In an unprecedented measure of international cooperation, the United States, the United Kingdom, and Australia announced on November 19, 2025, coordinated sanctions against Media Land LLC, a Russian company specializing in “bulletproof hosting.” Authorities from the three countries indicated that Media Land has played a central role in facilitating ransomware operations and in providing technical support for multiple malicious cyber activities.
For the governments involved, dismantling the infrastructure provided by Media Land is essential to stop the proliferation of criminal groups that rely on its ability to operate in the shadows. In this context, Media Land is presented not only as a technology service provider but as a key enabler within the global criminal ecosystem, capable of offering environments specifically designed to evade law enforcement actions and maintain the operational continuity of illicit networks.
This coordinated move, driven by intelligence agencies, regulatory bodies, and national security teams, seeks to dismantle a critical piece of the machinery that sustains one of the most dangerous and costly crimes of the digital age: ransomware. The governments’ decision to act simultaneously reflects the severity of the threats associated with the infrastructure provided by Media Land and underscores the conviction that without direct intervention against entities like Media Land, attacks will continue to escalate in sophistication and frequency.
The international attention now focused on Media Land highlights how this company, its servers, and its service network have become synonymous with digital impunity. By placing Media Land at the center of these sanctions, allied countries aim to send a clear message: infrastructure providers that support cybercrime can no longer operate without consequences, and Media Land is the first major example of this new strategy.

What is Media Land and Why is it So Important?
Media Land is a company based in St. Petersburg, Russia, dedicated to providing highly specialized web hosting services, and its name, Media Land, has become synonymous with infrastructure designed for anonymity and resistance to the law. Media Land’s servers are not ordinary: they are configured to resist authorities’ requests, ignore shutdown orders, and allow criminal actors to operate under an almost impunity shield.
Media Land’s reputation within illicit cyberspace is precisely due to this ability to provide nearly indestructible environments. This type of offering is called “bulletproof hosting,” and for many criminal groups, Media Land is the most stable and reliable reference when seeking infrastructure that does not comply with legal requirements. Thus, Media Land remains one of the best-known pillars of the bulletproof hosting ecosystem.
According to U.S. authorities, Media Land has provided services to criminal markets and prominent ransomware groups such as LockBit, BlackSuit, and Play, becoming a recurring name whenever the technical chain behind the most devastating attacks is investigated. Media Land’s robust and distributed infrastructure has been used in multiple distributed denial-of-service (DDoS) attacks against private companies and critical structures in the United States.
In several digital forensic operations, experts detected that crucial attack nodes were hosted on Media Land servers, further confirming that Media Land acts as a provider that allows cybercriminals to operate with exceptional freedom. For various security agencies, the repeated connection between major cyber incidents and Media Land demonstrates the magnitude of the role this company plays.
Media Land’s importance lies in its role as a facilitator: Media Land is not necessarily the author of the ransomware, but it provides the “digital highways” through which it is deployed. Many attacks would be impossible without the infrastructure Media Land provides, and criminal groups rely on Media Land to ensure a level of anonymity they could not otherwise achieve. Without access to robust servers and “accomplices” like those of Media Land, a considerable number of attacks could not be executed with the same efficiency or level of concealment.
This enabling function makes Media Land a critical piece of the global criminal machinery, which is why authorities consider acting directly against Media Land one of the most effective ways to weaken the ransomware ecosystem. In short, Media Land’s persistence, specialization, and technical resilience have transformed it into a central actor in contemporary cybercrime.
Who is Behind Media Land?
The sanctions not only target the main company but also the key figures operating directly within Media Land, showing the extent to which Media Land depends on a human structure that supports its illicit activities. Among the individuals identified, Aleksandr Volosovik stands out, CEO of Media Land, widely known in cybercriminal forums as “Yalishanda,” and described by authorities as the main public face of Media Land in the digital underground. Volosovik is credited with providing servers, technical support, and specialized assistance to ransomware and DDoS groups that relied fully on Media Land’s infrastructure.
