Executive Summary and Provider Overview
Quick-Reference Attributes
| Common Names | Media Land LLC; Medialand LLC; Yalishanda; Abushost; ML.Cloud LLC; Media Land Technology; Data Center Kirishi; real-hosting[.]biz (historic) |
|---|---|
| Node Type | Bulletproof Hosting Provider |
| Status | Degraded AS206728 fully active as of latest BGP snapshot; sanctioned in four jurisdictions; three principals indicted; no arrests, no seizures |
| PRODAFT Designation | LARVA-34 (EU designation lists LARVA-34 as a Volosovik alias) |
| Criminal Charges Corrected v2.1 | Case 1:24-CR-001161, Judge Barker, N.D. Ohio Eastern Division. Returned under seal 5 December 2024; unsealed 14 July 2026. Thirteen counts, plus a sentencing enhancement under 18 U.S.C. §3559(g)(1) and a forfeiture allegation. Defendants: Volosovik, Zatolokin, Pankova, Medialand LLC, ML.Cloud LLC. Signed by then US Attorney Rebecca C. Lutzko. Full count schedule in Section 08 |
| Documented Losses Corrected from indictment | Over $62M taken from Victims 1 through 44 as enumerated in the indictment. The DOJ press-release figure of 42 counts US victims only; Victim 2 (North Grenville, Canada) and Victim 16 (Redditch, UK) are the non-US entries. Sectors: banks, schools, government entities, hospitals, media companies. Ohio venue victims in Akron, Brookfield, Canton, Cleveland, Elyria, Findlay, Medina, Solon, Valley View |
| Rewards for Justice New in v2 | Up to $10M plus possible relocation, announced 14 July 2026, for information on foreign government-linked associates of the three defendants, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud |
| Entity Registration Jurisdiction | Russia: Media Land LLC registered St. Petersburg, October 2015 (semi-industrial district); Data Center Kirishi registered Leningrad Oblast, July 2022; ML.Cloud and Media Land Technology also Russia-registered, St. Petersburg |
| Infrastructure Hosting Jurisdiction Corrected in v2 | Multi-jurisdictional. Russia (primary: St. Petersburg; owned DC at Kirishi, Leningrad Oblast) plus documented physical infrastructure in Finland, the Netherlands, and the United States. v1 incorrectly assessed infrastructure as Russia-only |
| Assessed Operator Location | Russia: all three indicted defendants listed by DOJ as residing in St. Petersburg. Volosovik relocated from Vladivostok approximately 2018 per Intel 471. None in custody; Russia has no extradition treaty with the US |
| Active Period | ~2009 to present (Yalishanda brand, 15+ years); indictment traces Media Land operations to at least 2014; entity incorporated October 2015 |
| Primary ASN | AS206728 MEDIALAND-AS (RIPE; registered 2016-11-17; last modified 2025-01-21; active) |
| Secondary ASN Corrected from indictment | AS215376 ML.Cloud, hardware physically located in the Netherlands per the indictment. v1 incorrectly listed AS211805 from IPinfo. The indictment states Media Land and ML.Cloud controlled ASN blocks 206728 and 215376, running on hardware in Russia and the Netherlands respectively as of about June 2024 |
| IPv4 Prefixes (AS206728) | 45.141.84.0/24 (ML Cloud); 45.141.85.0/24 (Media Land); 45.141.86.0/24 (ML Cloud); 45.141.87.0/24 (Grisha Maslinikov); 91.220.163.0/24; 193.242.153.0/24 (IT Outsourcing LLC); 194.26.29.0/24; 194.26.69.0/24. Total 2,048 IPv4 |
| IPv6 Prefixes | 2a0b:7ec0:1320::/48; 2a0b:7ec0:7701::/48 |
| Fast-Flux Platform Confirmed from indictment | Platform domain ffv2.ru with the "ffpanel" web application. Supporting estate: ffpanel.ru, ffpanel.top, sshvps.net, abushost.ru. Backend database "ffpanel" with 41 tables holding registered users, domains, DNS records, credentials, service costs and cryptocurrency transactions. Tariff ladder quoted verbatim in Section 03 |
| Client Scale Confirmed from indictment | Approximately 389 unique usernames in the ffpanel backend, attributed to Client Conspirators 1, 3 to 8 and 14; over 5,000 unique registered domains; 17 Client Conspirators charged (CC1 to CC17). AS206728 IP allocation grew from over 3,800 (June 2024) to over 5,800 (July 2024) |
| BGP Peers / Upstream | AS49531 (NetCom-R LLC, RU); AS20632 (PJSC MegaFon, RU); AS202799 (SYSECT D.O.O., Montenegro); AS51538 (Lavrentyev A.A., RU). Historical RIPE IRR: AS3216 (Vimpelcom/Beeline), AS9049 (ERTH Corporation JSC) |
| RIPE Maintainers | mnt-ru-media-land-1; media-land-llc; NETWORK-SUPPORT-MNT; RIPE-NCC-END-MNT |
| Abuse Contact | Not publicly disclosed in RIPE WHOIS (personal data removed under RIPE policy). Indictment alleges defendants repeatedly ignored or falsified abuse reports |
| Clients Revised in v2 | The indictment names no ransomware group, referring only to Client Conspirators 1 to 17. Group names derive from the DOJ press release and OFAC: LockBit, BlackSuit, Play (CONFIRMED); BlackBasta, Evil Corp (CONFIRMED via leak correlation and UK FCDO); MedusaLocker (CREDIBLE, single source). Cl0p is named in neither the indictment nor the press release and is downgraded. Confirmed by the indictment itself: eight carding marketplaces by name and domain, plus Ermac and RedAlert Android banking trojans |
| Bitcoin Address (OFAC) | 18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB (designated, Volosovik) |
| Blocklist Status | Spamhaus SBL/CBL: confirmed listed; DROP/EDROP: probable; abuse.ch: probable. Specific current entry IDs not confirmed in open sources |
| Sanctions | OFAC CYBER3 (E.O. 13694 as amended), UK FCDO, AU DFAT: all 19 November 2025. EU (Council Decision (CFSP) 2026/1713; Implementing Regulation (EU) 2026/1714): 13 July 2026 |
| State Nexus Tier | Tolerated Safe Harbor (Tier 2 of 4). Held at Tier 2 in v2; RFJ framing logged as an escalation indicator, not a tier change |
Overall Assessment
Media Land LLC, operating under the underground brand "Yalishanda," is among the most thoroughly documented and longest-running Russian bulletproof hosting providers in the threat landscape, with confirmed activity from approximately 2009 to present. As of this revision the provider and its principals face the most complete Western enforcement stack applied to any BPH operator to date: criminal indictment in the United States, sanctions in four jurisdictions, and a $10 million intelligence bounty. None of it has yet altered the infrastructure.
Confirmed On 14 July 2026 the Department of Justice unsealed an indictment returned under seal on 5 December 2024 in the Northern District of Ohio, charging Volosovik, Zatolokin, Pankova, Medialand LLC, and ML.Cloud LLC with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, ten counts of wire fraud, and conspiracy to commit money laundering. The indictment names 42 US victim organizations across 21 states, with more than $62 million in documented losses, and identifies victims including banks, schools, government entities, hospitals, and media companies. The case is prosecuted by CCIPS Trial Attorney Christen Gallagher and AUSA Duncan T. Brown, investigated by FBI Cleveland with CISA and OFAC support, and materially assisted by the Dutch National Police and Public Prosecutor's Office, the UK National Crime Agency, and Australian authorities. [16]
Confirmed The indictment corrects a significant element of the prior assessment. Media Land's infrastructure was not confined to Russia: it operated out of Finland, the Netherlands, and the United States. That multi-jurisdictional footprint explains both the seven-year investigative timeline and the participation of Dutch law enforcement, and it materially changes the disruption calculus, because a portion of the estate sits inside jurisdictions where Western legal process reaches. It also reframes the provider's own marketing: Zatolokin's claim to BlackBasta that "this is all our own: our own data center, our own hardware" described the Russian core, not the whole estate. [16][17]
Confirmed The indictment also establishes that Pankova owned ML.Cloud LLC at the time of investigation, upgrading her from the support role assessed in v1 to a principal. It documents a fast-flux DNS product advertised on Exploit in December 2018 at $150 to $500 per month, a client database of roughly 389 usernames and more than 5,000 domains, service to 17 or more criminal groups, eight named carding marketplaces, and hosting for the Ermac and RedAlert Android banking trojans. [16][19][20]
Confirmed Separately, on 13 July 2026 the Council of the European Union designated Media Land LLC, ML.Cloud, and Volosovik under the EU cyber sanctions regime, making the EU a fourth sanctioning authority. The action was taken simultaneously with a UK package covering a different target set, the first time the EU and UK have acted at the same time under their respective cyber regimes. [21][22]
Status is held at Degraded rather than escalated to Disrupted. AS206728 remains fully active with all eight IPv4 and two IPv6 prefixes announced. No defendant is in custody, no servers have been seized, and Russia has no extradition treaty with the United States. FBI Cyber Division Assistant Director Brett Leatherman stated after the unsealing that the bureau believes Media Land "is likely still shielding criminal activity" and is actively monitoring for client migration. The enforcement stack is now near-complete on paper and almost entirely unrealized in effect: the practical pressure runs through financial and intelligence channels rather than any near-term prospect of trial. [19][20]
Lineage and Organizational Heritage
Entity and Brand Timeline
| Brand / Entity | Type | Role | Period | Confidence |
|---|---|---|---|---|
| Yalishanda | Underground brand / persona | Primary criminal trading name; used on Exploit, XSS, Dark Money and predecessor forums to advertise BPH services | ~2009 to present | Confirmed |
| real-hosting[.]biz | Early BPH domain | Service advertised circa 2011; accepted botnets, malware, adware, exploits, Zeus, IRC | ~2011 | Confirmed |
| abushost[.]ru / Abushost | Long-lived BPH brand | Among the most durable Yalishanda brand names; advertised on Exploit[.]in and XSS[.]pro per TRM Labs | ~2015 onward | Confirmed |
| Media Land operations (pre-incorporation) New in v2 | Operational activity | Indictment traces Media Land operational history to at least 2014, two years before open forum advertising under the Media Land structure | From at least 2014 | Confirmed |
| Media Land LLC (ООО Медиа Лэнд) | Russian LLC (OOO) | Legal entity providing surface-level commercial credibility; enabled contracts, IP leasing, and staff employment. Owned by Volosovik | Registered October 2015 to present | Confirmed |
| ML.Cloud LLC Revised in v2 | Russian LLC | Sister company; infrastructure used in conjunction with Media Land in ransomware and DDoS operations. Owned by Pankova at time of investigation and indictment | Active; dates not confirmed | Confirmed |
| Media Land Technology (MLT) | Russian LLC, 100% subsidiary | Wholly owned subsidiary of Media Land LLC per OFAC; likely infrastructure or services wrapper. Sanctioned but not charged | Active; dates not confirmed | Confirmed |
| Data Center Kirishi (DC Kirishi) | Russian LLC, 100% subsidiary | Wholly owned subsidiary registered July 2022; owned physical data center in Kirishi, Leningrad Oblast. Sanctioned but not charged | July 2022 to present | Confirmed |
| AS206728 (MEDIALAND-AS) | Autonomous System, RIPE | Primary network backbone; 8 IPv4 and 2 IPv6 prefixes, 2,048 IPv4 addresses | Registered Nov 17, 2016; active | Confirmed |
Predecessor Lineage and Early History
Yalishanda's criminal activity is confirmed from approximately 2009 and assessed to extend into the late 2000s. KrebsOnSecurity first encountered the persona in 2010 in connection with "Fizot," a botnet anonymization service built on TDSS-infected Windows machines. A 2010 registration for mo0be-world[.]com tied to [email protected] and the name Aleksandr Volosovyk provided the first documented link between persona and real identity. [1]
