U.S. Unseals Charges Against Russian Trio Over $62 Million Cybercrime Operation


U.S. prosecutors have unsealed an indictment charging three Russian nationals and two companies with operating bulletproof hosting infrastructure that allegedly supported ransomware, malware, phishing and other cybercrimes. Authorities say the activity caused more than $62 million in victim losses.

The defendants are Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin and Yulia Vladimirovna Pankova. The indictment also charges St. Petersburg-based Medialand LLC, commonly written as Media Land, and ML.Cloud LLC.

A federal grand jury returned the indictment in December 2024. The U.S. Department of Justice unsealed the charges in the Northern District of Ohio on July 14, 2026. All charges remain allegations, and the defendants are presumed innocent unless proven guilty.

Who Has Been Charged?

Prosecutors describe Volosovik as the owner of Media Land. Pankova allegedly owned ML.Cloud at the time of the investigation and indictment, while authorities describe Zatolokin as a Media Land employee involved in payments and coordination with customers.

The defendants face charges involving conspiracy to commit and aid computer fraud, conspiracy to commit wire fraud, wire fraud and conspiracy to commit money laundering.

The indictment does not allege that every server customer or activity associated with the companies was criminal. Prosecutors must prove that the defendants knowingly participated in the charged conduct.

DefendantAlleged role
Alexander Alexandrovich VolosovikOwner and operator associated with Media Land
Kirill Andreevich ZatolokinMedia Land employee allegedly involved in payments and coordination
Yulia Vladimirovna PankovaAlleged owner of ML.Cloud during the investigation and indictment
Medialand LLCRussia-based hosting company charged as a corporate defendant
ML.Cloud LLCRelated hosting company charged as a corporate defendant

What Is Bulletproof Hosting?

Bulletproof hosting providers supply servers, network addresses, domains and related technical services while resisting abuse complaints and law enforcement takedown efforts. Criminal customers can use this resilience to keep malicious infrastructure online for longer periods.

These services may move workloads between providers, replace blocked IP addresses, register new domains or conceal the people controlling the servers. Some use fast-flux techniques that rapidly rotate the IP addresses connected to a domain.

The U.S. Treasuryโ€™s Media Land sanctions announcement describes bulletproof hosting as infrastructure designed to evade detection and frustrate efforts to disrupt malicious cyber activity.

  • Command-and-control servers for malware
  • Ransomware negotiation and data-leak infrastructure
  • Phishing websites and credential-collection pages
  • Servers used for password-guessing attacks
  • Fraudulent domain registration
  • Criminal forums and online marketplaces
  • Distributed denial-of-service infrastructure

Media Land Allegedly Supported Criminal Customers

According to prosecutors, Media Land and ML.Cloud supplied criminal customers with servers and technical support used to infect computers, distribute ransomware and extort victims for money or cryptocurrency.

The companies also allegedly supported phishing, brute-force attacks, fraudulent domains and criminal marketplaces. Media Land infrastructure operated from several countries, including China, Finland, the Netherlands and the United States.

Authorities allege that Volosovik advertised the services on cybercrime forums and promoted features useful to criminal clients. The U.S. government has also identified โ€œYalishandaโ€ as an alias associated with him.

Victims Spanned 21 U.S. States

The indictment identifies 42 victims across 21 states. Prosecutors say affected sectors included banking, education, government, healthcare and media.

Ohio victims were located in or associated with Akron, Cleveland, Elyria, Medina, Solon and Valley View. Authorities also linked the alleged operation to victims outside the United States, including organizations in Australia, Canada, Europe, the United Arab Emirates and the United Kingdom.

The $62 million figure represents losses attributed by prosecutors to criminal activity supported by the alleged infrastructure. It does not represent a judgment or restitution order, and the government must prove its allegations in court.

Case detailReported information
Individual defendantsThree Russian nationals
Corporate defendantsMedia Land and ML.Cloud
Identified U.S. victims42
States represented21
Alleged victim lossesMore than $62 million
Indictment returnedDecember 2024
Indictment unsealedJuly 14, 2026

Ransomware Groups Allegedly Used the Infrastructure

The U.S. government has connected Media Land infrastructure to ransomware operations including LockBit, BlackSuit and Play. These groups have targeted organizations across multiple industries and countries.

The Treasury Departmentโ€™s coordinated sanctions notice also says Media Land infrastructure supported distributed denial-of-service attacks against U.S. companies and critical infrastructure.

Hosting providers occupy an important position in the cybercrime economy. Attackers can replace individual malware samples or phishing domains quickly, but reliable infrastructure, payment support and technical assistance help them maintain campaigns at scale.

United States, United Kingdom and Australia Imposed Sanctions

The United States, United Kingdom and Australia announced coordinated sanctions against Media Land-related targets in November 2025. The U.S. action covered Media Land, ML.Cloud, Volosovik, Zatolokin and Pankova, along with associated companies.

Under U.S. sanctions, property and interests in property belonging to designated people or entities that fall under U.S. jurisdiction are blocked. U.S. persons generally cannot conduct transactions involving those designated parties unless authorized or exempt.

