US Charges Alleged Operators of Russian Bulletproof Hosting Service, Seeking $62M in Damages
In a major crackdown on cybercrime infrastructure, US federal prosecutors have unsealed charges against three Russian nationals accused of providing “bulletproof hosting” (BPH) services to ransomware gangs that caused over $62 million in damages worldwide. The alleged operators of the BPH services, Media Land and ML.Cloud, are accused of leasing servers that facilitated malicious activities such as malware delivery, command-and-control operations, phishing attacks, and illicit content hosting.
The indictment alleges that Aleksandr Volosovik (also known as “Yalishanda” on cybercriminal forums) owned Media Land, while Yulia Pankova was the owner of ML Cloud and assisted with legal and financial matters. Kirill Zatolokin is accused of collecting customer payments for these services. The US Department of State has also offered a reward of up to $10 million through its Rewards for Justice (RFJ) program for any information on foreign government-linked associates of these actors, their malicious cyber activities, or foreign government-linked use of these companies.
Bulletproof hosting providers market themselves as “bulletproof” by ignoring victims’ complaints and subsequent law enforcement takedown requests. This allows them to continue operating despite efforts to disrupt their malicious activities. The two BPH services in question provided customers with infrastructure in multiple countries outside Russia, including China, Finland, the Netherlands, and the United States.
The US Department of State’s offer comes after previous sanctions were imposed by the US, UK, and Australia against the three defendants and two companies. In November, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) said that Media Land’s infrastructure was used to launch distributed denial-of-service (DDoS) attacks against U.S. companies and critical infrastructure, including telecommunications systems.
The US Attorney for the Northern District of Ohio, David M. Toepfer, emphasized the scope of the damage caused by these operations: “The victims in this case are not only in Ohio, but also in 20 other states across the country, touching every aspect of Americans’ lives.” He vowed to aggressively combat the efforts of individuals who hide behind computers anywhere in the world and seek to profit from targeting critical infrastructure.
This week’s developments follow a joint cyber sanctions package issued against Russia by the Council of the European Union in collaboration with the UK. The US charges highlight the ongoing effort to disrupt the infrastructure used by ransomware gangs and other malicious actors.
For security teams, this case serves as a reminder that vulnerabilities can exist even in seemingly secure environments. Regular testing and validation of defenses are crucial to preventing attacks from slipping through detection. By staying vigilant and proactive, organizations can reduce their risk exposure and stay one step ahead of attackers.
Source: Bleeping Computer — 2026-07-15