Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison — Threadlinqs Intelligence
As of 2026-08-05, Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison is a high-severity ransomware threat attributed to Ransom Cartel, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1902 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Ransom Cartel · FINANCIAL
Maksim Silnikau, a 40-year-old Belarusian national and creator of the Ransom Cartel ransomware, was sentenced to 16 years in federal prison on August 5, 2026, for conspiracy to commit offenses against
On August 5, 2026, U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia sentenced Maksim Silnikau (40, Belarusian national) to 16 years in federal prison for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Silnikau, known on Russian-language cybercrime forums since at least 2005 under the aliases "J.P. Morgan," "xxx," and "lansky," was the creator and administrator of the Ransom Cartel ransomware operation. He was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation, fled while awaiting extradition, and was recaptured while attempting to cross from Poland into Belarus before consenting to extradition to the United States.
Ransom Cartel launched publicly in December 2021 as a ransomware-as-a-service (RaaS) operation. Silnikau began developing the ransomware in May 2021, recruiting affiliates through underground forums, maintaining an affiliate website where members could manage attacks, negotiate ransoms, and split proceeds, and routing ransom payments through cryptocurrency mixers to obscure fund trails. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide spanning California, New York, Nebraska, and international locations. Notable attacks included an August 2022 breach of a medical technology startup developing robotic surgical tools that suffered two months of operational disruption, and a May 2023 attack on infrastructure used by a group of law firms causing disruptions ranging from days to months. One law firm paid a $125,000 ransom after nearly a month of disruption, and another paid $300,000 after suspending operations for almost a month. Combined losses from the law firm attacks totaled approximately $2.2 million.
Technical analysis by Palo Alto Networks Unit 42 revealed that Ransom Cartel shares substantial code-level similarities with the REvil (Sodinokibi) ransomware. Both encryptors use Salsa20 symmetric encryption combined with Curve25519-Donna elliptic curve Diffie-Hellman for key exchange, employ an identical 232-byte encrypted file footer structure, and share a nearly identical JSON configuration format. The session secret generation procedure is identical, and the samples contain three matching exports: Rathbuige, ServiceMain, and SvchostPushServiceGlobals. However, Ransom Cartel lacks REvil's heavy obfuscation (no string encryption, no API hashing), suggesting the operators possessed the core encryptor source code but not the full obfuscation engine, likely building from an earlier or stripped-down version of REvil. The first ransom note variant (January 2022) was nearly identical to REvil's notes in formatting and language, while a second variant (August 2022) was completely rewritten.
Ransom Cartel operated as a double-extortion RaaS, encrypting victim data and exfiltrating it for public release on a data leak site. The group uniquely escalated pressure by threatening to send stolen data to victims' partners, competitors, and news media. Initial access was primarily achieved through compromised credentials (VPN, RDP, SSH, Citrix) often purchased from initial access brokers. For privilege escalation, affiliates exploited the PrintNightmare vulnerability (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481). The toolset included DonPAPI for DPAPI credential dumping (targeting Wi-Fi keys, RDP passwords, browser credentials, Windows Credential Manager, and AdConnect secrets), Mimikatz and LaZagne for credential theft, Cobalt Strike for C2, PDQ Inventory (cracked) for network reconnaissance, Advanced Port Scanner and netscan.exe for network discovery, AnyDesk for remote access, Putty for SSH connections, BITSAdmin and PowerShell for payload retrieval, Rclone for data exfiltration to cloud storage (PCloud, MegaSync), and 7-Zip for data compression. Post-compromise, the ransomware terminates 43 targeted processes (including backup agents, d
Target sectors: education, manufacturing, utilities, energy, health, legal
Target regions: North America, Europe
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2021-1675, CVE-2021-34527, CVE-2021-34481, T1078, T1190, T1059, T1098, T1027, T1112, T1562, T1003, T1555, T1046