Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud — Threadlinqs Intelligence
As of 2026-07-20, Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud is a high-severity cybercrime threat attributed to Media Land LLC (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1580 · Severity: HIGH · Status: ACTIVE · Category: CYBERCRIME
Attribution: Media Land LLC · Russia · FINANCIAL
The U.S. Attorney's Office for the Northern District of Ohio unsealed a December 2024 indictment charging three Russian nationals — Alexander Alexandrovich Volosovik ("Yalishanda"), Kirill Andreevich
On December 2024 a federal grand jury in the Northern District of Ohio returned a sealed indictment against Alexander Alexandrovich Volosovik (43, alias "Yalishanda"), Kirill Andreevich Zatolokin (34), and Yulia Vladimirovna Pankova (29), along with the companies Media Land LLC and ML.Cloud LLC, both headquartered in St. Petersburg, Russia. The indictment was unsealed on 2026-07-14/15 alongside a U.S. State Department Rewards for Justice announcement and coincided with a new joint EU/UK sanctions package (2026-07-13) — the first collaborative EU/UK cyber sanctions action against Russia.
Prosecutors allege Volosovik owned and operated Media Land, Pankova owned and operated ML.Cloud (which took over portions of Media Land's book of business), and Zatolokin handled customer payment collection and cybercriminal coordination on their behalf. The two companies are alleged to have run a "bulletproof hosting" business model: knowingly renting server infrastructure to cybercriminals while ignoring or actively resisting law-enforcement abuse complaints and takedown requests, and rapidly reprovisioning or migrating infrastructure across jurisdictions to frustrate investigation. Servers tied to the operation were identified in Russia, China, Finland, the Netherlands, and the United States.
Customers of Media Land and ML.Cloud allegedly included the LockBit, BlackSuit, and Play ransomware operations, as well as a cluster of stolen-payment-card marketplaces (Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash) and services supporting phishing campaigns, credential/password brute-forcing, fraudulent domain registration, and malware distribution. The indictment cites 44 unnamed victims — including banks, K-12 schools, hospitals, government bodies, and media companies — across at least 21 U.S. states (including multiple Northern District of Ohio cities: Akron, Cleveland, Elyria, Medina, Solon, Valley View) plus victims in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom, with total documented losses exceeding $62 million.
Defendants face charges of conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. The case follows a Treasury OFAC sanctions action in November 2025 (joined by the UK and Australia) against Media Land, ML.Cloud, and a related entity, Data Center Kirishi, which was sanctioned but not named in the criminal indictment. FBI Assistant Director Brett Leatherman (Cyber Division) and Assistant Attorney General A. Tysen Duva of DOJ's Criminal Division both issued public statements framing the action as targeting "core services" and "criminal infrastructure" that underpin ransomware and fraud campaigns against U.S. critical institutions, rather than a single malware family or vulnerability. The investigation involved multi-year international cooperation with UK, Australian, and Dutch law enforcement partners.
No CVEs, malware binaries, or network-level technical IOCs were disclosed by DOJ; the only technical indicator published in initial reporting is a Tor-based public tip-reporting address associated with the case. This threat record documents bulletproof-hosting-enabled criminal infrastructure and its downstream enablement of ransomware, carding, and phishing operations — defenders should treat any observed traffic to/from historically Media Land / ML.Cloud-associated netblocks (Russia, and satellite infrastructure in China, Finland, and the Netherlands) as elevated-risk and correlate against known LockBit/BlackSuit/Play C2 and staging infrastructure.
Target sectors: financial services, banking, education, health, government administration, news - media, critical infrastructure, telecoms
Target regions: united states of america, australia, canada, European Union, united arab emirates, united kingdom
Related threats
- US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware
- US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs
- Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CYBERCRIME, HIGH, threat intelligence, cybersecurity, T1583.006, T1583.001, T1583.004, T1584, T1585.001, T1587.001, T1566, T1078, T1133, T1110.001