Sanctions can also affect companies owned 50 percent or more by blocked parties. Financial institutions and service providers must therefore screen transactions and business relationships for direct and indirect exposure.

European Union Adds Further Restrictions

The European Union imposed additional sanctions on July 13, 2026, one day before the Justice Department announced the unsealed indictment.

The Council of the European Union listed Media Land, ML.Cloud and Volosovik as part of a wider package targeting people and entities accused of enabling or conducting Russian cyber activity.

The Council said Media Land facilitated malware, ransomware and phishing operations affecting critical infrastructure and essential services in EU member states and elsewhere. The European action forms a separate legal measure from the U.S. criminal indictment.

ActionDateAuthority
Federal indictment returnedDecember 2024U.S. grand jury
Coordinated sanctions announcedNovember 19, 2025United States, United Kingdom and Australia
EU sanctions announcedJuly 13, 2026Council of the European Union
Indictment unsealedJuly 14, 2026U.S. District Court, Northern District of Ohio
Reward offer publicizedJuly 14, 2026U.S. Rewards for Justice

State Department Offers Reward of Up to $10 Million

The U.S. State Departmentโ€™s Rewards for Justice program is offering up to $10 million for qualifying information connected to Media Land, ML.Cloud and the named individuals.

The reward has a narrower scope than a general offer for information leading to an arrest. The official Media Land reward notice seeks information about people acting under the direction or control of a foreign government who participate in malicious cyber activity against U.S. critical infrastructure.

Wanted reward banner (Source – Justice.gov)

The Justice Department also said possible relocation may be available. People with relevant information should use only reporting options published on the official Rewards for Justice website, since copied Tor addresses can contain dangerous or misleading alterations.

The Reporting Channel Is Not an IOC

The Tor address publicized by the government is a channel for submitting tips to Rewards for Justice. It is not malicious infrastructure associated with Media Land and should not be added to threat-blocking systems as an indicator of compromise.

Security teams should also avoid copying sensitive reporting addresses from screenshots, reposts or third-party articles. A single incorrect character can send a user to the wrong destination or expose them to impersonation attempts.

The official Rewards for Justice page provides the current Tor destination and additional reporting methods. Users should verify that information directly before sending evidence.

Why Infrastructure Disruption Matters

Ransomware and phishing operations depend on more than malware. They need hosting, domains, network addresses, payment services, technical support and ways to replace infrastructure after defenders block it.

Targeting infrastructure providers can affect several criminal groups at once. Sanctions may restrict payments and business relationships, while criminal charges can expose operators, aliases, companies and alleged roles.

The EU sanctions action and the U.S.-led measures show increased international attention on companies accused of making cybercrime infrastructure more durable.

What Organizations Should Do

The charges do not identify a single vulnerability or malware family that organizations can patch. Defenders should focus on controls that reduce the success of phishing, credential theft, malware execution and ransomware movement.

Network teams can use hosting and domain intelligence to identify suspicious communication patterns. However, an IP address belonging to a hosting provider should not automatically be treated as proof of criminal activity because hosting ranges can change ownership or contain mixed customers.

The Justice Department case announcement describes the action as part of Operation Riptide, an FBI campaign targeting the actors, infrastructure and financial networks supporting cybercrime and fraud.

  • Apply security updates to internet-facing systems promptly.
  • Require phishing-resistant multi-factor authentication for sensitive accounts.
  • Restrict administrative access and monitor privilege changes.
  • Detect unusual outbound connections and newly registered domains.
  • Block known malicious infrastructure using current threat intelligence.
  • Maintain offline or isolated backups and test restoration procedures.
  • Separate critical systems to limit ransomware movement.
  • Train staff to identify phishing and unexpected authentication requests.
  • Preserve logs that can support investigations and infrastructure tracing.
  • Review vendors and hosting partners against current sanctions lists.

FAQ

Who was charged in the Media Land cybercrime case?

U.S. prosecutors charged Russian nationals Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin and Yulia Vladimirovna Pankova. The indictment also names Medialand LLC and ML.Cloud LLC as corporate defendants.

How much money did victims allegedly lose?

The Justice Department says cybercrimes supported by the alleged infrastructure caused more than $62 million in victim losses. This amount remains an allegation that prosecutors must prove in court.

What is bulletproof hosting?

Bulletproof hosting provides servers and related internet services designed to resist abuse complaints, regulatory action and law enforcement disruption. Criminals may use these services for ransomware, phishing, malware, fraudulent domains and command-and-control systems.

How many victims were identified in the indictment?

Prosecutors say criminal groups using Media Land and ML.Cloud services targeted 42 victims across 21 U.S. states. The affected sectors allegedly included banks, schools, hospitals, government entities and media companies.

What is the reward for information about Media Land?

The U.S. Rewards for Justice program is offering up to $10 million for qualifying information involving foreign government-linked associates, malicious cyber activity or foreign government-linked use of Media Land and ML.Cloud.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages