# US Charges Three Russian Nationals for Operating Bulletproof Hosting Service Used by Ransomware Gangs


Federal prosecutors have unsealed indictments against three Russian nationals accused of operating a sophisticated bulletproof hosting (BPH) service that allegedly provided critical infrastructure support to ransomware operations causing over $62 million in documented damages to victims worldwide. The charges represent a significant escalation in the U.S. government's effort to dismantle the technical backbone supporting ransomware-as-a-service (RaaS) criminal enterprises.


## The Charges


The U.S. Department of Justice filed charges against Aleksandr Ermolin, Dmitry Chikunov, and Igor Sinyakin, accusing them of conspiracy to commit wire fraud, conspiracy to commit computer fraud, and causing intentional damage to protected computers. According to the indictment, the defendants operated a bulletproof hosting provider that deliberately catered to cybercriminals, ensuring their malicious infrastructure remained online despite law enforcement and security researchers' efforts to take it down.


The allegations include:

  • Infrastructure support: Hosting command-and-control (C2) servers, payment processing systems, and data exfiltration platforms for ransomware operations
  • Obstruction assistance: Implementing technical measures specifically designed to evade law enforcement takedowns and security research
  • Money laundering facilitation: Processing cryptocurrency payments for ransom demands
  • Jurisdictional reach: Providing services that directly harmed U.S. entities, including healthcare facilities, municipalities, and small businesses

  • ## What Is Bulletproof Hosting?


    Bulletproof hosting represents a specialized dark web infrastructure service designed from inception to support illegal activity. Unlike conventional hosting providers that comply with law enforcement requests and DMCA takedowns, BPH services operate with the explicit understanding that their customers are criminals.


    Key characteristics of bulletproof hosting include:


    | Feature | Description |

    |---------|-------------|

    | Jurisdictional arbitrage | Hosted in countries with weak cybercrime enforcement or government complicity |

    | DDoS resilience | Hardened infrastructure designed to withstand distributed denial-of-service attacks from security researchers |

    | Law enforcement evasion | Policies explicitly refusing to cooperate with takedown requests or arrest warrants |

    | Anonymity layers | Cryptocurrency-only payments, no KYC verification, shell company registration |

    | Rapid failover | Automated migration systems to move infrastructure when compromised or identified |

    | Technical support | Customer service specifically trained to support illegal operations |


    The operators profited by charging significantly higher rates than legitimate hosting—sometimes 10-100x normal pricing—in exchange for guaranteed operational continuity and active countermeasures against law enforcement.


    ## Background and Context


    Bulletproof hosting has been a critical enabling technology for ransomware gangs for nearly two decades. Unlike other aspects of ransomware infrastructure that cybercriminals can improvise or rotate, hosting requires deep technical expertise, capital investment, and operational security that acts as a natural barrier to entry.


    By removing this barrier and offering hosting-as-a-service, providers like the alleged defendants transformed ransomware from a specialized technical crime into a scalable, franchisable business model. The indictment details how their infrastructure was used by multiple ransomware families, including operations targeting hospitals during the COVID-19 pandemic when attacks on healthcare facilities posed direct public health risks.


    The charges also highlight a growing enforcement strategy: rather than targeting individual ransomware operators (who are often difficult to locate and extradite), prosecutors are targeting the infrastructure providers whose services are essential to ransomware operations. Dismantling hosting providers creates cascading disruption across entire ransomware ecosystems.


    ## Technical Details and Evidence


    The indictment alleges that the defendants:


  • Hosted multiple C2 infrastructures: Operated servers specifically designed to command ransomware deployment, data exfiltration, and payment collection
  • Implemented anti-takedown measures: Configured "virtual private network" (VPN) systems, DNS masking, and rapid IP rotation to evade law enforcement identification and blocking
  • Maintained cryptocurrency payment systems: Processed cryptocurrency transactions totaling millions of dollars, facilitating ransom payments that funded further criminal operations
  • Provided technical support: Communicated with ransomware operators to resolve infrastructure issues, optimize deployment, and expand their criminal capabilities
  • Evaded previous takedowns: Rebuilt infrastructure multiple times after security researchers and law enforcement successfully identified and disrupted their services

  • The alleged operators understood their customers' needs intimately—the indictment suggests they actively optimized infrastructure specifically for ransomware operators' technical requirements, including low-latency performance, bandwidth reliability, and resilience against security researcher probing.


    ## Implications for Organizations and the Ransomware Ecosystem


    ### Disruption, But Not Elimination


    While the charges represent meaningful progress, they highlight a fundamental asymmetry in ransomware defense. The U.S. can prosecute Russian nationals, but extradition remains unlikely. Russian extradition treaties with the U.S. effectively prevent trial and imprisonment, meaning these individuals, if still at large, will likely face no real legal consequences.


    However, the indictment serves multiple purposes:


    1. Asset freezing: Any identified financial assets can be seized

    2. Operational disruption: Elevated law enforcement attention forces operators to reduce visibility and shift infrastructure

    3. Ecosystem degradation: Other bulletproof hosting providers face increased scrutiny and potential prosecution

    4. Ransomware fragmentation: Operators lose trusted infrastructure and must either relocate services or rebuild independent capabilities


    ### Increased Costs for Cybercriminals


    Successful prosecutions of infrastructure providers increase operational expenses for ransomware gangs. They must:

  • Find alternative hosting with lower reliability and higher prices
  • Invest in building proprietary infrastructure
  • Accept increased risk of law enforcement identification
  • Maintain larger reserves for rapid infrastructure migration

  • These costs compress profit margins, potentially making smaller operations unprofitable and consolidating the ransomware market around better-capitalized groups.


    ## Recommendations for Organizations


    ### Immediate Actions


  • Threat intelligence review: Work with security teams to identify if your organization has indicators of compromise linked to the indicted infrastructure
  • Incident response readiness: Ensure ransomware response playbooks are current and tested
  • Backup verification: Confirm offline backups are functioning and isolated from production networks

  • ### Longer-Term Strategy


  • Network segmentation: Reduce lateral movement paths that ransomware operators exploit
  • EDR deployment: Endpoint detection and response systems can identify ransomware behavior even when malware families are unknown
  • Incident response retainer: Establish relationships with experienced IR firms before an incident occurs
  • Insurance review: Ransomware insurance policies should be evaluated for adequate coverage limits and response support

  • ## HackWire Analysis


    Why this prosecution matters beyond the courtroom: The indictment of bulletproof hosting operators signals a strategic shift in ransomware enforcement—from chasing individual operators (who are numerous and often unreachable) to targeting the infrastructure layer that makes ransomware economics viable. This mirrors successful enforcement strategies against darknet markets like Silk Road, which collapsed when its hosting infrastructure was seized rather than its merchant base.


    However, the practical impact may be limited. Russian hosting providers operate in a jurisdiction where the government has little incentive to extradite cybercriminals to the U.S., and cryptocurrency's pseudonymity allows rapid capital repatriation. The real question is whether these indictments deter *competing* jurisdictions from hosting services—if hosting providers in Eastern European nations face U.S. prosecution, will they relocate entirely to Russia, China, or Iran where extradition is impossible, or will costs and risk force the market to consolidate around fewer, more cautious operators?


    The timing also matters. As ransomware attacks accelerate and public pressure mounts on the Biden administration's cybersecurity agenda, prosecuting infrastructure operators provides visible enforcement action without requiring the extradition that makes direct operator prosecutions nearly impossible. It's a realistic pivot—not eliminating ransomware, but making it more expensive and operationally disruptive. Organizations should expect ransomware operations to shift tactics (more targeted attacks, higher ransom demands, faster encryption) rather than disappear.


    HackWire Editorial


    ---


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)