A federal court in Alexandria, Virginia, has sentenced Maksim Silnikau, a 40-year-old Belarusian national, to 16 years in prison for his role in creating and operating the Ransom Cartel ransomware-as-a-service (RaaS) operation. Between 2021 and 2023, Ransom Cartel affiliates targeted at least 18 companies across the United States, including firms in California, New York, and Nebraska, as well as organizations abroad.
Silnikau, known online by aliases such as “J.P. Morgan,” “lansky,” and “xxx,” did not personally execute most of these cyber intrusions. Instead, he developed and managed the infrastructure that facilitated these attacks. This included the ransomware software, procurement of stolen credentials from initial access brokers, and a concealed platform where affiliates could oversee attacks, negotiate with victims, and distribute ransom proceeds. He also implemented a rating system to incentivize affiliates and utilized cryptocurrency mixers to obscure the financial trails of ransom payments.
The 16-year sentence surpasses the 13 years and seven months handed down to Yaroslav Vasinskyi in 2024 for his involvement in over 2,500 REvil ransomware attacks, which demanded more than $700 million in ransoms. Silnikau’s sentencing addresses only part of the legal actions against him; a separate federal case in New Jersey remains unresolved, with two co-defendants still at large.
Prosecutors in Virginia charged Silnikau with seven counts, resulting in convictions on three. The announcement did not specify restitution or forfeiture amounts, nor did it clarify whether Silnikau pleaded guilty or was convicted at trial.
There has been some discrepancy regarding the inception of Ransom Cartel. Prosecutors trace its origins to May 2021, while cybersecurity firm Palo Alto Networks’ Unit 42 first identified the operation in mid-January 2022. According to the indictment, Silnikau initially operated under a different name starting in May 2021, rebranding to “Ransom Cartel” later that year and attempting to publicize the operation through security news outlets.
The indictment also includes a May 4, 2021, advertisement posted by the conspiracy on a Russian-language cybercrime forum. The ad sought access to corporate networks outside the Commonwealth of Independent States, specifying a minimum revenue of $10 million and offering prices starting at $100.
The final charged act occurred on April 25, 2023, when Silnikau negotiated terms for supplying computers to be infected, just three months before his arrest in July 2023. He was extradited from Poland to the United States in August 2024.
While some have speculated about connections between Ransom Cartel and the notorious REvil ransomware group, Unit 42’s 2022 analysis indicated that Ransom Cartel operators possessed the original REvil source code but lacked the obfuscation engine used by REvil. The researchers suggested a possible link between the groups but did not confirm a direct rebranding. Neither the indictment nor the sentencing announcement referenced REvil.
Silnikau also faces separate charges in New Jersey related to the Angler Exploit Kit malvertising scheme, which operated from 2013 to 2022. This case involves co-defendants Volodymyr Kadariya and Andrei Tarasov, who remain at large. The U.S. Secret Service continues to list Tarasov as wanted, and the State Department is offering a reward of up to $2.5 million for information leading to Kadariya’s arrest or conviction.
This sentencing underscores the persistent threat posed by ransomware operations and the importance of international cooperation in bringing cybercriminals to justice. Organizations must remain vigilant, implementing robust cybersecurity measures and staying informed about evolving threats to protect against such sophisticated attacks.