By 2011 Yalishanda was advertising under real-hosting[.]biz. Intel 471 and Cisco researchers identified Yalishanda as a top-tier BPH provider at Black Hat 2017, noting that in a single 90-day period in 2017 the infrastructure hosted Dridex, Zeus, and multiple ransomware families. [1]
Confirmed New in v2 The indictment pushes documented Media Land operational history back to at least 2014, predating both open forum advertising under that structure and the October 2015 incorporation. It also places the company in a semi-industrial district of St. Petersburg. By August 2016 Volosovik and Zatolokin were advertising on the Dark Money forum under the pseudonym "podzemniy." [16][19][20]
Evidentiary Pillars
Confirmed Volosovik's identity as Yalishanda rests on: (1) 2010 domain registration linking [email protected] to Aleksandr Volosovyk; (2) a 2010 passport scan submitted to the ChronoPay payment processor confirming name, DOB, and birthplace; (3) Rusprofile.ru business registry listing him as director of Media Land LLC; (4) formal designation by OFAC, UK FCDO, and AU DFAT in November 2025 and by the EU in July 2026; (5) a REvil member using the handle "Unknown" addressing him by first name "Sasha" in a 2019 XSS arbitration thread; and (6) as of v2, a federal criminal indictment naming him with age and city of residence. [1][3][16]
Confirmed On 28 March 2025 an unknown actor leaked Media Land's internal database containing server configurations, client purchase history, user account data, and cryptocurrency addresses. Volosovik acknowledged the breach on a hacking forum, validating authenticity. PRODAFT, which designates the provider LARVA-34, assessed the leak as rare high-value insight into criminal infrastructure. The scale figures now alleged in the indictment (389 usernames, 5,000+ domains) are consistent with a client database of this kind. [4][5]
Yulia Vladimirovna Pankova (owner of ML.Cloud LLC; OFAC and UK-designated November 2025; indicted N.D. Ohio) is a different individual from Yuliya Vladimirovna Pankratova (leader of the Z-Pentest hacktivist group and a member of Cyber Army of Russia Reborn; EU-designated 13 July 2026, also named on the UK's 13 July list). The two names are similar, both are Russian women with the patronymic Vladimirovna, and both appear in cyber sanctions actions dated within 24 hours of each other. They are unconnected. Analysts consuming July 2026 sanctions reporting should verify which individual is referenced. [21][22]
Operator Profiles
2.1 Aleksandr Alexandrovich Volosovik: Owner and Principal Operator
| Full Name | Aleksandr Alexandrovich Volosovik (Александр Александрович Волосовик); DOJ spelling "Alexander Alexandrovich Volosovik" |
|---|---|
| Age / Date of Birth | 43 (per DOJ, July 2026); 30 January 1983 |
| Place of Birth | Brovary, Kyiv Oblast, Ukraine (confirmed via passport; family assessed to have relocated to Russia before 1990) |
| Citizenship | Russian Federation |
| Handle History | Yalishanda (primary); downlow; nishebrod; Stas_vl. EU designation additionally lists LARVA-34 |
| Education | School No. 80, Vladivostok (1990 to 2000); Far Eastern State Technical University (ДВГТУ), Institute of Mechanics, Automation and Advanced Technologies, Automated Production Systems, graduated 2005 |
| Geography | Brovary, Ukraine (birth); Vladivostok, Russia (schooling and university); Beijing, China (documented period; passport issued by Russian Embassy Beijing); St. Petersburg, Russia (current, per DOJ) |
| Role | Owner of Media Land LLC. Advertised services on criminal forums under Yalishanda; provided servers and conducted troubleshooting for ransomware and DDoS actors (OFAC) |
| Criminal Onset | Approximately 2009 confirmed; late 2000s assessed |
| Legal Status Revised in v2 | Indicted. N.D. Ohio, indictment returned 5 December 2024, unsealed 14 July 2026. Charges: conspiracy to commit and aid and abet computer fraud; conspiracy to commit wire fraud; ten counts of wire fraud; conspiracy to commit money laundering. Not in custody; assessed in Russia. Presumed innocent |
| Sanctions | OFAC (E.O. 13694 as amended), UK FCDO, AU DFAT: 19 November 2025. EU: 13 July 2026 (Council Decision (CFSP) 2026/1713) |
| Sanctioned BTC Address | 18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB |
| RFJ Exposure New in v2 | Named subject of the $10M Rewards for Justice offer for information on foreign government-linked associates and foreign government-linked use of his companies |
2.2 Yulia Vladimirovna Pankova: Owner of ML.Cloud LLC Substantially revised in v2
v1 assessed Pankova as a legal and financial associate to Volosovik, based on the OFAC designation language ("aware of Volosovik's illicit activity, has assisted Volosovik with legal issues, and has handled his finances") and her designation basis of having materially assisted him. The indictment establishes that she owned ML.Cloud LLC at the time of investigation and indictment. She is a corporate principal charged on the same counts as Volosovik, not a peripheral support figure. This is the largest single analytic correction in v2.
| Full Name | Yulia Vladimirovna Pankova |
|---|---|
| Age / Date of Birth | 29 (per DOJ, July 2026). DOB not published; derived range approximately 1996 to 1997 Analyst Inference |
| Location | St. Petersburg, Russia (per DOJ). Not in custody |
| Role | Owner of ML.Cloud LLC at the time of investigation and indictment; handled ML.Cloud's legal and financial operations. Per OFAC, also aware of Volosovik's illicit activity, assisted him with legal issues, and handled his personal finances |
| Analytic Note | Age 29 places her at approximately 18 to 19 when Media Land LLC was incorporated in October 2015 and approximately 27 at the time of the December 2024 indictment. The gap between her age and her ownership of a sister company to a long-running criminal enterprise raises an unresolved question about whether the ML.Cloud ownership is beneficial or nominal. Formal ownership is confirmed; the substance of control is not Analyst Inference |
| Relationship to Volosovik | Personal relationship confirmed via the OFAC photo release (Figure 2, sb0319) |
| Legal Status Revised in v2 | Indicted. N.D. Ohio, same counts and dates as Volosovik. Presumed innocent |
| Sanctions | OFAC, UK FCDO: 19 November 2025. Not named in the EU 13 July 2026 designation, which listed Volosovik only among the three defendants |
| Do Not Confuse With | Yuliya Vladimirovna Pankratova (Z-Pentest / CARR), EU-designated 13 July 2026. Unrelated individual |
2.3 Kirill Andreevich Zatolokin: Payments and Client Coordination
| Full Name | Kirill Andreevich Zatolokin (Кирилл Андреевич Затолокин) |
|---|---|
| Age / Date of Birth | 34 (per DOJ, July 2026); 30 April 1992 |
| Origin | Vladivostok, Russia; graduated School No. 23 (МОУ СОШ 23), Vladivostok, 2009 |
| Education | Beijing Institute of Fashion Technology, enrolled 2009; documented physically present in Beijing through at least 2014 |
| Handle | Slim Shady |
| Contact | Telegram @ohyehhellno, attributed to Zatolokin by Analyst1 from a forum screenshot showing the handle alongside the display name "Slim Shady"; observed in Yalishanda advertising from at least November 2018 |
| Known Emails | [email protected]; [email protected] (from 2013 to 2014 VKontakte job postings) |
| Operational Role | Collected customer payments and coordinated with cyber actors (OFAC and DOJ); primary customer support interface; direct liaison to BlackBasta operator "gg" per leaked chats; advertised on Dark Money forum under "podzemniy" alongside Volosovik from August 2016 |
| Current Location | St. Petersburg, Russia (per DOJ). Note: relocated from Vladivostok; v1 listed location as Russia unspecified |
| Connection to Volosovik | Both from Vladivostok; both spent time in Beijing; assessed by Analyst1 to have met in Beijing no earlier than May 2014 |
| Legal Status Revised in v2 | Indicted. N.D. Ohio, same counts and dates as Volosovik. Presumed innocent |
| Sanctions | OFAC, UK FCDO, AU DFAT: 19 November 2025 |
2.4 Andrei Valerevich Kozlov: Sanctioned, Not Indicted
| Full Name | Andrei Valerevich Kozlov |
|---|---|
| DOB / Location | Unknown; Russia assessed |
| Assessed Role | Employed by or associated with Media Land LLC; OFAC did not specify function |
| Legal Status Revised in v2 | Sanctioned by OFAC and UK FCDO on 19 November 2025. Not among the indicted defendants. No charges filed |
| Analytic Significance | Analyst Inference The indictment was returned in December 2024, eleven months before Kozlov was sanctioned, so his omission may simply reflect the charging record as it stood at that time rather than a judgment about his role. The alternative reading is that prosecutors held insufficient evidence to charge him. Either way, the three charged defendants map exactly onto the two corporate owners plus the payments lead, suggesting the charging theory is built around corporate control and money movement rather than the wider employee base |
2.5 "lapa": Infrastructure Staff, Alias Only
| Handle | lapa |
|---|---|
| Real Identity | Not published. The anonymous source behind the BlackBasta leak suggested an identity; Analyst1 declined to publish pending law enforcement confirmation |
| Role | Managed key parts of BlackBasta's infrastructure; procured SOCKS proxies layered over Media Land servers; received salary payments from BlackBasta operator gg totalling $94,000 USDT |
| USDT Address | 0xa0A7d2C6b288927cf73a5cf59970373262ea73c6, funded from 0xB54c17E5ea215f45A61E8790cf546AD175Af2Cf0 (gg) |
| Legal Status | Not sanctioned, not indicted; identity not publicly confirmed by law enforcement |
Disputed Assessments
Cl0p as a client: RESOLVED AGAINST. The indictment has now been read. It names no ransomware group at all, referring throughout to Client Conspirators 1 to 17, each using "a specific malware or ransomware variant, known to the Grand Jury." Trade reporting asserting that the indictment charges hosting for Cl0p is not supported by the document, and Cl0p appears in neither the indictment nor either DOJ press release. The claim is downgraded to Analyst Inference with no supporting primary evidence, and should not be carried into published product.
Two client conspirators are nonetheless identifiable from domain evidence in the indictment. Client Conspirator 4 established Egregorwiki.top and Wikiegregor.top (paragraph 169), pointing to Egregor. Client Conspirator 5 is associated with snatch.team through domain-expiry correspondence at paragraph 171(a) and (b), pointing to Snatch. Both are Analyst Inference drawn from the document, not government attributions, and both should be labelled as such.
Kozlov's function. Unresolved. See 2.4.
Resolved since v1. v1 flagged Pankova's and Kozlov's functional roles as an open question. Pankova's is now resolved (owner, ML.Cloud). Kozlov's remains open.
Operational and Business Model
Service Model
Confirmed Media Land and ML.Cloud sold servers, IP addresses, domains, SOCKS proxies, fast-flux DNS, and DDoS-resistant hosting to cybercriminal clients. The indictment characterises the offering as infrastructure that let clients both conduct criminal activity and evade law enforcement detection, marketed knowingly and intentionally to cybercriminals. Documented service categories include malware and ransomware delivery, victim extortion support, criminal marketplace hosting, fraudulent domain registration, and platforms for launching phishing and brute-force attacks. [16]
Two structural differentiators separate Media Land from most Russian BPH peers: owned physical data center hardware in the Russian core, marketed explicitly as superior to rented networks, and a mature fast-flux product sold as a distinct line item.
Fast-Flux Service Confirmed from indictment
Confirmed The indictment defines fast-flux as associating multiple IP addresses with a single domain and changing them rapidly, sometimes across hundreds or thousands of addresses, to keep properties reachable, hide the origin of malicious activity, and defeat ISP blocking. Media Land ran this as a distinct product on the ffv2.ru platform with an "ffpanel" web application, backed by a database of 41 tables recording registered users, domains, DNS accounts and credentials, service costs and cryptocurrency transactions. [24]
Confirmed Three separate advertisements are quoted in the indictment. Pricing is not stated as a period rate in the quoted text; the tariffs are reproduced as written. The 2016 and 2019 posts are denominated in WebMoney (WMZ), the 2018 post in dollars.
| Tier | Aug 2016, Dark Money | Dec 2018, Exploit | Jun 2019, Fog.ug |
|---|---|---|---|
| 1 domain in FastFlux panel | 70 WMZ | $150 | Not listed |
| 5 domains in FastFlux panel | 200 WMZ + free VPS | $250 | 200 WMZ + free VPS |
| 10 domains in FastFlux panel | 300 WMZ + free VPS | $350 | 300 WMZ + free VPS |
| Unlimited domains in FastFlux panel | 500 WMZ + free VPS | $500 | 500 WMZ + free VPS |
| .bit domain support add-on | Included | Free | +$100 to tariff |
Free VPS specification quoted as 2000 MHz / 1 GB / 50 GB. Correction to v1: Trade reporting gave only the $150 and $500 endpoints and described them as monthly. The ladder has four tiers, the currency differs by year, and no period is stated in the quoted advertisements.
SOCKS5 Proxy Service New in v2
Confirmed A separate product line not recorded in v2. On 12 October 2023 Yalishanda posted on Exploit.in under the topic "Socks5/https proxy service for brute force and various checkers, also ipv6 with open port 25," edited 23 March 2024, and reposted the same advertisement to XSS.IS on 13 November 2023. Two tariffs: 5,000 US and EU IPs with unlimited threads at $200, and several billion IPv6 addresses with open port 25, accessed via IPv4, at $500. The advertisement states the pool is refreshed daily and that the proxies suit brute-force and checker workloads. Open port 25 across a very large IPv6 pool is a direct spam-delivery capability. [24]
Fast-Flux Panel Feature Set New in v2
The December 2018 advertisement describes a custom proxy layer written in-house, replacing nginx and haproxy, deployed inside an encrypted container on the node. Per the copy, the container is accessible only until the first reboot, after which "access to it is lost even from us," a design explicitly marketed as preventing data center administrators from reading the config or determining the client's real backend IP. It also claims the proxy generates decoy connections to unrelated addresses using the same packet sizes as the real backend to frustrate traffic analysis, uses only KVM and XEN virtualisation, allocates each client a non-overlapping IP pool, and runs an automated checker that swaps NS servers within a minute of a domain being blocked. Three domain registrars are offered, described in the advertisement as being in Europe, China and Malaysia, which the seller characterises as "loyal" rather than bulletproof.
Verbatim Advertising and Operator Communications
Language and Supplier Reach New in v2
Confirmed The December 2018 Exploit advertisement lists support and billing channels in three languages: Jabber: billing2 (RU/ENG/CH), Jabber: Support (RU/ENG/CH), and a Telegram support and billing channel also marked RU/ENG/CH. Chinese-language customer support was a standing offering, not an ad hoc accommodation, which implies a Chinese-speaking client segment of some size. [24]
Confirmed The WhatsApp traffic between the principals records recurring procurement of Chinese proxy infrastructure and recurring problems with it. On 26 August 2017: "I have used some of that money to pay the Chinese on Yandex. You can see one of ours is dead. I can buy more, but you need to order socks." On 2 September 2017: "We had experienced that before with the Chinese. It's probably an account that was banned, so money cannot be added to it." On 9 September 2018: "Try a Chinese one, but you have to make sure he can open his ports," followed by "No, ports are closed. These Chinese proxies only have ports 80 and 443 open." [24]
Onboarding and Client Tiers
Forum advertising on Exploit[.]in, XSS[.]pro, Dark Money and predecessor platforms was the primary acquisition channel. Support ran through Telegram (@ohyehhellno) and Jabber, both listed consistently in advertising. No invitation-only or referral gate is documented.
A two-tier client structure is evident from leak data. Standard clients self-served through forum-advertised support channels. VIP clients such as BlackBasta held direct relationships with Zatolokin for custom deployments, bandwidth negotiation, and capacity planning, with access to owned data center hardware. [3]
Confirmed New in v2 Indictment-derived scale figures: approximately 389 usernames and more than 5,000 registered domains in the client database. Against 17 or more criminal groups served, this implies most usernames were individual criminal customers rather than group accounts, and that domain provisioning ran at roughly 13 domains per username. [19][20]
Abuse-Handling and Law Enforcement Posture
Confirmed Total non-cooperation was the advertised and practised posture. Forum advertising explicitly named Spamhaus as ignored. The indictment alleges the defendants repeatedly ignored or falsified abuse reports and rotated infrastructure to stay ahead of takedowns. The falsification allegation is new in v2 and is materially more serious than passive non-response: it implies active deception of upstream providers and registrars, which is also what makes the multi-jurisdictional footprint sustainable. [16]
Confirmed New in v2 The indictment specifies the mechanism. Abuse reports, intrusion alerts and anti-virus output were deliberately funnelled into operator-controlled mailboxes designed to look independent: [email protected], [email protected], [email protected] and [email protected]. Rather than suspending offending domains or accounts, the operators sent false replies, ignored reports, or offered the complaining client fast-flux to defeat the detection that had generated the report. Paragraph 123 lists four services sold on this basis: fraudulent abuse-report responses, rapid IP rotation, domain registration through the front company with added privacy services, and other protections shielding clients during intrusions and exfiltration.
Spamhaus had identified the platform early. On 12 November 2014 a forwarded Spamhaus notice reached [email protected] stating that s777shop.ru and ffv2.ru were "operated by cybercriminals and used to control infected computers (bots) using a so called botnet controller," and requesting suspension. The domain was blocked and Volosovik contested the block with the registrar two days later. The platform continued operating for another decade.
The only documented instance of customer dispute resolution across 15+ years is the August 2020 arbitration in which Yalishanda refunded $222.89 to a user called Loadbaks with a bare transaction hash and no acknowledgment.
OPSEC Posture
Volosovik registered Media Land LLC as a legitimate Russian entity to obtain commercial legitimacy, enabling contracts, IP leasing, and staff employment. His VKontakte and Odnoklassniki profiles used partial real-name attribution, indicating confidence in the Russian operating environment rather than technical OPSEC discipline. The sealing of the indictment for more than nineteen months suggests investigators judged that continued collection outweighed the deterrent value of early disclosure.
Confirmed The indictment records several. On 6 September 2018, seeking to have ffpanel.ru unblocked, Volosovik emailed the registrar from [email protected] and attached a scanned copy of his own passport (paragraph 205(f)). Domain sshvps.net was registered on 24 September 2015 with Volosovik's own name as Administrator, his telephone number 79811263828, his email [email protected], and Media Land named as Administrator Organization (paragraph 204). Both principals' iCloud accounts, tied to their real mobile numbers, retained screenshots of the ffv2.ru administrator panel showing client usernames with associated domains and IP resolutions (paragraphs 190 to 195). Operational coordination ran over WhatsApp tied to those same numbers from at least January 2017 (paragraph 196).
The 2018 advertisement markets an encrypted proxy container that even the operators cannot reach after reboot, and the same operator sent a registrar his passport. The technical tradecraft sold to clients was materially better than the administrative tradecraft the principals applied to themselves, and it is the administrative trail that produced the charging document.
Technical Capabilities and Infrastructure Footprint
Autonomous Systems Corrected from indictment
v1 listed AS211805 as the secondary ASN, sourced from IPinfo. The indictment states at paragraph 5 that Media Land and ML.Cloud "controlled two Autonomous System Numbering (ASN) blocks of IP addresses, ASN blocks 206728 and 215376, to host client services," and at paragraph 6 that since at least around June 2024 they controlled these two blocks "on hardware physically located in Russia and the Netherlands, respectively." AS215376 is the ML.Cloud Netherlands ASN. Paragraph 163 records both AS206728 and AS215376 addresses being used together to support the 24 October 2024 brute-force attack on Victim 44. [24]
| ASN | Name | RIR | Country | Registered | Status |
|---|---|---|---|---|---|
AS206728 | MEDIALAND-AS | RIPE | Russian Federation | 2016-11-17 | Active |
AS215376 | ML.Cloud | RIPE | Hardware in Netherlands | Unknown | Named in indictment |
Multi-Jurisdictional Infrastructure Footprint Corrected in v2
v1 stated that there was "no confirmed infrastructure in non-Russian jurisdictions." The DOJ indictment establishes that Media Land operated physical infrastructure in Finland, the Netherlands, and the United States in addition to Russia. DOJ attributes the seven-year investigative timeline and the necessity of Dutch law enforcement participation directly to this multi-jurisdictional footprint. This is the most operationally consequential correction in v2, because infrastructure inside Finland, the Netherlands, and the United States is reachable by Western legal process in a way that the St. Petersburg and Kirishi estate is not. [16][17]
| Jurisdiction | Role | Western Legal Reach | Confidence |
|---|---|---|---|
| Russia (St. Petersburg) | Primary operational base; entity registration; assessed operator residence | None | Confirmed |
| Russia (Kirishi, Leningrad Oblast) | Owned physical data center via DC Kirishi subsidiary; own hardware | None | Confirmed |
| Netherlands | AS215376 (ML.Cloud) hardware physically located in the Netherlands as of about June 2024. Dutch National Police and Public Prosecutor's Office provided material investigative assistance | Direct | Confirmed |
| Finland | FFPANEL.TOP resolved to 65.108.65.82, described in the indictment as "previously located in Finland" | Direct (EU member state) | Confirmed |
| United States | ffv2.ru fast-flux server at ISP1, physically in New Jersey, until 23 June 2024. ISP2 also US-based, supplying VPN services. Over $23,000 paid to ISP1 | Direct | Confirmed |
China Nexus: Supplier and Market, Not Hosting New in v2
The DOJ press release states that Media Land's infrastructure "also operated out of multiple countries including China, Finland, the Netherlands, and the United States." Chinese hosting of Media Land infrastructure is not corroborated anywhere in the reviewed portion of the charging document, which covers the general allegations, the full infrastructure section and all of Count 1. Every named server, IP and domain in that portion resolves to Russia, the United States, the Netherlands or Finland. China is therefore not carried in this profile as an infrastructure hosting jurisdiction. The full document has now been read and China is not alleged as a hosting jurisdiction anywhere in it, including across Counts 2 to 13, the sentencing enhancement and the forfeiture allegation. The claim rests on the press release alone.
What the document does evidence is a China relationship of a different character, on the supplier and market side rather than the hosting side. That is set out below and is analytically more useful than the press release formulation.
| Element | Evidence | Confidence |
|---|---|---|
| Chinese domain registrar in the product | The December 2018 Exploit advertisement offers clients three registrars, "Europe, China and Malaysia," described by the seller as "loyal." Domain registration through these registrars was a sold service with bulk registration and a random name generator | Confirmed |
| Chinese proxy procurement | WhatsApp traffic 2017 to 2018 records repeated purchase of Chinese proxies, payment "to the Chinese on Yandex," banned supplier accounts, and a recurring technical limitation that Chinese proxies had only ports 80 and 443 open | Confirmed |
| Chinese-language commercial support | Jabber and Telegram support and billing channels advertised as RU/ENG/CH in the December 2018 Exploit post | Confirmed |
| Operator ties to China | Volosovik resided in Beijing before Vladivostok and St. Petersburg; his travel passport was issued by the Russian Embassy in Beijing. Zatolokin enrolled at the Beijing Institute of Fashion Technology in 2009 and was documented in Beijing through at least 2014. The Yalishanda moniker is Mandarin for "Alexander" | Confirmed |
| Media Land infrastructure physically hosted in China | Asserted in the DOJ press release. Not corroborated in the reviewed portion of the indictment | Credible, uncorroborated |
Analyst Inference The documented pattern is a provider that bought Chinese proxy capacity, resold Chinese domain registration, and marketed in Chinese, run by two principals with years of personal residence in Beijing. That is a supplier and customer-base relationship, not an infrastructure footprint. The most economical explanation for the press release wording is that it generalises from these relationships rather than describing servers in China. Analysts should not carry "Media Land hosted infrastructure in China" forward without reading Counts 2 to 4 or obtaining separate technical corroboration.
