Federal prosecutors just unsealed an indictment against the alleged operators of Media Land, a St. Petersburg-based “bulletproof” hosting outfit accused of renting server space and technical support to ransomware crews, phishing operations, and carders for years. The damage is already done. Every ransomware note, every phishing kit, every credential-stuffing bot that ran through Media Land’s infrastructure did its job long before a grand jury ever saw the case. That’s the uncomfortable truth about cybersecurity when it comes to criminal infrastructure: takedowns and indictments arrive after the losses, not before them.
The same week, Malwarebytes flagged a scam ring using FaceTime calls and unpatched phones to drain bank accounts one victim at a time. Different scale, same lesson. Whether it’s a hosting company propping up organized ransomware or a scammer on a video call talking someone through a fraudulent transfer, the attackers are relying on infrastructure and trust that defenders were too slow to shut down or too slow to question.
A Hosting Company Ran Free. Ransomware Gangs Never Went Down.
Bulletproof hosting is the unglamorous plumbing behind a huge share of internet crime. These providers don’t hack anyone directly. They sell resilience: servers that ignore abuse complaints, infrastructure that gets migrated the moment a takedown notice lands, and tech support for criminal customers who need their command-and-control panels to stay online through a law enforcement sweep.
The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.
That’s the part worth sitting with. This wasn’t a single exploit or a single victim. It was a business, operating with enough polish to offer “tech support” to criminal tenants, for long enough that its infrastructure became a known quantity to threat intelligence teams well before any charges existed. Every ransomware operator who rented space there got a head start most defenders never see coming, because the hosting layer sits below the visibility most organizations have into their own attack surface.
Indictments against operators like this matter, but they don’t retroactively patch the exposure that infrastructure enabled. Security teams that treated “the servers are in Russia and won’t respond to abuse reports” as someone else’s problem spent years exposed to traffic that a halfway-decent brute-force and threat-protection posture could have blocked at the door, indictment or not.
The Same Trust Gap Shows Up At The Individual Level
Scale down from nation-state-adjacent hosting infrastructure to a single phone call, and the pattern repeats. The FaceTime bank-draining scam Malwarebytes documented doesn’t rely on a zero-day. It relies on a victim answering a video call from someone posing as a bank representative, walking them through “verification” steps on a device that’s often behind on updates, and using that trust to extract credentials or push a fraudulent transfer through.

No firewall stops a person from voluntarily reading a one-time code to someone they believe is calling from their bank. That’s the point. Attackers at every scale, from bulletproof hosting operators renting infrastructure to gangs, down to a lone scammer on FaceTime, are exploiting trust relationships that sit outside the reach of conventional threat detection. The infrastructure indictment and the video-call scam are the same failure mode wearing different clothes: defenders assumed a boundary existed where none actually did.
There’s a small but genuinely useful counterexample worth noting here. Cloudflare’s rollout of EDE code 33 on 1.1.1.1, which now tells clients directly when DNSSEC validation was bypassed after a broken key rollover took down the .AL top-level domain, is the opposite instinct. Instead of quietly working around a failure and hoping nobody notices the gap in trust, the resolver now surfaces it. That kind of transparency, applied consistently, is what closes the gap between “we assumed it was secure” and “we verified it was secure.”
What Actually Reduces Exposure Between Indictments
Waiting for law enforcement to dismantle criminal infrastructure is not a security hardening strategy. Neither is trusting that every video call, email, or login attempt is what it claims to be. Defense in depth means building controls that don’t depend on the other side playing fair.
- Block traffic from known bulletproof hosting ranges and abuse-tolerant ASNs at the firewall, and refresh those blocklists on a schedule rather than after an incident.
- Apply aggressive brute-force lockouts on every externally reachable login, VPN, and RDP endpoint; credential stuffing from rented infrastructure is still the cheapest way in.
- Train staff and customer-facing teams that “verification” over video or phone is a social engineering vector, not a security feature, and give them a scripted way to hang up and call back through a known number.
- Keep personal and corporate mobile devices patched on the same cadence as servers; the FaceTime scam depended on outdated software as much as it depended on the phone call itself.
- Treat DNS resolution integrity as part of your threat detection stack, not an afterthought; resolvers that flag bypassed validation, like Cloudflare’s EDE 33, give incident response teams a signal they didn’t have before.
- Review third-party and hosting-provider relationships in your own supply chain for the same abuse-tolerance red flags prosecutors just laid out against Media Land.
None of this requires waiting on a federal case to close. Bulletproof hosting providers will keep operating until the next indictment, and there will always be another one after that. Scammers will keep finding new apps to abuse for the same old confidence trick. The organizations and individuals who come out ahead are the ones who stopped assuming trust and started verifying it, one login, one call, one DNS response at a time.
Sources
- US unseals indictment against alleged operators of Russian bulletproof hosting service
- Warning: Scammers are using FaceTime to empty bank accounts
- A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
