EDP / BPH Providers / Media Land LLC / Yalishanda
Media Land LLC / Yalishanda
Russia-based bulletproof hosting provider | St. Petersburg, Russia | Active since ~2009 | AS206728 (MEDIALAND-AS) | Sanctioned US/UK/AU Nov 19, 2025 and EU Jul 13, 2026 | Indicted N.D. Ohio (Case 1:24-CR-001161, Judge Barker), unsealed Jul 14, 2026
Degraded

Executive Summary and Provider Overview

v2.2 Current as of 27 July 2026. Supersedes v2 (26 July 2026) and v1 (June 2026). Built on direct review of the charging document in United States v. Volosovik et al., Case 1:24-CR-001161 (N.D. Ohio).
Source The full charging document has now been read, all 75 pages, Counts 1 through 13 plus the sentencing enhancement and forfeiture allegation. The v2 caveat about unread counts is retired. Where this profile departs from the DOJ press releases or from trade reporting, the charging document governs.
Changes Since v2.1: all 56 charged domains swept against RDAP and live DNS. medialand.pro found live in Media Land's own address space and named in no source; ffv2.ru found on German hosting created after the sanctions; live Deutsche Telekom phishing in the designated prefix; and Grisha Maslinikov identified on two prefixes but in no enforcement action. Full change record.
Indicted and Sanctioned Operators: Escalated Module
Aleksandr Alexandrovich Volosovik
Owner, Media Land LLC / Principal Operator
Age / DOB: 43; 30 January 1983
Birthplace: Brovary, Kyiv Oblast, Ukraine
Citizenship: Russian Federation
Location: St. Petersburg, Russia (DOJ; not in custody)
Handles: Yalishanda, downlow, nishebrod, Stas_vl, LARVA-34
Email: [email protected] | [email protected]
Phone: +7 981 126 3828 | iCloud: 1373199991
BTC (OFAC): 18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB
INDICTED N.D. OHIO, UNSEALED JUL 14, 2026 OFAC · UK FCDO · AU DFAT (Nov 2025) · EU (Jul 2026)
Yulia Vladimirovna Pankova
Owner, ML.Cloud LLC / Legal and Financial Operations
Age: 29 (DOB approx. 1996 to 1997, derived)
Location: St. Petersburg, Russia (DOJ; not in custody)
Role: Owned ML.Cloud at time of investigation and indictment; handled its legal and financial operations; per OFAC also handled Volosovik's personal finances
Note: Distinct from Yuliya V. Pankratova (Z-Pentest / CARR)
INDICTED N.D. OHIO, UNSEALED JUL 14, 2026 OFAC · UK FCDO (Nov 2025)
Kirill Andreevich Zatolokin
Payments and Client Coordination
Age / DOB: 34; 30 April 1992
Origin: Vladivostok, Russia
Location: St. Petersburg, Russia (DOJ; not in custody)
Handles: slim shady, g_host, podzemniy, podzemniyl
Telegram: @ohyehhellno
Phone: +7 999 220 2488 | iCloud: 1004652016
Email: [email protected]; [email protected]
INDICTED N.D. OHIO, UNSEALED JUL 14, 2026 OFAC · UK FCDO · AU DFAT (Nov 2025)
Andrei Valerevich Kozlov
Associated Individual (sanctioned, not indicted)
DOB / Location: Unknown; Russia assessed
Role: Employed by or associated with Media Land LLC; function not specified by OFAC
Analytic note: Omission from the December 2024 indictment despite November 2025 designation suggests either a peripheral role or insufficient charging evidence
OFAC · UK FCDO (Nov 2025) · NOT INDICTED
Degraded
Operational Status
3
Individuals Indicted
$62M+
US Victim Losses (DOJ)
$10M
Rewards for Justice Offer
44
Victims in Indictment
4
Sanctioning Authorities
AS206728
Primary ASN (Active)
~2009
Active Since (Yalishanda)
17
Client Conspirators Charged
5,000+
Registered Domains
389
ffpanel Usernames
$2M+
On-Chain Volume (TRM)
Listed
Spamhaus / Blocklist

Quick-Reference Attributes

Common NamesMedia Land LLC; Medialand LLC; Yalishanda; Abushost; ML.Cloud LLC; Media Land Technology; Data Center Kirishi; real-hosting[.]biz (historic)
Node TypeBulletproof Hosting Provider
StatusDegraded AS206728 fully active as of latest BGP snapshot; sanctioned in four jurisdictions; three principals indicted; no arrests, no seizures
PRODAFT DesignationLARVA-34 (EU designation lists LARVA-34 as a Volosovik alias)
Criminal Charges Corrected v2.1Case 1:24-CR-001161, Judge Barker, N.D. Ohio Eastern Division. Returned under seal 5 December 2024; unsealed 14 July 2026. Thirteen counts, plus a sentencing enhancement under 18 U.S.C. §3559(g)(1) and a forfeiture allegation. Defendants: Volosovik, Zatolokin, Pankova, Medialand LLC, ML.Cloud LLC. Signed by then US Attorney Rebecca C. Lutzko. Full count schedule in Section 08
Documented Losses Corrected from indictmentOver $62M taken from Victims 1 through 44 as enumerated in the indictment. The DOJ press-release figure of 42 counts US victims only; Victim 2 (North Grenville, Canada) and Victim 16 (Redditch, UK) are the non-US entries. Sectors: banks, schools, government entities, hospitals, media companies. Ohio venue victims in Akron, Brookfield, Canton, Cleveland, Elyria, Findlay, Medina, Solon, Valley View
Rewards for Justice New in v2Up to $10M plus possible relocation, announced 14 July 2026, for information on foreign government-linked associates of the three defendants, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud
Entity Registration JurisdictionRussia: Media Land LLC registered St. Petersburg, October 2015 (semi-industrial district); Data Center Kirishi registered Leningrad Oblast, July 2022; ML.Cloud and Media Land Technology also Russia-registered, St. Petersburg
Infrastructure Hosting Jurisdiction Corrected in v2Multi-jurisdictional. Russia (primary: St. Petersburg; owned DC at Kirishi, Leningrad Oblast) plus documented physical infrastructure in Finland, the Netherlands, and the United States. v1 incorrectly assessed infrastructure as Russia-only
Assessed Operator LocationRussia: all three indicted defendants listed by DOJ as residing in St. Petersburg. Volosovik relocated from Vladivostok approximately 2018 per Intel 471. None in custody; Russia has no extradition treaty with the US
Active Period~2009 to present (Yalishanda brand, 15+ years); indictment traces Media Land operations to at least 2014; entity incorporated October 2015
Primary ASNAS206728 MEDIALAND-AS (RIPE; registered 2016-11-17; last modified 2025-01-21; active)
Secondary ASN Corrected from indictmentAS215376 ML.Cloud, hardware physically located in the Netherlands per the indictment. v1 incorrectly listed AS211805 from IPinfo. The indictment states Media Land and ML.Cloud controlled ASN blocks 206728 and 215376, running on hardware in Russia and the Netherlands respectively as of about June 2024
IPv4 Prefixes (AS206728)45.141.84.0/24 (ML Cloud); 45.141.85.0/24 (Media Land); 45.141.86.0/24 (ML Cloud); 45.141.87.0/24 (Grisha Maslinikov); 91.220.163.0/24; 193.242.153.0/24 (IT Outsourcing LLC); 194.26.29.0/24; 194.26.69.0/24. Total 2,048 IPv4
IPv6 Prefixes2a0b:7ec0:1320::/48; 2a0b:7ec0:7701::/48
Fast-Flux Platform Confirmed from indictmentPlatform domain ffv2.ru with the "ffpanel" web application. Supporting estate: ffpanel.ru, ffpanel.top, sshvps.net, abushost.ru. Backend database "ffpanel" with 41 tables holding registered users, domains, DNS records, credentials, service costs and cryptocurrency transactions. Tariff ladder quoted verbatim in Section 03
Client Scale Confirmed from indictmentApproximately 389 unique usernames in the ffpanel backend, attributed to Client Conspirators 1, 3 to 8 and 14; over 5,000 unique registered domains; 17 Client Conspirators charged (CC1 to CC17). AS206728 IP allocation grew from over 3,800 (June 2024) to over 5,800 (July 2024)
BGP Peers / UpstreamAS49531 (NetCom-R LLC, RU); AS20632 (PJSC MegaFon, RU); AS202799 (SYSECT D.O.O., Montenegro); AS51538 (Lavrentyev A.A., RU). Historical RIPE IRR: AS3216 (Vimpelcom/Beeline), AS9049 (ERTH Corporation JSC)
RIPE Maintainersmnt-ru-media-land-1; media-land-llc; NETWORK-SUPPORT-MNT; RIPE-NCC-END-MNT
Abuse ContactNot publicly disclosed in RIPE WHOIS (personal data removed under RIPE policy). Indictment alleges defendants repeatedly ignored or falsified abuse reports
Clients Revised in v2The indictment names no ransomware group, referring only to Client Conspirators 1 to 17. Group names derive from the DOJ press release and OFAC: LockBit, BlackSuit, Play (CONFIRMED); BlackBasta, Evil Corp (CONFIRMED via leak correlation and UK FCDO); MedusaLocker (CREDIBLE, single source). Cl0p is named in neither the indictment nor the press release and is downgraded. Confirmed by the indictment itself: eight carding marketplaces by name and domain, plus Ermac and RedAlert Android banking trojans
Bitcoin Address (OFAC)18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB (designated, Volosovik)
Blocklist StatusSpamhaus SBL/CBL: confirmed listed; DROP/EDROP: probable; abuse.ch: probable. Specific current entry IDs not confirmed in open sources
SanctionsOFAC CYBER3 (E.O. 13694 as amended), UK FCDO, AU DFAT: all 19 November 2025. EU (Council Decision (CFSP) 2026/1713; Implementing Regulation (EU) 2026/1714): 13 July 2026
State Nexus TierTolerated Safe Harbor (Tier 2 of 4). Held at Tier 2 in v2; RFJ framing logged as an escalation indicator, not a tier change

Overall Assessment

Media Land LLC, operating under the underground brand "Yalishanda," is among the most thoroughly documented and longest-running Russian bulletproof hosting providers in the threat landscape, with confirmed activity from approximately 2009 to present. As of this revision the provider and its principals face the most complete Western enforcement stack applied to any BPH operator to date: criminal indictment in the United States, sanctions in four jurisdictions, and a $10 million intelligence bounty. None of it has yet altered the infrastructure.

Confirmed On 14 July 2026 the Department of Justice unsealed an indictment returned under seal on 5 December 2024 in the Northern District of Ohio, charging Volosovik, Zatolokin, Pankova, Medialand LLC, and ML.Cloud LLC with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, ten counts of wire fraud, and conspiracy to commit money laundering. The indictment names 42 US victim organizations across 21 states, with more than $62 million in documented losses, and identifies victims including banks, schools, government entities, hospitals, and media companies. The case is prosecuted by CCIPS Trial Attorney Christen Gallagher and AUSA Duncan T. Brown, investigated by FBI Cleveland with CISA and OFAC support, and materially assisted by the Dutch National Police and Public Prosecutor's Office, the UK National Crime Agency, and Australian authorities. [16]

Confirmed The indictment corrects a significant element of the prior assessment. Media Land's infrastructure was not confined to Russia: it operated out of Finland, the Netherlands, and the United States. That multi-jurisdictional footprint explains both the seven-year investigative timeline and the participation of Dutch law enforcement, and it materially changes the disruption calculus, because a portion of the estate sits inside jurisdictions where Western legal process reaches. It also reframes the provider's own marketing: Zatolokin's claim to BlackBasta that "this is all our own: our own data center, our own hardware" described the Russian core, not the whole estate. [16][17]

Confirmed The indictment also establishes that Pankova owned ML.Cloud LLC at the time of investigation, upgrading her from the support role assessed in v1 to a principal. It documents a fast-flux DNS product advertised on Exploit in December 2018 at $150 to $500 per month, a client database of roughly 389 usernames and more than 5,000 domains, service to 17 or more criminal groups, eight named carding marketplaces, and hosting for the Ermac and RedAlert Android banking trojans. [16][19][20]

Confirmed Separately, on 13 July 2026 the Council of the European Union designated Media Land LLC, ML.Cloud, and Volosovik under the EU cyber sanctions regime, making the EU a fourth sanctioning authority. The action was taken simultaneously with a UK package covering a different target set, the first time the EU and UK have acted at the same time under their respective cyber regimes. [21][22]

Status is held at Degraded rather than escalated to Disrupted. AS206728 remains fully active with all eight IPv4 and two IPv6 prefixes announced. No defendant is in custody, no servers have been seized, and Russia has no extradition treaty with the United States. FBI Cyber Division Assistant Director Brett Leatherman stated after the unsealing that the bureau believes Media Land "is likely still shielding criminal activity" and is actively monitoring for client migration. The enforcement stack is now near-complete on paper and almost entirely unrealized in effect: the practical pressure runs through financial and intelligence channels rather than any near-term prospect of trial. [19][20]

Lineage and Organizational Heritage

Entity and Brand Timeline

Brand / EntityTypeRolePeriodConfidence
YalishandaUnderground brand / personaPrimary criminal trading name; used on Exploit, XSS, Dark Money and predecessor forums to advertise BPH services~2009 to presentConfirmed
real-hosting[.]bizEarly BPH domainService advertised circa 2011; accepted botnets, malware, adware, exploits, Zeus, IRC~2011Confirmed
abushost[.]ru / AbushostLong-lived BPH brandAmong the most durable Yalishanda brand names; advertised on Exploit[.]in and XSS[.]pro per TRM Labs~2015 onwardConfirmed
Media Land operations (pre-incorporation) New in v2Operational activityIndictment traces Media Land operational history to at least 2014, two years before open forum advertising under the Media Land structureFrom at least 2014Confirmed
Media Land LLC (ООО Медиа Лэнд)Russian LLC (OOO)Legal entity providing surface-level commercial credibility; enabled contracts, IP leasing, and staff employment. Owned by VolosovikRegistered October 2015 to presentConfirmed
ML.Cloud LLC Revised in v2Russian LLCSister company; infrastructure used in conjunction with Media Land in ransomware and DDoS operations. Owned by Pankova at time of investigation and indictmentActive; dates not confirmedConfirmed
Media Land Technology (MLT)Russian LLC, 100% subsidiaryWholly owned subsidiary of Media Land LLC per OFAC; likely infrastructure or services wrapper. Sanctioned but not chargedActive; dates not confirmedConfirmed
Data Center Kirishi (DC Kirishi)Russian LLC, 100% subsidiaryWholly owned subsidiary registered July 2022; owned physical data center in Kirishi, Leningrad Oblast. Sanctioned but not chargedJuly 2022 to presentConfirmed
AS206728 (MEDIALAND-AS)Autonomous System, RIPEPrimary network backbone; 8 IPv4 and 2 IPv6 prefixes, 2,048 IPv4 addressesRegistered Nov 17, 2016; activeConfirmed

Predecessor Lineage and Early History

Yalishanda's criminal activity is confirmed from approximately 2009 and assessed to extend into the late 2000s. KrebsOnSecurity first encountered the persona in 2010 in connection with "Fizot," a botnet anonymization service built on TDSS-infected Windows machines. A 2010 registration for mo0be-world[.]com tied to [email protected] and the name Aleksandr Volosovyk provided the first documented link between persona and real identity. [1]

