# Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud

> The U.S. Attorney's Office for the Northern District of Ohio unsealed a December 2024 indictment charging three Russian nationals — Alexander Alexandrovich Volosovik ("Yalishanda"), Kirill Andreevich Zatolokin, and Yulia Vladimirovna Pankova — and their companies Media Land LLC and ML.Cloud LLC with operating "bulletproof hosting" infrastructure that knowingly serviced LockBit, BlackSuit, and Play ransomware operations, stolen-card marketplaces, phishing kits, and brute-force attack platforms, causing more than $62 million in losses to 44 identified victims across 21 U.S. states and multiple allied countries over a seven-year FBI investigation. The State Department's Rewards for Justice program is offering up to $10 million for information tying the operators to foreign-government activity, following coordinated U.S./UK/Australian sanctions in November 2025 and a joint EU/UK sanctions package in July 2026.

- **Published:** 2026-07-20T00:00:00Z
- **Last reviewed:** 2026-07-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1580
- **ID:** TL-2026-1580
- **Severity:** HIGH
- **Category:** CYBERCRIME
- **Status:** ACTIVE
- **Actor:** Media Land LLC (Russia)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On December 2024 a federal grand jury in the Northern District of Ohio returned a sealed indictment against Alexander Alexandrovich Volosovik (43, alias "Yalishanda"), Kirill Andreevich Zatolokin (34), and Yulia Vladimirovna Pankova (29), along with the companies Media Land LLC and ML.Cloud LLC, both headquartered in St. Petersburg, Russia. The indictment was unsealed on 2026-07-14/15 alongside a U.S. State Department Rewards for Justice announcement and coincided with a new joint EU/UK sanctions package (2026-07-13) — the first collaborative EU/UK cyber sanctions action against Russia.

Prosecutors allege Volosovik owned and operated Media Land, Pankova owned and operated ML.Cloud (which took over portions of Media Land's book of business), and Zatolokin handled customer payment collection and cybercriminal coordination on their behalf. The two companies are alleged to have run a "bulletproof hosting" business model: knowingly renting server infrastructure to cybercriminals while ignoring or actively resisting law-enforcement abuse complaints and takedown requests, and rapidly reprovisioning or migrating infrastructure across jurisdictions to frustrate investigation. Servers tied to the operation were identified in Russia, China, Finland, the Netherlands, and the United States.

Customers of Media Land and ML.Cloud allegedly included the LockBit, BlackSuit, and Play ransomware operations, as well as a cluster of stolen-payment-card marketplaces (Briansclub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, and Bidencash) and services supporting phishing campaigns, credential/password brute-forcing, fraudulent domain registration, and malware distribution. The indictment cites 44 unnamed victims — including banks, K-12 schools, hospitals, government bodies, and media companies — across at least 21 U.S. states (including multiple Northern District of Ohio cities: Akron, Cleveland, Elyria, Medina, Solon, Valley View) plus victims in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom, with total documented losses exceeding $62 million.

Defendants face charges of conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. The case follows a Treasury OFAC sanctions action in November 2025 (joined by the UK and Australia) against Media Land, ML.Cloud, and a related entity, Data Center Kirishi, which was sanctioned but not named in the criminal indictment. FBI Assistant Director Brett Leatherman (Cyber Division) and Assistant Attorney General A. Tysen Duva of DOJ's Criminal Division both issued public statements framing the action as targeting "core services" and "criminal infrastructure" that underpin ransomware and fraud campaigns against U.S. critical institutions, rather than a single malware family or vulnerability. The investigation involved multi-year international cooperation with UK, Australian, and Dutch law enforcement partners.

No CVEs, malware binaries, or network-level technical IOCs were disclosed by DOJ; the only technical indicator published in initial reporting is a Tor-based public tip-reporting address associated with the case. This threat record documents bulletproof-hosting-enabled criminal infrastructure and its downstream enablement of ransomware, carding, and phishing operations — defenders should treat any observed traffic to/from historically Media Land / ML.Cloud-associated netblocks (Russia, and satellite infrastructure in China, Finland, and the Netherlands) as elevated-risk and correlate against known LockBit/BlackSuit/Play C2 and staging infrastructure.

## MITRE ATT&CK

- T1583.006 Web Services
- T1583.001 Domains
- T1583.004 Server
- T1584 Compromise Infrastructure
- T1585.001 Social Media Accounts
- T1587.001 Malware
- T1566 Phishing
- T1078 Valid Accounts
- T1133 External Remote Services
- T1110.001 Password Guessing
- T1110.004 Credential Stuffing
- T1090.003 Multi-hop Proxy
- T1102 Web Service
- T1071 Application Layer Protocol
- T1486 Data Encrypted for Impact
- T1657 Financial Theft
- T1567 Exfiltration Over Web Service
- T1213 Data from Information Repositories
- T1027 Obfuscated Files or Information
- T1583.008 Malvertising
- T1087 Account Discovery

## Sources

- [U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses](https://cybersecuritynews.com/russian-trio-in-cybercrimes/)
- [Office of Public Affairs | Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more)
- [US unseals indictment against alleged operators of Russian bulletproof hosting service](https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting)
- [US charges alleged operators of Russian bulletproof hosting service](https://www.bleepingcomputer.com/news/security/us-charges-alleged-russian-bulletproof-hosting-service-operators/)
- [Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/)
- [DOJ Indicts Russian Bulletproof Hosting Operators Over $62 Million Cybercrime Losses](https://cyberpress.org/doj-russian-bulletproof-hosting-operators/)
- [US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims](https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/)
- [US Indicts Russian Bulletproof Hosting Provider Media Land and Three Operators](https://www.technadu.com/us-indicts-russian-bulletproof-hosting-provider-media-land-and-three-operators/631146/)
- [DOJ charges 3 Russian nationals in scheme powering cyberattacks on U.S.](https://www.washingtontimes.com/news/2026/jul/15/doj-charges-3-russian-nationals-scheme-powering-cyberattacks-us/)
- [Russian fraudsters siphoned $63 million from Americans and global citizens: DOJ](https://www.foxnews.com/politics/doj-charges-3-russians-alleged-63m-cybercrime-scheme-targeting-americans)
- [Feds Target Widely Used Russian Bulletproof Hosting Services](https://www.govinfosecurity.com/feds-target-widely-used-russian-bulletproof-hosting-services-a-32230)
- [Meet the World's Biggest 'Bulletproof' Hoster](https://krebsonsecurity.com/2019/07/meet-the-worlds-biggest-bulletproof-hoster/)
- [UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp](https://hackread.com/uk-bulletproof-hosting-operator-lockbit-evil-corp/)
- [US government seizes approximately 145 criminal marketplace domains (BidenCash)](https://www.justice.gov/usao-edva/pr/us-government-seizes-approximately-145-criminal-marketplace-domains)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1580
