Threat reportCybercrimeTL-2026-1580
Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud
Russian Bulletproof Hosting Operators Indicted (TL-2026-1580), also tracked as Media Land / ML.Cloud Bulletproof Hosting Indictment, is a high-severity cybercrime threat, first published 2026-07-20. It is attributed to Media Land LLC (Russia) with high confidence, affects Media Land LLC Bulletproof hosting infrastructure, maps to 21 MITRE ATT&CK techniques (T1027, T1071, T1078), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 2Media Land LLC
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-1580
- Threat ID
- TL-2026-1580
- Also known as
- Media Land / ML.Cloud Bulletproof Hosting Indictment, Yalishanda Bulletproof Hosting Case
- Severity
- HIGH
- Status
- ACTIVE
- Category
- CYBERCRIME
- First published
- Last reviewed
- Attribution
- Media Land LLC, ML.Cloud LLC
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, education, health, government administration, news - media, critical infrastructure, telecoms
- Target regions
- united states of america, australia, canada, European Union, united arab emirates, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Russian Bulletproof Hosting Operators Indicted
Malware and tooling: Black Basta - S1070, Evil Corp, LockBit, Playcrypt - S1162, black suit
How Russian Bulletproof Hosting Operators Indicted works
The U.S. Attorney's Office for the Northern District of Ohio unsealed a December 2024 indictment charging three Russian nationals — Alexander Alexandrovich Volosovik ("Yalishanda"), Kirill Andreevich Zatolokin, and Yulia Vladimirovna Pankova — and their companies Media Land LLC and ML.Cloud LLC with operating "bulletproof hosting" infrastructure that knowingly serviced LockBit, BlackSuit, and Play ransomware operations, stolen-card marketplaces, phishing kits, and brute-force attack platforms, causing more than $62 million in losses to 44 identified victims across 21 U.S. states and multiple allied countries over a seven-year FBI investigation. The State Department's Rewards for Justice program is offering up to $10 million for information tying the operators to foreign-government activity, following coordinated U.S./UK/Australian sanctions in November 2025 and a joint EU/UK sanctions package in July 2026.
On December 2024 a federal grand jury in the Northern District of Ohio returned a sealed indictment against Alexander Alexandrovich Volosovik (43, alias "Yalishanda"), Kirill Andreevich Zatolokin (34), and Yulia Vladimirovna Pankova (29), along with the companies Media Land LLC and ML.Cloud LLC, both headquartered in St. Petersburg, Russia. The indictment was unsealed on 2026-07-14/15 alongside a U.S. State Department Rewards for Justice announcement and coincided with a new joint EU/UK sanctions package (2026-07-13) — the first collaborative EU/UK cyber sanctions action against Russia.
Prosecutors allege Volosovik owned and operated Media Land, Pankova owned and operated ML.Cloud (which took over portions of Media Land's book of business), and Zatolokin handled customer payment collection and cybercriminal coordination on their behalf. The two companies are alleged to have run a "bulletproof hosting" business model: knowingly renting server infrastructure to cybercriminals while ignoring or actively resisting law-enforcement abuse complaints and takedown requests, and rapidly reprovisioning or migrating infrastructure across jurisdictions to frustrate investigation. Servers tied to the operation were identified in Russia, China, Finland, the Netherlands, and the United States.
Customers of Media Land and ML.Cloud allegedly included the LockBit, BlackSuit, and Play ransomware operations, as well as a cluster of stolen-payment-card marketplaces (Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash) and services supporting phishing campaigns, credential/password brute-forcing, fraudulent domain registration, and malware distribution. The indictment cites 44 unnamed victims — including banks, K-12 schools, hospitals, government bodies, and media companies — across at least 21 U.S. states (including multiple Northern District of Ohio cities: Akron, Cleveland, Elyria, Medina, Solon, Valley View) plus victims in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom, with total documented losses exceeding $62 million.
Defendants face charges of conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. The case follows a Treasury OFAC sanctions action in November 2025 (joined by the UK and Australia) against Media Land, ML.Cloud, and a related entity, Data Center Kirishi, which was sanctioned but not named in the criminal indictment. FBI Assistant Director Brett Leatherman (Cyber Division) and Assistant Attorney General A. Tysen Duva of DOJ's Criminal Division both issued public statements framing the action as targeting "core services" and "criminal infrastructure" that underpin ransomware and fraud campaigns against U.S. critical institutions, rather than a single malware family or vulnerability. The investigation involved multi-year international cooperation with UK, Australian, and Dutch law enforcement partners.
No CVEs, malware binaries, or network-level technical IOCs were disclosed by DOJ; the only technical indicator published in initial reporting is a Tor-based public tip-reporting address associated with the case. This threat record documents bulletproof-hosting-enabled criminal infrastructure and its downstream enablement of ransomware, carding, and phishing operations — defenders should treat any observed traffic to/from historically Media Land / ML.Cloud-associated netblocks (Russia, and satellite infrastructure in China, Finland, and the Netherlands) as elevated-risk and correlate against known LockBit/BlackSuit/Play C2 and staging infrastructure.
