{"id":8625,"date":"2025-11-21T10:03:40","date_gmt":"2025-11-21T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/21\/authorities-sanctioned-russia-based-bulletproof-hosting-provider-for-supporting-ransomware-operations\/"},"modified":"2025-11-21T10:03:40","modified_gmt":"2025-11-21T10:03:40","slug":"authorities-sanctioned-russia-based-bulletproof-hosting-provider-for-supporting-ransomware-operations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/21\/authorities-sanctioned-russia-based-bulletproof-hosting-provider-for-supporting-ransomware-operations\/","title":{"rendered":"Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations"},"content":{"rendered":"<p>    Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land.<\/p>\n<p>This Russia-based <a href=\"https:\/\/cybersecuritynews.com\/russian-hackers-using-russia-based-bulletproof-network\/\" target=\"_blank\" rel=\"noreferrer noopener\">bulletproof<\/a> hosting company provides infrastructure to ransomware and other cybercriminals.<\/p>\n<p>The U.S. Federal Bureau of Investigation also coordinated the action targeting the company\u2019s leadership team and related entities.<\/p>\n<p>Bulletproof hosting providers offer specialized servers designed to help criminals hide their activities and avoid law enforcement.<\/p>\n<p>These services give ransomware gangs, hackers, and other cybercriminals the infrastructure they need to launch attacks against businesses and critical infrastructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-media-land-s-criminal-operations\"><strong>Media Land\u2019s Criminal Operations<\/strong><\/h2>\n<p>Media Land, headquartered in St. Petersburg, Russia, supplied hosting services to major ransomware groups, including LockBit, <a href=\"https:\/\/cybersecuritynews.com\/blacksuit-ransomware-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">BlackSuit<\/a>, and Play.<\/p>\n<p>The company\u2019s infrastructure was also used for distributed denial-of-service (<a href=\"https:\/\/cybersecuritynews.com\/gcore-mitigates-record-breaking-6-tbps-ddos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">DDoS attacks<\/a> targeting U.S. companies and critical systems. Company leadership played direct roles in the criminal operation.<\/p>\n<p>Aleksandr Volosovik, Media Land\u2019s general director, advertised the company\u2019s services on cybercriminal forums under the alias \u201cYalishanda\u201d and provided servers to ransomware actors.<\/p>\n<p>Kirill Zatolokin, an employee, collected payments from customers and coordinated with other cyber actors. Yulia Pankova assisted Volosovik with legal matters and financial management.<\/p>\n<p>The Treasury also designated Hypercore Ltd., a UK-registered company created by the Aeza Group after it was sanctioned in July 2025. Aeza attempted to rebrand and hide its connections to avoid sanctions.<\/p>\n<p><a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0319\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Treasury officials<\/a> designated new companies and individuals involved in the evasion effort, including directors Maksim Makarov and Ilya Zakirov. Related entities in Serbia and Uzbekistan were also targeted.<\/p>\n<p>All property and assets belonging to the designated individuals and companies in the United States are now frozen.<\/p>\n<p>U.S. persons and businesses are prohibited from conducting transactions with these entities. Financial institutions engaging with sanctioned parties risk enforcement actions.<\/p>\n<p>The U.S. Treasury emphasized that these coordinated international actions demonstrate a commitment to preventing ransomware and protecting citizens from <a href=\"https:\/\/cybersecuritynews.com\/russian-cybercrime-market-hub-transferring-from-rdp-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybercrime<\/a>.<\/p>\n<p>The Cybersecurity and Infrastructure Security Agency released additional guidance on protecting against bulletproof hosting providers.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/bulletproof-hosting-provider-sanctioned\/\">Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/bulletproof-hosting-provider-sanctioned\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. The U.S. Federal Bureau of Investigation also coordinated the action targeting the company\u2019s leadership team [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,231],"tags":[130],"class_list":["post-8625","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-ransomware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8625"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8625"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8625\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}