Ransom Cartel is a ransomware-as-a-service operation publicly launched in late 2021 and created by Belarusian cybercriminal Maksim Silnikau, also known by aliases including J.P. Morgan, xxx, and lansky. The group recruited affiliates through Russian-speaking cybercrime forums and operated a partner model in which the administrator supplied ransomware tooling, stolen credentials, and access support while affiliates conducted intrusions against victim organizations. Ransom Cartel targeted businesses in the United States and other countries between 2021 and 2023. Documented operations involved unauthorized access to corporate networks, theft of sensitive data, encryption of victim systems, and extortion demands for either decryption or non-publication of stolen information. The operation maintained hidden infrastructure and an affiliate panel used to coordinate attacks, communicate with co-conspirators, negotiate with victims, and distribute ransom proceeds. Investigators also linked the group to cooperation with initial access brokers and laundering of ransom payments through cryptocurrency mixing services. The group is associated with at least 18 victim organizations worldwide and caused multimillion-dollar losses. Reported victim sectors include medical technology and legal services, and known U.S. victims included organizations in California, New York, and Nebraska. Security researchers observed technical similarities between the Ransom Cartel encryptor and REvil, although public reporting did not conclusively establish that Ransom Cartel was a direct successor to REvil. The operation was significantly disrupted following Silnikau’s 2023 arrest and subsequent extradition to the United States.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS-вымогательская группировка, проводившая атаки как минимум против 18 организаций в США и других странах в 2021–2023 годах, похищала корпоративные данные, шифровала системы и вымогала выкуп за расшифровку и непубликацию украденной информации.
Ransomware-as-a-service operation developed by Maksim Silnikau, recruiting affiliates via underground forums, providing stolen credentials and encryption tools, coordinating attacks and ransom negotiations through an affiliate site, and collaborating with initial access brokers while laundering proceeds through cryptocurrency mixers.
A ransomware-as-a-service operation created in 2021 by Maksim Silnikau that provided affiliates with stolen credentials, ransomware, and a hidden panel to monitor attacks, negotiate ransoms, and split proceeds. From 2021 to 2023, its conspirators attacked at least 18 companies worldwide and used data theft plus ransom demands, including promises not to publish stolen data.
Ransomware-as-a-service operation developed and administered by Maksim Silnikau. Affiliates targeted businesses, stole sensitive data before encryption, negotiated ransom payments, and used hidden infrastructure to coordinate attacks and distribute proceeds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.