IPv4 Prefix Table (AS206728)
| Prefix | Registered Description | RPKI | IRR |
|---|---|---|---|
45.141.84.0/24 | ML CLOUD LLC | Valid | Valid |
45.141.85.0/24 | Media Land LLC | Valid | Valid |
45.141.86.0/24 | ML CLOUD LLC | Valid | Valid |
45.141.87.0/24 | Grisha Maslinikov | Valid | Valid |
91.220.163.0/24 | Media Land LLC | Valid | Valid |
193.242.153.0/24 | IT Outsourcing LLC | No ROA | Valid |
194.26.29.0/24 | Media Land LLC | Valid | Valid |
194.26.69.0/24 | Media Land LLC | Valid | Valid |
Note: 45.141.87.0/24 is the prefix containing IP 45.141.87.127, cited in Zatolokin's speed-test message to BlackBasta. It is registered to an individual name (Grisha Maslinikov) rather than a corporate entity, and 193.242.153.0/24 is registered to IT Outsourcing LLC and lacks a ROA. Both are candidate nominee registrations worth further examination.
IPv6 Prefixes (AS206728)
| Prefix | Registered Description | RPKI |
|---|---|---|
2a0b:7ec0:1320::/48 | Media Land LLC | Valid |
2a0b:7ec0:7701::/48 | Media Land LLC | Valid |
Named Infrastructure Estate New in v2
Confirmed The indictment names the criminal-side infrastructure directly, which the press release did not. This is the operational core of the BPH service, run on servers deliberately separated from the public-facing ML.Cloud estate.
| Asset | Role | Location and IP history |
|---|---|---|
ffv2.ru | Primary fast-flux platform and "ffpanel" admin application; backend database of 41 tables; hosted the carding marketplace DNS zone entries | IP 104.194.11.236 at ISP1, physically in New Jersey, United States, from at least 21 May 2020 until 23 June 2024. Migrated 24 June 2024 to Russian IP 45.141.85.184 inside AS206728, abuse contact [email protected] |
ffpanel.top | Fast-flux panel infrastructure | Resolved to 65.108.65.82, previously located in Finland |
ffpanel.ru | Fast-flux panel; also served as RedAlert command-and-control | C2 IP 8.208.10.54; separately reported at 47.254.171.103; blocked by registrar Sept 2018 |
sshvps.net | Abuse-handling front; registered 24 Sept 2015 with Volosovik named as Administrator and Media Land as Administrator Organization | Mail infrastructure: abuse@, alex@, zakaz@, domaine@, 18394_alex@ |
abushost.ru | Long-running brand domain and Jabber host; linked to [email protected] from 17 March 2014 | Registered 10 Jan 2015 via [email protected] |
s777shop.ru | Named by Spamhaus alongside ffv2.ru as a botnet controller, Nov 2014 | Not further described in the read portion |
Post-Indictment Domain and IP Sweep, 27 July 2026 New v2.2
All 56 domains named in the paragraph 253 enhancement were checked against RDAP registration data and live DNS, and the resolved addresses were traced back to their announcing networks. Method: RDAP for registration state, DNS-over-HTTPS for current resolution, RIPE and Hurricane Electric for prefix attribution. Analyst Inference throughout on questions of who controls what, since registration records for these domains are privacy-shielded and .ru carries no public RDAP.
Confirmed sshvps.net, the abuse-handling front that Volosovik registered in his own name with Media Land as Administrator Organization, still resolves to 45.141.85.101. That address sits inside 45.141.85.0/24, announced by AS206728 and registered to Media Land LLC. The same address carries the PTR ml.cloud and also serves medialand.pro. A second host, 45.141.85.50, has PTR ns1.ml.cloud and serves ns1.medialand.pro, ns1.ml.cloud and ns1.sshvps.net.
medialand.pro is not named in the indictment, nor in any sanctions listing or vendor reporting reviewed for this profile. It is a new indicator. The self-referential naming and the shared nameserver set place it firmly in the same estate.
The RIPE route object for 45.141.85.0/24 was last modified 24 November 2025, five days after the trilateral sanctions. Someone was administering this prefix after designation.
Confirmed ffv2.ru currently resolves to 144.31.255.18, PTR vm1112055.hosted-by.u1host.com. The prefix 144.31.255.0/24 is announced by AS213877, U1 DIGITAL SERVICES LTD, registrant u1host ltd, maintainer u1host-mnt, sited in Frankfurt. Its RIPE route object was created 15 December 2025, roughly a month after the sanctions.
Movement history for this one domain now reads: New Jersey at 104.194.11.236 until 23 June 2024, then Russia at 45.141.85.184, and now Germany at 144.31.255.18.
Analyst Inference Treat with care. The u1host range is a commodity VPS estate of roughly 196 hosts with generic vmNNNNNN PTRs, so presence there is cheap and proves little on its own. Three readings are open and the evidence does not separate them: the operators re-pointed the domain to disposable hosting after designation; the domain lapsed and was re-registered by an unrelated party; or it is parked. .ru publishes no RDAP, so registration date and registrant cannot be checked. What can be said is that a domain central to ten wire fraud counts is live on a European prefix created after the sanctions, and that is worth a vendor with passive DNS history resolving properly.
Confirmed Of 47 gTLD domains checked by RDAP, 42 are no longer registered, including both operator-derived names (volosovichkov.info, volosovichkov-taxi.info), the platform bot domain ffv2panelbot.info, cardhouse.info, and every brand-impersonation domain. Only two are registered, and both look like ordinary drop-catch by unrelated parties rather than continuity: s3dns.com re-registered 8 November 2025 through Cloudflare and parked on IONOS in Berlin, and publicdns.info re-registered 6 January 2026 through NameCheap, resolving to OVH in France on nameservers at upstelecom.com. Neither has any observable tie to Media Land.
Analyst Inference The pattern is consistent with a burned estate. These were disposable domains for a fast-flux product, and once the product was charged there was no reason to renew them. It also means the enhancement list is largely of historical value for pivoting, not a live target set. The exception is the small live cluster in Finding A.
Confirmed 45.141.85.173, in the same Media Land prefix, currently serves treueprogramm-magentamoments-bestandskunden.com. The name is a German-language lure impersonating Deutsche Telekom's MagentaMoments customer loyalty programme. Also on the prefix: nameservers for cherrymail.net, and a cluster of algorithmically-styled .ru names (alendelm.ru, werbongo.ru, wertengo.ru, akeqant.ru, belpvale.ru, percevogen.ru, frencowep.ru, frolovale.ru, arturowen.ru, rolexform.ru) consistent with the bulk registration and random name generator advertised in the December 2018 Exploit post.
This is criminal hosting continuing in designated address space, which bears directly on the Section 10 trajectory assessment.
Confirmed RDAP returns Grisha Maslinikov as the organisation contact on 45.141.85.0/24, and Hurricane Electric records the same name as the registrant of 45.141.87.0/24. Both are Media Land prefixes under AS206728, and 45.141.87.0/24 contains the IP Zatolokin used in his speed-test message to BlackBasta.
Analyst Inference Maslinikov appears in no sanctions listing and no count of the indictment. He may be a nominee, an administrative contact, or a real staff member. Either way a name attached to two prefixes of a designated bulletproof host, absent from every enforcement action, is an unexploited lead and the most promising single thread this sweep produced.
Falsely Registered Domains (18 U.S.C. 3559(g)(1)) New v2.1
Confirmed Paragraph 253 of the indictment enumerates roughly 56 domains that Volosovik and Zatolokin registered with false names and addresses and used in furtherance of Counts 1 to 13. This list appears in no press release and is the single largest set of new indicators the document provides. Grouped below by evident function.
| Cluster | Domains | Analytic note |
|---|---|---|
| Operator-derived | volosovichkov.info volosovichkov-taxi.info | Both derive from Volosovik's own surname. Registering criminal infrastructure under a name-derived domain is a significant attribution handle and a further OPSEC failure alongside the passport disclosure |
| Fast-flux platform | ffv2panelbot.info | Ties directly to the ffv2.ru fast-flux panel and its Telegram or Jabber bot |
| DNS-themed infrastructure | vesperdns.info dndpark.info dnsmhere.ru newserversdns222.info dnsmherell.info pspark.info mydnshelpers.info mydnsserver.info unitednstools.info chernobyldns.info s3dns.com lambdadns.com besdns.ru cptdns.info publicdns.ru publicdns.info domain4dns.info fifdns.info proxy-dns1.ru proxy-dns2.ru boxodns.info rocodns.info cntdnsnet.info setdnsnet.info dnspods.ru dmsmanagercu.info | The bulk of the estate. Consistent with the fast-flux product, which required large pools of disposable NS and resolver domains that could be rotated when blacklisted |
| Brand impersonation | protonomail.info protonommail.info amazkonto.info amazondeutschland.info microsoft-windows-defender-update.ru googleu.ru googleup.ru googleclouddns.com mobirevolutconfirmation.com | Typosquats and lookalikes for ProtonMail, Amazon (including a German-market variant), Microsoft Defender, Google Cloud DNS and Revolut. Phishing and credential-harvesting oriented rather than DNS plumbing |
| Financial and marketplace | xmrdealshere.ru wedoaccounting.ru cardhouse.info | xmrdealshere.ru points at Monero dealing and is the only overt crypto-trading domain in the set. cardhouse.info corresponds to the Cardhouse carding marketplace named separately at paragraph 207 |
| Hosting and misc | vhost-vps.ru carshomce.info nicedomainname.info jackladamada.info jackladamadab.info targetpost.info greatdor.info greatdor.ru fatraf.info lincomap.ru min0taur.ru vipedron.ru dsfgghgsfadfgh.info fablirsgd.ru sdfsdfsdfsdfdsfsdf.ru 54bb47h.ru | Mixed. Several are keyboard-mash throwaways consistent with the bulk registration and random name generator advertised in the December 2018 Exploit post |
Analyst Inference Two operational reads. First, the heavy .info and .ru concentration is consistent with the advertised "Europe, China and Malaysia" registrar set, which the seller described as loyal rather than bulletproof. Second, the presence of brand-impersonation domains alongside DNS plumbing in the same charged set indicates Media Land was registering phishing domains for clients as a service, not merely hosting infrastructure that clients populated themselves. That is a more active role than the hosting-only framing in the press releases.
Third-Party Providers New in v2
| Entity | Description | Financial detail |
|---|---|---|
| ISP1 | US-based ISP, outside the Northern District of Ohio, location known to the Grand Jury. Hosted the ffv2.ru fast-flux server | Approximately $2,100 paid to lease ffv2.ru server space, 21 May 2020 to 23 June 2024. Over $23,000 total to ISP1 for multiple servers over the same period. Volosovik used client number 18394 |
| ISP2 | US-based ISP, outside the Northern District of Ohio. Supplied VPN services and other infrastructure | Account established 21 May 2020 by Zatolokin using [email protected] |
Analyst Inference Both ISPs are US entities that were, on the government's account, taking payment from Media Land for years. Neither is charged. That the fast-flux platform central to the whole scheme sat on a leased server in New Jersey until June 2024 is the single most consequential fact in the document for disruption purposes, and it is also the most likely explanation for the seven-year investigative timeline: US-hosted infrastructure is reachable by subpoena and search warrant in a way the Russian estate is not.
Upstream Transit Chain
| Peer ASN | Entity | Country | Role |
|---|---|---|---|
AS49531 | NetCom-R LLC | Russian Federation | IPv4 and IPv6 upstream peer |
AS20632 | PJSC MegaFon | Russian Federation | IPv4 upstream peer; major Russian carrier |
AS202799 | SYSECT D.O.O. | Montenegro | IPv4 upstream peer; only non-Russian peer |
AS51538 | Lavrentyev Aleksandr Arkadievich | Russian Federation | IPv4 upstream peer; individual registrant |
AS3216 (historical) | Vimpelcom / Beeline | Russian Federation | Historical transit per RIPE IRR import/export records |
AS9049 (historical) | ERTH Corporation JSC | Russian Federation | Historical transit per RIPE IRR import/export records |
De-peering events: Confirmed No documented upstream de-peering events for AS206728 in open sources, including in the period following the November 2025 sanctions and the July 2026 indictment and EU designation. All four observed peers remained in place across the latest BGP snapshot. Unlike PROSPERO (AS200593, Bearhost), which drew public scrutiny over a Kaspersky Lab upstream relationship in 2025, no equivalent upstream controversy has been reported for MEDIALAND-AS. The absence of de-peering after four-jurisdiction sanctions and a US indictment is itself a finding: the Russian upstream chain is not responsive to Western designation, and SYSECT D.O.O. in Montenegro is the only peer plausibly subject to European pressure.
Physical Infrastructure and Capacity
Confirmed Data Center Kirishi, a wholly owned subsidiary registered July 2022 in Kirishi, Leningrad Oblast, represents owned physical data center capacity with own hardware, confirmed by Zatolokin directly to a client. This differentiates Media Land from BPH operators that lease all upstream capacity. Documented capacity from the BlackBasta negotiation: standard plan of 20 Gbps per 100 servers, with the client's approximately 200-server deployment consuming 17 to 20 Gbps and a proposed scale to 50 Gbps. [3]
Hosted Activity Types
- Malware command-and-control servers
- Fast-flux DNS evasion infrastructure New in v2
- Code-signing infrastructure
- Phishing kit hosting and phishing launch platforms
- Brute-force attack launch platforms New in v2
- Data exfiltration panels
- Ransomware operational platforms and victim extortion support
- Data leak site hosting
- Criminal marketplace hosting, including eight named carding markets New in v2
- Fraudulent domain registration New in v2
- DDoS botnet infrastructure, including attacks on US critical infrastructure and telecommunications
- SOCKS proxy networks layered over Media Land servers
- Android banking trojan infrastructure (Ermac, RedAlert) New in v2
Blocklist Standing
| List | Status | Evidence |
|---|---|---|
| Spamhaus SBL | Listed (confirmed) | SBL and CBL listings documented by researchers in the 2019 KrebsOnSecurity article comments; advertising explicitly claims to ignore Spamhaus, confirming an ongoing listing relationship |
| Spamhaus CBL | Listed (confirmed) | Confirmed via 2019 KrebsOnSecurity community analysis of the IP ranges |
| Spamhaus DROP / EDROP | Probable | EDROP covers cybercriminal-controlled IP space. Four-jurisdiction sanctions and a US indictment make listing highly likely, but no direct current entry confirmation was obtained |
| abuse.ch Feodo Tracker | Probable | Confirmed C2 hosting in the IP ranges; specific entry IDs not confirmed |
| abuse.ch URLhaus | Probable | Phishing and malware URL hosting documented by PRODAFT and DOJ; entry-level confirmation not obtained |
| abuse.ch MalwareBazaar | Unknown | No direct confirmation in open sources |
| Firehol | Probable | No direct confirmation; aggregate list behaviour and SBL/CBL status strongly suggest inclusion |
Known Weaknesses
Revised in v2. The correction to the infrastructure jurisdiction picture changes the weakness profile substantially.
- Western-jurisdiction infrastructure. Physical infrastructure in the Netherlands, Finland, and the United States is directly reachable by Western legal process. This is the single most actionable weakness identified in this profile and did not appear in v1. Dutch authorities have demonstrated both capability and willingness in this space, seizing 800 servers from Stark Industries in May 2026
- Infrastructure concentration. All announced prefixes sit under a single ASN, making AS-level blocking straightforward for defenders
- Thin peering. Four observed upstream peers provide limited routing redundancy
- Fixed owned hardware. DC Kirishi is a locatable, immovable choke point, subject in principle to Russian domestic action that has not materialised
- Financial exposure. Four-jurisdiction sanctions plus an SDN-listed Bitcoin address restrict compliant exchange access; clients face secondary sanctions exposure
- Insider risk. The $10M Rewards for Justice offer, published in Russian as well as English, is an explicit attempt to induce defection from within the operation or its periphery. The provider has already suffered one insider or adversary leak in March 2025
- Nominee registrations. Two prefixes registered to a named individual and to an unrelated LLC, one lacking a ROA, are potential attribution and enforcement handles
Financial Infrastructure
Payment Methods
Confirmed Cryptocurrency-only payment. Bitcoin and USDT (ERC-20) are documented in leak, sanctions, and indictment material. The indictment alleges the defendants accepted cryptocurrency specifically to protect client identities. No fiat payment channel is documented. [3][7][16]
Known Wallet Clusters
| Address | Currency | Attribution | Source |
|---|---|---|---|
18dLDAWi8LmrHbEq3QzDJb9SLxCf4uimXB | Bitcoin | Aleksandr Volosovik / Media Land LLC; OFAC SDN-listed | OFAC, 19 Nov 2025 [7] |
1PY4JX82rhKTSyP7ywhJgiYeVvTcpcaW8d | Bitcoin | Yalishanda refund address from the August 2020 forum arbitration | Analyst1 [3] |
0xa0A7d2C6b288927cf73a5cf59970373262ea73c6 | USDT (ERC-20) | "lapa," Media Land infrastructure staffer; received $94,000 in salary from BlackBasta | Analyst1 / Arkham [3] |
0xB54c17E5ea215f45A61E8790cf546AD175Af2Cf0 | USDT (ERC-20) | BlackBasta operator "gg"; sending wallet for lapa salary payments | Analyst1 [3] |
| Cluster: "Yalishanda - bulletproof hoster" New in v2 | Bitcoin | Named attribution cluster used by the government; received 0.23 BTC ($4,665) from Client Conspirator 5, 5 Sept 2022 | Indictment para 212 [24] |
Wallet registered to [email protected] New in v2 | Bitcoin | Received a share of funds traced to the Victim 2 ransomware extortion, 21 Oct 2021 | Indictment para 208 [24] |
lapa Salary Payments (BlackBasta to Media Land Infrastructure Staff)
| Transaction Hash | Amount | Date |
|---|---|---|
0xb77e237067282cb497cc5246c3c047ce36de2c2d6a3a15e395808a696a84cb34 | $20,000 USDT | 13 February 2024 |
0x321dc9d6d2110a47ce9000d9e0fc983987fe59a318d5d889623ed08e1c0f42e2 | $23,000 USDT | 23 February 2024 |
0x792f1533ba55c3059520ba39e29e9b1b0e8f43da3a7208b417b1d443959ec0a9 | $15,000 USDT | 7 March 2024 |
0x1988652a17c8cd3f5f7a14d83cf6162c0943bf9b9cd96d4756d5f7c52214a1ff | $25,000 USDT | 27 March 2024 |
0xa5eca747fdc92a81693d166e24c942501c581be063e858620891c9b709acb36a | $11,000 USDT | 30 May 2024 |
Total $94,000 USDT. Two additional BTC transactions on 1 April 2024 (0.01163 BTC and 0.01019 BTC, approximately $829 and $727) were paid by gg to lapa-supplied addresses for SOCKS proxy procurement. Source: Analyst1 / Arkham. [3]
On-Chain Volume
Confirmed TRM Labs documented more than $2 million in received volume across wallets linked to Yalishanda and Abushost, with direct and indirect flow intersections across BlackSuit, BlackBasta, LockBit, and MedusaLocker. [10]
Confirmed Chainalysis assessed Volosovik's services as supporting "nearly every component of the cyber kill chain," monitoring thousands of addresses and millions of dollars in transactions across underground exchanges, laundering services, scammers, hackers, and ransomware operators including sanctioned LockBit administrator Dmitry Khoroshev. [6]
New in v2 The DOJ figure of $62 million is a victim loss total across 42 named US organizations, not provider revenue. It should not be reconciled against the TRM $2M received-volume figure, which measures funds reaching identified Yalishanda-linked wallets. The two metrics measure different things and both are consistent: a BPH provider captures a small fraction of the downstream criminal proceeds its infrastructure enables.
Three-Phase Laundering Model
Phase 1, receipt. Ransomware payments reach client groups in Bitcoin. Media Land receives hosting fees in BTC or USDT, with fast-flux and bandwidth billed as recurring monthly subscriptions.
Phase 2, conversion. BlackBasta operator gg stated in leaked chats that funds paid to lapa for SOCKS procurement and salary came from money already "cleaned" by an internal laundering operation. USDT was used for stable-value salary payments post-laundering. TRM identifies flows to intermediary wallets and major global exchanges.
Phase 3, cash-out. Funds move through no-KYC exchanges and OTC desks consistent with Russian cybercrime cash-out patterns. Specific venues for Media Land and Volosovik remain unidentified in open sources, in contrast to ZServers where Garantex is confirmed. This remains an intelligence gap.
Confirmed Count 13 charges conspiracy to commit money laundering under 18 U.S.C. 1956(h), running from 14 June 2016 to the date of the indictment. The specified unlawful activities are wire fraud (1343) and fraudulent access to computers (1030). Three distinct objects are charged:
- Concealment laundering, 1956(a)(1)(B)(i). Financial transactions involving criminal proceeds, designed to conceal the nature, location, source, ownership and control of those proceeds.
- International transmission, 1956(a)(2)(B)(i). Transporting, transmitting or transferring funds from a place in the United States to and through a place outside the United States, knowing the transfer was designed to conceal. This is the object that gives the New Jersey server its second significance: it is not only where the fast-flux platform sat, it is the US nexus that makes the outbound transfer chargeable.
- Monetary transactions over $10,000, 1957. Engaging in monetary transactions in criminally derived property worth more than $10,000, through a financial institution and affecting interstate and foreign commerce.
Confirmed The mechanism alleged at paragraphs 249 to 251: the defendants and their client conspirators directed ransomware victims to pay into anonymous cryptocurrency accounts provided and controlled by them; they maintained infrastructure in the United States and abroad that concealed the nature, location, source, ownership and control of funds moving from victims in the Northern District of Ohio and elsewhere; and client conspirators sent proceeds exceeding $10,000 to cryptocurrency accounts controlled by Volosovik and Zatolokin, "either through ACH, wire transfer, or other electronic fund transfers."
Analyst Inference The reference to ACH and wire transfer is the most significant single line for financial-leverage purposes. It indicates the government is not treating this as a purely on-chain flow: at least some proceeds moved over conventional banking rails, which means regulated intermediaries touched them and records exist. That is a materially better disruption surface than a crypto-only chain.
Still open. No exchange, OTC desk or money services business is named anywhere in the document, and the forfeiture paragraph itemises no specific wallets or sums. The cash-out venue gap is narrowed but not closed: the mechanism is now documented, the endpoints are not.
