Two major leak-driven investigations detailed how criminal and state-aligned cyber operations are enabled by supporting ecosystems. Internal chat logs attributed to the BlackBasta ransomware group—reportedly ~200,000 messages in a leaked JSON archive—were followed by a separate database leak tied to Media Land, which investigators linked to Yalishanda, a long-running bulletproof hosting provider allegedly used to support ransomware infrastructure (including server configurations, customer records, user accounts, and cryptocurrency wallet data). Separately, a large leak from Beijing-based security firm KnownSec was reported to expose a “vertically integrated” contractor model supporting China’s Ministry of Public Security, including the ZoomEye internet intelligence platform integrated with a classified “TargetDB” and references to offensive tooling (e.g., GhostX) used for reconnaissance, intrusion, and persistence.
Other items in the set were not about these leak-driven exposures and instead covered unrelated topics: a PR firm’s Wikipedia manipulation (disinformation), a Citizen Lab job posting, generic ransomware resilience guidance, a general cyber-attacks timeline, a vendor’s 2026 threat landscape outlook, a law-enforcement disruption of a ransomware crew in Ukraine/Germany, a podcast on vulnerability management/incident response, an Olympics cybersecurity risk report, German legislative proposals expanding BND hacking/surveillance powers, and a malware-newsletter link roundup. Those references do not materially add to the specific story of the BlackBasta/Yalishanda infrastructure leaks or the KnownSec leak and should be treated as separate reporting streams.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The leaked KnownSec materials described ZoomEye feeding a classified TargetDB that allegedly tracked more than 24,000 organizations and 378 million IP addresses across 26 regions. They also identified tools including GhostX, Un-Mail, and Passive Radar, along with an offensive research unit called 404 Lab and a breached-credential data lake.
By January 2026, leaked internal KnownSec documents reportedly revealed how the Beijing-based firm supported China's Ministry of Public Security and other state entities with offensive cyber capabilities. The materials described a vertically integrated system for reconnaissance, intrusion, and long-term surveillance.
On November 19, 2025, OFAC, coordinated with Australia and the United Kingdom, sanctioned Media Land and its subsidiary Data Center Kirishi. The action also identified Aleksandr Volosovik and Kirill Zatolokin as key individuals supporting the infrastructure.
In March 2025, a second leak released a database associated with Media Land, a seemingly legitimate Russian business. The data reportedly revealed infrastructure and customer details connecting Media Land to ransomware operations and to Yalishanda.
In February 2025, a Telegram user named ExploitWhispers leaked BlackBasta's internal communications, publishing a JSON archive of about 200,000 messages. The leak reportedly exposed real-world identities and operational details linked to the ransomware group.
The exposed JSON archive of roughly 200,000 BlackBasta messages extended through September 2024. The material reportedly documented the group's infrastructure use and internal coordination over that period.
A large archive of BlackBasta internal communications that was later exposed covered messages from September 2023 through September 2024. These chats reportedly revealed operational details and identities tied to the ransomware group.
The leaked reporting says Yalishanda had been operating since late 2009, allegedly providing hosting and technical support that later enabled ransomware activity. It was described as part of the infrastructure layer supporting groups such as BlackBasta.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.