MITRE ATT&CK techniques used in TL-2026-1580
Defense Evasion
T1027 Obfuscated Files or Information
Command and Control
T1071 Application Layer Protocol; T1090.003 Multi-hop Proxy; T1102 Web Service
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing
Discovery
Credential Access
T1110.001 Password Guessing; T1110.004 Credential Stuffing
Collection
T1213 Data from Information Repositories
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Domains; T1583.004 Server; T1583.006 Web Services; T1583.008 Malvertising; T1584 Compromise Infrastructure; T1585.001 Social Media Accounts; T1587.001 Malware
Affected products and versions in Russian Bulletproof Hosting Operators Indicted
- Media Land LLC — Bulletproof hosting infrastructure
Vulnerable versions: all hosting infrastructure operated by Media Land LLC through 2026-07 - ML.Cloud LLC — Bulletproof hosting infrastructure
Vulnerable versions: all hosting infrastructure operated by ML.Cloud LLC through 2026-07 - Data Center Kirishi — Colocation / hosting infrastructure
Vulnerable versions: infrastructure sanctioned by OFAC in November 2025
Remediation for Russian Bulletproof Hosting Operators Indicted
Immediate actions
- Block/monitor inbound and outbound traffic to netblocks historically associated with Media Land LLC and ML.Cloud LLC hosting infrastructure in Russia, China, Finland, and the Netherlands
- Flag connections to the published Tor reporting address (he5dybnt7sr6cm32xt77pazmtm65qy6irivtruqfc5ep7eiodiad.onion) and surrounding onion infrastructure for triage rather than automatic block, since it is a law-enforcement tip line
- Review historical DNS/WHOIS and passive-DNS records for domains registered through infrastructure tied to Media Land / ML.Cloud for retrospective compromise hunting
- Add LockBit, BlackSuit, and Play ransomware indicators/playbooks to active detection and IR runbooks given their confirmed use of this hosting infrastructure
Longer-term hardening
- Incorporate bulletproof-hosting provider intelligence (ASN/netblock reputation feeds) into perimeter and DNS-layer blocking
- Establish threat-intel feeds tracking OFAC-sanctioned entities (Media Land, ML.Cloud, Data Center Kirishi) for automated blocklist updates
- Strengthen card-not-present fraud monitoring given the confirmed link between this infrastructure and major carding marketplaces (Briansclub, Bidencash, and others)
- Coordinate with sector-ISACs (financial services, healthcare, education, government) to share IOCs tied to ransomware groups that historically relied on bulletproof hosting
Timeline of Russian Bulletproof Hosting Operators Indicted
- Media Land LLC is officially registered in St. Petersburg, Russia by Aleksandr Volosovik, formalizing a bulletproof hosting operation Volosovik (alias "Yalishanda"/"Downlow"/"Stas_vl") had already run informally for years from prior bases in Beijing and Vladivostok.
- FBI opens investigation into Media Land LLC and associated bulletproof hosting infrastructure, beginning a seven-year probe into services enabling ransomware, phishing, and carding operations.
- Security journalist Brian Krebs (KrebsOnSecurity) publicly identifies Alexander Volosovik as the operator behind the "Yalishanda" bulletproof hosting persona and ties him to Media Land LLC, the first major public exposure of the operation ahead of the criminal case.
- The BidenCash stolen-card marketplace, later identified as a customer of Media Land/ML.Cloud hosting infrastructure, begins operating; it goes on to traffic more than 15 million payment-card records and 117,000+ customer accounts before its 2025 takedown.
- A federal grand jury in the Northern District of Ohio returns a sealed indictment against Alexander Volosovik, Kirill Zatolokin, Yulia Pankova, Media Land LLC, and ML.Cloud LLC on computer fraud, wire fraud, and money laundering conspiracy charges.
- U.S. Secret Service and FBI, with the Dutch National High Tech Crime Unit, Shadowserver Foundation, and Searchlight Cyber, seize approximately 145 domains belonging to the BidenCash carding marketplace — one of the cybercrime services later named as a Media Land/ML.Cloud hosting customer.
- U.S. Treasury OFAC, joined by the UK and Australia, sanctions Media Land, ML.Cloud, and Data Center Kirishi for providing bulletproof hosting services to ransomware and cybercrime operations; the UK's National Crime Agency separately exposes Volosovik's role in supporting LockBit, Evil Corp, and Black Basta.
- The European Union and United Kingdom announce a joint cyber sanctions package targeting Russian bulletproof hosting infrastructure — their first collaborative cyber sanctions action against Russia.
- The U.S. State Department's Rewards for Justice program announces a reward of up to $10 million for information linking the defendants or their companies to foreign-government-directed malicious cyber activity.
- The Northern District of Ohio unseals the December 2024 indictment, publicly charging Volosovik, Zatolokin, Pankova, Media Land LLC, and ML.Cloud LLC.
- DOJ, cybersecurity trade press (BleepingComputer, CyberScoop, TechCrunch, The Record, GovInfoSecurity) and mainstream outlets report on the indictment, naming LockBit, BlackSuit, and Play ransomware operations plus multiple carding marketplaces as customers of the hosting services.
Sources cited for Russian Bulletproof Hosting Operators Indicted
- U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
- Office of Public Affairs | Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses
- US unseals indictment against alleged operators of Russian bulletproof hosting service
- US charges alleged operators of Russian bulletproof hosting service
- Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
- DOJ Indicts Russian Bulletproof Hosting Operators Over $62 Million Cybercrime Losses
- US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims
- US Indicts Russian Bulletproof Hosting Provider Media Land and Three Operators
- DOJ charges 3 Russian nationals in scheme powering cyberattacks on U.S.
- Russian fraudsters siphoned $63 million from Americans and global citizens: DOJ
- Feds Target Widely Used Russian Bulletproof Hosting Services
- Meet the World's Biggest 'Bulletproof' Hoster
- UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp
- US government seizes approximately 145 criminal marketplace domains (BidenCash)
Detection coverage for TL-2026-1580
As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1580 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.