Sanctions and Regulatory Risk
| Authority | Date | Targets | Instrument |
|---|---|---|---|
| OFAC (United States) | 19 Nov 2025 | Media Land LLC, ML Cloud, Media Land Technology, Data Center Kirishi; Volosovik, Zatolokin, Pankova, Kozlov; Volosovik BTC address | E.O. 13694 as amended by E.O. 13757, 14144, 14306 |
| UK FCDO | 19 Nov 2025 | Joined the OFAC action in full | UK cyber sanctions regime |
| AU DFAT | 19 to 20 Nov 2025 | Joined in part: Media Land LLC, ML.Cloud, Volosovik, Zatolokin | Australian autonomous sanctions |
| European Union New in v2 | 13 Jul 2026 | Media Land LLC, ML.Cloud, Volosovik | Council Decision (CFSP) 2026/1713; Implementing Regulation (EU) 2026/1714 |
EU measures impose an asset freeze, prohibit EU citizens and companies from making funds or economic resources available, and add a travel ban barring entry to or transit through EU territory for designated natural persons. The travel ban is a distinct instrument from the US and UK measures and narrows the set of countries the principals can transit, which matters given that arrests of Russian cybercrime suspects have historically occurred during travel. [21]
Client Profile and Hosted Operations
The indictment names no ransomware group. All clients appear as Client Conspirator 1 through Client Conspirator 17, each using "a specific malware or ransomware variant, known to the Grand Jury." Group names in the table below derive from the DOJ press release and the OFAC designation, not from the charging document. Trade reporting stating that the indictment charges hosting for LockBit, Cl0p and Play misreads the document. The entities the indictment does name are the eight carding marketplaces, two Android banking trojans, and one marketplace client relationship, all tabulated separately below.
Client Conspirator Schedule (as charged) New in v2
Confirmed Seventeen client conspirators, sixteen described as groups conducting ransomware and extortion, one (CC17) conducting brute-force attacks and unknown to the Grand Jury. Fast-flux accounts on ffv2.ru are attributed to CC1, CC3 to CC8, and CC14.
| Client | Service provided | Victims charged | Identification |
|---|---|---|---|
| CC1 | Fast-flux hosting for leak sites and communication platforms, from 24 Feb 2021; false domain registration | Victims 15 to 24 (10 overt acts) | Not identified |
| CC2 | Domains on ffv2.ru; ransom payments sent to Volosovik-controlled wallets | Victim 2 (Canada) | Not identified |
| CC3 | Over 250 domains hosted; account email [email protected] | Victims 30 to 39 (10 overt acts) | Not identified |
| CC4 | BPH for domains Egregorwiki.top and Wikiegregor.top established on ffv2.ru, 20 Sept 2020 | Victim 3 (2 overt acts) | Analyst Inference Egregor, from domain naming |
| CC5 | Domains on ffv2.ru from 28 June 2017; domain-expiry correspondence for snatch.team; paid 0.23 BTC for Victim 7 attack infrastructure | Victims 4 to 9 (8 overt acts) | Analyst Inference Snatch, from domain naming |
| CC6 | Domains on ffv2.ru, 24 Feb 2021 to 1 July 2023 | Victims 10, 11, 12 | Not identified |
| CC7 | Domains on ffv2.ru | Victim 1 (Newton, MA municipality) | Not identified |
| CC8 | False domain registration, Media Land IPs, ffv2.ru hosting | Victims 13, 14 | Not identified |
| CC9 to CC16 | False domain registration and Media Land IP use during malware and ransomware attacks | Victims 25 to 29, 40 to 43 | Not identified |
| CC17 | Brute-force attacks using both Media Land (AS206728) and ML.Cloud (AS215376) IPs, 24 Oct 2024 | Victim 44 | Unknown to the Grand Jury |
Criminal Marketplaces Named in the Indictment Confirmed from indictment
Confirmed Paragraph 207 tabulates eight marketplaces and forums hosted on the ffv2.ru server as of 6 March 2023, each hosting representing a separate overt act. This upgrades the v2 CREDIBLE label to CONFIRMED and supplies the domains, which the press release lacked.
| Marketplace / Forum | Domains hosted on Media Land infrastructure | Description (per indictment) |
|---|---|---|
| Briansclub | Briansclub.cm, Brianscrabs.de | Carding marketplace to sell and buy stolen credit card data. Serviced from 21 May 2020 until at least 16 April 2024 |
| Cardhouse | Cardhouse.cc | Re-seller on the Bypass Market, a darknet marketplace selling stolen credit card information |
| crdclub | Crdclub.su | Forum to advertise stolen credit cards |
| Club2crd | Club2crd.cc | Russian language carding forum |
| Verified | Verified.mn | Darkweb criminal forum |
| Fullzinfo | Fullzinfo.com | Selling PII, credit card and financial account information |
| Swipestore | Swipestore.cc | Carding marketplace to sell and buy stolen credit card data |
| Bidencash | Bidencash.link, Bidencash.rip | Carding marketplace to sell and buy stolen credit card data |
Malware Families Named in the Indictment Confirmed from indictment
| Family | Evidence in the document | Media Land IPs |
|---|---|---|
| RedAlert (Trojan-Banker.AndroidOS.RedAlert 2.0) | Abuse reports from Deloitte CyberSOC ([email protected]) 30 Aug 2018 and from BFK 29 Nov 2018. Distributed as "Update Flash Player" / AdobeFlashPlayer.apk. Operators replied "this client is blocked" and did not block | 185.100.222.28, 185.254.121.69; C2 at ffpanel.ru (8.208.10.54); gateway 188.68.208.159 |
| Ermac | Abuse report from [email protected] 11 July 2022: "We have detected an ERMAC malware incident against Santander, on a website hosted by Media Land LLC." Recurrence reported April 2023 | 45.141.85.29 |
Crimeware Verticals by Evidence Tier
| Client / Activity | Category | Confidence | Sources |
|---|---|---|---|
| LockBit | Ransomware | Confirmed | OFAC; DOJ indictment; Chainalysis (LockBit admin Khoroshev explicitly cited) [6][7][16] |
| BlackBasta | Ransomware | Confirmed | Analyst1 leak correlation; OFAC; UK FCDO [3][7][8] |
| BlackSuit | Ransomware | Confirmed | OFAC sb0319; DOJ indictment [7][16] |
| Play | Ransomware | Confirmed | OFAC sb0319; DOJ indictment [7][16] |
| Evil Corp | Ransomware / CaaS | Confirmed | UK FCDO / Foreign Secretary statement; Intel 471 Dridex hosting 2017 [8] |
| Cl0p Downgraded | Ransomware | Analyst Inference Unsupported | Not named in the indictment or either DOJ press release. Claim originates in trade reporting that misattributed group names to the charging document. Should not be published as a Media Land client on current evidence |
| MedusaLocker | Ransomware | Credible Single Source | TRM Labs on-chain analysis only [10] |
| Client Conspirators 1 to 17 | Ransomware (CC1 to CC16), brute force (CC17) | Confirmed | Indictment paras 14 to 30. None named; see Client Conspirator schedule above [24] |
| Briansclub, Bidencash, Cardhouse, Club2crd, crdclub, Fullzinfo, Swipestore, Verified | Carding marketplaces | Confirmed | Indictment para 207, tabulated by name and domain; see table above [24] |
| Ermac, RedAlert | Android banking trojans | Confirmed | Indictment paras 205 and 206, with quoted third-party abuse reports and specific IPs [24] |
| Underground exchanges and laundering services | Financial crime infrastructure | Confirmed | OFAC; Chainalysis [6][7] |
| Initial access brokers | Access brokerage | Confirmed | OFAC; Chainalysis [6][7] |
| Malware-as-a-Service operators | MaaS | Confirmed | PRODAFT LARVA-34; OFAC [4][7] |
| DDoS attack infrastructure | DDoS | Confirmed | OFAC: DDoS attacks against US companies and critical infrastructure including telecommunications [7] |
| Magecart and card-skimming infrastructure | Financial fraud | Credible | KrebsOnSecurity 2019 [1] |
Victimology New in v2
| Victims in Indictment | 44 enumerated (Victim 1 through Victim 44). 42 US, plus Victim 2 (North Grenville, Canada) and Victim 16 (Redditch, United Kingdom) |
|---|---|
| Documented Losses | Over $62 million taken from Victims 1 through 44 (indictment para 141) |
| Victim Sectors | Banks, schools, government entities, hospitals, media companies (per US Attorney Toepfer) |
| Charging District Nexus | N.D. Ohio Eastern Division. Ohio victims: Akron, Brookfield, Canton, Cleveland (x2), Elyria, Findlay, Medina, Solon, Valley View. Several are specified as having had servers physically in the district, which establishes venue |
| International Victims | Australia, EU member states, UAE, Canada, United Kingdom |
| First and Last Charged Acts | Earliest: 17 March 2014 (Volosovik links [email protected] to [email protected]). Latest: 24 October 2024, brute-force attack on Victim 44 using both AS206728 and AS215376 addresses |
| Notable Victim Types | Victim 1 is a municipality (Newton, Massachusetts). The remainder are described as commercial businesses. The press release adds banks, schools, government entities, hospitals and media companies |
Analyst Inference The victim sector mix (hospitals, schools, government, banks) is characteristic of opportunistic ransomware affiliate targeting rather than directed collection against strategic targets. This weighs against a state-tasking interpretation of the client base, and is one reason the state nexus assessment is held at Tier 2 despite the Rewards for Justice framing discussed in Section 07.
Notable Hosted Cases
Confirmed BlackBasta maintained approximately 200 servers on Media Land infrastructure consuming 17 to 20 Gbps, with negotiated plans to reach 50 Gbps. Infrastructure staffer "lapa" managed day-to-day operations and SOCKS proxy procurement layered over Media Land servers. Zatolokin personally handled the account. Confirmed USDT payments to lapa from operator gg: $94,000 across five transactions between February and May 2024. This remains the most granular publicly documented BPH-to-ransomware operational relationship in any source. [3]
Confirmed OFAC states that Volosovik's hosting services supported sanctioned LockBit administrator Dmitry Khoroshev (LockBitSupp), establishing a confirmed administrator-level link to the LockBit RaaS operation rather than merely an affiliate-level one. [6][7]
Credible The indictment alleges Media Land hosted eight of the largest stolen credit card marketplaces operating in 2023, including Briansclub and Bidencash. If accurate, Media Land was not merely a ransomware enabler but a dominant single point of hosting concentration for the carding economy in that year, which is a materially broader ecosystem role than v1 assessed. [19]
Confirmed A REvil member using the handle "Unknown" addressed Volosovik by his first name "Sasha" during a 2019 XSS arbitration thread, showing his real identity was known within top-tier Russian ransomware circles well before Western public exposure. [3]
State Nexus Assessment
Jurisdictional Separation
All three jurisdictions remain analytically distinct and must not be conflated. The change in v2 is that the infrastructure jurisdiction is now the least Russia-concentrated of the three, having previously been assessed as the most.
Assigned Tier: TOLERATED SAFE HARBOR (Tier 2 of 4)
Media Land is assessed at Tier 2, Tolerated Safe Harbor. The Russian state is assessed to be aware of operations and to refrain from enforcement or prosecution of the operators. The tier is held, not raised, in this revision. The Rewards for Justice framing discussed below is logged as an escalation indicator that would support a move to Tier 3 (Probable Cooperation) if substantiated, but a US government offer to buy intelligence on a question is evidence that the question is open, not evidence of the answer.
Escalation Indicator: Rewards for Justice Scope New in v2
Confirmed On 14 July 2026 the Department of State's Rewards for Justice program offered up to $10 million and possible relocation for actionable information on "foreign government-linked associates of Pankova, Volosovik and Zatolokin, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud." [16][18]
Analyst Inference This phrasing is unusual for a cybercrime bounty. RFJ offers in criminal cases more commonly seek information on identity, location, or assets. Scoping the offer to foreign-government-linked associates and foreign-government-linked use of the companies indicates the US government treats the question of state connection as open and investigatively live, and is willing to pay substantially to resolve it. Publication of the poster in Russian alongside English reinforces that the intended respondent is inside Russia or the Russian-speaking underground.
Three further contextual data points bear on the question without resolving it:
- TechCrunch characterised the two hosts as having provided infrastructure to "criminals and state-backed hackers," though this phrasing does not appear in the DOJ press release and is not sourced to a named official. Single Source
- The UK FCDO noted in its November 2025 designation that Volosovik worked with Evil Corp, a group whose senior leadership the US Treasury has previously linked to FSB tasking. This is a second-order link through a client, not a direct link.
- The EU's 13 July 2026 statement, issued the day before the unsealing, described a broader Russian cyber ecosystem in which the Russian Intelligence Services have "tasked cybercriminals to collect intelligence to support Russia's military and foreign policy objectives." Media Land was designated in the same package, but the tasking language was applied to the ecosystem and to specific GRU-linked entities such as IMPULS and CARR, not to Media Land. Analysts should not read the ecosystem statement as a Media Land-specific attribution.
Evidence Supporting Tier 2
- Volosovik was publicly named by KrebsOnSecurity in July 2019 with full identifying detail including a passport scan. No Russian domestic enforcement action followed in the seven years since.
- Media Land LLC has operated as a registered Russian entity since October 2015, filing required regulatory disclosures. Running a criminal BPH service through a registered company with a named director is only rational if domestic prosecution risk is assessed as negligible.
- Krebs observed in 2019 that BPH administrators operating from within Russia are unlikely to be arrested provided they remain in country. Validated by the continued at-large status of all four designated individuals through July 2026, now including through an unsealed US indictment.
- Russian state documentation continued to be issued to Volosovik through the period of peak Yalishanda activity, including the Beijing-issued travel passport.
- Moscow renewed warnings to Russian nationals against travel to countries that transfer suspects to US jurisdiction following the indictment, which is consistent with protective tolerance rather than either indifference or control.
Negative Evidence: Against Tier 3 or Tier 4
- No named Western intelligence service, government body, or vendor has asserted direct GRU, FSB, or SVR tasking of Volosovik, Pankova, Zatolokin, or Media Land. The RFJ offer seeks such information rather than asserting it.
- The indictment charges ordinary criminal statutes: computer fraud, wire fraud, money laundering. It contains no espionage, export control, or foreign agent counts, and DOJ's press release makes no state-nexus allegation.
- OFAC designated under E.O. 13694 (cyber-enabled activities) rather than any Russia state-actor-specific authority. The EU designated under the cyber sanctions regime (Decision 2019/797) rather than the Russia destabilising-activities regime (Decision 2024/2643), which it applied the same day to GRU-linked targets. This is a meaningful distinction in EU instrument selection: the Council placed Media Land in the criminal-ecosystem basket, not the state-actor basket.
- Victimology is characteristic of opportunistic ransomware monetisation (hospitals, schools, municipal government, banks) rather than directed collection against strategic or governmental targets.
- The client base is broadly commercial: ransomware affiliates, carding marketplaces, Android banking trojan operators, fraud operators, IABs. A state-tasked platform would be expected to show a narrower and more purposive client profile.
Indicators that would move the assessment to Tier 3. Documented handler relationships between any principal and an RIS officer; evidence that specific hosting was provisioned to a state-attributed intrusion set on request; RFJ-derived reporting that becomes public; a superseding indictment adding espionage or foreign-agent counts; or explicit attribution language in a future OFAC, FCDO, or EU designation. None of these is present as of 26 July 2026.
Law Enforcement and Regulatory Response
This section was rewritten in v2. v1 recorded no arrests, no indictments, and no charges.
Criminal Indictment New in v2
| Charging Document | Federal grand jury indictment, returned under seal 5 December 2024; unsealed 14 July 2026 |
|---|---|
| District | Northern District of Ohio |
| DOJ Reference | Office of Public Affairs Press Release 26-773 |
| Individual Defendants | Alexander Alexandrovich Volosovik (43), St. Petersburg; Kirill Andreevich Zatolokin (34), St. Petersburg; Yulia Vladimirovna Pankova (29), St. Petersburg |
| Corporate Defendants | Medialand LLC, St. Petersburg; ML.Cloud LLC, St. Petersburg |
| Charges Corrected v2.1 | Thirteen counts plus an enhancement and forfeiture. See the count schedule below |
| Alleged Conduct | Provision of bulletproof hosting infrastructure enabling clients to infect victims with malware and ransomware and extort them for money and cryptocurrency; support to criminal marketplaces; fraudulent domain registration; phishing and brute-force launch platforms; repeatedly ignoring or falsifying abuse reports; rotating infrastructure to evade takedowns; accepting cryptocurrency to protect client identities |
| Victims | 42 US victim organizations across 21 states; more than $62 million in losses |
| Investigating Agencies | FBI Cleveland Division, with assistance from CISA and OFAC |
| Prosecutors | Trial Attorney Christen Gallagher, Criminal Division CCIPS; AUSA Duncan T. Brown, N.D. Ohio |
| International Assistance | National Police of the Netherlands; Public Prosecutor's Office of the Netherlands; UK National Crime Agency; UK FCDO; Australian DFAT; Australian Federal Police |
| Custody Status | None of the three defendants is in custody. All assessed to be in Russia. No US-Russia extradition treaty. All presumed innocent |
| Broader Campaign | Part of Operation Riptide, an FBI campaign launched 9 June 2026 targeting criminal actors, infrastructure, and financial networks behind cybercrime and fraud |
Analyst Inference The seven-month sealing period between return and unsealing, and the twenty-month gap between the December 2024 indictment and the July 2026 unsealing, indicate the charges were held while other activity proceeded. The November 2025 sanctions fell inside that window. The most probable reading is that the sanctions were sequenced first to impose financial cost while the criminal case remained protected, with unsealing timed to follow the EU designation and to accompany the Rewards for Justice launch as a combined pressure package.
Count Schedule New v2.1
Confirmed The DOJ press releases summarise the charges as four categories, which is accurate but compresses the structure. The document charges thirteen numbered counts and adds a sentencing enhancement and a forfeiture allegation that neither press release mentions.
| Count | Offence | Statute | Period charged |
|---|---|---|---|
| 1 | Conspiracy to commit and aid and abet computer fraud | 18 U.S.C. 371 and 2, predicated on 1030(a)(2)(C), (a)(4), (a)(5)(A), (a)(7)(B), (a)(7)(C) | From 17 March 2014 |
| 2 | Conspiracy to commit wire fraud | 18 U.S.C. 1349 | From 19 February 2016 |
| 3 to 12 | Wire fraud, ten substantive counts, one per victim wire | 18 U.S.C. 1343 and 2 | From 17 December 2018 |
| 13 | Conspiracy to commit money laundering | 18 U.S.C. 1956(h) | From 14 June 2016 |
| Enhancement | False registration of a domain name, in furtherance of Counts 1 to 13 | 18 U.S.C. 3559(g)(1) | Throughout |
| Forfeiture | Proceeds and facilitating property for Counts 1, 2 to 12, and 13 | 18 U.S.C. 982(a)(2)(B), 1030(i), 981(a)(1)(C), 982(a)(1); 28 U.S.C. 2461(c) | Throughout |
Analyst Inference The three conspiracy counts carry three different start dates: computer fraud from March 2014, wire fraud from February 2016, money laundering from June 2016. The government is dating each conspiracy to the earliest act it can evidence for that offence rather than to a single origin point for the enterprise. The 17 December 2018 start for the substantive wire fraud counts is the date of the Exploit fast-flux advertisement, which suggests those ten counts are built on the fast-flux product specifically rather than on hosting in general.
Substantive Wire Fraud Counts 3 to 12 New v2.1
Confirmed Each count pairs one victim with one client conspirator and one piece of Media Land infrastructure. Paragraph 244 states that Volosovik and Zatolokin "controlled and maintained servers in New Jersey and Russia" that transmitted fraudulent responses to ransomware attacks, "including agreements to pay ransoms, receive locker passwords, and other communications related to malware attacks." The recurring New Jersey entry is the ISP1 server hosting ffv2.ru.
| Victim | Client Conspirator | Date | Infrastructure | Victim location |
|---|---|---|---|---|
| Victim 3 | CC4 (assessed Egregor) | 2020 to 2021 | Domains on ffv2.ru | Solon, OH |
| Victim 4 | CC5 (assessed Snatch) | 2021 | Domain on ffv2.ru | Medina, OH |
| Victim 5 | CC5 | 2019 | Domain on ffv2.ru | Akron, OH |
| Victim 6 | CC5 | 2020 | Domain on ffv2.ru | Brookfield, OH |
| Victim 10 | CC6 | 2 February 2023 | Domains and users on ffv2.ru | Findlay, OH; server New Jersey |
| Victim 11 | CC6 | 24 February 2021 | Domains and users on ffv2.ru | Cleveland, OH; server New Jersey |
| Victim 12 | CC6 | 1 July 2023 | Domains and users on ffv2.ru | Cleveland, OH; server New Jersey |
| Victim 13 | CC8 | 2020 | Domain on ffv2.ru | Elyria, OH |
| Victim 14 | CC8 | 2020 | Domain on ffv2.ru | Valley View, OH |
| Victim 44 | CC unknown to the Grand Jury | 24 October 2024 | Media Land and ML.Cloud IP addresses from ASNs 206728 and 215376 | Canton, OH |
The final count is the only one drawing on both autonomous systems together, and it independently corroborates the AS215376 correction. Note also that the wire fraud conspiracy schedule at paragraph 241 records a Media Land IP logging into a Mega.nz account on 24 March 2021 in connection with Client Conspirator 15 and Victim 42, the only named third-party storage service in the document.
Sentencing Enhancement: False Domain Registration New v2.1
Confirmed Neither press release mentions it, but the indictment charges a sentencing enhancement under 18 U.S.C. 3559(g)(1) for knowingly registering domains with false names and addresses "in a manner that prevented the effective identification of and contact with" the defendants, and using them in the course of Counts 1 to 13. Paragraph 253 enumerates roughly 56 such domains, listed in Section 04. These are the highest-value new indicators in the document.
Forfeiture Allegation New v2.1
Confirmed The government seeks forfeiture of all property constituting or derived from proceeds of Count 1, all personal property used or intended to be used to facilitate Count 1, all property traceable to Counts 2 through 12, and all property involved in Count 13 plus anything traceable to it. Authorities cited: 18 U.S.C. 982(a)(2)(B), 1030(i), 981(a)(1)(C), 982(a)(1), and 28 U.S.C. 2461(c). No specific assets, wallets or sums are itemised in the forfeiture paragraph.
Rewards for Justice Offer New in v2
| Authority | US Department of State, Rewards for Justice program; Diplomatic Security Service Cyber and Technology Security |
|---|---|
| Amount | Up to $10,000,000, plus possible relocation |
| Announced | 14 July 2026, concurrent with the unsealing |
| Scope | Actionable information on foreign government-linked associates of Pankova, Volosovik, and Zatolokin; their malicious cyber activities; or foreign government-linked use of Media Land or ML.Cloud |
| Reporting Channel | Tor-based tip channel published by RFJ; posters released in English and Russian |
| Analytic Read | An insider-recruitment instrument aimed at the operation's periphery, and simultaneously a signal that the state-nexus question is investigatively open. See Section 07 |
Sanctions Chronology
Server Seizures
Confirmed None against Media Land as of 26 July 2026. This is notable in context: Dutch authorities seized 800 servers from Stark Industries in May 2026 and 127 servers from ZServers/XHost in February 2025, and the Dutch National Police and Public Prosecutor's Office materially assisted the Media Land investigation. Dutch capability, willingness, and case involvement are all established, and Media Land is now confirmed to have had Netherlands infrastructure. The absence of a seizure to date is therefore a choice or a sequencing decision rather than a capability gap, and a Netherlands or Finland action remains a plausible near-term development.
