Threat reportRansomwareTL-2026-1902
Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison
Ransom Cartel ransomware creator Maksim Silnikau sentenced (TL-2026-1902) is a high-severity ransomware operation, first published 2026-08-05. It is attributed to Ransom Cartel with high confidence, affects VMware ESXi, references 3 CVEs (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481), maps to 17 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 1Ransom Cartel
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-1902
- Threat ID
- TL-2026-1902
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Ransom Cartel
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education, manufacturing, utilities, energy, health, legal
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Ransom Cartel ransomware creator Maksim Silnikau sentenced
Malware and tooling: AnyDesk, Cobalt Strike, MimiKatz, Ransomcartel, Sodinokibi, Advanced Port Scanner, AnyDesk, BITSAdmin - S0190, Cobalt Strike, DonPAPI, LaZagne - S0349, Mimikatz
How Ransom Cartel ransomware creator Maksim Silnikau sentenced works
Maksim Silnikau, a 40-year-old Belarusian national and creator of the Ransom Cartel ransomware, was sentenced to 16 years in federal prison on August 5, 2026, for conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft. Ransom Cartel (publicly launched December 2021, sharing code-level similarities with REvil/Sodinokibi) operated as a ransomware-as-a-service scheme targeting at least 18 companies worldwide, attempting to extort at least $5.2 million with over $6.7 million in identified losses, including a medical technology startup and multiple law firms. Silnikau also operated a separate malvertising scheme distributing the Angler Exploit Kit from 2013 to 2022 with co-conspirators Volodymyr Kadariya and Andrei Tarasov.
On August 5, 2026, U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia sentenced Maksim Silnikau (40, Belarusian national) to 16 years in federal prison for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Silnikau, known on Russian-language cybercrime forums since at least 2005 under the aliases "J.P. Morgan," "xxx," and "lansky," was the creator and administrator of the Ransom Cartel ransomware operation. He was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation, fled while awaiting extradition, and was recaptured while attempting to cross from Poland into Belarus before consenting to extradition to the United States.
Ransom Cartel launched publicly in December 2021 as a ransomware-as-a-service (RaaS) operation. Silnikau began developing the ransomware in May 2021, recruiting affiliates through underground forums, maintaining an affiliate website where members could manage attacks, negotiate ransoms, and split proceeds, and routing ransom payments through cryptocurrency mixers to obscure fund trails. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide spanning California, New York, Nebraska, and international locations. Notable attacks included an August 2022 breach of a medical technology startup developing robotic surgical tools that suffered two months of operational disruption, and a May 2023 attack on infrastructure used by a group of law firms causing disruptions ranging from days to months. One law firm paid a $125,000 ransom after nearly a month of disruption, and another paid $300,000 after suspending operations for almost a month. Combined losses from the law firm attacks totaled approximately $2.2 million.
Technical analysis by Palo Alto Networks Unit 42 revealed that Ransom Cartel shares substantial code-level similarities with the REvil (Sodinokibi) ransomware. Both encryptors use Salsa20 symmetric encryption combined with Curve25519-Donna elliptic curve Diffie-Hellman for key exchange, employ an identical 232-byte encrypted file footer structure, and share a nearly identical JSON configuration format. The session secret generation procedure is identical, and the samples contain three matching exports: Rathbuige, ServiceMain, and SvchostPushServiceGlobals. However, Ransom Cartel lacks REvil's heavy obfuscation (no string encryption, no API hashing), suggesting the operators possessed the core encryptor source code but not the full obfuscation engine, likely building from an earlier or stripped-down version of REvil. The first ransom note variant (January 2022) was nearly identical to REvil's notes in formatting and language, while a second variant (August 2022) was completely rewritten.