By 2011 Yalishanda was advertising under real-hosting[.]biz. Intel 471 and Cisco researchers identified Yalishanda as a top-tier BPH provider at Black Hat 2017, noting that in a single 90-day period in 2017 the infrastructure hosted Dridex, Zeus, and multiple ransomware families. [1]

Confirmed New in v2 The indictment pushes documented Media Land operational history back to at least 2014, predating both open forum advertising under that structure and the October 2015 incorporation. It also places the company in a semi-industrial district of St. Petersburg. By August 2016 Volosovik and Zatolokin were advertising on the Dark Money forum under the pseudonym "podzemniy." [16][19][20]

Evidentiary Pillars

Identity Confirmation: Multiple Corroborating Sources

Confirmed Volosovik's identity as Yalishanda rests on: (1) 2010 domain registration linking [email protected] to Aleksandr Volosovyk; (2) a 2010 passport scan submitted to the ChronoPay payment processor confirming name, DOB, and birthplace; (3) Rusprofile.ru business registry listing him as director of Media Land LLC; (4) formal designation by OFAC, UK FCDO, and AU DFAT in November 2025 and by the EU in July 2026; (5) a REvil member using the handle "Unknown" addressing him by first name "Sasha" in a 2019 XSS arbitration thread; and (6) as of v2, a federal criminal indictment naming him with age and city of residence. [1][3][16]

Leak Validation: Media Land Internal Data, March 2025

Confirmed On 28 March 2025 an unknown actor leaked Media Land's internal database containing server configurations, client purchase history, user account data, and cryptocurrency addresses. Volosovik acknowledged the breach on a hacking forum, validating authenticity. PRODAFT, which designates the provider LARVA-34, assessed the leak as rare high-value insight into criminal infrastructure. The scale figures now alleged in the indictment (389 usernames, 5,000+ domains) are consistent with a client database of this kind. [4][5]

Deconfliction Warning: Name Collision

Yulia Vladimirovna Pankova (owner of ML.Cloud LLC; OFAC and UK-designated November 2025; indicted N.D. Ohio) is a different individual from Yuliya Vladimirovna Pankratova (leader of the Z-Pentest hacktivist group and a member of Cyber Army of Russia Reborn; EU-designated 13 July 2026, also named on the UK's 13 July list). The two names are similar, both are Russian women with the patronymic Vladimirovna, and both appear in cyber sanctions actions dated within 24 hours of each other. They are unconnected. Analysts consuming July 2026 sanctions reporting should verify which individual is referenced. [21][22]

Operator Profiles

2.1 Aleksandr Alexandrovich Volosovik: Owner and Principal Operator

Full NameAleksandr Alexandrovich Volosovik (Александр Александрович Волосовик); DOJ spelling "Alexander Alexandrovich Volosovik"
Age / Date of Birth43 (per DOJ, July 2026); 30 January 1983
Place of BirthBrovary, Kyiv Oblast, Ukraine (confirmed via passport; family assessed to have relocated to Russia before 1990)
CitizenshipRussian Federation
Handle HistoryYalishanda (primary); downlow; nishebrod; Stas_vl. EU designation additionally lists LARVA-34
EducationSchool No. 80, Vladivostok (1990 to 2000); Far Eastern State Technical University (ДВГТУ), Institute of Mechanics, Automation and Advanced Technologies, Automated Production Systems, graduated 2005
GeographyBrovary, Ukraine (birth); Vladivostok, Russia (schooling and university); Beijing, China (documented period; passport issued by Russian Embassy Beijing); St. Petersburg, Russia (current, per DOJ)
RoleOwner of Media Land LLC. Advertised services on criminal forums under Yalishanda; provided servers and conducted troubleshooting for ransomware and DDoS actors (OFAC)
Criminal OnsetApproximately 2009 confirmed; late 2000s assessed
Legal Status Revised in v2Indicted. N.D. Ohio, indictment returned 5 December 2024, unsealed 14 July 2026. Charges: conspiracy to commit and aid and abet computer fraud; conspiracy to commit wire fraud; ten counts of wire fraud; conspiracy to commit money laundering. Not in custody; assessed in Russia. Presumed innocent
SanctionsOFAC (E.O. 13694 as amended), UK FCDO, AU DFAT: 19 November 2025. EU: 13 July 2026 (Council Decision (CFSP) 2026/1713)
Sanctioned BTC Address18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB
RFJ Exposure New in v2Named subject of the $10M Rewards for Justice offer for information on foreign government-linked associates and foreign government-linked use of his companies

2.2 Yulia Vladimirovna Pankova: Owner of ML.Cloud LLC Substantially revised in v2

Assessment Change

v1 assessed Pankova as a legal and financial associate to Volosovik, based on the OFAC designation language ("aware of Volosovik's illicit activity, has assisted Volosovik with legal issues, and has handled his finances") and her designation basis of having materially assisted him. The indictment establishes that she owned ML.Cloud LLC at the time of investigation and indictment. She is a corporate principal charged on the same counts as Volosovik, not a peripheral support figure. This is the largest single analytic correction in v2.

Full NameYulia Vladimirovna Pankova
Age / Date of Birth29 (per DOJ, July 2026). DOB not published; derived range approximately 1996 to 1997 Analyst Inference
LocationSt. Petersburg, Russia (per DOJ). Not in custody
RoleOwner of ML.Cloud LLC at the time of investigation and indictment; handled ML.Cloud's legal and financial operations. Per OFAC, also aware of Volosovik's illicit activity, assisted him with legal issues, and handled his personal finances
Analytic NoteAge 29 places her at approximately 18 to 19 when Media Land LLC was incorporated in October 2015 and approximately 27 at the time of the December 2024 indictment. The gap between her age and her ownership of a sister company to a long-running criminal enterprise raises an unresolved question about whether the ML.Cloud ownership is beneficial or nominal. Formal ownership is confirmed; the substance of control is not Analyst Inference
Relationship to VolosovikPersonal relationship confirmed via the OFAC photo release (Figure 2, sb0319)
Legal Status Revised in v2Indicted. N.D. Ohio, same counts and dates as Volosovik. Presumed innocent
SanctionsOFAC, UK FCDO: 19 November 2025. Not named in the EU 13 July 2026 designation, which listed Volosovik only among the three defendants
Do Not Confuse WithYuliya Vladimirovna Pankratova (Z-Pentest / CARR), EU-designated 13 July 2026. Unrelated individual

2.3 Kirill Andreevich Zatolokin: Payments and Client Coordination

Full NameKirill Andreevich Zatolokin (Кирилл Андреевич Затолокин)
Age / Date of Birth34 (per DOJ, July 2026); 30 April 1992
OriginVladivostok, Russia; graduated School No. 23 (МОУ СОШ 23), Vladivostok, 2009
EducationBeijing Institute of Fashion Technology, enrolled 2009; documented physically present in Beijing through at least 2014
HandleSlim Shady
ContactTelegram @ohyehhellno, attributed to Zatolokin by Analyst1 from a forum screenshot showing the handle alongside the display name "Slim Shady"; observed in Yalishanda advertising from at least November 2018
Known Emails[email protected]; [email protected] (from 2013 to 2014 VKontakte job postings)
Operational RoleCollected customer payments and coordinated with cyber actors (OFAC and DOJ); primary customer support interface; direct liaison to BlackBasta operator "gg" per leaked chats; advertised on Dark Money forum under "podzemniy" alongside Volosovik from August 2016
Current LocationSt. Petersburg, Russia (per DOJ). Note: relocated from Vladivostok; v1 listed location as Russia unspecified
Connection to VolosovikBoth from Vladivostok; both spent time in Beijing; assessed by Analyst1 to have met in Beijing no earlier than May 2014
Legal Status Revised in v2Indicted. N.D. Ohio, same counts and dates as Volosovik. Presumed innocent
SanctionsOFAC, UK FCDO, AU DFAT: 19 November 2025

2.4 Andrei Valerevich Kozlov: Sanctioned, Not Indicted

Full NameAndrei Valerevich Kozlov
DOB / LocationUnknown; Russia assessed
Assessed RoleEmployed by or associated with Media Land LLC; OFAC did not specify function
Legal Status Revised in v2Sanctioned by OFAC and UK FCDO on 19 November 2025. Not among the indicted defendants. No charges filed
Analytic SignificanceAnalyst Inference The indictment was returned in December 2024, eleven months before Kozlov was sanctioned, so his omission may simply reflect the charging record as it stood at that time rather than a judgment about his role. The alternative reading is that prosecutors held insufficient evidence to charge him. Either way, the three charged defendants map exactly onto the two corporate owners plus the payments lead, suggesting the charging theory is built around corporate control and money movement rather than the wider employee base

2.5 "lapa": Infrastructure Staff, Alias Only

Handlelapa
Real IdentityNot published. The anonymous source behind the BlackBasta leak suggested an identity; Analyst1 declined to publish pending law enforcement confirmation
RoleManaged key parts of BlackBasta's infrastructure; procured SOCKS proxies layered over Media Land servers; received salary payments from BlackBasta operator gg totalling $94,000 USDT
USDT Address0xa0A7d2C6b288927cf73a5cf59970373262ea73c6, funded from 0xB54c17E5ea215f45A61E8790cf546AD175Af2Cf0 (gg)
Legal StatusNot sanctioned, not indicted; identity not publicly confirmed by law enforcement

Disputed Assessments

Cl0p as a client: RESOLVED AGAINST. The indictment has now been read. It names no ransomware group at all, referring throughout to Client Conspirators 1 to 17, each using "a specific malware or ransomware variant, known to the Grand Jury." Trade reporting asserting that the indictment charges hosting for Cl0p is not supported by the document, and Cl0p appears in neither the indictment nor either DOJ press release. The claim is downgraded to Analyst Inference with no supporting primary evidence, and should not be carried into published product.

Two client conspirators are nonetheless identifiable from domain evidence in the indictment. Client Conspirator 4 established Egregorwiki.top and Wikiegregor.top (paragraph 169), pointing to Egregor. Client Conspirator 5 is associated with snatch.team through domain-expiry correspondence at paragraph 171(a) and (b), pointing to Snatch. Both are Analyst Inference drawn from the document, not government attributions, and both should be labelled as such.

Kozlov's function. Unresolved. See 2.4.

Resolved since v1. v1 flagged Pankova's and Kozlov's functional roles as an open question. Pankova's is now resolved (owner, ML.Cloud). Kozlov's remains open.

Operational and Business Model

Service Model

Confirmed Media Land and ML.Cloud sold servers, IP addresses, domains, SOCKS proxies, fast-flux DNS, and DDoS-resistant hosting to cybercriminal clients. The indictment characterises the offering as infrastructure that let clients both conduct criminal activity and evade law enforcement detection, marketed knowingly and intentionally to cybercriminals. Documented service categories include malware and ransomware delivery, victim extortion support, criminal marketplace hosting, fraudulent domain registration, and platforms for launching phishing and brute-force attacks. [16]

Two structural differentiators separate Media Land from most Russian BPH peers: owned physical data center hardware in the Russian core, marketed explicitly as superior to rented networks, and a mature fast-flux product sold as a distinct line item.

Fast-Flux Service Confirmed from indictment

Confirmed The indictment defines fast-flux as associating multiple IP addresses with a single domain and changing them rapidly, sometimes across hundreds or thousands of addresses, to keep properties reachable, hide the origin of malicious activity, and defeat ISP blocking. Media Land ran this as a distinct product on the ffv2.ru platform with an "ffpanel" web application, backed by a database of 41 tables recording registered users, domains, DNS accounts and credentials, service costs and cryptocurrency transactions. [24]

Confirmed Three separate advertisements are quoted in the indictment. Pricing is not stated as a period rate in the quoted text; the tariffs are reproduced as written. The 2016 and 2019 posts are denominated in WebMoney (WMZ), the 2018 post in dollars.

TierAug 2016, Dark MoneyDec 2018, ExploitJun 2019, Fog.ug
1 domain in FastFlux panel70 WMZ$150Not listed
5 domains in FastFlux panel200 WMZ + free VPS$250200 WMZ + free VPS
10 domains in FastFlux panel300 WMZ + free VPS$350300 WMZ + free VPS
Unlimited domains in FastFlux panel500 WMZ + free VPS$500500 WMZ + free VPS
.bit domain support add-onIncludedFree+$100 to tariff

Free VPS specification quoted as 2000 MHz / 1 GB / 50 GB. Correction to v1: Trade reporting gave only the $150 and $500 endpoints and described them as monthly. The ladder has four tiers, the currency differs by year, and no period is stated in the quoted advertisements.

SOCKS5 Proxy Service New in v2

Confirmed A separate product line not recorded in v2. On 12 October 2023 Yalishanda posted on Exploit.in under the topic "Socks5/https proxy service for brute force and various checkers, also ipv6 with open port 25," edited 23 March 2024, and reposted the same advertisement to XSS.IS on 13 November 2023. Two tariffs: 5,000 US and EU IPs with unlimited threads at $200, and several billion IPv6 addresses with open port 25, accessed via IPv4, at $500. The advertisement states the pool is refreshed daily and that the proxies suit brute-force and checker workloads. Open port 25 across a very large IPv6 pool is a direct spam-delivery capability. [24]

Fast-Flux Panel Feature Set New in v2

The December 2018 advertisement describes a custom proxy layer written in-house, replacing nginx and haproxy, deployed inside an encrypted container on the node. Per the copy, the container is accessible only until the first reboot, after which "access to it is lost even from us," a design explicitly marketed as preventing data center administrators from reading the config or determining the client's real backend IP. It also claims the proxy generates decoy connections to unrelated addresses using the same packet sizes as the real backend to frustrate traffic analysis, uses only KVM and XEN virtualisation, allocates each client a non-overlapping IP pool, and runs an automated checker that swaps NS servers within a minute of a domain being blocked. Three domain registrars are offered, described in the advertisement as being in Europe, China and Malaysia, which the seller characterises as "loyal" rather than bulletproof.

