ThreatPaper
RansomwareFinancial FraudBotnet & DDoSHigh

Media Land: The Bulletproof Hosting Business That Kept Ransomware Online

By hemker444 · 3 Sept 2026 · 16 min read

Threat Actor: Alexander Volosovik ("Yalishanda"), Kirill Zatolokin, Yulia Pankova; Medialand LLC and ML.Cloud LLC — indicted, not in custody · Target: 42 victims across 21 US states — banks, schools, government bodies, hospitals and media — plus US telecommunications and critical infrastructure via DDoS

Source: www.justice.gov


Executive Summary

Ransomware groups do not build infrastructure. They rent it.

On 14 July 2026 the Department of Justice unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two companies with running the rental business. Medialand LLC and ML.Cloud LLC, both of St Petersburg, are alleged to have supplied servers and internet infrastructure to criminal clients including the LockBit, BlackSuit and Play ransomware operations — leasing capacity designed to survive what would ordinarily remove it.

The product being sold was not computing. Commodity hosting is abundant and cheap. What Media Land is alleged to have sold is the guarantee that follows: that abuse reports would be ignored, that takedown requests would go unanswered, and that law enforcement would be met with silence. In the trade this is called bulletproof hosting, and it is a service industry with pricing, account management and support.

The division of labour named in the indictment reads like any small company. Alexander Alexandrovich Volosovik, 43 — operating under the long-established handle "Yalishanda" — owned Medialand. Yulia Vladimirovna Pankova, 29, owned ML.Cloud and is alleged to have handled legal and financial matters. Kirill Andreevich Zatolokin, 34, collected customer payments. Someone did the billing.

The infrastructure spanned Russia, China, Finland, the Netherlands and the United States. Prosecutors identified 42 victims across 21 US states — banks, schools, government bodies, hospitals and media organisations — with losses exceeding $62 million, and allege the infrastructure was also used to launch denial-of-service attacks against American telecommunications and critical infrastructure.

Three dates matter more than the charges. The indictment was returned in December 2024 and stayed sealed. Media Land was sanctioned in November 2025 in a coordinated action by the US, UK and Australia. The indictment was unsealed in July 2026, with the European Union following. That is a nineteen-month gap between charging and unsealing, and a sequence in which the financial instrument was deployed first and the criminal one second.

None of the three defendants is in US custody. All are in St Petersburg, and the State Department is offering up to $10 million through Rewards for Justice — not only for information leading to their arrest, but specifically for information about foreign government connections to Media Land and ML.Cloud. That last phrase is the most interesting sentence in the entire announcement, and nothing published elaborates on it.

This is the second paper in this archive on the infrastructure layer rather than the attackers, after the Funnull sanctions that followed the polyfill.io compromise. Both are the same recognition: it is often easier to reach the company selling the shovels than the people digging.

Verification of Claims

Claim: Three Russian nationals and two companies were indicted for operating bulletproof hosting services. → Verified — The DOJ unsealed the indictment on 14 July 2026 in the Northern District of Ohio, naming Alexander Alexandrovich Volosovik, 43; Kirill Andreevich Zatolokin, 34; Yulia Vladimirovna Pankova, 29; Medialand LLC; and ML.Cloud LLC, all of St Petersburg.

Claim: The services were used by the LockBit, BlackSuit and Play ransomware operations. → Alleged — Reported consistently and attributed to the indictment. The DOJ's own press release does not name specific ransomware families; the attribution to LockBit, BlackSuit and Play appears in reporting drawing on the charging documents. As with everything in an indictment, it is an allegation that has not been tested at trial.

Claim: The defendants caused more than $62 million in victim losses. → Alleged, and the causation deserves stating precisely — The figure is the DOJ's, describing losses from the cybercrimes the conspiracy is charged with enabling. The defendants are not alleged to have deployed ransomware themselves; they are charged with conspiracy and aiding and abetting, which is a theory under which the losses caused by their customers attach to them. That is a legitimate charging theory and it is not the same statement as "Media Land stole $62 million." Reporting that collapses the two describes a hosting company as a ransomware crew.

