Federal prosecutors named hospitals among the confirmed victims as they unsealed charges against three Russians accused of running infrastructure that hosted phishing, malware, and DDoS attacks against organizations in at least 21 states.

 

What happened

US federal prosecutors have unsealed charges against three Russian nationals accused of operating Media Land and ML.Cloud, bulletproof hosting services that provided infrastructure to ransomware gangs, including LockBit, BlackSuite, and Play. According to BleepingComputer, the indictment names Aleksandr Volosovik, who used the alias Yalishanda on cybercriminal forums, as the owner of Media Land, Yulia Pankova as the owner of ML Cloud, who assisted with legal and financial matters, and Kirill Zatolokin as the person who collected customer payments. Prosecutors allege the services caused more than $62 million in damages to victims worldwide. Bulletproof hosting providers lease servers specifically designed to resist takedown efforts, ignoring abuse complaints and law enforcement requests while supporting malware delivery, command-and-control operations, phishing, and illegal content hosting.

 

Going deeper

Media Land and ML.Cloud offered infrastructure spanning multiple countries beyond Russia, including China, Finland, the Netherlands, and the United States, giving ransomware affiliates a geographically distributed base from which to launch and sustain attacks. The Department of the Treasury's Office of Foreign Assets Control previously found that Media Land's infrastructure was used to launch distributed denial-of-service attacks against US companies and critical infrastructure, including telecommunications systems. The US, UK, and Australia sanctioned all three defendants and both companies in November 2025 for providing attack infrastructure and technical support to multiple ransomware and cybercrime operations. This week, the Council of the European Union added its own sanctions against Media Land, ML.Cloud and Volosovik, marking the first joint cyber sanctions package issued jointly by the EU and UK against Russia.

 

What was said

United States Attorney David M. Toepfer stated, as reported by BleepingComputer, "The victims in this case are not only in Ohio, but also in 20 other states across the country, touching every aspect of Americans' lives. They include banks, schools, government entities, hospitals, and media companies. Together with our international partners, we will aggressively combat the efforts of individuals who hide behind computers anywhere in the world who seek to profit and wreak havoc by targeting the infrastructures that support our communities." The Department of State's Rewards for Justice program is separately offering up to $10 million for information on any foreign government-linked associates of the defendants, their malicious cyber activities, or foreign government-linked use of the two companies.

 

In the know

The charges arrive as part of a broader, coordinated international effort against the infrastructure that supports ransomware operations rather than only targeting the ransomware groups themselves. According to BleepingComputer's coverage of the earlier November 2025 sanctions, Media Land had already been formally linked to supporting some of the most active ransomware operations targeting US organizations before this week's criminal indictment escalated the case from sanctions to formal federal charges. Targeting hosting providers rather than individual ransomware affiliates reflects a strategy directed at disrupting the shared infrastructure layer that multiple different ransomware groups depend on simultaneously.

 

The big picture

Bulletproof hosting providers occupy a specific and consequential role in the ransomware ecosystem. They are not the groups that break into hospital networks or write extortion notes, but they are the ones who keep the servers running when law enforcement tries to shut an attack down. A ransomware affiliate using LockBit or Play still needs infrastructure that will not disappear the moment a victim organization or investigator files an abuse report, and that is precisely the service Media Land and ML.Cloud is alleged to have sold. According to the Treasury Department's Office of Foreign Assets Control designation, Media Land's infrastructure supported ransomware operations that have repeatedly targeted US critical infrastructure sectors, placing hosting providers like this one directly in the supply chain behind attacks that disrupt hospital operations and expose patient data across the country.

 

FAQs

What is bulletproof hosting, and why does it matter to ransomware operations?

Bulletproof hosting refers to server infrastructure specifically marketed to criminal customers because the provider ignores abuse complaints and resists law enforcement takedown requests. Ransomware groups depend on hosting that will not be shut down mid-attack, and bulletproof hosting providers fill that need, functioning as a critical piece of infrastructure supporting the broader ransomware ecosystem rather than conducting attacks themselves.

 

Why are US prosecutors charging the hosting operators rather than only the ransomware groups that used their services?

Disrupting a single ransomware group's operations does not remove the infrastructure that group and others relied on. Charging the hosting provider directly targets a shared resource used by multiple ransomware operations simultaneously, aiming to reduce the overall capacity of the ransomware ecosystem rather than addressing one group at a time.

 

How does the Rewards for Justice program factor into this case?

The State Department's Rewards for Justice program is offering up to $10 million for information about any foreign government connections to the defendants or their companies, going beyond the criminal charges themselves to investigate whether state-linked actors were involved in directing or benefiting from the hosting operation.

 

What does it mean that the EU and UK issued a joint sanctions package alongside the US charges?

Coordinated sanctions across multiple governments limit the defendants' and companies' ability to access financial systems, conduct business, or operate infrastructure across a wider set of jurisdictions simultaneously. A joint package specifically signals aligned international pressure rather than a single country acting alone against Russian-based cybercriminal infrastructure.

 

What does this case mean for healthcare organizations concerned about ransomware risk?

While criminal charges against a hosting provider do not immediately reduce the risk of a specific attack, sustained international pressure on the infrastructure layer supporting ransomware groups can raise the operational cost and difficulty of running these operations over time. Healthcare organizations should continue treating ransomware as an active and changing threat, regardless of individual enforcement actions, since affiliates and infrastructure providers routinely rebuild and relocate after disruption.