Verbatim Advertising and Operator Communications

Yalishanda, Exploit forum, 2011 (KrebsOnSecurity, 2019)
"Based in Asia and Europe. It is allowed to host: ordinary sites, doorway pages, satellites, codecs, adware, tds, warez, pharma, spyware, exploits, zeus, IRC, etc. Passive SPAM is allowed... Forbidden: Any outgoing Email spam, DP, porn, phishing (exclude phishing email, social networks). There is a server with instant activation under botnets (zeus) and so on."
Volosovik and Zatolokin as "podzemniy," Dark Money forum, 17 August 2016, Post ID 760355 (indictment para 143) Extended from indictment
"Hello! We are glad to offer you BP hosting services. We keep any projects. All except child porn. Our services: Hosting; VPS/VDS; Dedicated servers; FastFlux (not on bots) open all ports, no problems with ssl; Domain registration; Server administration. Only here: Own DC, with server / VPS give access to reboot panel. KVM on request. Implemented a unique system that is not on the market. FastFlux with very complex logic, FastFlux on the legs, not on the bots, no packet loss and a failure in speed... Our service is for serious people who need server stability and availability for years!!!! You'll forget about hosting problems! Prices, you will be pleasantly surprised."
Zatolokin to Volosovik, WhatsApp, 8 November 2017 (indictment para 145 and 197(i)) New in v2
"Half of my panel is in red, nobody answers. If they won't wake up, we will have maybe 5 to 7 clients left. We need to get new ones, start advertising on forums like 'Dark Money.'"
Zatolokin to Volosovik, WhatsApp, 20 August 2018 (indictment para 197(m)) New in v2
"Kirill, I have forgot to tell you it's time for these two clients, Guest and Neverforget, to pay up. Get the money from them. Once we receive the money, I'll try to procure tickets for you."
Volosovik and Zatolokin to a German security researcher, 29 November 2018 (indictment para 205(k) and 205(m)) New in v2
"this client is blocked" (sent from [email protected] and [email protected] in response to two separate RedAlert command-and-control abuse reports). When in fact, per the indictment, the client conspirators continued to distribute malware through Media Land infrastructure.
Volosovik, Exploit forum, December 2018 (per indictment) New in v2
"Leading-edge FastFlux! Bulletproof hosting"
Slim Shady (Zatolokin) to BlackBasta operator gg, leaked chats, July 2024
"RU. These are servers from a private data center, not public ones like many others use, where networks are simply rented. This is all our own: our own data center, our own hardware, etc. If you take volume, we can also deploy in Europe, if needed."
Slim Shady (Zatolokin) to gg, speed test on IP 45.141.87.127, leaked chats
"How's that? 5x faster than your other hoster on downloads and 2x faster on uploads :)"

Language and Supplier Reach New in v2

Confirmed The December 2018 Exploit advertisement lists support and billing channels in three languages: Jabber: billing2 (RU/ENG/CH), Jabber: Support (RU/ENG/CH), and a Telegram support and billing channel also marked RU/ENG/CH. Chinese-language customer support was a standing offering, not an ad hoc accommodation, which implies a Chinese-speaking client segment of some size. [24]

Confirmed The WhatsApp traffic between the principals records recurring procurement of Chinese proxy infrastructure and recurring problems with it. On 26 August 2017: "I have used some of that money to pay the Chinese on Yandex. You can see one of ours is dead. I can buy more, but you need to order socks." On 2 September 2017: "We had experienced that before with the Chinese. It's probably an account that was banned, so money cannot be added to it." On 9 September 2018: "Try a Chinese one, but you have to make sure he can open his ports," followed by "No, ports are closed. These Chinese proxies only have ports 80 and 443 open." [24]

Onboarding and Client Tiers

Forum advertising on Exploit[.]in, XSS[.]pro, Dark Money and predecessor platforms was the primary acquisition channel. Support ran through Telegram (@ohyehhellno) and Jabber, both listed consistently in advertising. No invitation-only or referral gate is documented.

A two-tier client structure is evident from leak data. Standard clients self-served through forum-advertised support channels. VIP clients such as BlackBasta held direct relationships with Zatolokin for custom deployments, bandwidth negotiation, and capacity planning, with access to owned data center hardware. [3]

Confirmed New in v2 Indictment-derived scale figures: approximately 389 usernames and more than 5,000 registered domains in the client database. Against 17 or more criminal groups served, this implies most usernames were individual criminal customers rather than group accounts, and that domain provisioning ran at roughly 13 domains per username. [19][20]

Abuse-Handling and Law Enforcement Posture

Confirmed Total non-cooperation was the advertised and practised posture. Forum advertising explicitly named Spamhaus as ignored. The indictment alleges the defendants repeatedly ignored or falsified abuse reports and rotated infrastructure to stay ahead of takedowns. The falsification allegation is new in v2 and is materially more serious than passive non-response: it implies active deception of upstream providers and registrars, which is also what makes the multi-jurisdictional footprint sustainable. [16]

Confirmed New in v2 The indictment specifies the mechanism. Abuse reports, intrusion alerts and anti-virus output were deliberately funnelled into operator-controlled mailboxes designed to look independent: [email protected], [email protected], [email protected] and [email protected]. Rather than suspending offending domains or accounts, the operators sent false replies, ignored reports, or offered the complaining client fast-flux to defeat the detection that had generated the report. Paragraph 123 lists four services sold on this basis: fraudulent abuse-report responses, rapid IP rotation, domain registration through the front company with added privacy services, and other protections shielding clients during intrusions and exfiltration.

Spamhaus had identified the platform early. On 12 November 2014 a forwarded Spamhaus notice reached [email protected] stating that s777shop.ru and ffv2.ru were "operated by cybercriminals and used to control infected computers (bots) using a so called botnet controller," and requesting suspension. The domain was blocked and Volosovik contested the block with the registrar two days later. The platform continued operating for another decade.

The only documented instance of customer dispute resolution across 15+ years is the August 2020 arbitration in which Yalishanda refunded $222.89 to a user called Loadbaks with a bare transaction hash and no acknowledgment.

OPSEC Posture

Volosovik registered Media Land LLC as a legitimate Russian entity to obtain commercial legitimacy, enabling contracts, IP leasing, and staff employment. His VKontakte and Odnoklassniki profiles used partial real-name attribution, indicating confidence in the Russian operating environment rather than technical OPSEC discipline. The sealing of the indictment for more than nineteen months suggests investigators judged that continued collection outweighed the deterrent value of early disclosure.

Documented OPSEC Failures New in v2

Confirmed The indictment records several. On 6 September 2018, seeking to have ffpanel.ru unblocked, Volosovik emailed the registrar from [email protected] and attached a scanned copy of his own passport (paragraph 205(f)). Domain sshvps.net was registered on 24 September 2015 with Volosovik's own name as Administrator, his telephone number 79811263828, his email [email protected], and Media Land named as Administrator Organization (paragraph 204). Both principals' iCloud accounts, tied to their real mobile numbers, retained screenshots of the ffv2.ru administrator panel showing client usernames with associated domains and IP resolutions (paragraphs 190 to 195). Operational coordination ran over WhatsApp tied to those same numbers from at least January 2017 (paragraph 196).

The 2018 advertisement markets an encrypted proxy container that even the operators cannot reach after reboot, and the same operator sent a registrar his passport. The technical tradecraft sold to clients was materially better than the administrative tradecraft the principals applied to themselves, and it is the administrative trail that produced the charging document.

Technical Capabilities and Infrastructure Footprint

Autonomous Systems Corrected from indictment

Correction to v1

v1 listed AS211805 as the secondary ASN, sourced from IPinfo. The indictment states at paragraph 5 that Media Land and ML.Cloud "controlled two Autonomous System Numbering (ASN) blocks of IP addresses, ASN blocks 206728 and 215376, to host client services," and at paragraph 6 that since at least around June 2024 they controlled these two blocks "on hardware physically located in Russia and the Netherlands, respectively." AS215376 is the ML.Cloud Netherlands ASN. Paragraph 163 records both AS206728 and AS215376 addresses being used together to support the 24 October 2024 brute-force attack on Victim 44. [24]

ASNNameRIRCountryRegisteredStatus
AS206728MEDIALAND-ASRIPERussian Federation2016-11-17Active
AS215376ML.CloudRIPEHardware in NetherlandsUnknownNamed in indictment

Multi-Jurisdictional Infrastructure Footprint Corrected in v2

Correction to v1

v1 stated that there was "no confirmed infrastructure in non-Russian jurisdictions." The DOJ indictment establishes that Media Land operated physical infrastructure in Finland, the Netherlands, and the United States in addition to Russia. DOJ attributes the seven-year investigative timeline and the necessity of Dutch law enforcement participation directly to this multi-jurisdictional footprint. This is the most operationally consequential correction in v2, because infrastructure inside Finland, the Netherlands, and the United States is reachable by Western legal process in a way that the St. Petersburg and Kirishi estate is not. [16][17]

JurisdictionRoleWestern Legal ReachConfidence
Russia (St. Petersburg)Primary operational base; entity registration; assessed operator residenceNoneConfirmed
Russia (Kirishi, Leningrad Oblast)Owned physical data center via DC Kirishi subsidiary; own hardwareNoneConfirmed
NetherlandsAS215376 (ML.Cloud) hardware physically located in the Netherlands as of about June 2024. Dutch National Police and Public Prosecutor's Office provided material investigative assistanceDirectConfirmed
FinlandFFPANEL.TOP resolved to 65.108.65.82, described in the indictment as "previously located in Finland"Direct (EU member state)Confirmed
United Statesffv2.ru fast-flux server at ISP1, physically in New Jersey, until 23 June 2024. ISP2 also US-based, supplying VPN services. Over $23,000 paid to ISP1DirectConfirmed

China Nexus: Supplier and Market, Not Hosting New in v2

Scope of the China Relationship

The DOJ press release states that Media Land's infrastructure "also operated out of multiple countries including China, Finland, the Netherlands, and the United States." Chinese hosting of Media Land infrastructure is not corroborated anywhere in the reviewed portion of the charging document, which covers the general allegations, the full infrastructure section and all of Count 1. Every named server, IP and domain in that portion resolves to Russia, the United States, the Netherlands or Finland. China is therefore not carried in this profile as an infrastructure hosting jurisdiction. The full document has now been read and China is not alleged as a hosting jurisdiction anywhere in it, including across Counts 2 to 13, the sentencing enhancement and the forfeiture allegation. The claim rests on the press release alone.

What the document does evidence is a China relationship of a different character, on the supplier and market side rather than the hosting side. That is set out below and is analytically more useful than the press release formulation.

ElementEvidenceConfidence
Chinese domain registrar in the productThe December 2018 Exploit advertisement offers clients three registrars, "Europe, China and Malaysia," described by the seller as "loyal." Domain registration through these registrars was a sold service with bulk registration and a random name generatorConfirmed
Chinese proxy procurementWhatsApp traffic 2017 to 2018 records repeated purchase of Chinese proxies, payment "to the Chinese on Yandex," banned supplier accounts, and a recurring technical limitation that Chinese proxies had only ports 80 and 443 openConfirmed
Chinese-language commercial supportJabber and Telegram support and billing channels advertised as RU/ENG/CH in the December 2018 Exploit postConfirmed
Operator ties to ChinaVolosovik resided in Beijing before Vladivostok and St. Petersburg; his travel passport was issued by the Russian Embassy in Beijing. Zatolokin enrolled at the Beijing Institute of Fashion Technology in 2009 and was documented in Beijing through at least 2014. The Yalishanda moniker is Mandarin for "Alexander"Confirmed
Media Land infrastructure physically hosted in ChinaAsserted in the DOJ press release. Not corroborated in the reviewed portion of the indictmentCredible, uncorroborated

Analyst Inference The documented pattern is a provider that bought Chinese proxy capacity, resold Chinese domain registration, and marketed in Chinese, run by two principals with years of personal residence in Beijing. That is a supplier and customer-base relationship, not an infrastructure footprint. The most economical explanation for the press release wording is that it generalises from these relationships rather than describing servers in China. Analysts should not carry "Media Land hosted infrastructure in China" forward without reading Counts 2 to 4 or obtaining separate technical corroboration.

IPv4 Prefix Table (AS206728)

PrefixRegistered DescriptionRPKIIRR
45.141.84.0/24ML CLOUD LLCValidValid
45.141.85.0/24Media Land LLCValidValid
45.141.86.0/24ML CLOUD LLCValidValid
45.141.87.0/24Grisha MaslinikovValidValid
91.220.163.0/24Media Land LLCValidValid
193.242.153.0/24IT Outsourcing LLCNo ROAValid
194.26.29.0/24Media Land LLCValidValid
194.26.69.0/24Media Land LLCValidValid

Note: 45.141.87.0/24 is the prefix containing IP 45.141.87.127, cited in Zatolokin's speed-test message to BlackBasta. It is registered to an individual name (Grisha Maslinikov) rather than a corporate entity, and 193.242.153.0/24 is registered to IT Outsourcing LLC and lacks a ROA. Both are candidate nominee registrations worth further examination.

IPv6 Prefixes (AS206728)

PrefixRegistered DescriptionRPKI
2a0b:7ec0:1320::/48Media Land LLCValid
2a0b:7ec0:7701::/48Media Land LLCValid

Named Infrastructure Estate New in v2

Confirmed The indictment names the criminal-side infrastructure directly, which the press release did not. This is the operational core of the BPH service, run on servers deliberately separated from the public-facing ML.Cloud estate.

AssetRoleLocation and IP history
ffv2.ruPrimary fast-flux platform and "ffpanel" admin application; backend database of 41 tables; hosted the carding marketplace DNS zone entriesIP 104.194.11.236 at ISP1, physically in New Jersey, United States, from at least 21 May 2020 until 23 June 2024. Migrated 24 June 2024 to Russian IP 45.141.85.184 inside AS206728, abuse contact [email protected]
ffpanel.topFast-flux panel infrastructureResolved to 65.108.65.82, previously located in Finland
ffpanel.ruFast-flux panel; also served as RedAlert command-and-controlC2 IP 8.208.10.54; separately reported at 47.254.171.103; blocked by registrar Sept 2018
sshvps.netAbuse-handling front; registered 24 Sept 2015 with Volosovik named as Administrator and Media Land as Administrator OrganizationMail infrastructure: abuse@, alex@, zakaz@, domaine@, 18394_alex@
abushost.ruLong-running brand domain and Jabber host; linked to [email protected] from 17 March 2014Registered 10 Jan 2015 via [email protected]
s777shop.ruNamed by Spamhaus alongside ffv2.ru as a botnet controller, Nov 2014Not further described in the read portion

Post-Indictment Domain and IP Sweep, 27 July 2026 New v2.2

All 56 domains named in the paragraph 253 enhancement were checked against RDAP registration data and live DNS, and the resolved addresses were traced back to their announcing networks. Method: RDAP for registration state, DNS-over-HTTPS for current resolution, RIPE and Hurricane Electric for prefix attribution. Analyst Inference throughout on questions of who controls what, since registration records for these domains are privacy-shielded and .ru carries no public RDAP.

Finding A: Media Land's own domains are live inside its own IP space, after sanctions

Confirmed sshvps.net, the abuse-handling front that Volosovik registered in his own name with Media Land as Administrator Organization, still resolves to 45.141.85.101. That address sits inside 45.141.85.0/24, announced by AS206728 and registered to Media Land LLC. The same address carries the PTR ml.cloud and also serves medialand.pro. A second host, 45.141.85.50, has PTR ns1.ml.cloud and serves ns1.medialand.pro, ns1.ml.cloud and ns1.sshvps.net.

medialand.pro is not named in the indictment, nor in any sanctions listing or vendor reporting reviewed for this profile. It is a new indicator. The self-referential naming and the shared nameserver set place it firmly in the same estate.

The RIPE route object for 45.141.85.0/24 was last modified 24 November 2025, five days after the trilateral sanctions. Someone was administering this prefix after designation.

Finding B: the fast-flux platform domain has moved to German hosting since sanctions

Confirmed ffv2.ru currently resolves to 144.31.255.18, PTR vm1112055.hosted-by.u1host.com. The prefix 144.31.255.0/24 is announced by AS213877, U1 DIGITAL SERVICES LTD, registrant u1host ltd, maintainer u1host-mnt, sited in Frankfurt. Its RIPE route object was created 15 December 2025, roughly a month after the sanctions.

Movement history for this one domain now reads: New Jersey at 104.194.11.236 until 23 June 2024, then Russia at 45.141.85.184, and now Germany at 144.31.255.18.

