Threat reportCybercrimeTL-2026-1580

Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud

highACTIVE

Russian Bulletproof Hosting Operators Indicted (TL-2026-1580), also tracked as Media Land / ML.Cloud Bulletproof Hosting Indictment, is a high-severity cybercrime threat, first published 2026-07-20. It is attributed to Media Land LLC (Russia) with high confidence, affects Media Land LLC Bulletproof hosting infrastructure, maps to 21 MITRE ATT&CK techniques (T1027, T1071, T1078), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
2Media Land LLC
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1580

Threat ID
TL-2026-1580
Also known as
Media Land / ML.Cloud Bulletproof Hosting Indictment, Yalishanda Bulletproof Hosting Case
Severity
HIGH
Status
ACTIVE
Category
CYBERCRIME
First published
Last reviewed
Attribution
Media Land LLC, ML.Cloud LLC
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
financial services, banking, education, health, government administration, news - media, critical infrastructure, telecoms
Target regions
united states of america, australia, canada, European Union, united arab emirates, united kingdom
Detection rules
9
Indicators of compromise
23

Malware and tooling in Russian Bulletproof Hosting Operators Indicted

Malware and tooling: Black Basta - S1070, Evil Corp, LockBit, Playcrypt - S1162, black suit

How Russian Bulletproof Hosting Operators Indicted works

The U.S. Attorney's Office for the Northern District of Ohio unsealed a December 2024 indictment charging three Russian nationals — Alexander Alexandrovich Volosovik ("Yalishanda"), Kirill Andreevich Zatolokin, and Yulia Vladimirovna Pankova — and their companies Media Land LLC and ML.Cloud LLC with operating "bulletproof hosting" infrastructure that knowingly serviced LockBit, BlackSuit, and Play ransomware operations, stolen-card marketplaces, phishing kits, and brute-force attack platforms, causing more than $62 million in losses to 44 identified victims across 21 U.S. states and multiple allied countries over a seven-year FBI investigation. The State Department's Rewards for Justice program is offering up to $10 million for information tying the operators to foreign-government activity, following coordinated U.S./UK/Australian sanctions in November 2025 and a joint EU/UK sanctions package in July 2026.

On December 2024 a federal grand jury in the Northern District of Ohio returned a sealed indictment against Alexander Alexandrovich Volosovik (43, alias "Yalishanda"), Kirill Andreevich Zatolokin (34), and Yulia Vladimirovna Pankova (29), along with the companies Media Land LLC and ML.Cloud LLC, both headquartered in St. Petersburg, Russia. The indictment was unsealed on 2026-07-14/15 alongside a U.S. State Department Rewards for Justice announcement and coincided with a new joint EU/UK sanctions package (2026-07-13) — the first collaborative EU/UK cyber sanctions action against Russia.

Prosecutors allege Volosovik owned and operated Media Land, Pankova owned and operated ML.Cloud (which took over portions of Media Land's book of business), and Zatolokin handled customer payment collection and cybercriminal coordination on their behalf. The two companies are alleged to have run a "bulletproof hosting" business model: knowingly renting server infrastructure to cybercriminals while ignoring or actively resisting law-enforcement abuse complaints and takedown requests, and rapidly reprovisioning or migrating infrastructure across jurisdictions to frustrate investigation. Servers tied to the operation were identified in Russia, China, Finland, the Netherlands, and the United States.

Customers of Media Land and ML.Cloud allegedly included the LockBit, BlackSuit, and Play ransomware operations, as well as a cluster of stolen-payment-card marketplaces (Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash) and services supporting phishing campaigns, credential/password brute-forcing, fraudulent domain registration, and malware distribution. The indictment cites 44 unnamed victims — including banks, K-12 schools, hospitals, government bodies, and media companies — across at least 21 U.S. states (including multiple Northern District of Ohio cities: Akron, Cleveland, Elyria, Medina, Solon, Valley View) plus victims in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom, with total documented losses exceeding $62 million.

Defendants face charges of conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. The case follows a Treasury OFAC sanctions action in November 2025 (joined by the UK and Australia) against Media Land, ML.Cloud, and a related entity, Data Center Kirishi, which was sanctioned but not named in the criminal indictment. FBI Assistant Director Brett Leatherman (Cyber Division) and Assistant Attorney General A. Tysen Duva of DOJ's Criminal Division both issued public statements framing the action as targeting "core services" and "criminal infrastructure" that underpin ransomware and fraud campaigns against U.S. critical institutions, rather than a single malware family or vulnerability. The investigation involved multi-year international cooperation with UK, Australian, and Dutch law enforcement partners.

No CVEs, malware binaries, or network-level technical IOCs were disclosed by DOJ; the only technical indicator published in initial reporting is a Tor-based public tip-reporting address associated with the case. This threat record documents bulletproof-hosting-enabled criminal infrastructure and its downstream enablement of ransomware, carding, and phishing operations — defenders should treat any observed traffic to/from historically Media Land / ML.Cloud-associated netblocks (Russia, and satellite infrastructure in China, Finland, and the Netherlands) as elevated-risk and correlate against known LockBit/BlackSuit/Play C2 and staging infrastructure.

