```html ```
top of page

The DOJ Took 18 Months to Indict a Bulletproof Host. A Defender Blocks One in a Day. Here's the Method — and Why We Keep a Shitlist.

  • Writer: Patrick Duggan
    Patrick Duggan
  • Jul 16
  • 5 min read

Updated: Aug 11

The Justice Department unsealed an indictment this week against three Russian nationals and two companies for running the infrastructure under a big slice of the cybercrime economy. The companies are Media Land LLC and ML.Cloud LLC, both out of St. Petersburg. The people are Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova. The charge sheet — computer-fraud conspiracy, wire fraud, money laundering — covers 42 victims across 21 US states and roughly 62 million dollars in losses. The State Department attached a reward of up to 10 million dollars for information on their government-linked associates.


It is a good indictment and the people who built it did hard, patient work. It is also a history lesson, and reading it as anything else is how defenders keep losing. Here is the date that tells you why: the grand jury returned this indictment in December 2024. It was unsealed this week. That is roughly eighteen months between "the government knew" and "the government could say," and the bulletproof host operated the whole time. A defender does not have eighteen months. A defender has the length of one feed refresh.



What Bulletproof Hosting Actually Is


Bulletproof hosting is not a hacking tool. It is a utility. Media Land and ML.Cloud rented servers, the way any host does — except their entire value proposition was that they would ignore abuse complaints, tip off customers before law enforcement arrived, and keep the lights on for ransomware crews, C2 operators, and stealer campaigns that a normal provider would evict in an hour. It is the electricity under the whole operation. Every campaign we write about — the infostealers, the ransomware, the C2 that phones home — runs on a box someone rented from a shop exactly like this.


Note one detail from the indictment, because it is the detail that decides how you defend against it: the infrastructure was not in Russia. It was in China, Finland, the Netherlands, and the United States. Bulletproof hosts rent clean-country IP space on purpose, so that a defender sorting by geography sees Amsterdam and Ashburn, not St. Petersburg, and waves it through. You cannot block this by country. The malice is not in the location. It is in the network.



The Defender's Version of an Indictment


So what does a defender do instead of waiting for a grand jury? The same thing the grand jury did — identify infrastructure where abuse is not an incident but the business model — except do it by behavior, in a day, and enforce it at the edge.


We keep a list for exactly this. Internally we call it the Shitlist, and the name is honest about what earns a spot. It is not a list of networks that had a bad week. Every provider catches some abuse; that is noise. A network makes the Shitlist only when we can show, by density, that abuse is the whole tenant base — when the ratio of malicious IPs to total IPs is so high there is no plausible legitimate customer being harmed by blocking the entire autonomous system. Right now that list holds five networks: BUCKLOG on FBW Networks, DMZHOST on TECHOFF, the one that registered itself as the Church of Cyberology, STORMINDUSTRIES, and ColocaTel. Those five are not on it because someone reported them. They are on it because the math said abuse was the point.


And here is the mechanism that makes it a defense and not a wall chart: our edge feed ages indicators out after a week to stay current, but the Shitlist re-asserts its networks every single day. We re-resolve each one's current IP prefixes and write them back into the blocklist before they can lapse. So a bulletproof ASN we condemned in February is still being blocked in July without a human touching it, while a one-off malicious IP correctly expires. The durable-malicious infrastructure stays blocked exactly as long as it stays malicious.



The Honest Part


Media Land and ML.Cloud are not on our five. We will say that plainly, because a defender playbook that pretends it already had every answer is worthless. The specific ASNs the DOJ named this week are not ones our density method had promoted to permanent-block status — the indictment is genuinely new information to our list, not a confirmation of it.


But that is the point of the method, not a hole in it. The DOJ just published, with a grand jury behind it, exactly the finding our Shitlist is built to produce: here is infrastructure where abuse is the business. That is the strongest possible signal to run their prefixes through our density check and, if the math holds, add them — which is a same-day action on our side, not an eighteen-month one. The indictment is not the end of the defensive story. It is a very well-sourced tip for the front of it.



Why This Is the Left-of-Boom Move


Take down three operators and the model does not die. We wrote the same thing when the feds shuttered the ShinyHunters leak site — the takedown is the easy part, and treating it as the win is how the next one goes up next week. Bulletproof hosting is a market. Media Land had competitors before this indictment and it has them today, and the customers — the ransomware crews, the stealer operators — are already renting the next box in a clean country.


The only defense that keeps pace with a market is one that targets the market's product instead of its owners. The owners get indicted every eighteen months, if they are unlucky and travel to the wrong airport. The product — malicious network space where abuse is the business — can be identified by its own behavior and blocked the day it lights up, by anyone running a feed that thinks in autonomous systems instead of individual IPs. The DOJ did the hard, slow, necessary work of holding three people accountable. The defender's job is the fast, repeatable work of making sure that by the time the indictment is unsealed, the infrastructure it describes has already been dark on your network for months.


Keep a Shitlist. Rank by density, not by report volume. Re-assert it daily. And when the Justice Department hands you a fully-sourced list of networks where abuse was the business, do in an afternoon what took them a year and a half to say out loud.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=the-doj-took-18-months-to-indict-a-bulletproof-host-a-defender-blocks-one-in-a-day-here-s-the-meth



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page