Analyst Inference Treat with care. The u1host range is a commodity VPS estate of roughly 196 hosts with generic vmNNNNNN PTRs, so presence there is cheap and proves little on its own. Three readings are open and the evidence does not separate them: the operators re-pointed the domain to disposable hosting after designation; the domain lapsed and was re-registered by an unrelated party; or it is parked. .ru publishes no RDAP, so registration date and registrant cannot be checked. What can be said is that a domain central to ten wire fraud counts is live on a European prefix created after the sanctions, and that is worth a vendor with passive DNS history resolving properly.

Finding C: the charged domain estate is almost entirely abandoned

Confirmed Of 47 gTLD domains checked by RDAP, 42 are no longer registered, including both operator-derived names (volosovichkov.info, volosovichkov-taxi.info), the platform bot domain ffv2panelbot.info, cardhouse.info, and every brand-impersonation domain. Only two are registered, and both look like ordinary drop-catch by unrelated parties rather than continuity: s3dns.com re-registered 8 November 2025 through Cloudflare and parked on IONOS in Berlin, and publicdns.info re-registered 6 January 2026 through NameCheap, resolving to OVH in France on nameservers at upstelecom.com. Neither has any observable tie to Media Land.

Analyst Inference The pattern is consistent with a burned estate. These were disposable domains for a fast-flux product, and once the product was charged there was no reason to renew them. It also means the enhancement list is largely of historical value for pivoting, not a live target set. The exception is the small live cluster in Finding A.

Finding D: live phishing content in Media Land address space

Confirmed 45.141.85.173, in the same Media Land prefix, currently serves treueprogramm-magentamoments-bestandskunden.com. The name is a German-language lure impersonating Deutsche Telekom's MagentaMoments customer loyalty programme. Also on the prefix: nameservers for cherrymail.net, and a cluster of algorithmically-styled .ru names (alendelm.ru, werbongo.ru, wertengo.ru, akeqant.ru, belpvale.ru, percevogen.ru, frencowep.ru, frolovale.ru, arturowen.ru, rolexform.ru) consistent with the bulk registration and random name generator advertised in the December 2018 Exploit post.

This is criminal hosting continuing in designated address space, which bears directly on the Section 10 trajectory assessment.

Finding E: an unexploited name in the registry records

Confirmed RDAP returns Grisha Maslinikov as the organisation contact on 45.141.85.0/24, and Hurricane Electric records the same name as the registrant of 45.141.87.0/24. Both are Media Land prefixes under AS206728, and 45.141.87.0/24 contains the IP Zatolokin used in his speed-test message to BlackBasta.

Analyst Inference Maslinikov appears in no sanctions listing and no count of the indictment. He may be a nominee, an administrative contact, or a real staff member. Either way a name attached to two prefixes of a designated bulletproof host, absent from every enforcement action, is an unexploited lead and the most promising single thread this sweep produced.

Falsely Registered Domains (18 U.S.C. 3559(g)(1)) New v2.1

Confirmed Paragraph 253 of the indictment enumerates roughly 56 domains that Volosovik and Zatolokin registered with false names and addresses and used in furtherance of Counts 1 to 13. This list appears in no press release and is the single largest set of new indicators the document provides. Grouped below by evident function.

ClusterDomainsAnalytic note
Operator-derivedvolosovichkov.info volosovichkov-taxi.infoBoth derive from Volosovik's own surname. Registering criminal infrastructure under a name-derived domain is a significant attribution handle and a further OPSEC failure alongside the passport disclosure
Fast-flux platformffv2panelbot.infoTies directly to the ffv2.ru fast-flux panel and its Telegram or Jabber bot
DNS-themed infrastructurevesperdns.info dndpark.info dnsmhere.ru newserversdns222.info dnsmherell.info pspark.info mydnshelpers.info mydnsserver.info unitednstools.info chernobyldns.info s3dns.com lambdadns.com besdns.ru cptdns.info publicdns.ru publicdns.info domain4dns.info fifdns.info proxy-dns1.ru proxy-dns2.ru boxodns.info rocodns.info cntdnsnet.info setdnsnet.info dnspods.ru dmsmanagercu.infoThe bulk of the estate. Consistent with the fast-flux product, which required large pools of disposable NS and resolver domains that could be rotated when blacklisted
Brand impersonationprotonomail.info protonommail.info amazkonto.info amazondeutschland.info microsoft-windows-defender-update.ru googleu.ru googleup.ru googleclouddns.com mobirevolutconfirmation.comTyposquats and lookalikes for ProtonMail, Amazon (including a German-market variant), Microsoft Defender, Google Cloud DNS and Revolut. Phishing and credential-harvesting oriented rather than DNS plumbing
Financial and marketplacexmrdealshere.ru wedoaccounting.ru cardhouse.infoxmrdealshere.ru points at Monero dealing and is the only overt crypto-trading domain in the set. cardhouse.info corresponds to the Cardhouse carding marketplace named separately at paragraph 207
Hosting and miscvhost-vps.ru carshomce.info nicedomainname.info jackladamada.info jackladamadab.info targetpost.info greatdor.info greatdor.ru fatraf.info lincomap.ru min0taur.ru vipedron.ru dsfgghgsfadfgh.info fablirsgd.ru sdfsdfsdfsdfdsfsdf.ru 54bb47h.ruMixed. Several are keyboard-mash throwaways consistent with the bulk registration and random name generator advertised in the December 2018 Exploit post

Analyst Inference Two operational reads. First, the heavy .info and .ru concentration is consistent with the advertised "Europe, China and Malaysia" registrar set, which the seller described as loyal rather than bulletproof. Second, the presence of brand-impersonation domains alongside DNS plumbing in the same charged set indicates Media Land was registering phishing domains for clients as a service, not merely hosting infrastructure that clients populated themselves. That is a more active role than the hosting-only framing in the press releases.

Third-Party Providers New in v2

EntityDescriptionFinancial detail
ISP1US-based ISP, outside the Northern District of Ohio, location known to the Grand Jury. Hosted the ffv2.ru fast-flux serverApproximately $2,100 paid to lease ffv2.ru server space, 21 May 2020 to 23 June 2024. Over $23,000 total to ISP1 for multiple servers over the same period. Volosovik used client number 18394
ISP2US-based ISP, outside the Northern District of Ohio. Supplied VPN services and other infrastructureAccount established 21 May 2020 by Zatolokin using [email protected]

Analyst Inference Both ISPs are US entities that were, on the government's account, taking payment from Media Land for years. Neither is charged. That the fast-flux platform central to the whole scheme sat on a leased server in New Jersey until June 2024 is the single most consequential fact in the document for disruption purposes, and it is also the most likely explanation for the seven-year investigative timeline: US-hosted infrastructure is reachable by subpoena and search warrant in a way the Russian estate is not.

Upstream Transit Chain

Peer ASNEntityCountryRole
AS49531NetCom-R LLCRussian FederationIPv4 and IPv6 upstream peer
AS20632PJSC MegaFonRussian FederationIPv4 upstream peer; major Russian carrier
AS202799SYSECT D.O.O.MontenegroIPv4 upstream peer; only non-Russian peer
AS51538Lavrentyev Aleksandr ArkadievichRussian FederationIPv4 upstream peer; individual registrant
AS3216 (historical)Vimpelcom / BeelineRussian FederationHistorical transit per RIPE IRR import/export records
AS9049 (historical)ERTH Corporation JSCRussian FederationHistorical transit per RIPE IRR import/export records

De-peering events: Confirmed No documented upstream de-peering events for AS206728 in open sources, including in the period following the November 2025 sanctions and the July 2026 indictment and EU designation. All four observed peers remained in place across the latest BGP snapshot. Unlike PROSPERO (AS200593, Bearhost), which drew public scrutiny over a Kaspersky Lab upstream relationship in 2025, no equivalent upstream controversy has been reported for MEDIALAND-AS. The absence of de-peering after four-jurisdiction sanctions and a US indictment is itself a finding: the Russian upstream chain is not responsive to Western designation, and SYSECT D.O.O. in Montenegro is the only peer plausibly subject to European pressure.

Physical Infrastructure and Capacity

Confirmed Data Center Kirishi, a wholly owned subsidiary registered July 2022 in Kirishi, Leningrad Oblast, represents owned physical data center capacity with own hardware, confirmed by Zatolokin directly to a client. This differentiates Media Land from BPH operators that lease all upstream capacity. Documented capacity from the BlackBasta negotiation: standard plan of 20 Gbps per 100 servers, with the client's approximately 200-server deployment consuming 17 to 20 Gbps and a proposed scale to 50 Gbps. [3]

Hosted Activity Types

Blocklist Standing

ListStatusEvidence
Spamhaus SBLListed (confirmed)SBL and CBL listings documented by researchers in the 2019 KrebsOnSecurity article comments; advertising explicitly claims to ignore Spamhaus, confirming an ongoing listing relationship
Spamhaus CBLListed (confirmed)Confirmed via 2019 KrebsOnSecurity community analysis of the IP ranges
Spamhaus DROP / EDROPProbableEDROP covers cybercriminal-controlled IP space. Four-jurisdiction sanctions and a US indictment make listing highly likely, but no direct current entry confirmation was obtained
abuse.ch Feodo TrackerProbableConfirmed C2 hosting in the IP ranges; specific entry IDs not confirmed
abuse.ch URLhausProbablePhishing and malware URL hosting documented by PRODAFT and DOJ; entry-level confirmation not obtained
abuse.ch MalwareBazaarUnknownNo direct confirmation in open sources
FireholProbableNo direct confirmation; aggregate list behaviour and SBL/CBL status strongly suggest inclusion

Known Weaknesses

Revised in v2. The correction to the infrastructure jurisdiction picture changes the weakness profile substantially.

Financial Infrastructure

Payment Methods

Confirmed Cryptocurrency-only payment. Bitcoin and USDT (ERC-20) are documented in leak, sanctions, and indictment material. The indictment alleges the defendants accepted cryptocurrency specifically to protect client identities. No fiat payment channel is documented. [3][7][16]

Known Wallet Clusters

AddressCurrencyAttributionSource
18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXBBitcoinAleksandr Volosovik / Media Land LLC; OFAC SDN-listedOFAC, 19 Nov 2025 [7]
1PY4JX82rhKTSyP7ywhJgiYeVvTcpcaW8dBitcoinYalishanda refund address from the August 2020 forum arbitrationAnalyst1 [3]
0xa0A7d2C6b288927cf73a5cf59970373262ea73c6USDT (ERC-20)"lapa," Media Land infrastructure staffer; received $94,000 in salary from BlackBastaAnalyst1 / Arkham [3]
0xB54c17E5ea215f45A61E8790cf546AD175Af2Cf0USDT (ERC-20)BlackBasta operator "gg"; sending wallet for lapa salary paymentsAnalyst1 [3]
Cluster: "Yalishanda - bulletproof hoster" New in v2BitcoinNamed attribution cluster used by the government; received 0.23 BTC ($4,665) from Client Conspirator 5, 5 Sept 2022Indictment para 212 [24]
Wallet registered to [email protected] New in v2BitcoinReceived a share of funds traced to the Victim 2 ransomware extortion, 21 Oct 2021Indictment para 208 [24]

lapa Salary Payments (BlackBasta to Media Land Infrastructure Staff)

Transaction HashAmountDate
0xb77e237067282cb497cc5246c3c047ce36de2c2d6a3a15e395808a696a84cb34$20,000 USDT13 February 2024
0x321dc9d6d2110a47ce9000d9e0fc983987fe59a318d5d889623ed08e1c0f42e2$23,000 USDT23 February 2024
0x792f1533ba55c3059520ba39e29e9b1b0e8f43da3a7208b417b1d443959ec0a9$15,000 USDT7 March 2024
0x1988652a17c8cd3f5f7a14d83cf6162c0943bf9b9cd96d4756d5f7c52214a1ff$25,000 USDT27 March 2024
0xa5eca747fdc92a81693d166e24c942501c581be063e858620891c9b709acb36a$11,000 USDT30 May 2024

Total $94,000 USDT. Two additional BTC transactions on 1 April 2024 (0.01163 BTC and 0.01019 BTC, approximately $829 and $727) were paid by gg to lapa-supplied addresses for SOCKS proxy procurement. Source: Analyst1 / Arkham. [3]

On-Chain Volume

Confirmed TRM Labs documented more than $2 million in received volume across wallets linked to Yalishanda and Abushost, with direct and indirect flow intersections across BlackSuit, BlackBasta, LockBit, and MedusaLocker. [10]

Confirmed Chainalysis assessed Volosovik's services as supporting "nearly every component of the cyber kill chain," monitoring thousands of addresses and millions of dollars in transactions across underground exchanges, laundering services, scammers, hackers, and ransomware operators including sanctioned LockBit administrator Dmitry Khoroshev. [6]

New in v2 The DOJ figure of $62 million is a victim loss total across 42 named US organizations, not provider revenue. It should not be reconciled against the TRM $2M received-volume figure, which measures funds reaching identified Yalishanda-linked wallets. The two metrics measure different things and both are consistent: a BPH provider captures a small fraction of the downstream criminal proceeds its infrastructure enables.

Three-Phase Laundering Model

Phase 1, receipt. Ransomware payments reach client groups in Bitcoin. Media Land receives hosting fees in BTC or USDT, with fast-flux and bandwidth billed as recurring monthly subscriptions.

Phase 2, conversion. BlackBasta operator gg stated in leaked chats that funds paid to lapa for SOCKS procurement and salary came from money already "cleaned" by an internal laundering operation. USDT was used for stable-value salary payments post-laundering. TRM identifies flows to intermediary wallets and major global exchanges.

Phase 3, cash-out. Funds move through no-KYC exchanges and OTC desks consistent with Russian cybercrime cash-out patterns. Specific venues for Media Land and Volosovik remain unidentified in open sources, in contrast to ZServers where Garantex is confirmed. This remains an intelligence gap.

Count 13: The Money Laundering Theory Resolved v2.1

Confirmed Count 13 charges conspiracy to commit money laundering under 18 U.S.C. 1956(h), running from 14 June 2016 to the date of the indictment. The specified unlawful activities are wire fraud (1343) and fraudulent access to computers (1030). Three distinct objects are charged:

  • Concealment laundering, 1956(a)(1)(B)(i). Financial transactions involving criminal proceeds, designed to conceal the nature, location, source, ownership and control of those proceeds.
  • International transmission, 1956(a)(2)(B)(i). Transporting, transmitting or transferring funds from a place in the United States to and through a place outside the United States, knowing the transfer was designed to conceal. This is the object that gives the New Jersey server its second significance: it is not only where the fast-flux platform sat, it is the US nexus that makes the outbound transfer chargeable.
  • Monetary transactions over $10,000, 1957. Engaging in monetary transactions in criminally derived property worth more than $10,000, through a financial institution and affecting interstate and foreign commerce.

Confirmed The mechanism alleged at paragraphs 249 to 251: the defendants and their client conspirators directed ransomware victims to pay into anonymous cryptocurrency accounts provided and controlled by them; they maintained infrastructure in the United States and abroad that concealed the nature, location, source, ownership and control of funds moving from victims in the Northern District of Ohio and elsewhere; and client conspirators sent proceeds exceeding $10,000 to cryptocurrency accounts controlled by Volosovik and Zatolokin, "either through ACH, wire transfer, or other electronic fund transfers."

