DOJ Indicts Russian Bulletproof Hosting Operators
The US charged three Russians behind Media Land and ML.Cloud, hosting that powered LockBit, Cl0p and Play ransomware. Inside the $62M bulletproof hosting takedown.
The infrastructure that keeps ransomware running just took a public hit. The U.S. Department of Justice has unsealed an indictment charging three Russian nationals and two affiliated companies with operating “bulletproof hosting” services that, prosecutors say, provided the technical backbone for a decade of cyberattacks against American targets. The scheme is tied to more than $62 million in documented victim losses and to some of the most destructive ransomware crews in operation.
The indictment, returned in December 2024 in the Northern District of Ohio and unsealed the week of July 14, 2026, names Alexander Volosovik — known in criminal circles by the handle “Yalishanda” — along with Kirill Zatolokin and Yulia Pankova, and the companies Media Land and ML.Cloud, both headquartered in St. Petersburg, Russia. The case is a rare direct strike at a part of the cybercrime economy that usually stays invisible: not the gangs that pull the trigger, but the service providers that make the shot possible.
What “bulletproof hosting” actually is
To understand why this matters, it helps to understand what the defendants allegedly sold. Bulletproof hosting (BPH) is exactly what it sounds like — server and network infrastructure marketed to criminals on the explicit promise that the provider will ignore abuse complaints, subpoenas, and law-enforcement takedown requests. Where a legitimate host will pull a malicious server within hours of a valid report, a bulletproof host treats those reports as a feature to route around, not a problem to fix.
That reliability is the product. Ransomware crews, phishing operators, and malware distributors depend on infrastructure that stays online long enough to run a campaign — command-and-control servers to steer infected machines, staging servers to deliver payloads, and hosting for leak sites and phishing pages. According to the indictment, Media Land and ML.Cloud provided all of it, and did so knowingly, coordinating directly with cybercriminal customers and structuring the business to keep that infrastructure resilient against disruption.
Prosecutors describe a clear division of labor. Volosovik owned Media Land. Pankova owned ML.Cloud. Zatolokin was allegedly responsible for collecting payments and coordinating services with the criminal clientele — the operational glue between the infrastructure and the people renting it. To evade takedowns, the services allegedly spread infrastructure across multiple countries outside Russia, including China, Finland, the Netherlands, and even the United States, so that losing any single host would not sink a customer’s operation.
The clients read like a ransomware most-wanted list
What elevates this from a routine cybercrime case is the customer roster. The DOJ says the hosting infrastructure powered attacks by LockBit, Cl0p, BlackSuit, and Play — four of the most prolific ransomware operations of the past several years — along with at least 13 other criminal groups. Between them, those crews have hit hospitals, schools, municipal governments, and Fortune 500 companies, and have driven the kind of ransomware campaigns we have tracked across the industry.
The scale of the underlying business is striking. Court documents indicate Media Land’s client database held roughly 389 usernames and more than 5,000 registered domains — a wholesale operation serving hundreds of criminal customers rather than a boutique arrangement with a single gang. The indictment cites 44 victims who collectively suffered the $62 million in losses attributed to groups the services enabled, spanning banks, schools, government entities, hospitals, and media organizations across the country.
That structure is the point. By renting infrastructure rather than owning it, ransomware operators keep their own hands clean of the hosting layer and can migrate quickly when one provider is disrupted. Bulletproof hosts, in turn, profit from every campaign without ever deploying a payload themselves. It is a service economy, and dismantling it requires going after the service layer directly.
The charges — and the reward
The defendants are charged with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. As is typical when the accused are Russian nationals believed to be inside Russia, arrests are unlikely in the near term; the practical value of an indictment like this lies in constraining the defendants’ movement, exposing their infrastructure and aliases, and building the evidentiary record for future action.
The unsealing was paired with a financial lever. The State Department’s Rewards for Justice program announced an offer of up to $10 million for information on the defendants’ foreign-government-linked associates or their malicious cyber activity — a signal that investigators view Media Land as a node in a broader, possibly state-adjacent, ecosystem rather than an isolated criminal shop. Naming “Yalishanda,” a handle long known to threat researchers, connects a real identity to years of underground activity and complicates the operator’s ability to simply rebrand and continue.
Why the infrastructure layer is the right target
Law enforcement has spent years playing whack-a-mole with ransomware brands. Takedowns of gangs like LockBit have produced dramatic headlines, but the crews often reconstitute under new names because the surrounding economy — the hosting, the money laundering, the initial-access brokers — survives intact. Going after bulletproof hosting attacks a shared dependency that many groups rely on at once.
That is the same logic behind other recent moves to pull the rug out from under criminal infrastructure, from disrupting file-transfer platforms abused for extortion to the forced shutdown of services turned into a security threat. If a single host is serving hundreds of criminal customers, degrading or seizing it imposes cost across the entire ecosystem, not just on one gang. It raises the price of doing business, forces migrations that burn time and money, and — when paired with public attribution — chips away at the trust that holds these criminal marketplaces together.
The catch is that bulletproof hosting is stubbornly resilient by design. Operators expect to be targeted, which is why they distribute infrastructure across jurisdictions and keep reserve capacity ready. An indictment against people beyond easy reach does not, by itself, turn the servers off. But it does something subtler: it converts a quiet, low-risk business into a named, exposed, internationally pursued one, and it warns the next would-be operator that “bulletproof” is a marketing claim, not a legal shield.
What it means
This case is a reminder that the ransomware problem is an economy, not a set of villains — and economies are attacked most effectively at their shared infrastructure.
For defenders, the takeaways are practical. The victims here were the usual cross-section — hospitals, schools, banks, local governments — targeted not for who they are but for how reachable and how under-defended they are. Nothing about a bulletproof-hosting indictment changes the fundamentals of defense: patch known-exploited vulnerabilities quickly, enforce multi-factor authentication everywhere, segment networks so a single compromise cannot spread, and adopt a zero-trust posture that assumes breach rather than trusting the perimeter. The hosting takedown removes one supplier; it does not remove the demand.
For the broader fight, disruption is a war of attrition. Every host exposed, every alias burned, every payment rail cut raises the operating cost of ransomware without ever requiring an arrest. That is a slower, less satisfying model than a perp walk, but it may be the more durable one — the same pattern of industrialized, service-based cybercrime runs through the large-scale extortion campaigns hitting data-rich organizations, and starving those campaigns of infrastructure is one of the few levers that scales.
What to watch next. Two things. First, whether the naming of Media Land triggers voluntary de-peering or seizure of the servers it distributed across cooperative jurisdictions like the Netherlands and Finland — that, more than the charges themselves, would take capacity offline. Second, whether the Rewards for Justice offer surfaces information tying these operators to state-linked actors, which would reframe bulletproof hosting from ordinary cybercrime into an instrument of something larger. Either way, the message the DOJ intended is clear: the plumbing of the ransomware economy is now a target in its own right.
Tagged
Keep reading
Chisato · · 5 min read Cl0p Exploits PTC Windchill Zero-Day (CVE-2026-12569)
Cl0p is exploiting a critical PTC Windchill and FlexPLM flaw, CVE-2026-12569, for unauthenticated RCE and mass engineering-data theft in a double-extortion wave.
Chisato · · 5 min read Kudankulam Nuclear Plant Data Breach: What Leaked
Ransomware group World Leaks published 19,000 files tied to India's Kudankulam nuclear plant, leaked via contractor Reliance and data host Yotta.
Chisato · · 6 min read Coca-Cola Fairlife Ransomware Attack Halts US Production
Coca-Cola disclosed in an SEC 8-K that a ransomware attack on dairy subsidiary fairlife forced a temporary suspension of all US production operations.