Post-Disruption Client Migration
Confirmed FBI Cyber Division Assistant Director Brett Leatherman stated after the unsealing that the bureau believes Media Land "is likely still shielding criminal activity" and that the FBI is actively monitoring for client migration: "We're looking for that now, to understand where those shifts may be and what opportunities are available to us in law enforcement and in the intelligence community to target those." [19]
Analyst Inference Precedent argues that migration, if it occurs, will be fast and largely successful. After the May 2026 Stark Industries seizure, GreyNoise researchers documented what they characterised as a seamless migration of attack infrastructure to new autonomous systems with near-identical behavioural signatures. The 2023 Genesis Market takedown produced replacement markets within weeks. Media Land's own position is stronger than either of those cases, however, because its core infrastructure has not been seized, so its clients have no forcing event compelling them to move. The pressure on them is reputational and sanctions-derived rather than operational.
Five Eyes Guidance
On 19 November 2025, CISA with US, UK, Australian, Canadian, and New Zealand partners released "Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers," advising ISPs to build high-confidence malicious resource block lists, conduct regular traffic analysis, implement know-your-customer verification for new hosting clients, and block traffic from known BPH autonomous system numbers. The guidance was released concurrently with the Media Land sanctions, confirming BPH providers as the primary intended target. [6][8]
Connected Groups and Ecosystem Relationships
Every connected entity claim carries two confidence labels assessed independently. Tier 1 asks whether Media Land hosted the entity's infrastructure. Tier 2 asks whether Media Land operators knew the client's identity and coordinated operationally. These are distinct claims requiring distinct evidence and are never collapsed.
Egregorwiki.top and Wikiegregor.top on the ffv2.ru server." The domain naming is a direct and unambiguous reference to Egregor, and the September 2020 date matches Egregor's active period. The government did not name the group, so this is Analyst Inference from primary-source domain evidence rather than a government attribution, and is labelled Credible rather than Confirmed on that basis. T2: Not established. Paragraph 170 records two overt acts against Victim 3 (Solon, Ohio) on 4 October 2020 and 29 December 2021, the second causing damage to Victim 3's systems. Nothing in the read portion speaks to operator-level knowledge of the client's identity.[email protected] to [email protected] concerning expiry and WHOIS updates for the domain snatch.team, in a passage describing services provided to Client Conspirator 5. Snatch is the evident referent. CC5 is the most heavily charged client in the document, with eight overt acts spanning 28 June 2017 to 6 July 2022 against Victims 4 through 9. Analyst Inference as to identity. T2: Uniquely among the client conspirators, the financial link is documented: paragraph 212 records Volosovik receiving 0.23 BTC ($4,665) through the "Yalishanda - bulletproof hoster" cluster from CC5 on 5 September 2022, specifically for infrastructure used in the 6 August 2022 attack on Victim 7, which Victim 7 had paid on 13 August. Receiving a share of a specific ransom, keyed to a specific victim and attack date, evidences knowledge of what the client was doing, though not necessarily of who they were.Trajectory Assessment
Infrastructure Churn
Confirmed AS206728 remains fully active. All eight IPv4 prefixes and both IPv6 prefixes are announced, 2,048 IPv4 addresses are originated, and all four observed upstream peers remain in place. No ASN deregistration, prefix withdrawal, transit change, or de-peering has occurred through the November 2025 sanctions, the July 2026 EU designation, or the July 2026 indictment unsealing. No new ASN registrations or new Russian corporate registrations by any principal have been identified. [13]
The contrast with Aeza Group remains instructive and has now widened. Aeza began entity restructuring and infrastructure migration within weeks of its July 2025 designation, prompting a second OFAC action in November 2025 against its front companies. Media Land, sanctioned in four jurisdictions and now criminally charged, has made no observable reconstitution move. Analyst Inference Two readings are available and are not mutually exclusive: the operators assess Russian territorial protection as sufficient and see no need to restructure, or the Russian core of the estate is not portable in the way Aeza's leased capacity was, because DC Kirishi represents owned hardware in a fixed location. The owned-infrastructure model that gave Media Land a commercial edge may also be what makes it least able to run.
Market Position
Media Land occupies the top tier of the Russian BPH market on every available axis: 15+ years of continuous operation, flagship-tier ransomware clientele, owned physical data center capacity, a mature fast-flux product sold as a distinct line, and, per the indictment, concentration of eight major carding marketplaces plus 17 or more criminal groups. The provider has absorbed a public identity exposure in 2019, two damaging leaks in 2025, sanctions in four jurisdictions, and a US criminal indictment without observable operational interruption. That resilience is a property of the jurisdiction, not of the tradecraft.
Disruption History Assessment
| Instrument | Status | Observed Effect on Operations |
|---|---|---|
| Public identity exposure (2019) | Applied | None observable; operations continued and scaled |
| Adversary and insider leaks (2025) | Applied twice | None observable; breach acknowledged on forum, service continued |
| Sanctions, four jurisdictions (2025 to 2026) | Applied | Financial friction assessed; no infrastructure effect; no de-peering |
| Criminal indictment (2026) | Applied | No arrests; no infrastructure effect to date |
| Rewards for Justice bounty (2026) | Applied | Too recent to assess; targets insider defection |
| Arrests | Not applied | Blocked by absence of extradition treaty and defendants' non-travel |
| Server seizure | Not applied | Now newly feasible against Netherlands, Finland, and US infrastructure |
| Upstream de-peering | Not applied | Only SYSECT D.O.O. (Montenegro) is plausibly subject to European pressure |
| Russian domestic action | Not applied | Assessed very unlikely; see Section 07 |
Trajectory Direction: DEGRADED and STABLE
Assessment unchanged in direction from v1, with higher confidence and a changed basis. Media Land is assessed as Degraded but operationally stable. Every applied instrument to date has been financial, legal, or reputational; none has touched the infrastructure. The provider retains its ASN, its prefixes, its peers, its owned data center, and its principals.
What changed in v2 is that the disruption ceiling is now higher than v1 assessed. v1 concluded that "physical disruption is not achievable under current conditions given wholly Russia-based infrastructure." That premise was wrong. Infrastructure in the Netherlands, Finland, and the United States is within reach, Dutch authorities are already case participants with demonstrated seizure capability, and a partial seizure action is a realistic near-term possibility. Such an action would not end the provider, whose core is in Russia, but it would remove the multi-jurisdictional redundancy that the indictment identifies as a deliberate resilience feature.
Watch indicators, next 6 to 12 months:
- Seizure or takedown action against Netherlands, Finland, or US-hosted Media Land infrastructure
- New ASN or prefix registrations, or new Russian corporate registrations, by any principal or associate (reconstitution signal)
- Withdrawal of any of the four upstream peers, particularly SYSECT D.O.O. (AS202799, Montenegro)
- Client migration to alternative BPH providers, per the FBI's stated monitoring focus
- Superseding indictment, additional defendants, or added counts, especially any with a state-nexus character
- Any public product of the Rewards for Justice offer
- Travel by any defendant to a jurisdiction with US transfer arrangements
- Russian domestic action, which would be a significant and unexpected departure from the Tier 2 assessment
Mandatory Intelligence Gaps
Newly created in v2. The indictment anonymises all seventeen. CC4 and CC5 are identifiable from domain evidence as Egregor and Snatch. CC1 is the most likely candidate for a major RaaS given ten charged victims and dedicated leak-site fast-flux hosting from February 2021, but is not identified. Correlating the charged victim cities and dates against public ransomware victim lists is a tractable next step.
The DOJ press release asserts Media Land infrastructure operated out of China. The reviewed portion of the indictment does not corroborate it, though it does document a Chinese registrar, Chinese proxy procurement and Chinese-language support. Either the hosting claim rests on Counts 2 to 4, or the press release generalises from the supplier relationships. Resolving this requires reading the remaining counts or separate technical corroboration. Until then China is carried as a supplier and market relationship only, not a hosting jurisdiction.
Newly created in v2. Both are US-based ISPs "known to the Grand Jury" and outside the charging district. ISP1 hosted the ffv2.ru fast-flux platform in New Jersey and took over $23,000 from the defendants. Neither is charged. Identifying them would clarify whether the US hosting was obtained through misrepresentation or lax onboarding, which bears directly on the CISA know-your-customer guidance.
Narrowed in v2.1, still open. Count 13 has now been read and documents the mechanism: victims directed to pay into anonymous cryptocurrency accounts, funds transmitted from the United States to points outside it, transactions over $10,000, and proceeds reaching Volosovik and Zatolokin "either through ACH, wire transfer, or other electronic fund transfers." The ACH and wire reference is new and important because it implies regulated intermediaries. But no exchange, OTC desk or money services business is named anywhere in the document, and the forfeiture paragraph itemises no wallets or sums. Mechanism documented; endpoints still unidentified.
Carried forward, narrowed. The indictment says ML.Cloud was "publicly owned by" Pankova, a formulation that stops short of asserting beneficial ownership. Against that, paragraphs 132 and 133 give her substantive conduct: ML.Cloud provided the legitimate-appearing cover for the criminal infrastructure, and she enabled payment for that infrastructure through Media Land accounts and credit cards. She is also charged on every count. The open question is now narrower: whether she directed ML.Cloud or was installed as its registered owner while others directed it.
Carried forward from v1 and now sharpened. Sanctioned in November 2025 but absent from the December 2024 indictment. Whether this reflects charging-record timing or evidentiary insufficiency is unresolved.
Carried forward from v1. No visibility into client attrition, pricing changes, or capacity utilisation after November 2025 or July 2026. The FBI is monitoring migration but has published nothing.
Elevated in v2. The Rewards for Justice offer establishes that the US government treats the state-connection question as open. No public evidence resolves it in either direction.
v2 was built on Count 1 only, the extraction having truncated at page 60. All 75 pages have now been read. This closed the count-structure error (thirteen counts, not four), produced the Count 13 laundering theory, and surfaced the 3559(g)(1) domain enhancement that no press release mentioned.
v1 recorded no charges against any principal. Resolved: three principals and two corporate entities indicted in the Northern District of Ohio, unsealed 14 July 2026.
v1 assessed her as a legal and financial associate of unspecified seniority. Resolved: owner of ML.Cloud LLC at the time of investigation and indictment.
v1 assessed infrastructure as Russia-only. The press release corrected this. The charging document pins the specifics: ffv2.ru on a leased server in New Jersey until 23 June 2024; FFPANEL.TOP in Finland; AS215376 hardware in the Netherlands.
Cl0p was carried at CREDIBLE in drafting, pending document review. Resolved against: the indictment names no ransomware group, and Cl0p appears in no primary source. Claim withdrawn.
All three were carried at CREDIBLE from trade reporting in drafting. All now CONFIRMED from the document, with domains, IPs and quoted third-party abuse reports.
v1 assessed St. Petersburg from entity registration and 2018 Intel 471 reporting. Resolved: DOJ lists all three defendants as residing in St. Petersburg as of the charging document.
Recent Reporting
Sources
Revision History and Change Record
Full provenance for every revision of this profile. Retained so that any claim, correction or withdrawal can be traced to the revision that made it and the source that prompted it.
| v1 | June 2026. Initial profile. Built on open-source reporting and the coordinated US, UK and Australian sanctions of 19 November 2025. |
|---|---|
| v2 | 26 July 2026. Triggered by the DOJ indictment unsealing (14 July 2026) and the EU designation (13 July 2026). Built on direct review of the charging document in United States v. Volosovik et al., Case 1:24-CR-001161 (N.D. Ohio), read through the end of Count 1 only, the text extraction having truncated at page 60. |
| v2.1 | 27 July 2026. Current. Full charging document read, all 75 pages. Count structure corrected from four categories to thirteen counts plus a sentencing enhancement and forfeiture. Count 13 money laundering theory documented. 56 falsely registered domains added. |