Claim: 42 victims across 21 US states were identified. → Alleged — The DOJ gives these figures, describing victims including banks, schools, government entities, hospitals and media organisations. No victim has been named publicly in the released statements.

Claim: Media Land was sanctioned before being charged. → Verified, and the sequence is unusual — OFAC, Australia's Department of Foreign Affairs and Trade, and the UK's Foreign, Commonwealth and Development Office announced coordinated sanctions on Media Land on 19 November 2025. The indictment had been returned in December 2024 and was not unsealed until 14 July 2026. The financial instrument therefore landed roughly eight months before the criminal charge became public, on conduct that had already been charged in secret.

Claim: The defendants have been arrested. → False — Nothing in the public record indicates any defendant is in custody. All three are located in St Petersburg, and the State Department is offering a reward of up to $10 million through Rewards for Justice, which would be unnecessary for defendants already held. Extradition from Russia is not realistically available.

Claim: Sanctions ended these operations. → False, on the available evidence — Aeza Group, another Russia-based bulletproof hosting provider, was sanctioned in July 2025 and subsequently used Hypercore Ltd, a UK-based front company, to continue operating — a fact that emerged in the November 2025 designations, which named Hypercore alongside Serbian and Uzbek companies providing technical support. Sanctioning a bulletproof hosting provider raises its costs and complicates its banking; it has not, in the documented cases, stopped it.

Claim: The reward is for the defendants' capture. → Partially true, and the more specific part is more interesting — The Rewards for Justice offer covers information about associates, and specifically about foreign government connections to Media Land and ML.Cloud. The US government is publicly paying for evidence of a state relationship it has not asserted. That is not the same as a bounty for an arrest, and no public document explains what prompted it.

Timeline

Date Actor Event Source
Before 2024 Volosovik ("Yalishanda") Operates Medialand; long-established presence in bulletproof hosting Reporting
2024-12 Grand jury, N.D. Ohio Indictment returned against three individuals and two companies; sealed DOJ
2025-07 OFAC Aeza Group, a separate Russian BPH provider, sanctioned Treasury
2025-11-19 OFAC / Australia DFAT / UK FCDO Coordinated sanctions on Media Land; also designate Aeza's UK front company Hypercore Ltd and Serbian and Uzbek technical support companies Treasury
2026-07-14 DOJ Indictment unsealed; State Department announces up to $10M reward including for foreign government connections DOJ
2026-07 European Union Issues matching sanctions Reporting

Attack Anatomy

The Product — Indifference, Sold by the Month

A bulletproof host runs the same equipment as any other host. What distinguishes it is a policy: complaints are not acted on, takedown requests are not honoured, and law enforcement enquiries are not answered.

That indifference is the product. A phishing page on ordinary infrastructure survives hours after it is reported. A ransomware leak site on ordinary infrastructure is removed once identified. A command-and-control server on ordinary infrastructure is null-routed on the first credible abuse report. Every one of those failures is a business cost for a criminal operation, and bulletproof hosting is the service that removes it.

Prosecutors describe infrastructure spread across Russia, China, Finland, the Netherlands and the United States. The geographic spread is itself a control: jurisdictions with slow or absent mutual legal assistance are load-bearing, and the presence of US-located infrastructure alongside them is the detail that makes a US prosecution possible at all.

Technique mapping (this paper's assessment): T1583 Acquire Infrastructure; T1584 Compromise Infrastructure is not applicable — nothing was compromised, it was purchased.

The Business — Roles, Not Conspirators

The most striking feature of the indictment is how ordinary the structure is.

Volosovik ("Yalishanda")   owned Medialand
Pankova                    owned ML.Cloud; legal and financial matters
Zatolokin                  collected customer payments

There is an owner, a person handling contracts and money, and a person doing accounts receivable. Two registered legal entities. This is not a cell; it is a small company whose customers happen to be ransomware operations.

That matters for how the problem is understood. Ransomware is frequently modelled as a set of gangs. The economics say otherwise: it is a market with specialised suppliers, and the suppliers are the more stable element. LockBit has been disrupted repeatedly. The infrastructure providers serving it, and Play, and BlackSuit, were the same firm.

