Threat reportRansomwareTL-2026-1902

Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison

highACTIVE

Ransom Cartel ransomware creator Maksim Silnikau sentenced (TL-2026-1902) is a high-severity ransomware operation, first published 2026-08-05. It is attributed to Ransom Cartel with high confidence, affects VMware ESXi, references 3 CVEs (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481), maps to 17 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
1Ransom Cartel
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1902

Threat ID
TL-2026-1902
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Ransom Cartel
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
education, manufacturing, utilities, energy, health, legal
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
26

Malware and tooling in Ransom Cartel ransomware creator Maksim Silnikau sentenced

Malware and tooling: AnyDesk, Cobalt Strike, MimiKatz, Ransomcartel, Sodinokibi, Advanced Port Scanner, AnyDesk, BITSAdmin - S0190, Cobalt Strike, DonPAPI, LaZagne - S0349, Mimikatz

How Ransom Cartel ransomware creator Maksim Silnikau sentenced works

Maksim Silnikau, a 40-year-old Belarusian national and creator of the Ransom Cartel ransomware, was sentenced to 16 years in federal prison on August 5, 2026, for conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft. Ransom Cartel (publicly launched December 2021, sharing code-level similarities with REvil/Sodinokibi) operated as a ransomware-as-a-service scheme targeting at least 18 companies worldwide, attempting to extort at least $5.2 million with over $6.7 million in identified losses, including a medical technology startup and multiple law firms. Silnikau also operated a separate malvertising scheme distributing the Angler Exploit Kit from 2013 to 2022 with co-conspirators Volodymyr Kadariya and Andrei Tarasov.

On August 5, 2026, U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia sentenced Maksim Silnikau (40, Belarusian national) to 16 years in federal prison for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Silnikau, known on Russian-language cybercrime forums since at least 2005 under the aliases "J.P. Morgan," "xxx," and "lansky," was the creator and administrator of the Ransom Cartel ransomware operation. He was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation, fled while awaiting extradition, and was recaptured while attempting to cross from Poland into Belarus before consenting to extradition to the United States.

Ransom Cartel launched publicly in December 2021 as a ransomware-as-a-service (RaaS) operation. Silnikau began developing the ransomware in May 2021, recruiting affiliates through underground forums, maintaining an affiliate website where members could manage attacks, negotiate ransoms, and split proceeds, and routing ransom payments through cryptocurrency mixers to obscure fund trails. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide spanning California, New York, Nebraska, and international locations. Notable attacks included an August 2022 breach of a medical technology startup developing robotic surgical tools that suffered two months of operational disruption, and a May 2023 attack on infrastructure used by a group of law firms causing disruptions ranging from days to months. One law firm paid a $125,000 ransom after nearly a month of disruption, and another paid $300,000 after suspending operations for almost a month. Combined losses from the law firm attacks totaled approximately $2.2 million.

Technical analysis by Palo Alto Networks Unit 42 revealed that Ransom Cartel shares substantial code-level similarities with the REvil (Sodinokibi) ransomware. Both encryptors use Salsa20 symmetric encryption combined with Curve25519-Donna elliptic curve Diffie-Hellman for key exchange, employ an identical 232-byte encrypted file footer structure, and share a nearly identical JSON configuration format. The session secret generation procedure is identical, and the samples contain three matching exports: Rathbuige, ServiceMain, and SvchostPushServiceGlobals. However, Ransom Cartel lacks REvil's heavy obfuscation (no string encryption, no API hashing), suggesting the operators possessed the core encryptor source code but not the full obfuscation engine, likely building from an earlier or stripped-down version of REvil. The first ransom note variant (January 2022) was nearly identical to REvil's notes in formatting and language, while a second variant (August 2022) was completely rewritten.

Ransom Cartel operated as a double-extortion RaaS, encrypting victim data and exfiltrating it for public release on a data leak site. The group uniquely escalated pressure by threatening to send stolen data to victims' partners, competitors, and news media. Initial access was primarily achieved through compromised credentials (VPN, RDP, SSH, Citrix) often purchased from initial access brokers. For privilege escalation, affiliates exploited the PrintNightmare vulnerability (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481). The toolset included DonPAPI for DPAPI credential dumping (targeting Wi-Fi keys, RDP passwords, browser credentials, Windows Credential Manager, and AdConnect secrets), Mimikatz and LaZagne for credential theft, Cobalt Strike for C2, PDQ Inventory (cracked) for network reconnaissance, Advanced Port Scanner and netscan.exe for network discovery, AnyDesk for remote access, Putty for SSH connections, BITSAdmin and PowerShell for payload retrieval, Rclone for data exfiltration to cloud storage (PCloud, MegaSync), and 7-Zip for data compression. Post-compromise, the ransomware terminates 43 targeted processes (including backup agents, database servers, email clients, and security products) and over 30 backup and security services (including Veeam, Acronis, Sophos, Microsoft Exchange, and SQL Server). The ransomware targets VMware ESXi environments specifically, encrypting .vmdk, .vmem, .vswp, .vmsn, and .log files after authenticating to vCenter, enabling SSH, and creating accounts with UID 0 (root) for persistent access. Defense evasion includes clearing Windows Event Logs, PowerShell history, modifying firewall rules, and deleting operational tools post-use.

In a separate case, Silnikau was also charged in the District of New Jersey alongside co-conspirators Volodymyr Kadariya (38, Belarusian and Ukrainian national) and Andrei Tarasov (33, Russian national) for operating an international malvertising scheme from October 2013 to March 2022. The scheme used tens of fictitious entities and personas to trick advertising companies into delivering malicious advertisements distributing the Angler Exploit Kit, which targeted browser and plugin vulnerabilities. The Angler Exploit Kit was originally developed and rented by the Lurk cybercrime gang, whose members were arrested in 2016. The conspirators profited by selling access to compromised devices on Russian cybercrime forums, as well as stolen banking details and login credentials. Silnikau was a member of the "Direct Connection" Russian-language cybercrime forum from 2011 until its shuttering by law enforcement in 2016.

