Executive Summary
In June 2024, the Five Eyes intelligence alliance—comprising the US, UK, and Australia—executed coordinated sanctions against Russia-based bulletproof hosting provider Media Land, its executives, three subsidiaries, and entities supporting the previously sanctioned Aeza Group. These hosting providers were identified as key enablers for major ransomware groups (such as LockBit, BlackSuit, and Play), facilitating operations including malware delivery, phishing, and data extortion. Bulletproof hosting infrastructure aided threat actors by allowing them to mask malicious activity and evade law enforcement action, thereby supporting cybercrime at scale for nearly a decade.
This incident highlights the increasing focus by global regulators and law enforcement on disrupting the infrastructure and services that underpin the cybercrime ecosystem, rather than targeting individual attackers. The coordinated international response signals a trend toward attacking the foundational services cybercriminals rely on, underscoring the evolving strategies required to address rising ransomware and data extortion threats.
Why This Matters Now
As ransomware and cyber extortion attacks surge globally, targeting the unregulated infrastructure that supports these operations is increasingly urgent. The Five Eyes' actions represent a pivotal shift towards dismantling the backbone of cybercrime, rather than playing catch-up with individual attackers, raising the stakes for both threat actors and legitimate internet infrastructure operators.
Attack Path Analysis
Attackers leveraged bulletproof hosting infrastructure to deliver malware and phishing payloads for initial compromise via malicious emails or infected sites. After gaining access, they escalated privileges in compromised cloud and enterprise environments, potentially abusing misconfigurations or weak identities. Using east-west lateral movement, adversaries traversed cloud regions or workloads to expand foothold. They maintained persistent command & control connections back to infrastructure concealed with encrypted channels. Data and credentials were exfiltrated through covert or poorly governed outbound channels. Finally, ransomware payloads were activated, leading to data encryption, extortion, and operational disruption.
Kill Chain Progression
Initial Compromise
Description
Attackers used bulletproof hosting services to distribute malware or phishing payloads, leading to user or system compromise via email, malicious links, or exposed services.
Related CVEs
CVE-2024-4577
CVSS 9.8A vulnerability in PHP on Windows allows remote code execution via crafted requests.
Affected Products:
PHP PHP – < 8.1.10
Exploit Status:
exploited in the wildCVE-2023-22527
CVSS 9.8A vulnerability in Atlassian Confluence allows remote code execution via template injection.
Affected Products:
Atlassian Confluence – < 7.13.7
Exploit Status:
exploited in the wildCVE-2023-27532
CVSS 9.8A vulnerability in Veeam Backup & Replication allows authentication bypass leading to remote code execution.
Affected Products:
Veeam Backup & Replication – < 11.0.1.1261
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Acquire Infrastructure: Virtual Private Server
Compromise Infrastructure: Domains
Compromise Infrastructure: Web Services
Develop Capabilities: Malware
Phishing: Spearphishing Attachment
Web Service
Data Encrypted for Impact
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Response to Proactive Indicators of Compromise
Control ID: 12.10.6
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Procedures
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 8
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Visibility into Infrastructure Risks
Control ID: Infrastructure Pillar – Visibility and Analytics
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Art. 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Bulletproof hosting sanctions disrupt ransomware infrastructure targeting financial institutions, requiring enhanced egress security and zero trust segmentation against LockBit attacks.
Health Care / Life Sciences
Healthcare sector faces reduced ransomware threat from Media Land sanctions, but must strengthen encrypted traffic controls and anomaly detection capabilities.
Government Administration
Government agencies benefit from Five Eyes coordinated sanctions against bulletproof hosting, requiring multicloud visibility and threat detection for infrastructure protection.
Information Technology/IT
IT sector must implement kubernetes security and cloud firewall capabilities to protect against ransomware groups using sanctioned bulletproof hosting infrastructure.
Sources
- Five Eyes just made life harder for bulletproof hosting providershttps://cyberscoop.com/bulletproof-hosting-providers-sanctions-mitigation-media-land/Verified
- United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomwarehttps://home.treasury.gov/news/press-releases/sb0319Verified
- UK smashes Russian cybercrime networks responsible for attacks on UK businesseshttps://www.gov.uk/government/news/uk-smashes-russian-cybercrime-networks-responsible-for-attacks-on-uk-businessesVerified
- US, UK, and Australia sanction Russian 'bulletproof' web host used in ransomware attackshttps://techcrunch.com/2025/11/19/us-uk-and-australia-sanction-russian-bulletproof-web-host-used-in-ransomware-attacks/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, microsegmentation, robust egress controls, and centralized network visibility are critical in disrupting attacks enabled by bulletproof hosting, mitigating lateral movement, exfiltration, and ransomware impact in the kill chain. The CNSF capabilities validated here (such as egress filtering, inline threat detection, zero trust segmentation, and encrypted traffic controls) would have limited the adversary’s paths and exposed malicious infrastructure usage early.
Control: Cloud Firewall (ACF)
Mitigation: Malicious ingress blocked at the cloud perimeter.
Control: Zero Trust Segmentation
Mitigation: Minimized potential blast radius from compromised identities.
Control: East-West Traffic Security
Mitigation: Lateral movement is detected or blocked between tightly segmented workloads.
Control: Inline IPS (Suricata)
Mitigation: Command & control traffic is identified and terminated.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data theft and unauthorized uploads are blocked or alerted.
Ransomware activity and data encryption attempts are rapidly detected.
Impact at a Glance
Affected Business Functions
- IT Operations
- Customer Service
- Financial Transactions
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive customer data, including personal and financial information, due to ransomware attacks facilitated by Media Land's infrastructure.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce cloud perimeter controls with Cloud Native Firewalls and egress filtering to intercept malware delivery from untrusted infrastructure.
- • Deploy identity-based Zero Trust Segmentation to minimize privilege escalation and restrict east-west attacker movement.
- • Instrument robust East-West Traffic Security and multidisciplinary visibility to rapidly detect and investigate lateral movement and C2 channels.
- • Mandate continuous anomaly/threat detection to detect ransomware behaviors and respond early in the attack chain.
- • Apply centralized egress policy governance to ensure that only explicitly authorized destinations are reachable from workloads, blocking attacker-controlled data exfil paths.



