Leaked internal records exposed how the Black Basta ransomware operation relied on the bulletproof hosting provider Media Land (also known as Yalishanda) for servers, domains, proxy services, bandwidth, and technical support. A leak of roughly 190,000–200,000 Black Basta Matrix chat messages, followed by a leak of Media Land’s internal database, revealed operational links between the two organizations and identified Aleksandr Volosovik as the operator behind Yalishanda and Kirill Zatolokin (aka Slim Shady) as a support and infrastructure operator who bridged Media Land and Black Basta. The disclosures showed Black Basta functioning as a structured ransomware enterprise that used cryptocurrency to pay for infrastructure and maintained abuse-resistant services through a registered front company.
The leaked chats and subsequent research also detailed Black Basta’s attack methods across critical infrastructure victims, including phishing, Microsoft Teams and fake IT-support social engineering, exploitation of known vulnerabilities, and use of malware such as Qakbot, Pikabot, DarkGate, LummaC2, and Cobalt Strike. Researchers found the group abused EV code-signing certificates, reused credentials, created corporate-looking domains, and discussed zero-day and CVE exploitation while running double-extortion campaigns. U.S. and allied authorities later sanctioned Media Land, its subsidiary Data Center Kirishi, Volosovik, and Zatolokin for supporting cybercrime, underscoring how infrastructure providers enabled Black Basta’s global ransomware operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
29 events from the most recent confirmed update back to the earliest known activity.
On November 19, 2025, OFAC, coordinated with Australia and the United Kingdom, sanctioned Media Land, its subsidiary Data Center Kirishi, Aleksandr Volosovik, and Kirill Zatolokin for supporting cybercrime operations.
On March 28, 2025, an unknown actor leaked a database tied to Media Land's internal operations, exposing server configurations, client purchase history, user account data, and cryptocurrency addresses.
Expel reports that on February 20, 2025, ExploitWhispers said the Black Basta chats were leaked because the group had crossed a line by compromising a Russian bank.
Trustwave reports that the leaked Black Basta JSON dataset was reposted to Telegram by the persona ExploitWhispers on February 11, 2025, exposing more than 190,000 internal messages.
Sources report that in February 2025, an actor using the name ExploitWhispers publicly leaked Black Basta's internal Matrix chats, exposing roughly 190,000 to 200,000 messages and operational details.
On November 8, 2024, the joint #StopRansomware advisory was revised to add newer Black Basta tradecraft and refreshed indicators of compromise.
The CISA advisory states that in October 2024, Black Basta affiliates incorporated Microsoft Teams messages from legitimate external Teams accounts to impersonate technical support.
Reports on the leak state the exposed Black Basta internal chat logs run through September 28, 2024, marking the end of the leaked message set.
On July 29, 2024, Microsoft reported active exploitation of VMware ESXi privilege-escalation flaw CVE-2024-37085 by ransomware operators including Storm-0506, with observed cases leading to Akira and Black Basta deployments. Microsoft said it disclosed the issue to VMware through coordinated vulnerability disclosure and that VMware released a security update.
A July 22, 2024 discussion cited by Analyst1 said a 200-server Black Basta deployment on Media Land infrastructure was consuming 17–20 Gbps of bandwidth, with plans to increase to 50 Gbps.
The joint FBI, CISA, HHS, and MS-ISAC advisory on Black Basta was originally published on May 10, 2024, documenting the group's TTPs and impact across critical infrastructure sectors.
After the May 2024 Ascension healthcare incident, leaked chats show leader GG said the group had accidentally hit healthcare, provided a decryptor for free, ordered changes to SIM cards, VPSs, VPNs, and servers, and secretly directed development of a new ransomware operation based on Conti code.
A May 2024 chat described Black Basta phishing campaigns targeting Microsoft 365 and Azure using fraudulent domains, SSL certificates, reverse proxies, and cookie interception to bypass MFA. The chats said roughly 25 domains were needed to support the operation and advised using dropped domains to reduce detection risk.
The CISA advisory says that in May 2024, Black Basta affiliates used high-volume spam followed by phone-based social engineering posing as technical support, and asked victims to install tools such as AnyDesk or Microsoft Quick Assist.
Microsoft patched the Windows privilege escalation vulnerability CVE-2024-26169 on March 12, 2024, while stating at the time that there was no evidence of in-the-wild exploitation.
Symantec reported that another exploit variant used in a failed intrusion had a compilation timestamp of February 27, 2024, predating Microsoft's patch for CVE-2024-26169.
The CISA advisory states that starting in February 2024, Black Basta affiliates began exploiting ConnectWise vulnerability CVE-2024-1709 for initial access.
Symantec reported that one exploit variant later tied to suspected Black Basta activity carried a compilation timestamp of December 18, 2023, suggesting pre-patch availability of the tool.
Multiple reports state the leaked Black Basta chat corpus begins on September 18, 2023, marking the start of the exposed internal communications later analyzed by researchers.
In August 2023, the U.S. Department of Justice announced Operation Duck Hunt, a major takedown of Qakbot infrastructure. The action removed Qakbot malware from over 700,000 systems and disrupted an access channel used by Black Basta and other ransomware groups.
The Analyst1 report states that Data Center Kirishi was registered in July 2022 as a spin-off venture tied to the same infrastructure network as Media Land.
The CISA advisory states Black Basta was first identified in April 2022 as a ransomware-as-a-service operation.
After the August 2020 complaint, Yalishanda refunded Loadbaks and posted a Bitcoin transaction hash as proof, according to the Analyst1 report.
On August 27, 2020, a user named Loadbaks filed a forum complaint alleging Yalishanda failed to deliver a paid service and requested a refund of $222.89.
On July 22, 2019, a REvil member using the moniker Unknown referred to Volosovik by his real name, Sasha, in a forum conversation cited by Analyst1.
The Analyst1 report states that Brian Krebs publicly identified Aleksandr Volosovik in 2019 as the primary operator of Yalishanda.
The Analyst1 report says mentions of the Telegram handle @ohyehhellno in Yalishanda advertisements date back to November 2018, linking the account to customer support operations.
According to the Analyst1 report, Media Land LLC was officially registered in October 2015 by Aleksandr Volosovik as a front company tied to the Yalishanda infrastructure business.
The Analyst1 report states that Yalishanda had been operating since approximately late 2009 in the Russian-speaking cybercrime ecosystem as a bulletproof hosting provider.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
ontinue.com
Open sourceanalyst1.com
Open sourceexpel.com
Open sourceflare.io
Open sourcecloudflare.com
Open sourcetrustwave.com
Open sourcesecurity.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.