Alongside him is Kirill Zatolokin, a key Media Land employee responsible for managing payments from criminal clients and coordinating connections between different criminal actors operating through Media Land’s systems. Yulia Pankova was also sanctioned for assisting Volosovik in legal matters and in managing finances linked to Media Land’s illicit activity, becoming a key administrative piece within Media Land’s internal structure.
The sanctions also reach various satellite companies functioning as direct extensions of Media Land, reinforcing the technical and logistical network that has allowed Media Land to maintain its presence within global cybercrime. Among these entities is ML Cloud LLC, considered a sister company sharing resources, servers, and processes with Media Land, and whose role has been fundamental in executing ransomware and DDoS attacks supported by Media Land’s infrastructure.
Also included is Media Land Technology, a company fully integrated into the group and acting as part of the operational machinery that Media Land uses to diversify and conceal its technical activity. Finally, Data Center Kirishi appears as an additional component of Media Land’s network, providing physical capacity and connectivity to sustain illicit operations dependent on the ecosystem Media Land has built. These connections reinforce Media Land’s image as a complex, distributed conglomerate deeply embedded in malicious cyber activities.

A Broader Front: Aeza Group and Sanctions Evasion
The international action is not limited to Media Land, and authorities have emphasized that pursuing Media Land also involves closing alternative routes that other providers use to replicate Media Land’s illicit model. Part of this strategy aims to curb the expansion and reconfiguration of Aeza Group LLC, considered by many as an operator attempting to occupy the same space as Media Land within the “bulletproof hosting” ecosystem.
Following previous sanctions, Aeza undertook a rebranding and infrastructure dispersion operation aimed at hiding connections to its original activity, a maneuver similar to those previously executed by Media Land to reinforce its anonymity. To stop these tactics, sanctions were imposed on Hypercore Ltd., a British company used as a front to move IP infrastructure and replicate methods similar to Media Land, as well as on Smart Digital Ideas DOO (Serbia) and Datavice MCHJ (Uzbekistan), companies used to set up technical infrastructure without a public association with Aeza, in the same way that several entities operated covertly for Media Land.
Maksim Vladimirovich Makarov, the new director of Aeza, was also sanctioned, identified as responsible for key decisions related to evasion, along with Ilya Vladislavovich Zakirov, who participated in creating new companies and payment methods designed to conceal operations, repeating patterns reminiscent of Media Land’s attempts to remain outside regulatory reach.
Authorities highlighted that these sanctions aim to make it impossible for illicit hosting providers to easily migrate their infrastructure, a practice consistently associated with both Aeza and Media Land, and a recurring pattern among digital criminal companies attempting to reproduce the technical and operational persistence of Media Land.
Reaction of the Involved Countries
The United States applied these sanctions through the Office of Foreign Assets Control (OFAC), targeting both individuals and entities involved in malicious cyber activities from outside the country, emphasizing that the infrastructure provided by Media Land has been a key factor in these operations. U.S. authorities stressed that combating Media Land and any network associated with Media Land is essential to curb the global expansion of ransomware, as many attacks depend directly or indirectly on services that Media Land has provided for years.
The United States applied these sanctions through the Office of Foreign Assets Control (OFAC), targeting both individuals and entities involved in malicious cyber activities from outside the country, emphasizing that the infrastructure provided by Media Land has been a key factor in these operations. U.S. authorities stressed that combating Media Land and any network associated with Media Land is essential to curb the global expansion of ransomware, as many attacks depend directly or indirectly on services that Media Land has provided for years.
The U.K.’s National Crime Agency (NCA) classified Media Land as one of the most significant bulletproof hosting operators, linked to highly dangerous groups such as LockBit, Evil Corp, and Black Basta. For the NCA, Media Land’s recurring presence in cyberattack investigations demonstrates the depth of the role Media Land plays in the criminal ecosystem, making Media Land a priority in national security operations.