MITRE ATT&CK techniques used in TL-2026-1580

Defense Evasion

T1027 Obfuscated Files or Information

Command and Control

T1071 Application Layer Protocol; T1090.003 Multi-hop Proxy; T1102 Web Service

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing

Discovery

T1087 Account Discovery

Credential Access

T1110.001 Password Guessing; T1110.004 Credential Stuffing

Collection

T1213 Data from Information Repositories

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Domains; T1583.004 Server; T1583.006 Web Services; T1583.008 Malvertising; T1584 Compromise Infrastructure; T1585.001 Social Media Accounts; T1587.001 Malware

Affected products and versions in Russian Bulletproof Hosting Operators Indicted

  • Media Land LLC — Bulletproof hosting infrastructure
    Vulnerable versions: all hosting infrastructure operated by Media Land LLC through 2026-07
  • ML.Cloud LLC — Bulletproof hosting infrastructure
    Vulnerable versions: all hosting infrastructure operated by ML.Cloud LLC through 2026-07
  • Data Center Kirishi — Colocation / hosting infrastructure
    Vulnerable versions: infrastructure sanctioned by OFAC in November 2025

Remediation for Russian Bulletproof Hosting Operators Indicted

Immediate actions

  • Block/monitor inbound and outbound traffic to netblocks historically associated with Media Land LLC and ML.Cloud LLC hosting infrastructure in Russia, China, Finland, and the Netherlands
  • Flag connections to the published Tor reporting address (he5dybnt7sr6cm32xt77pazmtm65qy6irivtruqfc5ep7eiodiad.onion) and surrounding onion infrastructure for triage rather than automatic block, since it is a law-enforcement tip line
  • Review historical DNS/WHOIS and passive-DNS records for domains registered through infrastructure tied to Media Land / ML.Cloud for retrospective compromise hunting
  • Add LockBit, BlackSuit, and Play ransomware indicators/playbooks to active detection and IR runbooks given their confirmed use of this hosting infrastructure

Longer-term hardening

  • Incorporate bulletproof-hosting provider intelligence (ASN/netblock reputation feeds) into perimeter and DNS-layer blocking
  • Establish threat-intel feeds tracking OFAC-sanctioned entities (Media Land, ML.Cloud, Data Center Kirishi) for automated blocklist updates
  • Strengthen card-not-present fraud monitoring given the confirmed link between this infrastructure and major carding marketplaces (Briansclub, Bidencash, and others)
  • Coordinate with sector-ISACs (financial services, healthcare, education, government) to share IOCs tied to ransomware groups that historically relied on bulletproof hosting

Timeline of Russian Bulletproof Hosting Operators Indicted

  • Media Land LLC is officially registered in St. Petersburg, Russia by Aleksandr Volosovik, formalizing a bulletproof hosting operation Volosovik (alias "Yalishanda"/"Downlow"/"Stas_vl") had already run informally for years from prior bases in Beijing and Vladivostok.
  • FBI opens investigation into Media Land LLC and associated bulletproof hosting infrastructure, beginning a seven-year probe into services enabling ransomware, phishing, and carding operations.
  • Security journalist Brian Krebs (KrebsOnSecurity) publicly identifies Alexander Volosovik as the operator behind the "Yalishanda" bulletproof hosting persona and ties him to Media Land LLC, the first major public exposure of the operation ahead of the criminal case.
  • The BidenCash stolen-card marketplace, later identified as a customer of Media Land/ML.Cloud hosting infrastructure, begins operating; it goes on to traffic more than 15 million payment-card records and 117,000+ customer accounts before its 2025 takedown.
  • A federal grand jury in the Northern District of Ohio returns a sealed indictment against Alexander Volosovik, Kirill Zatolokin, Yulia Pankova, Media Land LLC, and ML.Cloud LLC on computer fraud, wire fraud, and money laundering conspiracy charges.
  • U.S. Secret Service and FBI, with the Dutch National High Tech Crime Unit, Shadowserver Foundation, and Searchlight Cyber, seize approximately 145 domains belonging to the BidenCash carding marketplace — one of the cybercrime services later named as a Media Land/ML.Cloud hosting customer.
  • U.S. Treasury OFAC, joined by the UK and Australia, sanctions Media Land, ML.Cloud, and Data Center Kirishi for providing bulletproof hosting services to ransomware and cybercrime operations; the UK's National Crime Agency separately exposes Volosovik's role in supporting LockBit, Evil Corp, and Black Basta.
  • The European Union and United Kingdom announce a joint cyber sanctions package targeting Russian bulletproof hosting infrastructure — their first collaborative cyber sanctions action against Russia.
  • The U.S. State Department's Rewards for Justice program announces a reward of up to $10 million for information linking the defendants or their companies to foreign-government-directed malicious cyber activity.
  • The Northern District of Ohio unseals the December 2024 indictment, publicly charging Volosovik, Zatolokin, Pankova, Media Land LLC, and ML.Cloud LLC.
  • DOJ, cybersecurity trade press (BleepingComputer, CyberScoop, TechCrunch, The Record, GovInfoSecurity) and mainstream outlets report on the indictment, naming LockBit, BlackSuit, and Play ransomware operations plus multiple carding marketplaces as customers of the hosting services.

Sources cited for Russian Bulletproof Hosting Operators Indicted

Detection coverage for TL-2026-1580

As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1580 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats