Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2579+ Articles
161+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. US Charges Three Russians for Operating Bulletproof Hosting Behind $62M Ransomware Campaign
US Charges Three Russians for Operating Bulletproof Hosting Behind $62M Ransomware Campaign
NEWS

US Charges Three Russians for Operating Bulletproof Hosting Behind $62M Ransomware Campaign

Federal prosecutors unsealed a 2024 indictment against three Russian nationals who ran Medialand LLC and ML.Cloud LLC — bulletproof hosting services used...

Dylan H.

News Desk

July 15, 2026
3 min read

The U.S. Department of Justice unsealed an indictment on July 14, 2026, charging three Russian nationals with running a bulletproof hosting (BPH) operation that served as the backbone for multiple ransomware gangs and cybercriminal marketplaces — enabling over $62 million in damages across 44 victims in 21 states.

The Accused

The indictment — returned by a federal grand jury in the Northern District of Ohio on December 5, 2024 and unsealed roughly 19 months later — names three defendants:

  • Alexander Alexandrovich Volosovik, 43, known online as "Yalishanda" — the owner and operator of Medialand LLC; a well-known handle on cybercriminal underground forums
  • Yulia Vladimirovna Pankova, 29 — owner of ML.Cloud LLC; handled legal and financial operations for both companies
  • Kirill Andreevich Zatolokin, 34 — responsible for collecting payments from criminal clients

All three are based in Russia. Given that no US–Russia extradition treaty exists, they are unlikely to face immediate arrest, but the charges make international travel significantly riskier.

The Hosting Operation

Volosovik, Pankova, and Zatolokin operated two St. Petersburg–headquartered companies — Medialand LLC and ML.Cloud LLC — providing classic bulletproof hosting services:

  • Fast-flux infrastructure: rapidly rotating domains across thousands of IP addresses to evade law enforcement takedowns and abuse complaints
  • Falsified abuse responses: ignoring or fabricating replies to takedown requests
  • On-demand rotation: churning infrastructure when it was burned or seized
  • Cryptocurrency-only payments: accepting Bitcoin and other cryptocurrencies to obscure financial trails

The operation maintained databases containing approximately 389 client usernames and over 5,000 registered domains.

Criminal Clients Served

The indictment alleges the trio operated their hosting for 17 criminal groups, including:

Ransomware gangs:

  • LockBit
  • BlackSuit
  • Play

Underground marketplaces (stolen cards, fullz, credentials):

  • BriansClub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, BiDenCash

Victim organizations span banks, schools, government entities, hospitals, and media companies across 21 US states.

Charges Filed

Each defendant faces:

  • Conspiracy to commit and aid/abet computer fraud
  • Conspiracy to commit wire fraud
  • 10 counts of wire fraud
  • Conspiracy to commit money laundering

The Northern District of Ohio was chosen as the venue due to the concentration of victims in that state.

Prior Sanctions

In November 2025, the US Treasury, UK, and Australia jointly sanctioned all three individuals and both companies. The EU separately sanctioned Medialand, Volosovik, and ML.Cloud. The criminal indictment escalates the pressure beyond asset freezes.

Rewards for Justice

The US State Department's Rewards for Justice program is offering up to $10 million for information on foreign government-linked individuals associated with the Medialand or ML.Cloud operations.

Why BPH Enforcement Matters

Bulletproof hosting is a force multiplier for ransomware gangs. Without reliable infrastructure, C2 servers cannot maintain persistence, leak sites go offline, and ransom negotiation portals disappear. Targeting BPH operators disrupts multiple ransomware groups simultaneously — a higher-leverage enforcement strategy than pursuing individual affiliates.

Defensive Recommendations

  1. Block known BPH IP ranges — threat intelligence feeds track BPH provider IP space
  2. Monitor for C2 communications — implement egress filtering and DNS monitoring
  3. Patch aggressively — ransomware entry points are commonly unpatched vulnerabilities
  4. Offline backups — maintain tested, air-gapped backups ransomware cannot reach
  5. Incident response planning — prepare a ransomware playbook before you need it

References

  • BleepingComputer — US charges alleged operators of Russian bulletproof hosting service
  • The Record — US unseals indictment against alleged operators of Russian bulletproof hosting service
#Ransomware#Russia#Cybercrime#DOJ#Bulletproof Hosting#LockBit

Related Articles

Dutch Raid Fails to Dent Russian Bulletproof Host THE.Hosting

Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the provider's core IP address space intact — and the...

6 min read

Netherlands Seizes 800 Servers of Hosting Firm Enabling

Dutch financial crime investigators (FIOD) arrested two men and seized 800 servers from a hosting company that provided bulletproof infrastructure...

4 min read

FBI: Breaking Affiliate Trust Was Key to LockBit's Takedown

An FBI agent reveals how Operation Cronos dismantled the world's largest ransomware group by exploiting fractures in LockBit's affiliate trust model — exposing the inner workings of a global cybercrime empire.

5 min read
Back to all News