Ransom Cartel is a financially motivated ransomware-as-a-service operation created by Belarusian cybercriminal Maksim Silnikau. Development began in May 2021, and the operation launched publicly in December 2021. It recruited affiliates through Russian-speaking cybercrime forums, supplied stolen credentials and ransomware tools, and maintained an affiliate portal for coordinating attacks, negotiating ransom demands, and distributing proceeds. Its targets have included manufacturing, education, utilities, energy, medical technology, and legal services organizations in the United States and other countries. Affiliates obtain initial access through stolen RDP, SSH, and VPN credentials, including access purchased from initial access brokers. Intrusions involve credential dumping with DonPAPI, LaZagne, and Mimikatz; network discovery and scanning; remote-access tools; Cobalt Strike; and Rclone for data exfiltration. Attackers have exploited PrintNightmare vulnerabilities for privilege escalation and used compromised VMware vCenter credentials to access ESXi hosts, enable SSH, and create root-equivalent accounts for persistent access. The ransomware targets Windows systems and VMware ESXi environments. Ransom Cartel uses double extortion, combining encryption with threats to publish stolen information on a leak site, and has also threatened to distribute sensitive data to victims' partners, competitors, and news outlets. Its ransomware shares encryption and configuration characteristics with REvil, but Ransom Cartel is not established as the same organization or a direct successor. Between 2021 and 2023, Ransom Cartel attacked at least 18 organizations worldwide, with identified victim losses exceeding $6.7 million. Silnikau's arrest in July 2023 disrupted the operation. He was extradited from Poland to the United States in August 2024 and sentenced to 16 years in prison in August 2026. His online aliases included J.P. Morgan, xxx, and lansky; these identify the administrator rather than alternative names for the group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The PrintNightmare exploit (CVE-2021-1675, CVE-2021-34527 and CVE-2021-34481) was used for privilege escalation.
The PrintNightmare exploit (CVE-2021-1675, CVE-2021-34527 and CVE-2021-34481) was used for privilege escalation.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison to other ransomware-related prosecutions.
Mentioned only as a separate ransomware-related prosecution involving its creator and administrator.
Suspected REvil spinoff using tooling similar to REvil's original codebase.
RaaS-вымогательская группировка, проводившая атаки как минимум против 18 организаций в США и других странах в 2021–2023 годах, похищала корпоративные данные, шифровала системы и вымогала выкуп за расшифровку и непубликацию украденной информации.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.