Ransom Cartel operated as a double-extortion RaaS, encrypting victim data and exfiltrating it for public release on a data leak site. The group uniquely escalated pressure by threatening to send stolen data to victims' partners, competitors, and news media. Initial access was primarily achieved through compromised credentials (VPN, RDP, SSH, Citrix) often purchased from initial access brokers. For privilege escalation, affiliates exploited the PrintNightmare vulnerability (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481). The toolset included DonPAPI for DPAPI credential dumping (targeting Wi-Fi keys, RDP passwords, browser credentials, Windows Credential Manager, and AdConnect secrets), Mimikatz and LaZagne for credential theft, Cobalt Strike for C2, PDQ Inventory (cracked) for network reconnaissance, Advanced Port Scanner and netscan.exe for network discovery, AnyDesk for remote access, Putty for SSH connections, BITSAdmin and PowerShell for payload retrieval, Rclone for data exfiltration to cloud storage (PCloud, MegaSync), and 7-Zip for data compression. Post-compromise, the ransomware terminates 43 targeted processes (including backup agents, database servers, email clients, and security products) and over 30 backup and security services (including Veeam, Acronis, Sophos, Microsoft Exchange, and SQL Server). The ransomware targets VMware ESXi environments specifically, encrypting .vmdk, .vmem, .vswp, .vmsn, and .log files after authenticating to vCenter, enabling SSH, and creating accounts with UID 0 (root) for persistent access. Defense evasion includes clearing Windows Event Logs, PowerShell history, modifying firewall rules, and deleting operational tools post-use.
In a separate case, Silnikau was also charged in the District of New Jersey alongside co-conspirators Volodymyr Kadariya (38, Belarusian and Ukrainian national) and Andrei Tarasov (33, Russian national) for operating an international malvertising scheme from October 2013 to March 2022. The scheme used tens of fictitious entities and personas to trick advertising companies into delivering malicious advertisements distributing the Angler Exploit Kit, which targeted browser and plugin vulnerabilities. The Angler Exploit Kit was originally developed and rented by the Lurk cybercrime gang, whose members were arrested in 2016. The conspirators profited by selling access to compromised devices on Russian cybercrime forums, as well as stolen banking details and login credentials. Silnikau was a member of the "Direct Connection" Russian-language cybercrime forum from 2011 until its shuttering by law enforcement in 2016.
Defenders should prioritize enforcing MFA on all remote access points, monitoring for Ransom Cartel-associated tooling (DonPAPI, PDQ Inventory, Rclone, Cobalt Strike), auditing ESXi environments for unauthorized UID 0 accounts, applying PrintNightmare patches, and implementing behavioral detection rules for Salsa20-based encryption patterns and ransomware-style process and service termination sequences.
MITRE ATT&CK techniques used in TL-2026-1902
Credential Access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Collection
Exfiltration
Affected products and versions in Ransom Cartel ransomware creator Maksim Silnikau sentenced
- VMware — ESXi
Vulnerable versions: 6.x; 7.x; 8.x - VMware — vCenter Server
Vulnerable versions: 6.x; 7.x; 8.x - Microsoft — Windows Server
Vulnerable versions: 2016; 2019; 2022 - Microsoft — Exchange Server
Vulnerable versions: 2016; 2019 - Microsoft — SQL Server
Vulnerable versions: 2016; 2019; 2022 - Veeam — Backup & Replication
Vulnerable versions: All versions - Acronis — Backup Software
Vulnerable versions: All versions - Microsoft — Windows Print Spooler
Vulnerable versions: All versions prior to August 2021
Fixed in: KB5005655; KB5005033 - Sophos — Endpoint Protection
Vulnerable versions: All versions targeted by service termination
Remediation for Ransom Cartel ransomware creator Maksim Silnikau sentenced
Patches
- Apply PrintNightmare patches (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481)
- Keep VMware vCenter and ESXi hosts on latest patched versions
- Apply Microsoft Exchange and SQL Server security updates
Immediate actions
- Block known Ransom Cartel IOC IP ranges (185.239.222.240, 108.62.103.193, 185.129.62.62, 185.143.223.13, 185.253.163.23) at perimeter
- Enforce MFA on all VPN, RDP, SSH, and Citrix access points
- Audit all ESXi hosts for unauthorized accounts with UID 0
- Scan registry for SOFTWARE\Google_Authenticator artifacts
- Monitor for DonPAPI, LaZagne, and Mimikatz execution events
- Review for unauthorized AnyDesk installations
Workarounds
- Restrict RDP access to jump hosts with MFA only
- Disable PowerShell script execution for non-administrator users where not required
- Restrict BITSAdmin usage to authorized administrative accounts via AppLocker or WDAC
- Disable LLMNR and NetBIOS over TCP/IP to reduce credential relay risk
- Block outbound SMB to reduce lateral movement surface
Longer-term hardening
- Deploy EDR with behavioral detection for Salsa20 encryption patterns and ransomware-style process termination sequences
- Implement network segmentation between IT networks and ESXi management planes
- Deploy Windows DPAPI auditing and enable Credential Guard
- Create detection rules for Rclone, BITSAdmin, and PDQ Inventory execution by non-administrative users
- Implement TOR exit node IP blocking at network perimeter
- Deploy PowerShell script block logging and constrained language mode
CVEs associated with Ransom Cartel ransomware creator Maksim Silnikau sentenced
CVE-2021-1675, CVE-2021-34527, CVE-2021-34481
Timeline of Ransom Cartel ransomware creator Maksim Silnikau sentenced
- Silnikau first becomes active on Russian-language cybercrime forums, establishing his presence in the underground ecosystem
- Silnikau joins the Direct Connection Russian-language cybercrime forum, remaining a member until its shutdown by law enforcement in 2016
- Silnikau, Kadariya, and Tarasov begin operating a large-scale international malvertising scheme distributing the Angler Exploit Kit through fictitious advertising entities
- Silnikau begins developing the Ransom Cartel ransomware, recruiting affiliates through underground forums and building the RaaS infrastructure
- Ransom Cartel affiliates attack a New York company, encrypting data and exfiltrating stolen information in a double-extortion operation
- Ransom Cartel publicly launches as a ransomware-as-a-service operation, with an affiliate website for managing attacks, negotiating ransoms, and splitting proceeds
- First ransom note variant observed, sharing strong structural similarities with REvil's notes including the same 16-byte hexadecimal UID format and similar wording
- Ransom Cartel affiliates attack a California company, stealing and encrypting data in a double-extortion operation
- Second ransom note variant observed, completely rewritten from the REvil-like original with different formatting and language
- Ransom Cartel attacks a medical technology startup developing robotic surgical tools, causing two months of operational disruption
- Ransom Cartel attacks infrastructure used by a group of law firms causing disruptions ranging from days to months; two firms paid $125,000 and $300,000 in ransoms, with combined losses of approximately $2.2 million
- Silnikau arrested in Spain as part of an international law enforcement operation targeting the Ransom Cartel operation
- Silnikau flees while awaiting extradition from Spain, later recaptured while attempting to cross from Poland into Belarus
- Indictments unsealed in the District of New Jersey and Eastern District of Virginia, charging Silnikau with computer fraud, wire fraud, and aggravated identity theft; co-conspirators Kadariya and Tarasov also charged in New Jersey malvertising case
- Silnikau sentenced to 16 years in federal prison by U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia for conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft
Sources cited for Ransom Cartel ransomware creator Maksim Silnikau sentenced
- Ransom Cartel ransomware creator sentenced to 16 years in prison
- Ransom Cartel Ransomware: A Possible Connection With REvil
- US Charges Three Eastern Europeans Over Ransomware and Malvertising
- Ransom Cartel linked to notorious REvil ransomware operation
- What is Ransom Cartel? A ransomware gang focused on reputational damage
- The link between Ransom Cartel and REvil
- DonPAPI - DPAPI dumping tool
- Ransom Cartel ransomware removal guide and analysis
- Ransom Cartel: A Detailed Analysis of The Last Version of REvil
- Tactics Tie Ransom Cartel Group to Defunct REvil
Detection coverage for TL-2026-1902
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1902 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.