Ransom Cartel is a ransomware-as-a-service operation that emerged in late 2021 and conducted double-extortion attacks against organizations in the United States and other countries. The malware and its operators have been linked to intrusions against at least 18 companies between 2021 and 2023, with victims spanning sectors including education, manufacturing, utilities and energy, legal services, and medical technology. Public reporting and court records identify Maksim Silnikau as the creator and administrator of the operation, which recruited affiliates through Russian-speaking cybercrime forums and worked with initial access brokers to obtain access to victim environments.
Ransom Cartel is notable for substantial technical overlap with REvil. Researchers assessed that the malware likely derived from an older REvil codebase or was developed by actors with access to earlier REvil source code, while lacking some of REvil’s more advanced obfuscation components. The ransomware’s configuration structure, ransom-note logic, session secret generation, and encryption workflow have all been reported as closely resembling REvil.
Observed intrusions show Ransom Cartel commonly gaining entry through compromised credentials for external remote services and then performing credential theft, reconnaissance, lateral movement, and data exfiltration before encryption. Operators have used tooling associated with credential recovery and post-compromise network operations, targeted both Windows systems and Linux-based VMware ESXi servers, and in some cases enabled remote administration features or created privileged accounts to maintain access. On virtualized environments, the actors have been observed shutting down virtual machines prior to encrypting ESXi-related data.
The operation followed a classic double-extortion model: affiliates stole corporate data, encrypted victim systems, and demanded payment either for decryption or for promises not to publish stolen information. Ransom Cartel also used aggressive pressure tactics, including threats to leak data to third parties and the media. The broader criminal service included affiliate management infrastructure used to coordinate attacks, communicate with victims, negotiate ransom demands, and distribute proceeds among participants. Authorities have also linked the operation to the use of cryptocurrency mixers to hinder tracing of ransom payments.
Ransom Cartel’s activity was reportedly disrupted after Silnikau’s arrest in 2023, but the malware remains a significant example of post-REvil ransomware evolution and of the continued reuse and adaptation of established ransomware code within the cybercriminal ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TA0004 Privilege Escalation T1068. Exploitation for Privilege Escalation Exploits Print Nightmare vulnerability. | Executive Summary Ransom Cartel is ransomware as a service (RaaS) that surfaced in mid-December 2021. This ransomware performs double extortion attacks and exhibits several similarities and technical overlaps with REvil ransomware.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Silnikau, along with alleged co-conspirators ... are charged with cybercrime offenses associated with a scheme to transmit the Angler Exploit Kit, other malware, and online scams to the computers of millions of unsuspecting victim internet users through online advertisements — so-called “malvertising” — and other means
Он активно вербовал других киберпреступников на русскоязычных хак-форумах для участия в атаках и партнерской RaaS-программе ..., снабжал их инструментами и украденными учетными данными для доступа к корпоративным системам.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor. However, the lack of some of REvil's obfuscation features led researchers to believe that it may have been created by a former core member of the operation...
The hackers removed confidential data without authorization and demanded a monetary payment to refrain from releasing the victim’s data.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used by the Ransom Cartel group to steal corporate data, encrypt systems, and extort victims for decryption or to prevent publication of stolen information. The operation also provided tooling, stolen credentials, and an affiliate panel for managing attacks and ransom negotiations.
Ransom Cartel is a ransomware-as-a-service operation developed by Maksim Silnikau. It recruited affiliates via underground forums, supplied stolen credentials and encryption tools, coordinated attacks and ransom negotiations through an affiliate site, and used initial access brokers and cryptocurrency mixers to support extortion operations.
Ransom Cartel is a ransomware strain created and operated by Maksim Silnikau and co-conspirators. It was used to attack at least 18 companies, disrupt victim operations, encrypt compromised computers, and extort payments from victims.
A ransomware-as-a-service operation created in 2021 whose operators and affiliates conducted attacks, stole data, demanded payment for decryption keys, and extorted victims by threatening to publish stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.