Blog

Class aptent taciti sociosqu ad litora

Russian Nationals Charged in Bulletproof Hosting Conspiracy

  • July 15, 2026
  • Clayton Rice, K.C.

Three Russian nationals have been charged with malicious cyber activities in an indictment returned by a grand jury in the United States District Court for the Northern District of Ohio. Two corporate defendants based in St. Petersburg are alleged to have provided bulletproof hosting services from which malware and ransomware attacks were launched. The targets were instructed to make payments using a money laundering scheme comprised of cryptocurrency accounts controlled by the defendants.

1. Introduction

On July 14, 2026, the United States Attorney’s Office, Northern District of Ohio, headquartered in Cleveland, announced the unsealing of an indictment charging three Russian nationals for their roles in malicious cyber activities against U.S. critical infrastructure affecting targets in 21 states and several countries. (here) The 13-count indictment consisting of 75 pages was returned by a federal grand jury and filed on December 5, 2024. (here) Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin and Yulia Vladimirovna Pankova are jointly charged in count 1 with conspiracy to commit and aid and abet computer fraud in violation of 18 U.S.C. §371. (here) There are also two corporate defendants, Media Land LLC and ML.Cloud LLC. The corporate defendants are alleged to have provided infrastructure for servers and internet services based in St. Petersburg, Russia.

2. Background

On November 19, 2025, just over a year after the indictment was filed, the United States Department of the Treasury announced that the Office of Foreign Assets Control, Australia’s Department of Foreign Affairs and Trade and Britain’s Foreign Commonwealth and Development Office were initiating coordinated sanctions targeting Media Land LLC described as “a Russia-based bulletproof hosting (BPH) service provider” for its role in supporting ransomware operations and other forms of cybercrime. (here) The treasury department asserted that Mr. Volosovik, the general director of Media Land LLC, frequently advertised the company on cyber forums under the alias “Yalishanda”. The treasury department also alleged that Ms. Pankova assisted Mr. Volosovik by providing financial or technological support.

Two days ago, on July 13, 2026, the Council of the European Union published a press release stating the Council was sanctioning Media Land LLC and its sister company, ML.Cloud LLC. (here) The Council alleged that Media Land “has been facilitating a wide array of malware attacks against both EU member states and globally” enabling “large-scale ransomware and phishing operations that targeted critical infrastructure and essential services among EU member states.” According to a post to Industrial Cyber, the EU said it “coordinated closely” with Britain on the announcement “citing a shared assessment of growing convergence between state and non-state cyber actors, and pledged continued cooperation with international partners, including NATO”. (here)

3. What is bulletproof hosting?

The indictment is a “speaking indictment” that goes beyond a skeletal statement of the alleged offences and includes a narrative of the underlying conduct. Speaking indictments often contain a glossary of technical terms that are case specific and this one is no exception. In a section containing relevant computer and internet terms, the term “bullet proof hoster” is described as an internet hosting service that is “resilient to complaints of illegal activity, allowing threat actors to engage in online criminal behavior.” [Clause 92] BPH providers are known in the world of cybercrime for “selling Internet Hosting Services while taking steps to maintain access and availability for clients, regardless of the type of data being hosted or activity being conducted.”

The indictment goes on to state that BPH providers often ignore abuse reports, obfuscate the users of their services from identification and disguise server resources to avoid detection or domain blacklisting. Whereas legitimate hosting service providers hold clients responsible for terms-of-service violations, BPH providers are lenient and often knowingly permit illegal activity. Many online resources emphasize the same features. I will select two for additional comment; one is titled What is Bulletproof hosting? posted by SentinelOne on July 31, 2025, and the other is titled What is bulletproof hosting? (And how DMCA-ignored differs) posted yesterday by BitVPS. (here and here)

In the SentinelOne post, the term “bulletproof hosting sites” is used to describe hosting services that are “considerably lenient” about the kinds of material they allow customers to upload and distribute.  According to the post to BitVPS, the term “bulletproof hosting” was historically used to describe providers that knowingly hosted illegal operations – spam campaigns, malware command-and-control and phishing kits – and refused to act on any complaint including from law enforcement. But that is not what a privacy-conscious system administrator renting an offshore VPS actually wants. “What most people mean when they type ‘bulletproof hosting’ is really DMCA-ignored offshore hosting: a provider that won’t yank your lawful content over a US-style takedown notice, sited in a jurisdiction where such notices carry no automatic force,” the post states. The takedown notices referred to here are issued under the U.S. Digital Millennium Copyright Act. (here)

4. Media Land’s Infrastructure

The core allegation, then, is that Media Land LLC and ML.Cloud LLC provided the infrastructure and tech support to the co-conspirators with the means to infect targeted computers with malware and ransomware and then extorted the targets for money and cryptocurrency. The targets were directed by the defendants to make ransom payments using a money laundering web of anonymous cryptocurrency accounts controlled by the defendants. The two companies also allegedly supported illegal marketplaces, fraudulent domain registrations and provided a launching platform for phishing and brute force attacks. Targeted entities included banks, schools and hospitals located in the United States and worldwide. International targets were located in Australia, the United Arab Emirates, Canada, Britain and the European Union.

5. Conclusion

The defendants are unlikely to be arrested given they are located in Russia and extraditions to the United States are rare. In a piece discussing the indictment titled US charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims, published today by TechCrunch, cybersecurity reporter Zack Whittaker said, “Russia is known to shield its citizens from overseas extradition requests, but law enforcement have previously arrested high-value suspects when they travel to countries with diplomatic agreements with the United States.” (here) A grand jury indictment can be a patient accusation.

Comments are closed.