Australia joined by announcing financial sanctions and travel bans against those responsible for Media Land and its related companies, insisting that disrupting Media Land is fundamental to protecting Australian institutions. Its government highlighted that Media Land’s services have enabled attacks affecting hospitals, schools, and Australian companies, and that curbing Media Land is a necessary measure to reduce the attack surface. It also noted that violating sanctions linked to Media Land could result in severe penalties, including significant fines and up to ten years in prison.
Implications of the Sanctions
From a legal and economic standpoint, the measures against Media Land have significant consequences, as asset freezes imply that any property or interest in property associated with Media Land and located in the sanctioning countries is fully blocked, as well as any financial resources that may be linked to entities related to Media Land.
Additionally, the prohibition of transactions prevents individuals or companies in the United States, the U.K., or Australia from engaging in any operations with Media Land, including payments, services, and contracts that could allow Media Land to continue its activity. Added to this are risks for financial institutions that, if interacting directly or indirectly with Media Land, may face sanctions or legal actions, reinforcing international pressure to isolate Media Land from the global economic system.
Likewise, personal deterrence measures, such as travel bans and restrictions on holding corporate positions, aim to limit the mobility and operational capacity of those responsible for Media Land, reducing the possibility that Media Land could reorganize its criminal infrastructure. Overall, these actions are expected to significantly increase the costs of digital crime and hinder the operation of ransomware and phishing networks that rely on bulletproof hosting, many of which have used Media Land’s services as an operational base.
Critiques, Limits, and Remaining Challenges
Although sanctions against Media Land represent a significant advance in the fight against cybercrime, they also raise important questions and challenges, especially because the evasion capacity demonstrated by companies like Aeza reflects tactics similar to those employed by Media Land, which could attempt to relocate using shell companies, international networks, and new corporate identities to keep the ecosystem Media Land built alive. There is also a clear balloon effect: if a criminal hosting provider like Media Land is dismantled, another could emerge to take its place, especially in jurisdictions without international cooperation agreements, replicating the model that Media Land perfected over the years.
Added to this is the complexity of cyberspace, where the distributed and global nature of the internet makes it difficult to impose exhaustive controls without affecting legitimate activities, a problem accentuated by the way Media Land leveraged this decentralized structure. Finally, the need for global cooperation is crucial, as even though the United States, the U.K., and Australia form a solid block against Media Land, long-term success depends on alliances with European, Asian, and other countries willing to coordinate efforts to prevent Media Land and similar actors from finding legal or technical refuge in less regulated territories.

Sanctions against Media Land mark a milestone in the global fight against ransomware and cybercrime, highlighting how Media Land’s infrastructure has been identified as a critical component in the chain of cyberattacks. By directly targeting Media Land, the involved countries adopt a strategic approach that goes beyond pursuing individual perpetrators, recognizing that dismantling Media Land’s infrastructure is essential to disrupt entire criminal networks. The Media Land case demonstrates that illicit hosting providers can amplify cybercriminals’ capacity, and confronting Media Land is a fundamental step to weaken these networks.
However, cybercrime remains dynamic and adaptable, and the experience with Media Land shows that even after severe sanctions, actors behind Media Land could attempt to reorganize, migrate infrastructure, or create new entities. The fight against threats like Media Land requires constant coordination among governments, legal innovation, technological advances, and sustained political commitment. Each measure adopted against Media Land reinforces the need to maintain vigilance over providers that, like Media Land, facilitate ransomware and DDoS attacks on an international scale.
The action against Media Land is an important advance, but also a reminder that global digital security depends on strong cooperation, constant monitoring, and the ability to anticipate new methods employed by criminals linked to Media Land. For companies and organizations seeking to protect themselves from risks similar to those associated with Media Land, ITD Consulting offers specialized solutions in cybersecurity and digital risk management. You can contact us by writing to [email protected] to receive comprehensive advice and effective strategies against threats facilitated by Media Land.