# Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison

> Maksim Silnikau, a 40-year-old Belarusian national and creator of the Ransom Cartel ransomware, was sentenced to 16 years in federal prison on August 5, 2026, for conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft. Ransom Cartel (publicly launched December 2021, sharing code-level similarities with REvil/Sodinokibi) operated as a ransomware-as-a-service scheme targeting at least 18 companies worldwide, attempting to extort at least $5.2 million with over $6.7 million in identified losses, including a medical technology startup and multiple law firms. Silnikau also operated a separate malvertising scheme distributing the Angler Exploit Kit from 2013 to 2022 with co-conspirators Volodymyr Kadariya and Andrei Tarasov.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1902
- **ID:** TL-2026-1902
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Ransom Cartel
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-1675, CVE-2021-34527, CVE-2021-34481

## Description

On August 5, 2026, U.S. District Judge Rossie D. Alston Jr. in the Eastern District of Virginia sentenced Maksim Silnikau (40, Belarusian national) to 16 years in federal prison for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Silnikau, known on Russian-language cybercrime forums since at least 2005 under the aliases "J.P. Morgan," "xxx," and "lansky," was the creator and administrator of the Ransom Cartel ransomware operation. He was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation, fled while awaiting extradition, and was recaptured while attempting to cross from Poland into Belarus before consenting to extradition to the United States.

Ransom Cartel launched publicly in December 2021 as a ransomware-as-a-service (RaaS) operation. Silnikau began developing the ransomware in May 2021, recruiting affiliates through underground forums, maintaining an affiliate website where members could manage attacks, negotiate ransoms, and split proceeds, and routing ransom payments through cryptocurrency mixers to obscure fund trails. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide spanning California, New York, Nebraska, and international locations. Notable attacks included an August 2022 breach of a medical technology startup developing robotic surgical tools that suffered two months of operational disruption, and a May 2023 attack on infrastructure used by a group of law firms causing disruptions ranging from days to months. One law firm paid a $125,000 ransom after nearly a month of disruption, and another paid $300,000 after suspending operations for almost a month. Combined losses from the law firm attacks totaled approximately $2.2 million.

Technical analysis by Palo Alto Networks Unit 42 revealed that Ransom Cartel shares substantial code-level similarities with the REvil (Sodinokibi) ransomware. Both encryptors use Salsa20 symmetric encryption combined with Curve25519-Donna elliptic curve Diffie-Hellman for key exchange, employ an identical 232-byte encrypted file footer structure, and share a nearly identical JSON configuration format. The session secret generation procedure is identical, and the samples contain three matching exports: Rathbuige, ServiceMain, and SvchostPushServiceGlobals. However, Ransom Cartel lacks REvil's heavy obfuscation (no string encryption, no API hashing), suggesting the operators possessed the core encryptor source code but not the full obfuscation engine, likely building from an earlier or stripped-down version of REvil. The first ransom note variant (January 2022) was nearly identical to REvil's notes in formatting and language, while a second variant (August 2022) was completely rewritten.

Ransom Cartel operated as a double-extortion RaaS, encrypting victim data and exfiltrating it for public release on a data leak site. The group uniquely escalated pressure by threatening to send stolen data to victims' partners, competitors, and news media. Initial access was primarily achieved through compromised credentials (VPN, RDP, SSH, Citrix) often purchased from initial access brokers. For privilege escalation, affiliates exploited the PrintNightmare vulnerability (CVE-2021-1675, CVE-2021-34527, CVE-2021-34481). The toolset included DonPAPI for DPAPI credential dumping (targeting Wi-Fi keys, RDP passwords, browser credentials, Windows Credential Manager, and AdConnect secrets), Mimikatz and LaZagne for credential theft, Cobalt Strike for C2, PDQ Inventory (cracked) for network reconnaissance, Advanced Port Scanner and netscan.exe for network discovery, AnyDesk for remote access, Putty for SSH connections, BITSAdmin and PowerShell for payload retrieval, Rclone for data exfiltration to cloud storage (PCloud, MegaSync), and 7-Zip for data compression. Post-compromise, the ransomware terminates 43 targeted processes (including backup agents, database servers, email clients, and security products) and over 30 backup and security services (including Veeam, Acronis, Sophos, Microsoft Exchange, and SQL Server). The ransomware targets VMware ESXi environments specifically, encrypting .vmdk, .vmem, .vswp, .vmsn, and .log files after authenticating to vCenter, enabling SSH, and creating accounts with UID 0 (root) for persistent access. Defense evasion includes clearing Windows Event Logs, PowerShell history, modifying firewall rules, and deleting operational tools post-use.

In a separate case, Silnikau was also charged in the District of New Jersey alongside co-conspirators Volodymyr Kadariya (38, Belarusian and Ukrainian national) and Andrei Tarasov (33, Russian national) for operating an international malvertising scheme from October 2013 to March 2022. The scheme used tens of fictitious entities and personas to trick advertising companies into delivering malicious advertisements distributing the Angler Exploit Kit, which targeted browser and plugin vulnerabilities. The Angler Exploit Kit was originally developed and rented by the Lurk cybercrime gang, whose members were arrested in 2016. The conspirators profited by selling access to compromised devices on Russian cybercrime forums, as well as stolen banking details and login credentials. Silnikau was a member of the "Direct Connection" Russian-language cybercrime forum from 2011 until its shuttering by law enforcement in 2016.

Defenders should prioritize enforcing MFA on all remote access points, monitoring for Ransom Cartel-associated tooling (DonPAPI, PDQ Inventory, Rclone, Cobalt Strike), auditing ESXi environments for unauthorized UID 0 accounts, applying PrintNightmare patches, and implementing behavioral detection rules for Salsa20-based encryption patterns and ransomware-style process and service termination sequences.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1027 Obfuscated Files or Information
- T1112 Modify Registry
- T1685 Disable or Modify Tools
- T1003 OS Credential Dumping
- T1555 Credentials from Password Stores
- T1046 Network Service Discovery
- T1021 Remote Services
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1489 Service Stop
- T1490 Inhibit System Recovery

## Sources

- [Ransom Cartel ransomware creator sentenced to 16 years in prison](https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/)
- [Ransom Cartel Ransomware: A Possible Connection With REvil](https://unit42.paloaltonetworks.com/ransom-cartel-ransomware/)
- [US Charges Three Eastern Europeans Over Ransomware and Malvertising](https://www.securityweek.com/us-unseals-charges-against-3-eastern-europeans-over-ransomware-malvertising/)
- [Ransom Cartel linked to notorious REvil ransomware operation](https://www.bleepingcomputer.com/news/security/ransom-cartel-linked-to-notorious-revil-ransomware-operation/)
- [What is Ransom Cartel? A ransomware gang focused on reputational damage](https://www.csoonline.com/article/574109/what-is-ransom-cartel-a-ransomware-gang-focused-on-reputational-damage.html)
- [The link between Ransom Cartel and REvil](https://securityaffairs.com/137328/cyber-crime/ransom-cartel-links-revil.html)
- [DonPAPI - DPAPI dumping tool](https://github.com/login-securite/DonPAPI)
- [Ransom Cartel ransomware removal guide and analysis](https://www.pcrisk.com/removal-guides/24205-ransom-cartel-ransomware)
- [Ransom Cartel: A Detailed Analysis of The Last Version of REvil](https://securityscorecard.com/wp-content/uploads/2024/01/Research-A-Detailed-Analysis-Of-The-Last-Version-Of-REvil-Ransomware.pdf)
- [Tactics Tie Ransom Cartel Group to Defunct REvil](https://www.darkreading.com/threat-intelligence/tactics-tie-ransom-cartel-group-to-defunct-revil-ransomware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1902
