CLEVELAND U.S. authorities have unsealed an indictment against three Russian nationals accused of operating a global cybercrime operation that allegedly enabled ransomware, malware, phishing, and other attacks against organizations in the United States and abroad.
The case follows a seven-year investigation led by the FBI’s Cleveland Division with support from the Cybersecurity and Infrastructure Security Agency (CISA), the Treasury Department’s Office of Foreign Assets Control (OFAC), and international partners.
A federal grand jury in December 2024 charged Alexander Alexandrovich Volosovik, 434343, Kirill Andreevich Zatolokin, 343434, and Yulia Vladimirovna Pankova, 292929, all of St. Petersburg, Russia.
The indictment also names Media Land LLC and ML, Cloud LLC, two companies based in St. Petersburg.
The defendants face allegations of conspiracy to commit computer fraud, aiding and abetting computer fraud, wire fraud, and money laundering conspiracy. The allegations in the indictment have not been proven in court.
Russian Trio Charged in Cybercrime
According to court documents, Media Land, owned by Volosovik, and ML. Cloud, owned by Pankova, provided “bulletproof hosting” services to cybercriminal customers.
Bulletproof hosts are infrastructure providers that market or lease servers, internet services, and technical support to customers engaged in illegal activity, while helping them avoid detection and disruption.
Authorities allege the companies supported criminal groups by providing the infrastructure required to infect victim systems with malware and ransomware, steal or encrypt data, and demand payments in money or cryptocurrency.
The infrastructure allegedly supported several forms of cybercrime, including ransomware operations, malware distribution, fraudulent domain registrations, phishing campaigns, brute-force attacks, criminal marketplaces, and distributed denial-of-service attacks.
Media Land reportedly operated infrastructure in several countries, including China, Finland, the Netherlands, and the United States.
The Justice Department said this international footprint helped cybercriminal customers maintain resilient operations and complicated law enforcement’s efforts to identify and remove malicious systems.
Victims included banks, schools, hospitals, government bodies, and media organizations.
They were located in 212121 U.S. states, including Ohio, California, Florida, Illinois, New York, Pennsylvania, Texas, Virginia, and Washington, as well as Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.
In Ohio, affected organizations were located in Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.
The State Department’s Rewards for Justice program is offering up to $10\$10$10 million, as well as possible relocation, for information about foreign government-linked associates of the accused, their malicious cyber activity, or foreign government-linked use of Media Land and ML. Cloud.
U.S. authorities sanctioned the individuals and companies in November 2025.
The sanctions block property under U.S. jurisdiction and generally prohibit U.S. persons from conducting transactions with the designated entities. The United Kingdom and Australia joined the designation action.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs
Click Here For The Original Source.
