The U.S. Department of Justice unsealed an indictment on July 14, 2026, charging three Russian nationals with running a bulletproof hosting (BPH) operation that served as the backbone for multiple ransomware gangs and cybercriminal marketplaces — enabling over $62 million in damages across 44 victims in 21 states.
The Accused
The indictment — returned by a federal grand jury in the Northern District of Ohio on December 5, 2024 and unsealed roughly 19 months later — names three defendants:
- Alexander Alexandrovich Volosovik, 43, known online as "Yalishanda" — the owner and operator of Medialand LLC; a well-known handle on cybercriminal underground forums
- Yulia Vladimirovna Pankova, 29 — owner of ML.Cloud LLC; handled legal and financial operations for both companies
- Kirill Andreevich Zatolokin, 34 — responsible for collecting payments from criminal clients
All three are based in Russia. Given that no US–Russia extradition treaty exists, they are unlikely to face immediate arrest, but the charges make international travel significantly riskier.
The Hosting Operation
Volosovik, Pankova, and Zatolokin operated two St. Petersburg–headquartered companies — Medialand LLC and ML.Cloud LLC — providing classic bulletproof hosting services:
- Fast-flux infrastructure: rapidly rotating domains across thousands of IP addresses to evade law enforcement takedowns and abuse complaints
- Falsified abuse responses: ignoring or fabricating replies to takedown requests
- On-demand rotation: churning infrastructure when it was burned or seized
- Cryptocurrency-only payments: accepting Bitcoin and other cryptocurrencies to obscure financial trails
The operation maintained databases containing approximately 389 client usernames and over 5,000 registered domains.
Criminal Clients Served
The indictment alleges the trio operated their hosting for 17 criminal groups, including:
Ransomware gangs:
- LockBit
- BlackSuit
- Play
Underground marketplaces (stolen cards, fullz, credentials):
- BriansClub, Cardhouse, crdclub, Club2crd, Verified, Fullzinfo, Swipestore, BiDenCash
Victim organizations span banks, schools, government entities, hospitals, and media companies across 21 US states.
Charges Filed
Each defendant faces:
- Conspiracy to commit and aid/abet computer fraud
- Conspiracy to commit wire fraud
- 10 counts of wire fraud
- Conspiracy to commit money laundering
The Northern District of Ohio was chosen as the venue due to the concentration of victims in that state.
Prior Sanctions
In November 2025, the US Treasury, UK, and Australia jointly sanctioned all three individuals and both companies. The EU separately sanctioned Medialand, Volosovik, and ML.Cloud. The criminal indictment escalates the pressure beyond asset freezes.
Rewards for Justice
The US State Department's Rewards for Justice program is offering up to $10 million for information on foreign government-linked individuals associated with the Medialand or ML.Cloud operations.
Why BPH Enforcement Matters
Bulletproof hosting is a force multiplier for ransomware gangs. Without reliable infrastructure, C2 servers cannot maintain persistence, leak sites go offline, and ransom negotiation portals disappear. Targeting BPH operators disrupts multiple ransomware groups simultaneously — a higher-leverage enforcement strategy than pursuing individual affiliates.
Defensive Recommendations
- Block known BPH IP ranges — threat intelligence feeds track BPH provider IP space
- Monitor for C2 communications — implement egress filtering and DNS monitoring
- Patch aggressively — ransomware entry points are commonly unpatched vulnerabilities
- Offline backups — maintain tested, air-gapped backups ransomware cannot reach
- Incident response planning — prepare a ransomware playbook before you need it