr Volosovik (alias "Yalishanda", also known online as "Downlow" and "Stas_vl"), Yulia Pankova, and Kirill Zatolokin, along with the companies Media Land LLC and ML.Cloud LLC, with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

Media Land, operated by Volosovik from a corporate office in St. Petersburg, Russia, and its sister company ML.Cloud, owned by Pankova, provided "bulletproof hosting" (BPH) infrastructure and technical support that deliberately ignored abuse complaints and law-enforcement takedown requests, enabling criminal clients to host malware delivery infrastructure, command-and-control servers, and phishing kits. Zatolokin collected customer payments and coordinated with cyber actors on the criminal clients' behalf. Recorded Future traces attacker activity on this infrastructure back to at least 2015 - a decade of continuous bulletproof-hosting service to the cybercrime ecosystem. Brian Krebs identified Volosovik as one of the world's largest bulletproof hosting operators as early as 2019.

The indictment ties Media Land/ML.Cloud infrastructure directly to the LockBit, BlackSuit (the Royal ransomware rebrand), and Play (Playcrypt) ransomware operations, as well as to DDoS attacks against US telecommunications carriers and critical infrastructure. The indictment cites 44 unnamed victims - including banks, schools, government entities, hospitals, and media companies across 21 US states - with combined losses exceeding $62 million. Media Land's customer base also reportedly included stolen-card/carding marketplaces such as Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash (the latter dismantled by law enforcement in 2025).

A data-driven infrastructure reconstruction (Disclosing.Observer, Nov 2025) mapped Media Land's full public address space - four consecutive /24s in 45.141.84.0/24-45.141.87.0/24, plus 91.220.163.0/24, 91.240.242.0/24 (since reallocated), 194.26.29.0/24, 194.26.69.0/24, and a Netherlands-geolocated "NL Subnet" (77.221.134.0/24) run by ML Cloud Ltd, together with IPv6 ranges 2a0b:7ec0:1320::/48 and 2a0b:7ec0:533::/48 - all announced under AS206728 and AS215376. The infrastructure runs a modern virtualization/orchestration stack (VXLAN overlays, IPMI, KVM, Libvirt, Ceph, PostgreSQL/MySQL) and remains reachable through peering relationships with JSC RetnNet (Russia) and RETN Limited (UK-based ISP), illustrating how BPH providers embed themselves in legitimate transit relationships to resist disconnection.

On November 19, 2025, the US Treasury OFAC, UK FCDO, and Australian DFAT jointly sanctioned Media Land, Volosovik, and Zatolokin, along with Media Land subsidiaries Media Land Technology (MLT) and Data Center Kirishi (DC Kirishi), blocking US-person transactions and property. A further EU/UK joint cyber sanctions package followed in July 2026. Related Five Eyes/industry action has also targeted other bulletproof hosters in the same ecosystem, including Aeza Group (previously sanctioned) and Hypercore (a UK-based provider sanctioned for helping Aeza reconstitute service after its own sanctioning).

The ransomware families this infrastructure supported carry well-documented CISA #StopRansomware TTPs: Play (AA23-352A) gains initial access via valid accounts purchased on dark-web markets, exploitation of public-facing applications (FortiOS CVE-2018-13379/CVE-2020-12812; Microsoft Exchange ProxyNotShell CVE-2022-41040/CVE-2022-41082), and external remote services (RDP/VPN); BlackSuit/Royal (AA23-061A) favors phishing for initial access and uses partial/intermittent encryption to speed impact while evading detection; LockBit operates a mature RaaS affiliate model with double-extortion data theft prior to encryption. Disrupting the bulletproof-hosting layer that fronts these operations - rather than only the ransomware payloads - is treated by CISA/FBI/Treasury as a force-multiplying mitigation because a single BPH provider services many otherwise-unrelated criminal groups simultaneously.

## MITRE ATT&CK

- T1590 Gather Victim Network Information
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1136 Create Account
- T1068 Exploitation for Privilege Escalation
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1498 Network Denial of Service

## Sources

- [US charges alleged operators of Russian bulletproof hosting service](https://www.bleepingcomputer.com/news/security/us-charges-alleged-russian-bulletproof-hosting-service-operators/)
- [Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more)
- [Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims (N.D. Ohio)](https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses)
- [US unseals indictment against alleged operators of Russian bulletproof hosting service](https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting)
- [US indicts Russians alleged to be at center of major cybercrime network](https://www.cnn.com/2026/07/14/politics/us-indicts-russia-cybercrime)
- [United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware](https://home.treasury.gov/news/press-releases/sb0319)
- [Cyber-related Designations; CAATSA - Russia-related Designations (OFAC Recent Actions)](https://ofac.treasury.gov/recent-actions/20251119)
- [Notice of OFAC Sanctions Action (Federal Register)](https://www.federalregister.gov/documents/2025/11/21/2025-20573/notice-of-ofac-sanctions-action)
- [Five Eyes just made life harder for bulletproof hosting providers](https://cyberscoop.com/bulletproof-hosting-providers-sanctions-mitigation-media-land/)
- [The Anatomy of a Bulletproof Hoster: A Data-Driven Reconstruction of Media Land](https://disclosing.observer/2025/11/24/bulletproof-hoster-anatomy-data-driven-reconstruction.html)
- [Russian bulletproof hosting provider sanctioned over ransomware ties](https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/)
- [US cracks down on Russian bulletproof hosting services enabling cybercrime](https://www.elliptic.co/blog/us-cracks-down-on-russian-bulletproof-hosting-services)
- [#StopRansomware: BlackSuit (Royal) Ransomware (AA23-061A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a)
- [#StopRansomware: Play Ransomware (AA23-352A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a)
- [Russian fraudsters siphoned $63 million from Americans and global citizens: DOJ](https://www.foxnews.com/politics/doj-charges-3-russians-alleged-63m-cybercrime-scheme-targeting-americans)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1355