The Customers — Named Ransomware Operations

LockBit, BlackSuit and Play are among the alleged clients. Each has been separately documented and each has done substantial damage.

BlackSuit will be familiar to readers of this archive: it is the operation behind the CDK Global compromise that halted dealer management systems across the North American automotive retail sector. The infrastructure that operation ran on was, on the allegation here, rented from a company in St Petersburg with a billing department.

The Secondary Use — Denial of Service

The indictment also alleges the infrastructure was used to launch denial-of-service attacks against American telecommunications and critical infrastructure.

This is a different use of the same asset and worth separating. Ransomware hosting is a passive service — the servers hold leak sites and C2. DDoS is an active use of capacity, and it suggests the infrastructure was rented not only as a place to hide but as a weapon to point.

T1498 Network Denial of Service.

Detection and Disruption — Financial First, Criminal Second

There is no intrusion to reconstruct here, so the interesting mechanism is the response rather than the attack.

The sequence — sealed indictment December 2024, sanctions November 2025, unsealing July 2026 — is a deliberate ordering. Sanctions do not require custody, do not require extradition and do not require proof beyond reasonable doubt. They attach to the entity, reach its banking, and expose anyone transacting with it to secondary risk. An indictment against three people in St Petersburg is, practically, a travel restriction and a statement of record.

The coordinated multinational design reflects the same logic: US, UK and Australian sanctions on the same day, with the EU following. A provider that can be sanctioned in one jurisdiction and banked in another has not been meaningfully constrained.

The investigation was led by the FBI's Cleveland Division with CISA, OFAC, the National Police of the Netherlands, the UK National Crime Agency and the Australian Federal Police.

Threat Actor Profile

Alexander Alexandrovich Volosovik, 43, of St Petersburg, alleged owner of Medialand, operating under the handle "Yalishanda" — a name with a long history in bulletproof hosting, which indicates this was not a new venture.

Yulia Vladimirovna Pankova, 29, of St Petersburg, alleged owner of ML.Cloud at the time of the investigation, alleged to have handled legal and financial matters.

Kirill Andreevich Zatolokin, 34, of St Petersburg, alleged to have collected customer payments.

All three are named in an unsealed indictment and all remain presumed innocent. None is in US custody, and none realistically will be while in Russia.

Two things about this profile are worth drawing out.

They are suppliers, not attackers. No allegation places them inside a victim network. Their alleged offence is providing the means and doing so knowingly, which is why the charges are conspiracy, aiding and abetting, wire fraud and money laundering rather than computer intrusion.

The state question is open and the US is paying to close it. The Rewards for Justice offer explicitly covers information about foreign government connections. That is a formal acknowledgement that the relationship between Russian bulletproof hosting and the Russian state is not established, and that the US government considers the answer worth up to $10 million. This paper records the question rather than answering it.

Technical Indicators

No indicators of compromise have been published, and for this incident type that is expected rather than a gap. There is no malware sample, no intrusion to detect, and no victim-side artefact — the subject is a company that rented servers.

What is operationally useful is the pattern rather than any address:

The service characteristics
  Abuse reports unanswered          Takedown requests ignored
  Law enforcement enquiries unmet   Infrastructure across
                                    RU · CN · FI · NL · US

Designated entities (OFAC, 19 Nov 2025)
  Media Land LLC
  Aeza Group LLC              (sanctioned July 2025)
  Hypercore Ltd, UK           (Aeza front company, post-sanction)
  Serbian and Uzbek technical support companies

Alleged criminal clients
  LockBit · BlackSuit · Play

Charges
  Conspiracy to commit and aid and abet computer fraud
  Conspiracy to commit wire fraud · Wire fraud
  Conspiracy to commit money laundering

The actionable control for a defender is not a blocklist of these addresses — they will change. It is checking whether your outbound traffic reaches hosting providers that appear on sanctions lists, and treating that as a compliance question as well as a security one.

Unusually for this archive, this section is the case.

Sanctions. OFAC designated Media Land on 19 November 2025 in coordinated action with Australia's Department of Foreign Affairs and Trade and the UK's Foreign, Commonwealth and Development Office. The same action designated Aeza Group's front companies — including UK-registered Hypercore Ltd — and Serbian and Uzbek entities providing technical support. The European Union subsequently issued matching sanctions.

