The United States, United Kingdom, and Australia have jointly imposed sanctions on Media Land, a Russian bulletproof hosting provider, along with its leadership and affiliated companies, for facilitating ransomware operations and other cybercrimes. Media Land has been identified as a critical infrastructure provider for major ransomware groups such as LockBit, BlackSuit, and Play, offering services that enable these actors to evade law enforcement and conduct attacks against businesses and critical infrastructure in the U.S. and allied countries. The sanctions also extend to related entities, including Hypercore Ltd. and Aeza Group, and target individuals responsible for managing and supporting these operations. Authorities highlighted that Media Land's infrastructure was used not only for ransomware but also for distributed denial-of-service (DDoS) attacks and other illicit activities, with its executives actively coordinating with cybercriminals and providing operational support.
In parallel with the sanctions, U.S. and international cyber agencies released new guidance to help internet service providers and network defenders mitigate risks from bulletproof hosting providers. The guidance recommends measures such as curating malicious resource lists, implementing network filters, monitoring traffic for anomalies, and sharing threat intelligence to disrupt the infrastructure that enables ransomware and other cyber threats. These coordinated actions underscore a broader effort by Western governments to dismantle the technical and financial networks that sustain global cybercrime operations, particularly those emanating from Russia and its network of bulletproof hosting services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On November 19, 2025, CISA released guidance, alongside NSA, to help organizations and service providers mitigate risks from bulletproof hosting providers and strengthen controls against ransomware-supporting infrastructure.
The U.S. sanctions package included alleged Media Land general director Aleksandr Volosovik, Yulia Pankova, other related parties, and a Bitcoin address linked to Volosovik, expanding the action beyond the hosting company itself.
As part of the November 19, 2025 action, authorities also designated Hypercore Ltd, a U.K.-based entity alleged to be a front for Aeza Group and used to continue operations after prior sanctions.
In the sanctions action, U.S., U.K., and Australian authorities publicly attributed Media Land's infrastructure to a wider range of malicious activity, including ransomware operations, DDoS attacks, malware infections, phishing, scams, and criminal marketplaces affecting victims and critical infrastructure.
On November 19, 2025, the United States, United Kingdom, and Australia announced coordinated sanctions against Russian bulletproof hosting provider Media Land, its leadership, and associated entities for allegedly supporting ransomware groups including LockBit, BlackSuit, and Play, as well as other cybercrime activity.
After the Aeza sanctions, a U.K.-based firm, Hypercore Ltd, was allegedly used as a front or rebranding vehicle to shift IP infrastructure and evade the earlier enforcement action.
In July 2025, the United States sanctioned Aeza Group, another Russian bulletproof hosting provider, as part of a broader campaign against infrastructure used by cybercriminals and ransomware operators.
A January 2025 operation disrupted ZServers, a Russian bulletproof hosting provider, in what later reporting described as an earlier major move against ransomware-supporting hosting infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
securityboulevard.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecisa.gov
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.