The Department of Justice has unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two Russia-based “bulletproof hosting” companies.
The entities are accused of enabling widespread cybercrimes that have collectively caused tens of millions of dollars in losses to victims across the United States.
The indictment, originally returned in December 2024, levies multiple heavy charges including conspiracy to commit and aid and abet computer fraud, wire fraud, and money laundering:
- Alexander Alexandrovich Volosovik (43) of St. Petersburg, Russia.
- Kirill Andreevich Zatolokin (34) of St. Petersburg, Russia.
- Yulia Vladimirovna Pankova (29) of St. Petersburg, Russia.
- Medialand LLC, headquartered in St. Petersburg, Russia.
- ML.Cloud LLC, headquartered in St. Petersburg, Russia.
US Charges Two “Bulletproof Hosting” Companies
Prosecutors allege that Medialand (owned by Volosovik) and ML.Cloud (owned by Pankova during the investigation period) provided dedicated server infrastructure tailored to block law enforcement interventions. Volosovik actively marketed these services on clandestine criminal forums, offering stable setups across global jurisdictions.
Co-conspirators leveraged these configurations to deploy various forms of malware, extort digital currencies, host illicit marketplaces, and orchestrate automated brute-force scripts. These methods closely resemble infrastructure footprints observed in previous Onyx ransomware operations.
The complete breakdown of criminal infrastructure, operations tracking, and explicit charging documents is hosted directly by the official DOJ release.

According to court filings, the operational footprint compromised 42 unique organizations across 21 states. The target matrix hit critical public segments including healthcare entities, financial organizations, schools, media agencies, and government systems.
To mitigate automated access threats from rogue nodes, defensive teams must continuously audit inbound traffic fields, closely monitoring systems for indicators that resemble gitpaste-12 malware infrastructure.
| Operational Service Component | Implicated Infrastructure Node | Targeted U.S. Sectors |
| Medialand LLC | Russia, China, Finland, Netherlands, and the U.S. | Banks, Schools, Government Entities |
| ML.Cloud LLC | Global proxy servers and routing systems | Hospitals, Media Companies |
Alongside the criminal disclosures, the State Department’s Rewards for Justice program announced an active reward offer of up to $10 million for information linking the defendants or their companies to foreign government entities.
This follows a series of coordinated restrictions enacted in November 2025 by the Treasury Department’s OFAC, which fully sanctioned all three individuals alongside Medialand’s corporate subsidiaries (Media Land Technology and Data Center Kirishi) and sister company ML.Cloud.
The UK’s Foreign Commonwealth and Development Office fully joined the sanctions package, while Australia’s Department of Foreign Affairs and Trade implemented matching partial measures.
The underlying multi-agency investigation was spearheaded by the FBI Cleveland Division with operational assistance from CISA, OFAC, and international law enforcement bodies including the Dutch National Police, UK National Crime Agency, and the Australian Federal Police.
The action falls under Operation Riptide, the FBI’s macro campaign targeting the cybercrime economy, launched in response to a 26% year-over-year surge bringing domestic cyber losses to $20 billion annually.