VYPR
breachPublished Aug 6, 2026· 2 sources

Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation

Maksim Silnikau, the architect behind the Ransom Cartel ransomware-as-a-service (RaaS) operation, has received a 16-year prison sentence for his role in facilitating attacks against at least 18 companies globally.

Maksim Silnikau, the creator and operator of the Ransom Cartel ransomware-as-a-service (RaaS) platform, has been sentenced to 16 years in federal prison. The sentencing, handed down on August 5th in Alexandria, Virginia, marks a significant judicial outcome for the Belarusian national who operated under various aliases including "J.P. Morgan," "lansky," and "xxx."

Launched in 2021, the Ransom Cartel operation was utilized by its affiliates to conduct attacks against a minimum of 18 companies worldwide between 2021 and 2023. These targets spanned across the United States, including firms in California, New York, and Nebraska, as well as international entities. Silnikau's role was not typically direct exploitation but rather the provision of the infrastructure and tools necessary for these attacks.

Silnikau built a comprehensive RaaS business model. This included developing the ransomware software itself, acquiring initial access credentials from other cybercriminals, and maintaining a private panel for affiliates. This panel served as a central hub for affiliates to monitor their ongoing attacks, negotiate ransom payments with victims, and manage the distribution of profits. He further incentivized affiliates through a rating system that rewarded more successful attackers and employed cryptocurrency mixers to obscure the illicit financial flows.

The sentencing of Silnikau to 16 years is notably longer than that of Yaroslav Vasinskyi, who received 13 years and seven months for his involvement in the REvil attacks. However, Silnikau's case is not fully resolved, as a separate federal prosecution in New Jersey against him and two other individuals remains pending, with those co-defendants still at large.

Prosecutors have detailed that the Ransom Cartel operation began in May 2021, although security researchers like Palo Alto Networks' Unit 42 did not observe its activity until mid-January 2022. An indictment unsealed in 2024 revealed that Silnikau initially ran the operation under a different name before rebranding it as "Ransom Cartel" in late 2021 and actively seeking publicity. His conspiracy posted advertisements on cybercrime forums seeking access to corporate networks outside the Commonwealth of Independent States, specifying revenue thresholds of $10 million and minimum payment offers of $100.

The last charged activity linked to Silnikau occurred on April 25, 2023, involving negotiations for supplying compromised systems for ransomware deployment. His arrest in July 2023 is believed to have significantly hampered Ransom Cartel's operations. Following his extradition from Poland to the United States in August 2024, the judicial proceedings have now concluded with his sentencing.

While some researchers have speculated about potential links between Ransom Cartel and the notorious REvil group due to shared source code elements, neither the indictment nor the sentencing documents explicitly mention REvil. Unit 42's analysis in 2022 found that while Ransom Cartel operators possessed REvil's original source code, they lacked its obfuscation engine, suggesting a possible but not confirmed connection.

Silnikau is also facing charges in a separate New Jersey case alongside Volodymyr Kadariya and Andrei Tarasov, related to the Angler Exploit Kit malvertising scheme that operated from 2013 to 2022. The New Jersey prosecution remains active, with Tarasov still listed as wanted by the Secret Service and a substantial reward offered for information leading to Kadariya's arrest.

The article provides further details on Silnikau's arrest and extradition, noting he was apprehended in Spain and extradited to the US in 2024 from Poland. It also elaborates on his involvement in separate criminal activities, including the distribution of the Angler exploit kit and other malware between 2013 and 2022, alongside international accomplices.

Synthesized by Vypr AI