Analyst Inference The reference to ACH and wire transfer is the most significant single line for financial-leverage purposes. It indicates the government is not treating this as a purely on-chain flow: at least some proceeds moved over conventional banking rails, which means regulated intermediaries touched them and records exist. That is a materially better disruption surface than a crypto-only chain.

Still open. No exchange, OTC desk or money services business is named anywhere in the document, and the forfeiture paragraph itemises no specific wallets or sums. The cash-out venue gap is narrowed but not closed: the mechanism is now documented, the endpoints are not.

Sanctions and Regulatory Risk

AuthorityDateTargetsInstrument
OFAC (United States)19 Nov 2025Media Land LLC, ML Cloud, Media Land Technology, Data Center Kirishi; Volosovik, Zatolokin, Pankova, Kozlov; Volosovik BTC addressE.O. 13694 as amended by E.O. 13757, 14144, 14306
UK FCDO19 Nov 2025Joined the OFAC action in fullUK cyber sanctions regime
AU DFAT19 to 20 Nov 2025Joined in part: Media Land LLC, ML.Cloud, Volosovik, ZatolokinAustralian autonomous sanctions
European Union New in v213 Jul 2026Media Land LLC, ML.Cloud, VolosovikCouncil Decision (CFSP) 2026/1713; Implementing Regulation (EU) 2026/1714

EU measures impose an asset freeze, prohibit EU citizens and companies from making funds or economic resources available, and add a travel ban barring entry to or transit through EU territory for designated natural persons. The travel ban is a distinct instrument from the US and UK measures and narrows the set of countries the principals can transit, which matters given that arrests of Russian cybercrime suspects have historically occurred during travel. [21]

Client Profile and Hosted Operations

Sourcing Correction v2

The indictment names no ransomware group. All clients appear as Client Conspirator 1 through Client Conspirator 17, each using "a specific malware or ransomware variant, known to the Grand Jury." Group names in the table below derive from the DOJ press release and the OFAC designation, not from the charging document. Trade reporting stating that the indictment charges hosting for LockBit, Cl0p and Play misreads the document. The entities the indictment does name are the eight carding marketplaces, two Android banking trojans, and one marketplace client relationship, all tabulated separately below.

Client Conspirator Schedule (as charged) New in v2

Confirmed Seventeen client conspirators, sixteen described as groups conducting ransomware and extortion, one (CC17) conducting brute-force attacks and unknown to the Grand Jury. Fast-flux accounts on ffv2.ru are attributed to CC1, CC3 to CC8, and CC14.

ClientService providedVictims chargedIdentification
CC1Fast-flux hosting for leak sites and communication platforms, from 24 Feb 2021; false domain registrationVictims 15 to 24 (10 overt acts)Not identified
CC2Domains on ffv2.ru; ransom payments sent to Volosovik-controlled walletsVictim 2 (Canada)Not identified
CC3Over 250 domains hosted; account email [email protected]Victims 30 to 39 (10 overt acts)Not identified
CC4BPH for domains Egregorwiki.top and Wikiegregor.top established on ffv2.ru, 20 Sept 2020Victim 3 (2 overt acts)Analyst Inference Egregor, from domain naming
CC5Domains on ffv2.ru from 28 June 2017; domain-expiry correspondence for snatch.team; paid 0.23 BTC for Victim 7 attack infrastructureVictims 4 to 9 (8 overt acts)Analyst Inference Snatch, from domain naming
CC6Domains on ffv2.ru, 24 Feb 2021 to 1 July 2023Victims 10, 11, 12Not identified
CC7Domains on ffv2.ruVictim 1 (Newton, MA municipality)Not identified
CC8False domain registration, Media Land IPs, ffv2.ru hostingVictims 13, 14Not identified
CC9 to CC16False domain registration and Media Land IP use during malware and ransomware attacksVictims 25 to 29, 40 to 43Not identified
CC17Brute-force attacks using both Media Land (AS206728) and ML.Cloud (AS215376) IPs, 24 Oct 2024Victim 44Unknown to the Grand Jury

Criminal Marketplaces Named in the Indictment Confirmed from indictment

Confirmed Paragraph 207 tabulates eight marketplaces and forums hosted on the ffv2.ru server as of 6 March 2023, each hosting representing a separate overt act. This upgrades the v2 CREDIBLE label to CONFIRMED and supplies the domains, which the press release lacked.

Marketplace / ForumDomains hosted on Media Land infrastructureDescription (per indictment)
BriansclubBriansclub.cm, Brianscrabs.deCarding marketplace to sell and buy stolen credit card data. Serviced from 21 May 2020 until at least 16 April 2024
CardhouseCardhouse.ccRe-seller on the Bypass Market, a darknet marketplace selling stolen credit card information
crdclubCrdclub.suForum to advertise stolen credit cards
Club2crdClub2crd.ccRussian language carding forum
VerifiedVerified.mnDarkweb criminal forum
FullzinfoFullzinfo.comSelling PII, credit card and financial account information
SwipestoreSwipestore.ccCarding marketplace to sell and buy stolen credit card data
BidencashBidencash.link, Bidencash.ripCarding marketplace to sell and buy stolen credit card data

Malware Families Named in the Indictment Confirmed from indictment

FamilyEvidence in the documentMedia Land IPs
RedAlert (Trojan-Banker.AndroidOS.RedAlert 2.0)Abuse reports from Deloitte CyberSOC ([email protected]) 30 Aug 2018 and from BFK 29 Nov 2018. Distributed as "Update Flash Player" / AdobeFlashPlayer.apk. Operators replied "this client is blocked" and did not block185.100.222.28, 185.254.121.69; C2 at ffpanel.ru (8.208.10.54); gateway 188.68.208.159
ErmacAbuse report from [email protected] 11 July 2022: "We have detected an ERMAC malware incident against Santander, on a website hosted by Media Land LLC." Recurrence reported April 202345.141.85.29

Crimeware Verticals by Evidence Tier

Client / ActivityCategoryConfidenceSources
LockBitRansomwareConfirmedOFAC; DOJ indictment; Chainalysis (LockBit admin Khoroshev explicitly cited) [6][7][16]
BlackBastaRansomwareConfirmedAnalyst1 leak correlation; OFAC; UK FCDO [3][7][8]
BlackSuitRansomwareConfirmedOFAC sb0319; DOJ indictment [7][16]
PlayRansomwareConfirmedOFAC sb0319; DOJ indictment [7][16]
Evil CorpRansomware / CaaSConfirmedUK FCDO / Foreign Secretary statement; Intel 471 Dridex hosting 2017 [8]
Cl0p DowngradedRansomwareAnalyst Inference UnsupportedNot named in the indictment or either DOJ press release. Claim originates in trade reporting that misattributed group names to the charging document. Should not be published as a Media Land client on current evidence
MedusaLockerRansomwareCredible Single SourceTRM Labs on-chain analysis only [10]
Client Conspirators 1 to 17Ransomware (CC1 to CC16), brute force (CC17)ConfirmedIndictment paras 14 to 30. None named; see Client Conspirator schedule above [24]
Briansclub, Bidencash, Cardhouse, Club2crd, crdclub, Fullzinfo, Swipestore, VerifiedCarding marketplacesConfirmedIndictment para 207, tabulated by name and domain; see table above [24]
Ermac, RedAlertAndroid banking trojansConfirmedIndictment paras 205 and 206, with quoted third-party abuse reports and specific IPs [24]
Underground exchanges and laundering servicesFinancial crime infrastructureConfirmedOFAC; Chainalysis [6][7]
Initial access brokersAccess brokerageConfirmedOFAC; Chainalysis [6][7]
Malware-as-a-Service operatorsMaaSConfirmedPRODAFT LARVA-34; OFAC [4][7]
DDoS attack infrastructureDDoSConfirmedOFAC: DDoS attacks against US companies and critical infrastructure including telecommunications [7]
Magecart and card-skimming infrastructureFinancial fraudCredibleKrebsOnSecurity 2019 [1]

Victimology New in v2

Victims in Indictment44 enumerated (Victim 1 through Victim 44). 42 US, plus Victim 2 (North Grenville, Canada) and Victim 16 (Redditch, United Kingdom)
Documented LossesOver $62 million taken from Victims 1 through 44 (indictment para 141)
Victim SectorsBanks, schools, government entities, hospitals, media companies (per US Attorney Toepfer)
Charging District NexusN.D. Ohio Eastern Division. Ohio victims: Akron, Brookfield, Canton, Cleveland (x2), Elyria, Findlay, Medina, Solon, Valley View. Several are specified as having had servers physically in the district, which establishes venue
International VictimsAustralia, EU member states, UAE, Canada, United Kingdom
First and Last Charged ActsEarliest: 17 March 2014 (Volosovik links [email protected] to [email protected]). Latest: 24 October 2024, brute-force attack on Victim 44 using both AS206728 and AS215376 addresses
Notable Victim TypesVictim 1 is a municipality (Newton, Massachusetts). The remainder are described as commercial businesses. The press release adds banks, schools, government entities, hospitals and media companies

Analyst Inference The victim sector mix (hospitals, schools, government, banks) is characteristic of opportunistic ransomware affiliate targeting rather than directed collection against strategic targets. This weighs against a state-tasking interpretation of the client base, and is one reason the state nexus assessment is held at Tier 2 despite the Rewards for Justice framing discussed in Section 07.

Notable Hosted Cases

BlackBasta 200-Server Deployment, 2023 to 2024

Confirmed BlackBasta maintained approximately 200 servers on Media Land infrastructure consuming 17 to 20 Gbps, with negotiated plans to reach 50 Gbps. Infrastructure staffer "lapa" managed day-to-day operations and SOCKS proxy procurement layered over Media Land servers. Zatolokin personally handled the account. Confirmed USDT payments to lapa from operator gg: $94,000 across five transactions between February and May 2024. This remains the most granular publicly documented BPH-to-ransomware operational relationship in any source. [3]

LockBit Administrator Dmitry Khoroshev

Confirmed OFAC states that Volosovik's hosting services supported sanctioned LockBit administrator Dmitry Khoroshev (LockBitSupp), establishing a confirmed administrator-level link to the LockBit RaaS operation rather than merely an affiliate-level one. [6][7]

Carding Marketplace Concentration New in v2

Credible The indictment alleges Media Land hosted eight of the largest stolen credit card marketplaces operating in 2023, including Briansclub and Bidencash. If accurate, Media Land was not merely a ransomware enabler but a dominant single point of hosting concentration for the carding economy in that year, which is a materially broader ecosystem role than v1 assessed. [19]

REvil Forum Confrontation, 2019

Confirmed A REvil member using the handle "Unknown" addressed Volosovik by his first name "Sasha" during a 2019 XSS arbitration thread, showing his real identity was known within top-tier Russian ransomware circles well before Western public exposure. [3]

State Nexus Assessment

Jurisdictional Separation

Entity Registration Jurisdiction
Russian Federation
Media Land LLC: St. Petersburg, October 2015, semi-industrial district. ML.Cloud LLC: St. Petersburg. Data Center Kirishi: Kirishi, Leningrad Oblast, July 2022. Media Land Technology: Russia. All OOO (LLC) structures under Russian law. Two corporate defendants (Medialand LLC, ML.Cloud LLC) are charged; MLT and DC Kirishi are sanctioned but not charged.
Infrastructure Hosting Jurisdiction Corrected in v2
Multi-jurisdictional
Russia primary (St. Petersburg operations; owned DC at Kirishi) plus Finland, the Netherlands, and the United States. v1 incorrectly assessed this as Russia-only. Three of the four jurisdictions are within reach of Western legal process.
Assessed Operator Location
Russian Federation
DOJ lists all three indicted defendants as residing in St. Petersburg, upgrading this from assessed to charged-document status. Volosovik relocated from Vladivostok approximately 2018. Kozlov: Russia assessed, unspecified. None in custody. No US-Russia extradition treaty.

All three jurisdictions remain analytically distinct and must not be conflated. The change in v2 is that the infrastructure jurisdiction is now the least Russia-concentrated of the three, having previously been assessed as the most.

Assigned Tier: TOLERATED SAFE HARBOR (Tier 2 of 4)

Tier Assessment: Held at Tier 2 in v2

Media Land is assessed at Tier 2, Tolerated Safe Harbor. The Russian state is assessed to be aware of operations and to refrain from enforcement or prosecution of the operators. The tier is held, not raised, in this revision. The Rewards for Justice framing discussed below is logged as an escalation indicator that would support a move to Tier 3 (Probable Cooperation) if substantiated, but a US government offer to buy intelligence on a question is evidence that the question is open, not evidence of the answer.

Escalation Indicator: Rewards for Justice Scope New in v2

Confirmed On 14 July 2026 the Department of State's Rewards for Justice program offered up to $10 million and possible relocation for actionable information on "foreign government-linked associates of Pankova, Volosovik and Zatolokin, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud." [16][18]

Analyst Inference This phrasing is unusual for a cybercrime bounty. RFJ offers in criminal cases more commonly seek information on identity, location, or assets. Scoping the offer to foreign-government-linked associates and foreign-government-linked use of the companies indicates the US government treats the question of state connection as open and investigatively live, and is willing to pay substantially to resolve it. Publication of the poster in Russian alongside English reinforces that the intended respondent is inside Russia or the Russian-speaking underground.

Three further contextual data points bear on the question without resolving it:

Evidence Supporting Tier 2

Negative Evidence: Against Tier 3 or Tier 4

Indicators that would move the assessment to Tier 3. Documented handler relationships between any principal and an RIS officer; evidence that specific hosting was provisioned to a state-attributed intrusion set on request; RFJ-derived reporting that becomes public; a superseding indictment adding espionage or foreign-agent counts; or explicit attribution language in a future OFAC, FCDO, or EU designation. None of these is present as of 26 July 2026.

Law Enforcement and Regulatory Response

This section was rewritten in v2. v1 recorded no arrests, no indictments, and no charges.

Criminal Indictment New in v2

Charging DocumentFederal grand jury indictment, returned under seal 5 December 2024; unsealed 14 July 2026
DistrictNorthern District of Ohio
DOJ ReferenceOffice of Public Affairs Press Release 26-773
Individual DefendantsAlexander Alexandrovich Volosovik (43), St. Petersburg; Kirill Andreevich Zatolokin (34), St. Petersburg; Yulia Vladimirovna Pankova (29), St. Petersburg
Corporate DefendantsMedialand LLC, St. Petersburg; ML.Cloud LLC, St. Petersburg
Charges Corrected v2.1Thirteen counts plus an enhancement and forfeiture. See the count schedule below
Alleged ConductProvision of bulletproof hosting infrastructure enabling clients to infect victims with malware and ransomware and extort them for money and cryptocurrency; support to criminal marketplaces; fraudulent domain registration; phishing and brute-force launch platforms; repeatedly ignoring or falsifying abuse reports; rotating infrastructure to evade takedowns; accepting cryptocurrency to protect client identities
Victims42 US victim organizations across 21 states; more than $62 million in losses
Investigating AgenciesFBI Cleveland Division, with assistance from CISA and OFAC
ProsecutorsTrial Attorney Christen Gallagher, Criminal Division CCIPS; AUSA Duncan T. Brown, N.D. Ohio
International AssistanceNational Police of the Netherlands; Public Prosecutor's Office of the Netherlands; UK National Crime Agency; UK FCDO; Australian DFAT; Australian Federal Police
Custody StatusNone of the three defendants is in custody. All assessed to be in Russia. No US-Russia extradition treaty. All presumed innocent
Broader CampaignPart of Operation Riptide, an FBI campaign launched 9 June 2026 targeting criminal actors, infrastructure, and financial networks behind cybercrime and fraud

Analyst Inference The seven-month sealing period between return and unsealing, and the twenty-month gap between the December 2024 indictment and the July 2026 unsealing, indicate the charges were held while other activity proceeded. The November 2025 sanctions fell inside that window. The most probable reading is that the sanctions were sequenced first to impose financial cost while the criminal case remained protected, with unsealing timed to follow the EU designation and to accompany the Rewards for Justice launch as a combined pressure package.

