ransomware
US Charges Russians Behind Media Land Bulletproof Host
2026-07-15

American prosecutors have unsealed an indictment against three Russians they say ran Media Land, a St. Petersburg hosting business that kept a large chunk of the world's ransomware and card-fraud economy online. The State Department has attached a reward of up to $10 million for information on the case, with a particular interest in any links between the operation and the Russian state.
The indictment, filed in December 2024 and now made public, names Aleksandr Volosovik, better known online as Yalishanda, as the owner of Media Land. Yulia Pankova allegedly ran a sister company called ML Cloud. Kirill Zatolokin handled the unglamorous end of the business: billing and customer service for the criminal clientele. Between them, the three face charges including conspiracy to commit computer fraud, wire fraud and money laundering. Prosecutors point to 44 victims and roughly $62 million in losses tied to groups the company hosted.
A greatest-hits customer list
The names on Media Land's alleged customer roster read like a summary of the last three years of ransomware coverage:
- LockBit, still the most prolific ransomware brand of the decade despite repeated takedowns.
- BlackSuit, the crew behind a run of high-profile attacks on schools and hospitals.
- Play, which has racked up victims across the US, Europe and Latin America.
- Stolen-card marketplaces including Briansclub and Bidencash, the latter dismantled in an international takedown last year.
Bulletproof hosts sell one thing above all else. It isn't uptime, or performance, or clever engineering. It's a promise to ignore abuse complaints and law enforcement requests, and to keep servers running when any legitimate provider would have pulled the plug hours earlier. That promise is what a ransomware crew is really paying for.
The extradition problem
Whether the three defendants ever see a US courtroom is another matter entirely. All three are believed to be in St. Petersburg. Russia has no extradition treaty with the United States, and Moscow has recently warned its own citizens against travelling to countries that might be inclined to hand them over. For now, the indictment functions less as a prosecution and more as a very public naming, sitting alongside sanctions announced in November with British and Australian partners, and investigative support from the Netherlands.
Why the paperwork still matters
It would be easy to dismiss all of this as theatre. The defendants are out of reach, the servers can be rebuilt, and the ransomware groups will find another host. But bulletproof hosting is the quiet backbone of the whole cybercrime economy. Every ransomware negotiation site, every leak blog, every carding market has to live somewhere, and the number of providers willing to host that traffic is smaller than it looks.
Naming the operators, freezing what payment rails can be frozen, and shrinking their travel map all make the business more expensive to run. Costs pushed onto the infrastructure layer eventually work their way down to the affiliates and initial-access brokers who rely on it. That doesn't end ransomware. It does make it a slightly worse business to be in, which, over time, is roughly how these ecosystems get worn down.