Skip to content
Sanctions on Russia

Sanctions on Russia

Weeklyblitz • November 22, 2025

In an unprecedented show of technological and diplomatic coordination, the United States, United Kingdom, and Australia have jointly imposed sanctions on two Russia-based cybercrime infrastructure providers-Media Land and Aeza Group-along with five executives and seven associated companies. The coordinated measures, announced in November, mark one of the most expansive multilateral actions to date targeting the global ecosystem that enables ransomware, distributed denial-of-service (DDoS) attacks, and a range of transnational cyber threats.

The sanctions represent growing recognition among Western governments that sophisticated cybercrime operations no longer revolve primarily around individual hackers or small groups. Instead, they depend on a well-organized support structure of contractors, hosting companies, payment processors, and technical enablers-many operating with virtual impunity in jurisdictions unwilling or unable to curb their activities. Bulletproof hosting providers such as Media Land sit at the heart of this infrastructure, effectively functioning as safe havens for criminals who seek servers resistant to takedown efforts, law enforcement interference, or detection by cybersecurity firms.

Bulletproof hosting, often abbreviated as BPH, goes far beyond ordinary web hosting. It is designed specifically for clients who intend to engage in illicit or high-risk online activity. BPH providers supply hardened infrastructure-servers, networks, anonymization layers, offshore corporate entities, and technical support-while deliberately ignoring or circumventing abuse complaints and legal requests from foreign authorities. For ransomware groups, who rely on stable command-and-control servers, data-leak platforms, and secure environments for extortion negotiations, BPH services are as essential as malware itself.

Media Land, headquartered in St. Petersburg, has long operated in this gray zone of cyber-infrastructure. The company has allegedly enabled operations by some of the world’s most notorious ransomware groups, including Lockbit, Play, and BlackSuit-three major actors linked to global extortion campaigns that have disrupted hospitals, schools, logistics companies, and critical infrastructure. The company’s servers have also reportedly been involved in large-scale DDoS attacks targeting US businesses, further underlining the extent to which its services supported both profit-driven cybercriminals and disruptive threat actors with possible geopolitical motivations.

The sanctions announcement described Media Land and its sister company, ML Cloud, as central players in a sprawling network that facilitated ransomware distribution, payment processing, and infrastructure obfuscation. ML Cloud is accused of providing storage and cloud solutions that ransomware gangs used for staging attacks, hosting stolen data, and negotiating ransom payments with victims.

While past sanctions and law enforcement actions have often targeted individual hackers or specific ransomware strains, this latest initiative shifts the focus toward corporate executives and operational staff who keep cybercriminal infrastructure running.

The US Treasury Department’s Office of Foreign Assets Control (OFAC) designated five individuals, beginning with Media Land’s general director Aleksandr Volosovik, who is accused of coordinating operations that directly supported ransomware campaigns. Another employee, Kirill Zatolokin, allegedly handled payments and internal logistics, ensuring that the company’s cybercriminal clients maintained uninterrupted access to servers. Yulia Pankova, described as a key assistant to Volosovik, is said to have provided financial and legal support that helped Media Land maintain operations despite prior scrutiny.

The sanctions also include executives from Aeza Group, a second Russia-based hosting provider previously linked to cybercriminal clients and noted for its attempts to bypass earlier Western restrictions. Aeza’s Maksim Vladimirovich Makarov and Ilya Vladislavovich Zakirov were designated for evading sanctions by shifting infrastructure and corporate registrations between jurisdictions in an attempt to stay ahead of enforcement actions.

This explicit targeting of individuals reflects a strategic shift: Western governments are increasingly pursuing the business operators behind cybercrime networks, not just the hackers who rent their services. By doing so, they aim to disrupt the financial incentives that make bulletproof hosting a profitable and persistent enterprise.

Also sanctioned were seven companies determined to be directly tied to Media Land and Aeza’s operations. These entities span multiple countries, demonstrating how BPH providers structure their infrastructure using international layers of shell companies and offshore registrations.

Inside Russia, the sanctioned companies include Media Land Technology, ML Cloud, and Data Center Kirishi. Outside Russia, the designations expand to:

These offshore entities allegedly helped the groups maintain global infrastructure, manage international payments, and obscure ownership trails. According to US officials, the companies were integral to evading law enforcement and continuing cybercriminal operations even after takedown attempts.

The involvement of Australia alongside the US and UK signals an expanding coalition of countries working to combat ransomware at a structural level. As Under Secretary for Terrorism and Financial Intelligence John K. Hurley emphasized, the goal is to dismantle not only criminal groups but also the backbone of services that enable them to thrive.

“Today’s trilateral action… demonstrates our collective commitment to combatting cybercrime and protecting our citizens,” Hurley said.

In addition, the coordinated approach increases the likelihood that designated individuals and companies will be frozen out of international financial systems. Any assets held in the United States or controlled by US financial institutions are already blocked, and private companies risk penalties if they continue engaging with sanctioned entities. Given the interconnected nature of global finance, such restrictions effectively cut off sanctioned individuals from a broad array of banking, logistics, and technology providers.

Sanctioning bulletproof hosting firms marks a strategic escalation in the broader fight against ransomware, but its long-term impact remains uncertain. Many hosting companies tied to cybercrime operate in jurisdictions where enforcement cooperation with Western nations is limited or nonexistent. Russia, in particular, has often declined to prosecute cybercriminals so long as their activities are directed at foreign targets.

Still, experts note that sanctions increase operational costs for cybercriminals, complicate their financial flows, and introduce legal risks for companies who enable them. By expanding designations to include offshore entities and individual executives, the US, UK, and Australia are signaling a willingness to disrupt the entire global supply chain of cybercrime.

Whether this coordinated action results in a measurable reduction in ransomware attacks remains to be seen. But one thing is clear: Western governments are broadening the battlefield, treating cybercrime not merely as a technological threat but as an international business ecosystem that requires sustained disruption at every level.

Please follow Blitz on Google News Channel