Count Schedule New v2.1

Confirmed The DOJ press releases summarise the charges as four categories, which is accurate but compresses the structure. The document charges thirteen numbered counts and adds a sentencing enhancement and a forfeiture allegation that neither press release mentions.

CountOffenceStatutePeriod charged
1Conspiracy to commit and aid and abet computer fraud18 U.S.C. 371 and 2, predicated on 1030(a)(2)(C), (a)(4), (a)(5)(A), (a)(7)(B), (a)(7)(C)From 17 March 2014
2Conspiracy to commit wire fraud18 U.S.C. 1349From 19 February 2016
3 to 12Wire fraud, ten substantive counts, one per victim wire18 U.S.C. 1343 and 2From 17 December 2018
13Conspiracy to commit money laundering18 U.S.C. 1956(h)From 14 June 2016
EnhancementFalse registration of a domain name, in furtherance of Counts 1 to 1318 U.S.C. 3559(g)(1)Throughout
ForfeitureProceeds and facilitating property for Counts 1, 2 to 12, and 1318 U.S.C. 982(a)(2)(B), 1030(i), 981(a)(1)(C), 982(a)(1); 28 U.S.C. 2461(c)Throughout

Analyst Inference The three conspiracy counts carry three different start dates: computer fraud from March 2014, wire fraud from February 2016, money laundering from June 2016. The government is dating each conspiracy to the earliest act it can evidence for that offence rather than to a single origin point for the enterprise. The 17 December 2018 start for the substantive wire fraud counts is the date of the Exploit fast-flux advertisement, which suggests those ten counts are built on the fast-flux product specifically rather than on hosting in general.

Substantive Wire Fraud Counts 3 to 12 New v2.1

Confirmed Each count pairs one victim with one client conspirator and one piece of Media Land infrastructure. Paragraph 244 states that Volosovik and Zatolokin "controlled and maintained servers in New Jersey and Russia" that transmitted fraudulent responses to ransomware attacks, "including agreements to pay ransoms, receive locker passwords, and other communications related to malware attacks." The recurring New Jersey entry is the ISP1 server hosting ffv2.ru.

VictimClient ConspiratorDateInfrastructureVictim location
Victim 3CC4 (assessed Egregor)2020 to 2021Domains on ffv2.ruSolon, OH
Victim 4CC5 (assessed Snatch)2021Domain on ffv2.ruMedina, OH
Victim 5CC52019Domain on ffv2.ruAkron, OH
Victim 6CC52020Domain on ffv2.ruBrookfield, OH
Victim 10CC62 February 2023Domains and users on ffv2.ruFindlay, OH; server New Jersey
Victim 11CC624 February 2021Domains and users on ffv2.ruCleveland, OH; server New Jersey
Victim 12CC61 July 2023Domains and users on ffv2.ruCleveland, OH; server New Jersey
Victim 13CC82020Domain on ffv2.ruElyria, OH
Victim 14CC82020Domain on ffv2.ruValley View, OH
Victim 44CC unknown to the Grand Jury24 October 2024Media Land and ML.Cloud IP addresses from ASNs 206728 and 215376Canton, OH

The final count is the only one drawing on both autonomous systems together, and it independently corroborates the AS215376 correction. Note also that the wire fraud conspiracy schedule at paragraph 241 records a Media Land IP logging into a Mega.nz account on 24 March 2021 in connection with Client Conspirator 15 and Victim 42, the only named third-party storage service in the document.

Sentencing Enhancement: False Domain Registration New v2.1

Confirmed Neither press release mentions it, but the indictment charges a sentencing enhancement under 18 U.S.C. 3559(g)(1) for knowingly registering domains with false names and addresses "in a manner that prevented the effective identification of and contact with" the defendants, and using them in the course of Counts 1 to 13. Paragraph 253 enumerates roughly 56 such domains, listed in Section 04. These are the highest-value new indicators in the document.

Forfeiture Allegation New v2.1

Confirmed The government seeks forfeiture of all property constituting or derived from proceeds of Count 1, all personal property used or intended to be used to facilitate Count 1, all property traceable to Counts 2 through 12, and all property involved in Count 13 plus anything traceable to it. Authorities cited: 18 U.S.C. 982(a)(2)(B), 1030(i), 981(a)(1)(C), 982(a)(1), and 28 U.S.C. 2461(c). No specific assets, wallets or sums are itemised in the forfeiture paragraph.

Rewards for Justice Offer New in v2

AuthorityUS Department of State, Rewards for Justice program; Diplomatic Security Service Cyber and Technology Security
AmountUp to $10,000,000, plus possible relocation
Announced14 July 2026, concurrent with the unsealing
ScopeActionable information on foreign government-linked associates of Pankova, Volosovik, and Zatolokin; their malicious cyber activities; or foreign government-linked use of Media Land or ML.Cloud
Reporting ChannelTor-based tip channel published by RFJ; posters released in English and Russian
Analytic ReadAn insider-recruitment instrument aimed at the operation's periphery, and simultaneously a signal that the state-nexus question is investigatively open. See Section 07

Sanctions Chronology

16 July 2019
KrebsOnSecurity publicly names Volosovik as Yalishanda with passport documentation. Intel 471 confirms the identity. No Russian domestic response. Operations continue for a further seven years.
5 December 2024
Federal grand jury in the Northern District of Ohio returns the indictment under seal. It remains sealed for more than nineteen months.
February 2025
ExploitWhispers leaks approximately 200,000 BlackBasta Matrix messages, exposing Zatolokin as "Slim Shady" and Media Land's BlackBasta liaison.
28 March 2025
Unknown actor leaks Media Land's internal database. Volosovik acknowledges the breach on a hacking forum.
19 November 2025
Coordinated trilateral sanctions. OFAC, UK FCDO, and AU DFAT designate four entities and four individuals. FBI coordination noted. CISA and Five Eyes partners release joint bulletproof hosting mitigation guidance the same day.
9 June 2026
FBI launches Operation Riptide, a campaign targeting shared cybercrime infrastructure providers, criminal VPNs, and laundering rails rather than individual ransomware groups.
13 July 2026
Council of the EU designates Media Land LLC, ML.Cloud, and Volosovik under the cyber sanctions regime (Decision (CFSP) 2026/1713; Implementing Regulation (EU) 2026/1714), imposing asset freeze and travel ban. Taken simultaneously with a UK package covering a separate target set, the first simultaneous EU and UK action under their respective cyber regimes. The EU is the fourth sanctioning authority against Media Land.
26 July 2026 (this revision)
Primary source obtained and read. Indictment in Case 1:24-CR-001161 (N.D. Ohio, filed 5 December 2024) retrieved from the N.D. Ohio filing and reviewed through the end of Count 1. Produced eleven corrections and upgrades recorded in the v2 changelog. filed_indictment.pdf
14 July 2026
DOJ unseals the indictment in the Northern District of Ohio. Rewards for Justice announces up to $10 million plus relocation for information on foreign government-linked associates and foreign government-linked use of the companies. Posters released in English and Russian.
26 July 2026 (as of this revision)
AS206728 remains fully active with all eight IPv4 and two IPv6 prefixes announced and all four upstream peers in place. No arrests. No server seizures. No confirmed reconstitution or rebranding. FBI Cyber Division assesses Media Land is likely still shielding criminal activity.

Server Seizures

Confirmed None against Media Land as of 26 July 2026. This is notable in context: Dutch authorities seized 800 servers from Stark Industries in May 2026 and 127 servers from ZServers/XHost in February 2025, and the Dutch National Police and Public Prosecutor's Office materially assisted the Media Land investigation. Dutch capability, willingness, and case involvement are all established, and Media Land is now confirmed to have had Netherlands infrastructure. The absence of a seizure to date is therefore a choice or a sequencing decision rather than a capability gap, and a Netherlands or Finland action remains a plausible near-term development.

Post-Disruption Client Migration

Confirmed FBI Cyber Division Assistant Director Brett Leatherman stated after the unsealing that the bureau believes Media Land "is likely still shielding criminal activity" and that the FBI is actively monitoring for client migration: "We're looking for that now, to understand where those shifts may be and what opportunities are available to us in law enforcement and in the intelligence community to target those." [19]

Analyst Inference Precedent argues that migration, if it occurs, will be fast and largely successful. After the May 2026 Stark Industries seizure, GreyNoise researchers documented what they characterised as a seamless migration of attack infrastructure to new autonomous systems with near-identical behavioural signatures. The 2023 Genesis Market takedown produced replacement markets within weeks. Media Land's own position is stronger than either of those cases, however, because its core infrastructure has not been seized, so its clients have no forcing event compelling them to move. The pressure on them is reputational and sanctions-derived rather than operational.

Five Eyes Guidance

On 19 November 2025, CISA with US, UK, Australian, Canadian, and New Zealand partners released "Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers," advising ISPs to build high-confidence malicious resource block lists, conduct regular traffic analysis, implement know-your-customer verification for new hosting clients, and block traffic from known BPH autonomous system numbers. The guidance was released concurrently with the Media Land sanctions, confirming BPH providers as the primary intended target. [6][8]

Connected Groups and Ecosystem Relationships

Every connected entity claim carries two confidence labels assessed independently. Tier 1 asks whether Media Land hosted the entity's infrastructure. Tier 2 asks whether Media Land operators knew the client's identity and coordinated operationally. These are distinct claims requiring distinct evidence and are never collapsed.

BlackBasta
Ransomware-as-a-Service // Active 2022 to 2024, assessed disbanded early 2025
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Confirmed
T1: Approximately 200 servers on Media Land infrastructure per correlated BlackBasta chat and Media Land internal leak datasets. IP 45.141.87.127 cited directly in a Zatolokin speed-test message. Bandwidth consumption of 17 to 20 Gbps documented in pricing negotiation. T2: Zatolokin personally managed the account, conducted capacity planning with operator gg, and had direct knowledge of client identity and operational scale. Media Land staffer lapa managed BlackBasta infrastructure day to day and received $94,000 USDT in salary from gg across five transactions. This is the most extensively documented BPH-client operational relationship in public reporting.
Analyst1 (corroborating) OFAC (corroborating) UK FCDO (corroborating) Chainalysis (corroborating) PRODAFT (corroborating) No disagreeing vendor assessment published
LockBit
Ransomware-as-a-Service // Active 2019 to 2024, disrupted Operation Cronos February 2024
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Credible
T1: OFAC states Media Land provided BPH services to ransomware actors "including prolific ransomware actors such as Lockbit." DOJ names LockBit among the groups using the infrastructure. Chainalysis confirms Volosovik's services supported sanctioned LockBit administrator Dmitry Khoroshev. T2: Administrator-level support is confirmed at the service level, which is stronger than affiliate-level hosting, but no leak-derived record of direct operational coordination between Volosovik or Zatolokin and LockBit leadership has been published. Upgraded from a purely commercial read by the Khoroshev linkage, but not to Confirmed.
OFAC (corroborating) DOJ (corroborating) Chainalysis (corroborating) UK FCDO (corroborating) No disagreeing vendor assessment published
Cl0p Downgraded
Ransomware and mass-exploitation operation // Active 2019 to present
Two-Tier Confidence
Tier 1, Infrastructure:Analyst Inference Unsupported
Tier 2, Operational:Analyst Inference Unsupported
Withdrawn as a sourced claim in v2. Cl0p was carried at CREDIBLE in drafting, on the strength of trade reporting that presented it as an indictment allegation. The indictment has now been read: it names no ransomware group, referring only to Client Conspirators 1 to 17. Cl0p appears in neither the charging document nor either DOJ press release nor the OFAC designation. There is no primary evidence for a Media Land to Cl0p relationship at either tier. The entry is retained only to record the correction and should not be carried into published product.
Origin: trade reporting misattribution Not in indictment Not in DOJ press releases Not in OFAC designation
Egregor New in v2
Ransomware-as-a-Service // Active 2020 to early 2021 // Assessed Client Conspirator 4
Two-Tier Confidence
Tier 1, Infrastructure:Credible
Tier 2, Operational:Analyst Inference
T1: Indictment paragraph 169 states that on or about 20 September 2020, Media Land, Volosovik and Zatolokin provided BPH services for Client Conspirator 4, "who established the domains Egregorwiki.top and Wikiegregor.top on the ffv2.ru server." The domain naming is a direct and unambiguous reference to Egregor, and the September 2020 date matches Egregor's active period. The government did not name the group, so this is Analyst Inference from primary-source domain evidence rather than a government attribution, and is labelled Credible rather than Confirmed on that basis. T2: Not established. Paragraph 170 records two overt acts against Victim 3 (Solon, Ohio) on 4 October 2020 and 29 December 2021, the second causing damage to Victim 3's systems. Nothing in the read portion speaks to operator-level knowledge of the client's identity.
DOJ indictment para 169 to 170 (domain evidence) No vendor has published this linkage
Snatch New in v2
Ransomware-as-a-Service // Active 2018 to present // Assessed Client Conspirator 5
Two-Tier Confidence
Tier 1, Infrastructure:Credible
Tier 2, Operational:Credible
T1: Paragraph 171(a) and (b) records two 2020 emails from [email protected] to [email protected] concerning expiry and WHOIS updates for the domain snatch.team, in a passage describing services provided to Client Conspirator 5. Snatch is the evident referent. CC5 is the most heavily charged client in the document, with eight overt acts spanning 28 June 2017 to 6 July 2022 against Victims 4 through 9. Analyst Inference as to identity. T2: Uniquely among the client conspirators, the financial link is documented: paragraph 212 records Volosovik receiving 0.23 BTC ($4,665) through the "Yalishanda - bulletproof hoster" cluster from CC5 on 5 September 2022, specifically for infrastructure used in the 6 August 2022 attack on Victim 7, which Victim 7 had paid on 13 August. Receiving a share of a specific ransom, keyed to a specific victim and attack date, evidences knowledge of what the client was doing, though not necessarily of who they were.
DOJ indictment paras 171, 209 to 212 (domain and on-chain evidence) No vendor has published this linkage
BlackSuit
Ransomware-as-a-Service // Active 2023 to present, assessed successor to Royal; subject of DOJ disruption August 2025
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Credible
T1: Named by OFAC (sb0319) and by DOJ among the ransomware operations that used Media Land infrastructure. TRM Labs independently places BlackSuit in the on-chain flow graph connected to Yalishanda and Abushost wallets. T2: No direct operational coordination evidence beyond the designation and the on-chain intersection. Business-level service relationship.
OFAC (corroborating) DOJ (corroborating) TRM Labs (corroborating) No disagreeing vendor assessment published
Play
Ransomware-as-a-Service // Active 2022 to present; approximately 900 victim entities identified by FBI as of May 2025
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Credible
T1: Named by OFAC (sb0319) and by DOJ among Media Land's ransomware clients. T2: No direct operational relationship evidence. Business-level service relationship inferred from designation and on-chain flows. Play's disruption of Rackspace hosted email illustrates the downstream reach of the hosting relationship but says nothing about operator coordination.
OFAC (corroborating) DOJ (corroborating) Chainalysis (corroborating) No disagreeing vendor assessment published
Evil Corp
Russia-based cybercrime group / Dridex / WastedLocker / Indrik Spider // Active 2009 to present
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Credible
T1: UK Foreign Secretary Yvette Cooper cited Volosovik as having worked with Evil Corp in the November 2025 designation. Intel 471 documented Dridex, Evil Corp's flagship malware, on Yalishanda infrastructure during a 90-day sample in 2017. T2: Credible given the relationship's duration and Evil Corp's prominence, but not documented at BlackBasta-level granularity. This is the connected entity with the most state-nexus significance, because Treasury has previously linked Evil Corp's senior leadership to FSB tasking, making this an indirect route by which Media Land infrastructure may have touched state-directed activity without Media Land itself being tasked.
UK FCDO (corroborating) Intel 471 (corroborating) No disagreeing vendor assessment published
MedusaLocker
Ransomware-as-a-Service // Active 2019 to present
Two-Tier Confidence
Tier 1, Infrastructure:Credible Single Source
Tier 2, Operational:Analyst Inference
T1: TRM Labs on-chain analysis places MedusaLocker in the flow graph connected to Yalishanda and Abushost wallets. Not corroborated by OFAC, DOJ, or any other government source, and not named in the indictment reporting. T2: Not established. Inference only from Tier 1 financial flows. Note that on-chain proximity can arise from shared intermediaries rather than a direct commercial relationship.
TRM Labs (single source) Not named by OFAC, DOJ, UK FCDO, or EU
Carding Marketplace Cluster New in v2
Briansclub, Bidencash, Cardhouse, Club2crd, crdclub, Fullzinfo, Swipestore, Verified // Stolen payment card marketplaces, 2023
Two-Tier Confidence
Tier 1, Infrastructure:Confirmed
Tier 2, Operational:Credible
T1 (upgraded in v2): Indictment paragraph 207 tabulates all eight by name with the specific domains hosted on Media Land infrastructure as of 6 March 2023, each hosting charged as a separate overt act. Briansclub is separately charged at paragraphs 186 to 187 as having been serviced from 21 May 2020 until at least 16 April 2024. T2: Not established for any individual marketplace. However, hosting eight competing marketplaces simultaneously implies a deliberate commercial posture toward the carding vertical rather than incidental client acquisition, and market operators of this scale would have required custom capacity and abuse-resistance arrangements. Operator awareness of client business type is now more than inference: the indictment describes the marketplaces by function in the same table that records the hosting, and the domains themselves (Crdclub, Club2crd, Swipestore) are self-describing. Awareness of individual marketplace operator identities remains unestablished, which is why Tier 2 sits at Credible rather than Confirmed.
DOJ indictment para 207 (primary source) DOJ indictment paras 186 to 187 (Briansclub) No vendor has published a formal assessment of this cluster
Aeza Group LLC
Russian bulletproof hosting provider // OFAC-designated 1 July 2025; UK-designated 19 November 2025
Two-Tier Confidence
Tier 1, Infrastructure:Analyst Inference
Tier 2, Operational:Analyst Inference
Aeza is a separate BPH provider designated in the same November 2025 coordinated action but as a distinct entity. Co-designation does not imply an infrastructure or operational relationship; both were swept for providing analogous services. No infrastructure sharing or operational coordination between Aeza and Media Land is documented. Aeza's post-designation restructuring through Hypercore Ltd (UK), Smart Digital Ideas DOO (Serbia), and Datavice MCHJ (Uzbekistan) appears to be an independent evasion strategy, and its contrast with Media Land's apparent non-response is analytically useful: two Russian BPH providers sanctioned months apart chose opposite reconstitution postures. Relationship type: same-sector co-designation, not client or partner.
No vendor has published a formal Media Land to Aeza relationship assessment

