The U.S. Department of State is offering up to $2.5 million for information leading to the arrest or conviction of Belarusian national Volodymyr Kadariya, who is accused of participating in a worldwide malware and malvertising operation. Authorities allege the organization distributed the Angler Exploit Kit, other malware and online scams from October 2013 through March 2022. Angler was at times a leading mechanism for delivering malware to compromised devices. Kadariya was indicted in the District of New Jersey on June 14, 2023, on conspiracy to commit wire fraud, conspiracy to commit computer fraud and two substantive wire fraud counts. Andrei Vladimirovich Tarasov and Maksim Silnikau are named as co-defendants in the alleged operation, which infected computers and sold stolen data and access.
Tarasov, known online as Aels and Lavander, was arrested in Germany in July 2023 but released in January 2024 after prosecutors concluded the U.S. charges were insufficiently concrete for extradition. The charges remain outstanding. Intel 471 reported in May 2025 that Tarasov was back in Russia and continued participating in cybercrime and spamming communities, including an earlier sale of compromised Zimbra server access and a May 2025 request for ways to compromise Zimbra servers at scale. His reported location and claims of helping the FBI identify cybercriminals remain partly or wholly unverified, but the reported Zimbra activity indicates continued interest in compromising enterprise email infrastructure.

See the reporting duties and controls this puts on the clock.
21 events from the most recent confirmed update back to the earliest known activity.
Lavander, identified as Aels, posted that he needed a way to hack Zimbra servers at scale.
The forum persona Lavander identified himself as Aels and claimed that he had returned to Russia through Poland and Kaliningrad before flying to Moscow. Intel 471 could not independently reproduce a separate forum claim concerning his border-crossing record.
Silnikau was extradited from Poland to the United States to face criminal proceedings.
The Kammergericht affirmed the decision underlying Tarasov's release.
Tarasov was released after Berlin prosecutors concluded that the U.S. charges were insufficiently concrete to support extradition.
International law enforcement arrested Silnikau in Estepona, Spain.
German police arrested Tarasov in Berlin and detained him in Moabit Prison for approximately six months.
Aels stated on the XSS forum that authorities had approached him about past wrongdoing and a U.S. case, shortly before his arrest.
A New Jersey grand jury indicted Tarasov, Silnikau, and Kadariya over the alleged malvertising operation. The charges included conspiracy to commit wire fraud, conspiracy to commit computer fraud and abuse, and two substantive wire fraud counts.
Aels offered to sell a manual about Microsoft Outlook spamming.
Aels auctioned web-shell access to 758 corporate Zimbra Collaboration Suite email servers, allegedly affecting more than 100,000 email accounts. The compromises reportedly exploited the CVE-2022-37042 authentication-bypass vulnerability.
A separate Eastern District of Virginia indictment alleges that Silnikau administered Ransom Cartel and other ransomware operations beginning in May 2021.
According to the indictment, Tarasov discussed a browser-locking extortion mechanism with Silnikau in June 2017.
Aels offered to sell a Microsoft Word remote-code-execution vulnerability based on a recently disclosed Microsoft Office zero-day.
Prosecutors allege that Tarasov, Maksim Silnikau, and Volodymyr Kadariya operated a malware-distribution scheme from October 2013 through March 2022, targeting millions of computers. The operation allegedly used malicious advertisements to deliver Angler and other malware, then sold compromised access and stolen data.
Around 2010, Andrei Tarasov's Aels persona joined Russian-speaking cybercrime communities and participated in discussions involving carding, malware spamming, vulnerability exploitation, and malicious traffic.
The U.S. State Department offered up to $2.5 million for information leading to Kadariya's arrest or conviction in any country over his alleged involvement in the malware operation.
Following his release in Spain, Silnikau was arrested in Poland before being extradited to the United States.
Spanish authorities released Silnikau following his arrest in Estepona. He was subsequently arrested in Poland.
The XSS persona Tagesanzeiger organized legal-defense donations and circulated a video confirmed by attorney Arkady Bukh, a court document, and a purported Tarasov letter. Intel 471 could not authenticate the letter.
The indictment alleges that Tarasov agreed to develop a $2,500 traffic distribution system for Kadariya. The system would selectively display malicious advertisements to reduce blocking and hinder researchers tracking the campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.