Ransom Cartel is a ransomware family distributed through a ransomware-as-a-service operation publicly launched in December 2021. It targets Windows systems and Linux-based VMware ESXi environments and uses double extortion, combining file encryption with data theft and threats to disclose stolen information. Victims have included organizations in education, manufacturing, utilities, energy, legal services, and medical technology in the United States and other countries. The operation also threatened to send sensitive information directly to victims’ partners, competitors, and news organizations.
Affiliates obtain initial access through compromised credentials for externally accessible RDP, SSH, and VPN services, including access purchased from initial access brokers. Observed intrusions involved DonPAPI, Mimikatz, and LaZagne for credential theft; network discovery and scanning utilities; remote-access software; Cobalt Strike for command and control; and Rclone for exfiltration. Attackers used PrintNightmare vulnerabilities for privilege escalation and SSH and RDP for lateral movement. In ESXi environments, they harvested browser-stored vCenter credentials, enabled SSH, created root-equivalent accounts for persistent access, and shut down virtual machines before encrypting their associated data.
The ransomware uses Salsa20 for file encryption and Curve25519-based key exchange, with SHA3 and AES used in session-secret handling. Its encrypted configuration specifies encryption exclusions, ransom-note contents, and processes and services to terminate, including backup, database, email, and security software. Windows variants can enable Safe Boot, and observed attack activity included event-log clearing. Ransom Cartel shares substantial technical similarities with REvil in its configuration structure, encryption workflow, session-secret generation, and early ransom notes, while employing considerably less obfuscation.
Maksim Silnikau created and administered the operation, recruited affiliates through Russian-speaking cybercrime forums, and supplied stolen credentials and encryption tools. An affiliate portal supported attack coordination, victim negotiations, and distribution of proceeds. Ransom Cartel attacks affected at least 18 companies between 2021 and 2023. Silnikau’s arrest in July 2023 disrupted the operation, and he was subsequently sentenced in the United States to 16 years in prison.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The PrintNightmare exploit (CVE-2021-1675, CVE-2021-34527 and CVE-2021-34481) was used for privilege escalation.
The PrintNightmare exploit (CVE-2021-1675, CVE-2021-34527 and CVE-2021-34481) was used for privilege escalation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Believed to have launched in December 2021, Ransom Cartel has made victims of organizations from among the education, manufacturing, utilities, and energy sectors with aggressive malware and tactics that resemble those used by REvil.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Silnikau, along with alleged co-conspirators ... are charged with cybercrime offenses associated with a scheme to transmit the Angler Exploit Kit, other malware, and online scams to the computers of millions of unsuspecting victim internet users through online advertisements — so-called “malvertising” — and other means
Он активно вербовал других киберпреступников на русскоязычных хак-форумах для участия в атаках и партнерской RaaS-программе ..., снабжал их инструментами и украденными учетными данными для доступа к корпоративным системам.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor. However, the lack of some of REvil's obfuscation features led researchers to believe that it may have been created by a former core member of the operation...
The hackers removed confidential data without authorization and demanded a monetary payment to refrain from releasing the victim’s data.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned only as a comparison to other U.S. prosecutions; the article provides no technical or operational details.
Named ransomware operation mentioned only as a separate, comparative criminal-sentencing case; no technical behavior is described.
Suspected REvil spinoff ransomware operation with tooling similarities to REvil's original codebase.
Ransomware used by the Ransom Cartel group to steal corporate data, encrypt systems, and extort victims for decryption or to prevent publication of stolen information. The operation also provided tooling, stolen credentials, and an affiliate panel for managing attacks and ransom negotiations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.