Trajectory Assessment

Infrastructure Churn

Confirmed AS206728 remains fully active. All eight IPv4 prefixes and both IPv6 prefixes are announced, 2,048 IPv4 addresses are originated, and all four observed upstream peers remain in place. No ASN deregistration, prefix withdrawal, transit change, or de-peering has occurred through the November 2025 sanctions, the July 2026 EU designation, or the July 2026 indictment unsealing. No new ASN registrations or new Russian corporate registrations by any principal have been identified. [13]

The contrast with Aeza Group remains instructive and has now widened. Aeza began entity restructuring and infrastructure migration within weeks of its July 2025 designation, prompting a second OFAC action in November 2025 against its front companies. Media Land, sanctioned in four jurisdictions and now criminally charged, has made no observable reconstitution move. Analyst Inference Two readings are available and are not mutually exclusive: the operators assess Russian territorial protection as sufficient and see no need to restructure, or the Russian core of the estate is not portable in the way Aeza's leased capacity was, because DC Kirishi represents owned hardware in a fixed location. The owned-infrastructure model that gave Media Land a commercial edge may also be what makes it least able to run.

Market Position

Media Land occupies the top tier of the Russian BPH market on every available axis: 15+ years of continuous operation, flagship-tier ransomware clientele, owned physical data center capacity, a mature fast-flux product sold as a distinct line, and, per the indictment, concentration of eight major carding marketplaces plus 17 or more criminal groups. The provider has absorbed a public identity exposure in 2019, two damaging leaks in 2025, sanctions in four jurisdictions, and a US criminal indictment without observable operational interruption. That resilience is a property of the jurisdiction, not of the tradecraft.

Disruption History Assessment

InstrumentStatusObserved Effect on Operations
Public identity exposure (2019)AppliedNone observable; operations continued and scaled
Adversary and insider leaks (2025)Applied twiceNone observable; breach acknowledged on forum, service continued
Sanctions, four jurisdictions (2025 to 2026)AppliedFinancial friction assessed; no infrastructure effect; no de-peering
Criminal indictment (2026)AppliedNo arrests; no infrastructure effect to date
Rewards for Justice bounty (2026)AppliedToo recent to assess; targets insider defection
ArrestsNot appliedBlocked by absence of extradition treaty and defendants' non-travel
Server seizureNot appliedNow newly feasible against Netherlands, Finland, and US infrastructure
Upstream de-peeringNot appliedOnly SYSECT D.O.O. (Montenegro) is plausibly subject to European pressure
Russian domestic actionNot appliedAssessed very unlikely; see Section 07

Trajectory Direction: DEGRADED and STABLE

Assessment unchanged in direction from v1, with higher confidence and a changed basis. Media Land is assessed as Degraded but operationally stable. Every applied instrument to date has been financial, legal, or reputational; none has touched the infrastructure. The provider retains its ASN, its prefixes, its peers, its owned data center, and its principals.

What changed in v2 is that the disruption ceiling is now higher than v1 assessed. v1 concluded that "physical disruption is not achievable under current conditions given wholly Russia-based infrastructure." That premise was wrong. Infrastructure in the Netherlands, Finland, and the United States is within reach, Dutch authorities are already case participants with demonstrated seizure capability, and a partial seizure action is a realistic near-term possibility. Such an action would not end the provider, whose core is in Russia, but it would remove the multi-jurisdictional redundancy that the indictment identifies as a deliberate resilience feature.

Watch indicators, next 6 to 12 months:

Mandatory Intelligence Gaps

Identity of Client Conspirators 1 to 3 and 6 to 17

Newly created in v2. The indictment anonymises all seventeen. CC4 and CC5 are identifiable from domain evidence as Egregor and Snatch. CC1 is the most likely candidate for a major RaaS given ten charged victims and dedicated leak-site fast-flux hosting from February 2021, but is not identified. Correlating the charged victim cities and dates against public ransomware victim lists is a tractable next step.

China hosting claim unresolved

The DOJ press release asserts Media Land infrastructure operated out of China. The reviewed portion of the indictment does not corroborate it, though it does document a Chinese registrar, Chinese proxy procurement and Chinese-language support. Either the hosting claim rests on Counts 2 to 4, or the press release generalises from the supplier relationships. Resolving this requires reading the remaining counts or separate technical corroboration. Until then China is carried as a supplier and market relationship only, not a hosting jurisdiction.

Identity of ISP1 and ISP2

Newly created in v2. Both are US-based ISPs "known to the Grand Jury" and outside the charging district. ISP1 hosted the ffv2.ru fast-flux platform in New Jersey and took over $23,000 from the defendants. Neither is charged. Identifying them would clarify whether the US hosting was obtained through misrepresentation or lax onboarding, which bears directly on the CISA know-your-customer guidance.

Cash-out venue mapping

Narrowed in v2.1, still open. Count 13 has now been read and documents the mechanism: victims directed to pay into anonymous cryptocurrency accounts, funds transmitted from the United States to points outside it, transactions over $10,000, and proceeds reaching Volosovik and Zatolokin "either through ACH, wire transfer, or other electronic fund transfers." The ACH and wire reference is new and important because it implies regulated intermediaries. But no exchange, OTC desk or money services business is named anywhere in the document, and the forfeiture paragraph itemises no wallets or sums. Mechanism documented; endpoints still unidentified.

Substance of Pankova's ML.Cloud control

Carried forward, narrowed. The indictment says ML.Cloud was "publicly owned by" Pankova, a formulation that stops short of asserting beneficial ownership. Against that, paragraphs 132 and 133 give her substantive conduct: ML.Cloud provided the legitimate-appearing cover for the criminal infrastructure, and she enabled payment for that infrastructure through Media Land accounts and credit cards. She is also charged on every count. The open question is now narrower: whether she directed ML.Cloud or was installed as its registered owner while others directed it.

Kozlov's function and omission from charges

Carried forward from v1 and now sharpened. Sanctioned in November 2025 but absent from the December 2024 indictment. Whether this reflects charging-record timing or evidentiary insufficiency is unresolved.

Post-sanctions and post-indictment operational tempo

Carried forward from v1. No visibility into client attrition, pricing changes, or capacity utilisation after November 2025 or July 2026. The FBI is monitoring migration but has published nothing.

State nexus resolution

Elevated in v2. The Rewards for Justice offer establishes that the US government treats the state-connection question as open. No public evidence resolves it in either direction.

CLOSED in v2.1: Full charging document read

v2 was built on Count 1 only, the extraction having truncated at page 60. All 75 pages have now been read. This closed the count-structure error (thirteen counts, not four), produced the Count 13 laundering theory, and surfaced the 3559(g)(1) domain enhancement that no press release mentioned.

CLOSED: Operator legal status

v1 recorded no charges against any principal. Resolved: three principals and two corporate entities indicted in the Northern District of Ohio, unsealed 14 July 2026.

CLOSED: Pankova's functional role

v1 assessed her as a legal and financial associate of unspecified seniority. Resolved: owner of ML.Cloud LLC at the time of investigation and indictment.

CLOSED: Infrastructure jurisdiction

v1 assessed infrastructure as Russia-only. The press release corrected this. The charging document pins the specifics: ffv2.ru on a leased server in New Jersey until 23 June 2024; FFPANEL.TOP in Finland; AS215376 hardware in the Netherlands.

CLOSED: Cl0p attribution

Cl0p was carried at CREDIBLE in drafting, pending document review. Resolved against: the indictment names no ransomware group, and Cl0p appears in no primary source. Claim withdrawn.

CLOSED: Carding, Ermac and RedAlert

All three were carried at CREDIBLE from trade reporting in drafting. All now CONFIRMED from the document, with domains, IPs and quoted third-party abuse reports.

CLOSED: Volosovik current location

v1 assessed St. Petersburg from entity registration and 2018 Intel 471 reporting. Resolved: DOJ lists all three defendants as residing in St. Petersburg as of the charging document.

Recent Reporting

14 July 2026
DOJ Office of Public Affairs unseals the indictment (Press Release 26-773), N.D. Ohio. Rewards for Justice announces the $10M offer. justice.gov and rewardsforjustice.net
13 July 2026
Council of the EU designates Media Land LLC, ML.Cloud, and Volosovik under the cyber sanctions regime, simultaneously with a UK package covering separate targets. consilium.europa.eu
15 to 16 July 2026
Trade coverage of the unsealing, including indictment-derived detail on fast-flux pricing, client database scale, the carding marketplace list, and Cl0p. TechCrunch, BleepingComputer, TechTimes, GovInfoSecurity.
9 June 2026
FBI launches Operation Riptide, targeting shared cybercrime infrastructure providers rather than individual ransomware groups. The Media Land action is presented as part of this campaign.
May 2026
Dutch authorities seize 800 servers from Stark Industries. GreyNoise documents seamless client migration to new autonomous systems, establishing the base-rate expectation for BPH disruption outcomes.
15 January 2026
Analyst1 publishes "Infrastructure in the Shadows" (Anastasia Sentsova), correlating the BlackBasta chat leak and the Media Land internal leak to document the Yalishanda to BlackBasta operational relationship. analyst1.com
19 November 2025
OFAC, UK FCDO, and AU DFAT announce coordinated sanctions against the Media Land network. CISA releases Five Eyes bulletproof hosting guidance. treasury.gov
7 April 2025
PRODAFT identifies Medialand as LARVA-34 and analyses the 28 March data leak, noting hosted infrastructure well beyond ransomware including code-signing, phishing, and data exfiltration systems.
28 March 2025
Unknown actor leaks the Media Land internal database. Volosovik acknowledges the breach on a hacking forum.
February 2025
ExploitWhispers leaks approximately 200,000 BlackBasta Matrix messages, exposing Zatolokin as "Slim Shady."