Defenders should prioritize enforcing MFA on all remote access points, monitoring for Ransom Cartel-associated tooling (DonPAPI, PDQ Inventory, Rclone, Cobalt Strike), auditing ESXi environments for unauthorized UID 0 accounts, applying PrintNightmare patches, and implementing behavioral detection rules for Salsa20-based encryption patterns and ransomware-style process and service termination sequences.

MITRE ATT&CK techniques used in TL-2026-1902

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Collection

T1560 Archive Collected Data

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Ransom Cartel ransomware creator Maksim Silnikau sentenced

  • VMware — ESXi
    Vulnerable versions: 6.x; 7.x; 8.x
  • VMware — vCenter Server
    Vulnerable versions: 6.x; 7.x; 8.x
  • Microsoft — Windows Server
    Vulnerable versions: 2016; 2019; 2022
  • Microsoft — Exchange Server
    Vulnerable versions: 2016; 2019
  • Microsoft — SQL Server
    Vulnerable versions: 2016; 2019; 2022
  • Veeam — Backup & Replication
    Vulnerable versions: All versions
  • Acronis — Backup Software
    Vulnerable versions: All versions
  • Microsoft — Windows Print Spooler
    Vulnerable versions: All versions prior to August 2021
    Fixed in: KB5005655; KB5005033
  • Sophos — Endpoint Protection
    Vulnerable versions: All versions targeted by service termination

Remediation for Ransom Cartel ransomware creator Maksim Silnikau sentenced

Patches

  • Apply PrintNightmare patches (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481)
  • Keep VMware vCenter and ESXi hosts on latest patched versions
  • Apply Microsoft Exchange and SQL Server security updates

Immediate actions

  • Block known Ransom Cartel IOC IP ranges (185.239.222.240, 108.62.103.193, 185.129.62.62, 185.143.223.13, 185.253.163.23) at perimeter
  • Enforce MFA on all VPN, RDP, SSH, and Citrix access points
  • Audit all ESXi hosts for unauthorized accounts with UID 0
  • Scan registry for SOFTWARE\Google_Authenticator artifacts
  • Monitor for DonPAPI, LaZagne, and Mimikatz execution events
  • Review for unauthorized AnyDesk installations

Workarounds

  • Restrict RDP access to jump hosts with MFA only
  • Disable PowerShell script execution for non-administrator users where not required
  • Restrict BITSAdmin usage to authorized administrative accounts via AppLocker or WDAC
  • Disable LLMNR and NetBIOS over TCP/IP to reduce credential relay risk
  • Block outbound SMB to reduce lateral movement surface

Longer-term hardening

  • Deploy EDR with behavioral detection for Salsa20 encryption patterns and ransomware-style process termination sequences
  • Implement network segmentation between IT networks and ESXi management planes
  • Deploy Windows DPAPI auditing and enable Credential Guard
  • Create detection rules for Rclone, BITSAdmin, and PDQ Inventory execution by non-administrative users
  • Implement TOR exit node IP blocking at network perimeter
  • Deploy PowerShell script block logging and constrained language mode

CVEs associated with Ransom Cartel ransomware creator Maksim Silnikau sentenced

CVE-2021-1675, CVE-2021-34527, CVE-2021-34481

Timeline of Ransom Cartel ransomware creator Maksim Silnikau sentenced

  • Silnikau first becomes active on Russian-language cybercrime forums, establishing his presence in the underground ecosystem
  • Silnikau joins the Direct Connection Russian-language cybercrime forum, remaining a member until its shutdown by law enforcement in 2016
  • Silnikau, Kadariya, and Tarasov begin operating a large-scale international malvertising scheme distributing the Angler Exploit Kit through fictitious advertising entities
  • Silnikau begins developing the Ransom Cartel ransomware, recruiting affiliates through underground forums and building the RaaS infrastructure
  • Ransom Cartel affiliates attack a New York company, encrypting data and exfiltrating stolen information in a double-extortion operation
  • Ransom Cartel publicly launches as a ransomware-as-a-service operation, with an affiliate website for managing attacks, negotiating ransoms, and splitting proceeds
  • First ransom note variant observed, sharing strong structural similarities with REvil's notes including the same 16-byte hexadecimal UID format and similar wording
  • Ransom Cartel affiliates attack a California company, stealing and encrypting data in a double-extortion operation
  • Second ransom note variant observed, completely rewritten from the REvil-like original with different formatting and language
  • Ransom Cartel attacks a medical technology startup developing robotic surgical tools, causing two months of operational disruption
  • Ransom Cartel attacks infrastructure used by a group of law firms causing disruptions ranging from days to months; two firms paid $125,000 and $300,000 in ransoms, with combined losses of approximately $2.2 million
  • Silnikau arrested in Spain as part of an international law enforcement operation targeting the Ransom Cartel operation
  • Silnikau flees while awaiting extradition from Spain, later recaptured while attempting to cross from Poland into Belarus
  • Indictments unsealed in the District of New Jersey and Eastern District of Virginia, charging Silnikau with computer fraud, wire fraud, and aggravated identity theft; co-conspirators Kadariya and Tarasov also charged in New Jersey malvertising case
  • Silnikau sentenced to 16 years in federal prison by U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia for conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft

Sources cited for Ransom Cartel ransomware creator Maksim Silnikau sentenced

Detection coverage for TL-2026-1902

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1902 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats