The Containment Era is here. →Explore

Executive Summary

In June 2024, the Five Eyes intelligence alliance—comprising the US, UK, and Australia—executed coordinated sanctions against Russia-based bulletproof hosting provider Media Land, its executives, three subsidiaries, and entities supporting the previously sanctioned Aeza Group. These hosting providers were identified as key enablers for major ransomware groups (such as LockBit, BlackSuit, and Play), facilitating operations including malware delivery, phishing, and data extortion. Bulletproof hosting infrastructure aided threat actors by allowing them to mask malicious activity and evade law enforcement action, thereby supporting cybercrime at scale for nearly a decade.

This incident highlights the increasing focus by global regulators and law enforcement on disrupting the infrastructure and services that underpin the cybercrime ecosystem, rather than targeting individual attackers. The coordinated international response signals a trend toward attacking the foundational services cybercriminals rely on, underscoring the evolving strategies required to address rising ransomware and data extortion threats.

Why This Matters Now

As ransomware and cyber extortion attacks surge globally, targeting the unregulated infrastructure that supports these operations is increasingly urgent. The Five Eyes' actions represent a pivotal shift towards dismantling the backbone of cybercrime, rather than playing catch-up with individual attackers, raising the stakes for both threat actors and legitimate internet infrastructure operators.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed gaps in infrastructure monitoring and enforcement capabilities, emphasizing the need for better east-west traffic inspection, segmentation, and regulatory alignment within cloud and hosting environments.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, microsegmentation, robust egress controls, and centralized network visibility are critical in disrupting attacks enabled by bulletproof hosting, mitigating lateral movement, exfiltration, and ransomware impact in the kill chain. The CNSF capabilities validated here (such as egress filtering, inline threat detection, zero trust segmentation, and encrypted traffic controls) would have limited the adversary’s paths and exposed malicious infrastructure usage early.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Malicious ingress blocked at the cloud perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Minimized potential blast radius from compromised identities.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement is detected or blocked between tightly segmented workloads.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Command & control traffic is identified and terminated.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound data theft and unauthorized uploads are blocked or alerted.

Impact (Mitigations)

Ransomware activity and data encryption attempts are rapidly detected.

Impact at a Glance

Affected Business Functions

  • IT Operations
  • Customer Service
  • Financial Transactions
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive customer data, including personal and financial information, due to ransomware attacks facilitated by Media Land's infrastructure.

Recommended Actions

  • Enforce cloud perimeter controls with Cloud Native Firewalls and egress filtering to intercept malware delivery from untrusted infrastructure.
  • Deploy identity-based Zero Trust Segmentation to minimize privilege escalation and restrict east-west attacker movement.
  • Instrument robust East-West Traffic Security and multidisciplinary visibility to rapidly detect and investigate lateral movement and C2 channels.
  • Mandate continuous anomaly/threat detection to detect ransomware behaviors and respond early in the attack chain.
  • Apply centralized egress policy governance to ensure that only explicitly authorized destinations are reachable from workloads, blocking attacker-controlled data exfil paths.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image