Sources

[1]KrebsOnSecurity, "Meet the World's Biggest 'Bulletproof' Hoster," 16 July 2019. krebsonsecurity.com
[2]UK Government, "UK smashes Russian cybercrime networks responsible for attacks on UK businesses," 19 November 2025. gov.uk
[3]Analyst1 (Anastasia Sentsova), "Infrastructure in the Shadows," 15 January 2026. analyst1.com
[4]PRODAFT, "Threat Actor Leaks Internal Data from Medialand (LARVA-34)," 7 April 2025. x.com/PRODAFT
[5]Cybersecurity-help.cz, "One of largest bulletproof web hosting providers Media Land got its internal data leaked," 2025. cybersecurity-help.cz
[6]Chainalysis, "U.S., U.K., and Australia Target Russian Cybercrime Infrastructure," November 2025. chainalysis.com
[7]U.S. Department of the Treasury / OFAC, "United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware," 19 November 2025. treasury.gov
[8]Bleeping Computer (Sergiu Gatlan), "Russian bulletproof hosting provider sanctioned over ransomware ties," 19 November 2025. bleepingcomputer.com
[9]Australian Government (AFP / DFAT), "Sanctions imposed on Russian cybercrime service providers for malicious cyber activity," 19 to 20 November 2025. afp.gov.au
[10]TRM Labs, "US, Australia, and UK Sanction Russian Cybercrime Infrastructure Supporting Ransomware," 20 November 2025. trmlabs.com
[11]Elliptic, "US cracks down on Russian bulletproof hosting services enabling cybercrime," November 2025. elliptic.co
[12]Reuters, "US, UK and Australia sanction Russian cyber firms over ransomware support," 19 November 2025. reuters.com
[13]Hurricane Electric BGP Toolkit, AS206728 MEDIALAND-AS. bgp.he.net
[14]CybersecurityNews, "Inside the Leaks that Exposed the Hidden Infrastructure Behind a Ransomware Operation," 2025. cybersecuritynews.com
[15]National Crime Agency (UK), "Prolific bulletproof hosting service sanctioned by the UK and allies," November 2025. nationalcrimeagency.gov.uk
[16]New in v2. U.S. Department of Justice, Office of Public Affairs, "Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses," Press Release 26-773, 14 July 2026. justice.gov
[17]New in v2. Bleeping Computer (Sergiu Gatlan), "US charges alleged operators of Russian bulletproof hosting service," 15 July 2026. bleepingcomputer.com
[18]New in v2. U.S. Department of State, Rewards for Justice, "Media Land" reward notice, 14 July 2026. rewardsforjustice.net
[19]New in v2. Tech Times (Kyle Belmonte), "DOJ Charges Russians Who Ran Hosting Infrastructure for LockBit, Cl0p, Play," 16 July 2026. Contains indictment-derived detail on fast-flux pricing, client database scale, carding marketplaces, and the Leatherman statement. techtimes.com
[20]New in v2. GovInfoSecurity / ISMG, "Feds Target Widely Used Russian Bulletproof Hosting Services," July 2026. govinfosecurity.com
[21]New in v2. Council of the European Union, "Russian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entities," 13 July 2026. Council Decision (CFSP) 2026/1713; Council Implementing Regulation (EU) 2026/1714. consilium.europa.eu
[22]New in v2. UK Foreign, Commonwealth & Development Office, "UK and EU strike Russian cyber networks with new sanctions," 13 July 2026. Used to establish that the UK's 13 July designation list does not include Media Land or its principals. gov.uk
[23]New in v2. TechCrunch (Zack Whittaker), "US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims," 15 July 2026. techcrunch.com
[24]PRIMARY SOURCE, new in v2. United States v. Volosovik, Zatolokin, Pankova, Medialand LLC and ML.Cloud LLC, Case No. 1:24-CR-001161, Indictment, U.S. District Court for the Northern District of Ohio, Eastern Division, filed 5 December 2024, unsealed 14 July 2026 (Judge Barker). Charging 18 U.S.C. 371, 1343, 1349, 1956 and 2. Reviewed through the end of Count 1 (document p. 60); Counts 2 to 4 not read. justice.gov filed_indictment.pdf
[25]New in v2. U.S. Attorney's Office, Northern District of Ohio, "Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims," 14 July 2026, updated 17 July 2026. justice.gov/usao-ndoh

Revision History and Change Record

Full provenance for every revision of this profile. Retained so that any claim, correction or withdrawal can be traced to the revision that made it and the source that prompted it.

v1June 2026. Initial profile. Built on open-source reporting and the coordinated US, UK and Australian sanctions of 19 November 2025.
v226 July 2026. Triggered by the DOJ indictment unsealing (14 July 2026) and the EU designation (13 July 2026). Built on direct review of the charging document in United States v. Volosovik et al., Case 1:24-CR-001161 (N.D. Ohio), read through the end of Count 1 only, the text extraction having truncated at page 60.
v2.127 July 2026. Current. Full charging document read, all 75 pages. Count structure corrected from four categories to thirteen counts plus a sentencing enhancement and forfeiture. Count 13 money laundering theory documented. 56 falsely registered domains added.
v2.1 // Full charging document read

Source: all 75 pages of the indictment, obtained directly rather than through the truncated extraction used for v2

v2 was built on Count 1 alone. The remaining counts have now been read and corrected several things v2 got wrong or could not see.

CorrectedCount structure. Not four counts. The indictment charges thirteen: Count 1 computer fraud conspiracy, Count 2 wire fraud conspiracy, Counts 3 to 12 ten substantive wire fraud counts, and Count 13 money laundering conspiracy. It also charges a sentencing enhancement under 18 U.S.C. 3559(g)(1) and a forfeiture allegation, neither of which appears in either DOJ press release.
AddedCount 13 money laundering theory. Three charged objects: concealment laundering (1956(a)(1)(B)(i)), international transmission of funds out of the United States (1956(a)(2)(B)(i)), and monetary transactions over $10,000 (1957). Proceeds reached Volosovik and Zatolokin "either through ACH, wire transfer, or other electronic fund transfers," which indicates conventional banking rails were touched, not only on-chain flows.
Added56 falsely registered domains. Paragraph 253 enumerates them. Includes two derived from Volosovik's own surname (volosovichkov.info, volosovichkov-taxi.info), the ffv2panelbot.info platform domain, a large DNS-infrastructure cluster, brand impersonations of ProtonMail, Amazon, Microsoft Defender, Google Cloud and Revolut, and xmrdealshere.ru. Now in Section 04.
AddedPer-count wire fraud schedule. Counts 3 to 12 map one victim to one client conspirator to one piece of infrastructure. Paragraph 244 confirms servers "in New Jersey and Russia." The Victim 44 count uses both AS206728 and AS215376 together, independently corroborating the AS215376 correction.
AddedThree separate conspiracy start dates: computer fraud from 17 March 2014, wire fraud from 19 February 2016, money laundering from 14 June 2016. The substantive wire fraud counts run from 17 December 2018, the date of the Exploit fast-flux advertisement.
AddedMega.nz appears in the paragraph 241 schedule: a Media Land IP logged into a Mega.nz account on 24 March 2021 in connection with Client Conspirator 15 and Victim 42. The only named third-party storage service in the document.
RevisedRead-limit caveat retired. The v2 front-matter warning that Counts 2 to 4 were unread is removed. The document has been read in full.
Corrections arising from primary-source review

Source: the charging document itself, obtained from the N.D. Ohio filing

Scope of review. The indictment was obtained from the N.D. Ohio filing and read directly. This revision reflects the document itself rather than DOJ press-release summaries or trade reporting. Read limit The retrieved text extraction covers the caption, general allegations, victim schedule, definitions, and the whole of Count 1 including all overt acts, ending at document page 60. At the time of v2, Counts 2 onward were beyond the extracted text and had not been read. Count structure was taken from the two DOJ press releases. This limitation was removed in v2.1, when the full document was obtained and read.

ScopedChina scoped to what the document evidences. China is not carried as an infrastructure hosting jurisdiction: the claim appears in the DOJ press release but is not corroborated in the reviewed portion of the charging document, and this profile does not publish uncorroborated hosting jurisdictions. The documented China relationship is retained in full and set out in Section 04: a Chinese domain registrar sold as part of the fast-flux product, recurring Chinese proxy procurement recorded in operator WhatsApp traffic, Chinese-language support and billing channels, and both principals' multi-year Beijing residence. The distinction is supplier and market versus hosting.
CorrectedSecond ASN was wrong. v1 listed AS211805 as the secondary ASN, taken from IPinfo. The indictment states Media Land and ML.Cloud controlled ASN blocks 206728 and 215376, and that as of about June 2024 those two blocks ran on hardware physically located in Russia and the Netherlands respectively. AS215376 is the ML.Cloud Netherlands ASN. Sections 01 and 04 corrected.
CorrectedThe indictment names no ransomware group. All seventeen clients appear only as "Client Conspirator 1" through "Client Conspirator 17," each using a malware or ransomware variant "known to the Grand Jury." Trade reporting stating that the indictment charges hosting for LockBit, Cl0p, and Play is not supported by the document. LockBit, BlackSuit, and Play are named in the DOJ press release and the OFAC designation, not in the indictment. Cl0p is not named in either. Section 06 and Section 09 revised; the Cl0p entry is downgraded.
CorrectedVictim count is 44, not 42. The indictment enumerates Victim 1 through Victim 44 and alleges over $62 million taken "from Victims 1 through 44." The press-release figure of 42 counts US victims only; Victim 2 (North Grenville, Canada) and Victim 16 (Redditch, United Kingdom) are the two non-US entries. Both figures are correct for what they measure.
UpgradedEight carding marketplaces: CREDIBLE to CONFIRMED. Paragraph 207 tabulates all eight by name with hosted domains: Briansclub (Briansclub.cm, Brianscrabs.de), Cardhouse (Cardhouse.cc), crdclub (Crdclub.su), Club2crd (Club2crd.cc), Verified (Verified.mn), Fullzinfo (Fullzinfo.com), Swipestore (Swipestore.cc), Bidencash (Bidencash.link, Bidencash.rip), all on the ffv2.ru server as of 6 March 2023.
UpgradedErmac and RedAlert: CREDIBLE to CONFIRMED. Both appear in quoted third-party abuse reports. Ermac at Media Land IP 45.141.85.29, reported by innotec.security on 11 July 2022 in an attack against Santander. RedAlert at 185.100.222.28 and 185.254.121.69 with C2 at ffpanel.ru, reported by Deloitte CyberSOC and BFK, typed as Trojan-Banker.AndroidOS.RedAlert 2.0.
UpgradedFast-flux tariffs: CONFIRMED and expanded. Three separate advertisements are quoted at length with full price ladders. Trade reporting gave only the $150 and $500 endpoints; the actual ladder has four tiers and the 2016 pricing is denominated in WebMoney (WMZ), not dollars. Section 03 rebuilt.
UpgradedScale figures: CONFIRMED. Approximately 389 unique usernames in the ffpanel backend, attributed specifically to Client Conspirators 1, 3 to 8 and 14; over 5,000 unique registered domains; 41 database tables. IP allocation to AS206728 grew from over 3,800 (June 2024) to over 5,800 (July 2024).
AddedThe fast-flux platform is named: ffv2.ru. Hosted at IP 104.194.11.236 on a leased server physically located in New Jersey, United States until 23 June 2024, then migrated to Russian IP 45.141.85.184 inside AS206728. Supporting estate: ffpanel.ru, ffpanel.top, sshvps.net, abushost.ru. FFPANEL.TOP resolved to 65.108.65.82, previously located in Finland. This is the concrete identification of the US and Finland infrastructure that the press release cited only in the abstract.
AddedTwo client conspirators are identifiable from the document. Client Conspirator 4 registered Egregorwiki.top and Wikiegregor.top; Client Conspirator 5 used snatch.team. These point to Egregor and Snatch respectively. The identification is analyst inference from domain evidence in the indictment, not an attribution the government made.
AddedSelector set. Eleven email accounts, four Jabber addresses, one Telegram handle, two Russian mobile numbers, two iCloud account IDs, and a named Bitcoin cluster ("Yalishanda - bulletproof hoster") are enumerated in Sections 02, 04 and 05.
AddedMoney laundering theory partially resolved. Paragraph 139 alleges payment accepted directly from cryptocurrency accounts holding ransomware proceeds. Paragraph 208 traces a share of the Victim 2 ransom into a Bitcoin wallet registered to [email protected]. Paragraph 212 records $4,665 (0.23 BTC) received from Client Conspirator 5 on 5 September 2022 for infrastructure used in the Victim 7 attack. Section 05 revised. Full Count 4 theory still unread.
AddedDocumented OPSEC failure. On 6 September 2018 Volosovik emailed a registrar from [email protected] to get ffpanel.ru unblocked and attached a scan of his own passport. Separately, Spamhaus had already named ffv2.ru and s777shop.ru as botnet controllers in November 2014. Section 03 revised.
RevisedPankova. The indictment says ML.Cloud was "publicly owned by" Pankova, wording that leaves beneficial ownership open, but paragraphs 132 and 133 give her a substantive role: ML.Cloud provided the legitimate-appearing cover for the criminal infrastructure, and she enabled payment for that infrastructure through Media Land accounts and credit cards. The v2 nominee-versus-beneficial gap stays open but narrows.
RevisedConspiracy start date pinned to 17 March 2014, the date Volosovik linked [email protected] to [email protected]. Earliest ransomware proceeds into operator wallets: 14 June 2016. Earliest advertising overt act: 17 August 2016 on Dark Money. Forums now include Antichat and Fog.ug alongside Exploit, XSS and Dark Money.
Changes from the July 2026 enforcement actions

Source: DOJ press releases, the EU Official Journal, and vendor reporting

These changes were prompted by the unsealing of a federal criminal indictment against Volosovik, Zatolokin and Pankova. Follow-on research surfaced two material corrections to v1 that were not part of the original trigger, and one secondary-source error requiring deconfliction.

AddedCriminal indictment. Returned under seal 5 December 2024, unsealed 14 July 2026, N.D. Ohio (DOJ Press Release 26-773). Volosovik, Zatolokin, Pankova, Medialand LLC, and ML.Cloud LLC charged with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, ten counts of wire fraud, and conspiracy to commit money laundering. 42 US victims across 21 states, $62M+ in losses. Section 08 rewritten.
AddedRewards for Justice offer. Up to $10M plus relocation, announced 14 July 2026, scoped specifically to "foreign government-linked associates" and "foreign government-linked use of Media Land or ML.Cloud." Treated as a state-nexus escalation indicator in Section 07.
AddedEU sanctions designation. Council Decision (CFSP) 2026/1713 and Implementing Regulation (EU) 2026/1714, 13 July 2026, designating Media Land LLC, ML.Cloud, and Volosovik. EU is now a fourth sanctioning authority. Section 08 and Section 01 metrics revised.
CorrectedInfrastructure hosting jurisdiction. v1 stated "no confirmed infrastructure in non-Russian jurisdictions." The indictment establishes Media Land operated physical infrastructure in Finland, the Netherlands, and the United States in addition to Russia. This is a material correction affecting Sections 04, 07, and the Section 01 attribute table, and it changes the disruption calculus.
CorrectedPankova's role. v1 assessed Pankova as a legal and financial associate to Volosovik based on the OFAC designation. The indictment establishes she owned ML.Cloud LLC at the time of investigation and indictment. She is a principal, not a support figure. Her operator profile is rewritten and her DOB range is now constrained (age 29 as of July 2026).
AddedFast-flux service line and pricing. Volosovik advertised a fast-flux DNS product on Exploit in December 2018 at $150/month (single domain) to $500/month (unlimited domains), rotating IPs every three to ten minutes. Added to Sections 03 and 04.
AddedScale metrics from indictment. Client database of approximately 389 usernames and more than 5,000 registered domains; 17 or more criminal groups served; eight named carding marketplaces; Ermac and RedAlert Android banking trojans. Sections 04 and 06.
RevisedClient roster. Cl0p added as a client at CREDIBLE (single source: indictment reporting, not named in the DOJ press release). Section 06 and Section 09.
RevisedOperator legal status. All operator profiles updated from "no indictment" to reflect charging status. Kozlov remains sanctioned but is not among the indicted defendants, which is itself an analytic signal.
CorrectedDeconfliction, secondary-source error. Several trade outlets reported that the UK jointly designated Media Land on 13 July 2026. The UK's 13 July list of 24 targets does not include Media Land, ML.Cloud, or any of the three defendants; the UK designated them in November 2025. The 13 July action was EU designation plus simultaneous UK action against a separate target set. Separately, Yuliya Vladimirovna Pankratova (Z-Pentest / CARR, EU-designated 13 July 2026) is a different individual from Yulia Vladimirovna Pankova of ML.Cloud. Do not conflate.
RevisedStatus held at Degraded. Not escalated to Disrupted. AS206728 remains fully active with all 10 prefixes announced; no arrests; no seizures. FBI Cyber Division assesses Media Land is "likely still shielding criminal activity." Sections 08 and 10.