Prosecution. Indictment returned December 2024 in the Northern District of Ohio, unsealed 14 July 2026. Charges: conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

Reward. Up to $10 million through the State Department's Rewards for Justice programme, covering information about associates and about foreign government connections to Media Land and ML.Cloud.

Investigation. FBI Cleveland Division leading, with CISA, OFAC, the National Police of the Netherlands, the UK National Crime Agency and the Australian Federal Police.

No custody, and no realistic prospect of it. Three defendants in St Petersburg, no extradition treaty that would produce them.

What this represents is a strategy rather than an outcome: raise the operating cost of the supplier when you cannot reach the customer. Whether it works is genuinely open, and the Aeza precedent — sanctioned, then continuing through a UK front company — is the strongest available evidence that it is at best a friction rather than a stop.

Impact Assessment

The quantified harm is alleged and untested. $62 million across 42 victims in 21 states, attributed to the hosting conspiracy under an aiding-and-abetting theory. With no defendant in custody, this will very likely never be tested at trial, which means the figure will stand permanently as an allegation reported as a fact.

The victim profile is the substance. Banks, schools, government bodies, hospitals and media organisations. Hospital ransomware has documented consequences for patient care, and this is the infrastructure layer that made those attacks operationally viable.

The structural finding is that ransomware is a supply chain. Disrupting operators is difficult, they rebrand, and their members disperse. The suppliers are fewer, more static, and — critically — they take payment, which makes them visible to financial instruments in a way an anonymous affiliate is not.

Sanctions raise costs without closing businesses. Aeza was sanctioned and continued through a UK front company. That is not an argument against sanctions; it is an argument that they are attrition rather than takedown, and should be described as such.

Front companies in Western jurisdictions are the weak point. Hypercore Ltd was UK-registered. The technical support entities were Serbian and Uzbek. A Russian bulletproof host with a British corporate wrapper is not a Russian problem exclusively, and company registration regimes are where that gets addressed.

Lessons and Defensive Recommendations

For Security Teams and SOC Analysts

Treat sanctioned-provider address space as a detection and a compliance signal simultaneously. Traffic to or from a designated entity's infrastructure is a security event and, potentially, a sanctions exposure.

Enrich outbound connections with hosting-provider reputation, not only IP reputation. The addresses rotate; the ASN and the provider are stickier, and bulletproof providers are a small and documented set.

Do not expect abuse reporting to work here. The defining property of these hosts is that reports go nowhere. Blocking is the available remedy, and it has to be your own.

For Hosting Providers and Registrars

Know your customer, and mean it. The distinction between a legitimate provider and this business is whether abuse handling exists in practice, not whether a policy document exists.

Front companies are the current evasion route. A UK-registered entity reselling capacity for a sanctioned Russian provider is the documented pattern, and it is visible to a provider willing to look at ownership rather than paperwork.

For Policymakers

The supplier layer is the reachable one, and the tooling is financial rather than criminal. This case is a clear demonstration: sanctions landed eight months before the criminal charge was even public, because sanctions do not require the defendant.

Coordination is what makes it bite. US, UK and Australia on the same day, EU following. A provider sanctioned in one jurisdiction and banked in another is inconvenienced, not constrained.

Corporate registration is a cyber control. Hypercore Ltd existed because it could be registered. That is a companies-registry problem with a cybersecurity consequence.

For Leadership and CISOs

Ransomware is a market with suppliers, and understanding it that way changes what disruption means. The gang that attacked you may be gone next year; the infrastructure it rented probably will not be.

Note what this case did not require. No arrest, no extradition, no trial. The instruments that reached this operation were a designation and an unsealed charge, and both landed while every defendant remained at home.

Sources

Original Incident Report →

Related Research

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail

Nobody was hacked. A Chinese CDN company bought the polyfill.io domain, and every site that had ever pasted the script tag started serving whatever the new owner wanted. Four months later it was redirecting phones to betting scams.

Financial FraudSupply Chain Attack

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware