Belarusian national Maksim Silnikau was sentenced in federal court in Alexandria, Virginia, to 16 years in prison for creating and operating the Ransom Cartel ransomware-as-a-service operation. U.S. prosecutors said Silnikau launched the scheme in May 2021, later rebranding it as Ransom Cartel, and recruited affiliates through underground Russian-language forums while seeking access to non-CIS corporate networks. He allegedly supplied stolen credentials, encryption tools, and a hidden management panel, and coordinated attacks and ransom negotiations through infrastructure he controlled.
Authorities said Ransom Cartel affiliates attacked at least 18 companies in the United States and abroad between 2021 and 2023, stealing corporate data and attempting to extort at least $5.2 million, with known victim losses exceeding $6.7 million. Prosecutors also said Silnikau worked with initial access brokers and laundered ransom proceeds through cryptocurrency mixers. He was arrested in Spain in 2023, briefly fled while awaiting extradition, was later captured near the Poland-Belarus border, and extradited to the United States; a separate federal case in New Jersey tied to the Angler Exploit Kit and co-defendants Volodymyr Kadariya and Andrei Tarasov remains pending.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On August 5, a federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison for conspiracy offenses tied to creating and operating Ransom Cartel. The Justice Department said the group attacked at least 18 companies between 2021 and 2023 and caused more than $6.7 million in known victim losses.
After being extradited from Poland, Maksim Silnikau made his initial appearance in Newark, New Jersey to face cybercrime charges in New Jersey and Virginia. The Justice Department said the cases covered both the long-running malvertising scheme and the Ransom Cartel ransomware operation.
After fleeing while awaiting extradition and later being apprehended near the Poland-Belarus border, Silnikau was extradited from Poland to the United States in August 2024. He was sent to face prosecution in the Eastern District of Virginia.
The indictment against Silnikau was unsealed in 2024, making details of the Ransom Cartel case public. The filing described the operation's origins, advertising, and affiliate structure.
One source notes that Yaroslav Vasinskyi received a sentence of 13 years and seven months in 2024 for more than 2,500 REvil attacks and over $700 million in ransom demands. The reference uses this as a comparison point for Silnikau's sentence.
Silnikau was arrested in Spain on July 18, 2023, as part of an international law enforcement operation. Prosecutors later said the arrest stalled Ransom Cartel's growth.
The indictment in the Virginia case was returned in June 2023. It charged Silnikau's role in creating and operating the Ransom Cartel ransomware-as-a-service scheme.
In May 2023, Ransom Cartel attacked infrastructure used by a group of law firms. The disruptions lasted from several days to multiple months, and two firms paid ransoms of $125,000 and $300,000 after prolonged outages.
The last charged act in the conspiracy occurred on April 25, 2023, when Silnikau negotiated terms for supplying computers to be locked. This marked the latest specific act cited in the indictment.
In an October 2022 report, Unit 42 assessed that Ransom Cartel likely had access to older versions of REvil source code based on substantial overlaps in malware configuration, encryption workflow, ransom notes, and file footer format. The report also documented the group's tactics, including use of compromised credentials, credential theft tools, and encryption of Windows and Linux ESXi systems.
In August 2022, a Ransom Cartel attack disrupted a medical technology startup developing robotic surgical technology for two months. The incident was cited by prosecutors as part of the group's victim impact.
Prosecutors said the operation was renamed Ransom Cartel in late 2021, and one source states it launched publicly in December 2021. Researchers later noted code similarities with REvil.
An indictment preserved a May 4, 2021 advertisement on a Russian-language cybercrime forum seeking access to corporate networks outside the CIS. The post set victim-size criteria and said access prices started at $100.
Court documents said Maksim Silnikau began developing the ransomware operation in May 2021, initially under another name. Prosecutors said he recruited affiliates and built the service around ransomware tooling and stolen access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.