Visualização de leitura

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

Ransom Cartel ransomware

A Ransom Cartel ransomware leader has been sentenced to 16 years in prison after being convicted of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft, according to the U.S. Department of Justice. Maksim Silnikau, a 40-year-old Belarusian national, was identified in court documents as the creator and administrator of the Ransom Cartel ransomware strain, which was developed in 2021. Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and was also a member of the cybercrime website Direct Connection between 2011 and 2016.

Ransom Cartel Ransomware Operation

Beginning in May 2021, Silnikau developed the ransomware scheme and recruited participants through cybercrime forums. He distributed information and tools to participants, including stolen credentials linked to compromised computers and tools designed to encrypt or lock those systems. Silnikau also maintained a hidden website used by himself and his co-conspirators to monitor and control ransomware operations. According to the court documents, the website provided a platform for the group to communicate with one another, interact with victims, send and negotiate ransom demands, and manage the distribution of funds among the conspirators. The operation targeted companies between 2021 and 2023. During that period, Ransom Cartel ransomware conspirators carried out attacks against at least 18 companies around the world, including organizations based in California, New York, Nebraska, and other countries outside the United States.

Ransomware Attacks Targeted Companies Worldwide

The ransomware attacks involved data theft and monetary demands. The attackers sought payment in exchange for providing keys to unlock stolen data or for promises not to publish the information taken from victims. The operation’s growth was disrupted following Silnikau’s arrest in July 2023. He was later extradited from Poland to face prosecution in the Eastern District of Virginia and the District of New Jersey. The sentencing announcement was made by Theophani K. Stamos, First Assistant U.S. Attorney for the Eastern District of Virginia; Acting Special Agent in Charge Andrew Forrest of the U.S. Secret Service Criminal Investigative Division; Chris Ormerod, Special Agent in Charge of the FBI Kansas City Field Office; and Craig L. Tremaroli, Special Agent in Charge of the FBI Albany Field Office.

Maksim Silnikau Sentenced to 16 Years

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence. The U.S. Attorney’s Office for the District of New Jersey and the Computer Crime and Intellectual Property section also assisted with the case. Assistant U.S. Attorney Jonathan S. Keim and former Assistant U.S. Attorney Zoe Bedell prosecuted the case. The 16 years in prison sentence follows the disruption of an international ransomware operation that targeted at least 18 companies during its active period. Silnikau’s role, according to court documents, extended across the development and administration of the ransomware strain, recruitment of participants, provision of attack tools, victim communications, and management of funds generated through the operation.

Ransom Cartel Leader Sentenced to 16 Years in U.S.

A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation.

Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia handed the 40-year-old Belarusian 16 years in prison for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

“According to court documents, Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware strain, created in 2021.” reads the press release published by DoJ. “Silnikau had been a member of Russian-speaking cybercrime forums since at least 2005 and was a member of the notorious cybercrime website Direct Connection from 2011 to 2016, when the site was shuttered after the arrest of its administrator.”

Silnikau wasn’t new to this world when he launched it. He’d been active on Russian-speaking cybercrime forums since at least 2005, and spent five years, from 2011 to 2016, embedded in Direct Connection, one of the more notorious cybercrime sites of that era, until police arrested its administrator and shut it down. Ransom Cartel, in other words, was the work of someone who’d already spent over a decade learning how this economy runs.

What he actually built was infrastructure, not intrusions. He supplied participants with stolen credentials and locking software, then ran a hidden site where affiliates monitored ongoing attacks, negotiated ransom demands with victims, and split the proceeds among themselves. That hidden panel was the real product: Silnikau wasn’t selling malware, he was selling a functioning business.

Between 2021 and 2023, Ransom Cartel conspirators hit at least 18 companies, spanning California, New York, Nebraska, and targets outside the US entirely. The pitch to would-be affiliates, preserved in the indictment, set a floor on what kind of victims were worth their time: “Revenue: from $10 million. Prices from $100 and up.” That’s not a hacker fishing for any target that’ll bite; that’s someone running numbers on which victims can actually afford to pay.

“From 2021 to 2023, Silnikau’s Ransom Cartel conspirators executed ransomware attacks on at least 18 companies around the world, including companies based in California, New York, Nebraska, and countries other than the United States.” continues the press release. “The hackers stole data and demanded monetary payments in exchange for the key to unlock the stolen data, or in exchange for a promise not to publish the victim’s data. Ransom Cartel’s growth was disrupted by the arrest of Silnikau in July 2023.”

Silnikau’s arrest in July 2023 is what stalled the operation’s growth, according to prosecutors. Poland extradited him to face charges in the Eastern District of Virginia roughly a year later, in August 2024.

Sixteen years sounds like a lot until you set it against Yaroslav Vasinskyi’s 13 years and seven months for running over 2,500 REvil attacks worth more than $700 million in demands back in 2024. Ransom Cartel’s scale was smaller, but the sentence landed heavier, which says something about how prosecutors and judges are calibrating these cases as the pattern repeats.

This Virginia case is only half the story, and the DOJ’s own announcement doesn’t mention the other half. Silnikau faces a separate, unresolved prosecution in New Jersey over the Angler Exploit Kit malvertising scheme, which ran from 2013 to 2022 alongside two co-defendants, Volodymyr Kadariya and Andrei Tarasov, both still at large. The Secret Service still lists Tarasov as wanted, and the State Department has a $2.5 million reward out for information leading to Kadariya.

Belarusian cybercriminal involved in the mass malware distribution Ransom Cartel

There’s also a lingering question researchers never fully resolved: whether Ransom Cartel was connected to REvil at all. Palo Alto Networks’ Unit 42 found the operators holding REvil’s original source code but apparently missing the obfuscation engine that gang relied on, and speculated the two groups crossed paths at some point without ever calling it a rebrand. Neither the indictment nor this week’s sentencing announcement brings up REvil once, so that thread stays exactly where it’s always been: interesting, unresolved, and somebody else’s problem to chase down.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ransom Cartel)

❌