US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims
A seven-year US investigation culminates in the unsealing of an indictment against three Russian nationals and two companies for operating 'bulletproof' hosting services that facilitated cyberattacks totaling over $62 million.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

A seven-year investigation by U.S. authorities culminated this week in the unsealing of a December 2024 indictment against three Russian nationals and two St. Petersburg-based companies, Medialand LLC and ML.Cloud LLC, accusing them of operating "bulletproof" hosting services that enabled cyberattacks netting over $62 million from 44 victims across 21 U.S. states. Alexander Alexandrovich Volosovik, 43, Kirill Andreevich Zatolokin, 34, and Yulia Vladimirovna Pankova, 29, are charged with conspiracy to commit and aid and abet computer fraud, conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. This action, supported by parallel sanctions from the United States, the United Kingdom, and Australia in November 2025, signals a deepening commitment by international law enforcement to dismantle the foundational infrastructure of global cybercrime, rather than merely pursuing individual actors.
The core of the indictment reveals that Medialand and ML.Cloud provided essential digital havens for notorious ransomware groups such as LockBit, BlackSuit, and Play, as well as facilitating widespread phishing campaigns, malware distribution, Distributed Denial of Service (DDoS) attacks, brute-force attacks, and various forms of online fraud. These "bulletproof" services are characterized by their deliberate resistance to takedown requests, legal pressure, and abuse complaints, often operating in jurisdictions with lenient laws or limited cooperation with international law enforcement. The indicted companies allegedly maintained infrastructure not only in Russia but also in China, Finland, the Netherlands, and even the United States, allowing their criminal clientele to evade detection and maintain operational continuity despite attempts at disruption. Volosovik, reportedly using the alias "Yalishanda" on cybercriminal forums, actively advertised these illicit services, touting features specifically designed to benefit threat actors, including anonymity and the ability to move malicious infrastructure rapidly between servers.
This indictment marks a critical escalation in the ongoing battle against cybercrime, shifting focus from merely prosecuting the "trigger-pullers" to targeting the underlying ecosystem that enables them. For too long, the cybercrime landscape has resembled a game of "whack-a-mole," where the takedown of one ransomware group or malware operation often led to its rapid re-emergence under a new guise or the rise of a successor. By directly indicting and sanctioning the infrastructure providers, law enforcement aims to make the entire criminal enterprise more expensive, unreliable, and risky. This strategy increases the "cost of doing business" for cybercriminals, forcing them to expend more resources on rebuilding, retooling, and seeking new, less resilient hosts, thereby slowing their operations and diminishing their profits. The victims in this case spanned diverse sectors, including banks, schools, government entities, hospitals, and media companies, underscoring the broad societal impact of such hosting services on critical infrastructure and everyday life.
Historically, legitimate hosting providers enforce strict acceptable use policies and cooperate with law enforcement, promptly removing illegal content. Bulletproof hosts, in stark contrast, intentionally disregard these norms, providing a digital sanctuary where illicit activities can thrive with minimal interference. Previous attempts to disrupt cybercrime infrastructure have included takedowns of specific ransomware groups like LockBit and AlphV, and operations against botnets such as Volt Typhoon. While these efforts have shown temporary success in reducing victim numbers, the inherent resilience of the cybercrime ecosystem often allowed for quick recovery. This latest action against Medialand and ML.Cloud represents a more systemic approach, aiming to sever the operational lifeline for multiple criminal groups simultaneously. The U.S. Department of State's offer of a reward up to $10 million for information, particularly regarding any foreign government links to the activities of the indicted individuals and companies, further underscores the strategic importance of this disruption and hints at broader geopolitical concerns surrounding such illicit infrastructure.
Looking ahead, this indictment sets a significant precedent. It signals to other "bulletproof" hosting providers that they are not immune to international legal action, even if operating from non-extradition countries like Russia. While the immediate apprehension of the indicted individuals may be challenging due to the lack of an extradition treaty between the U.S. and Russia, the sanctions and the unsealed indictment severely limit their ability to conduct business globally and travel freely. The increased focus on infrastructure takedowns, alongside growing international cooperation, could lead to a more fragmented and less reliable global ecosystem for cybercriminals. However, the adaptive nature of cybercrime means that new bulletproof hosts or alternative methods for maintaining illicit operations will inevitably emerge. The challenge for law enforcement will be to maintain sustained pressure, continuously identifying and disrupting new nodes in the cybercrime supply chain, ensuring that the costs of operating such services consistently outweigh the potential profits, thereby making the digital underground less hospitable for malicious actors.