Back to Feed
RansomwareAug 6, 2026

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Ransom Cartel creator Maksim Silnikau sentenced to 16 years for ransomware-as-a-service operation.

Summary

Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies globally, with Silnikau providing the ransomware, stolen credentials, and a platform for affiliates to manage attacks and negotiate with victims. He also operated a rating system for affiliates and used cryptocurrency mixers for payments.

Full text

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service Swati KhandelwalAug 06, 2026Ransomware / Cybercrime A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department. Silnikau, a 40-year-old Belarusian national who worked under the handles "J.P. Morgan," "lansky" and "xxx," did not carry out most of those intrusions himself. He built the business around them: the locking software, the stolen credentials he bought from initial access brokers, and a hidden panel where affiliates monitored attacks, negotiated with victims and split proceeds. He ran a ratings system that rewarded the productive ones, and pushed ransom payments through cryptocurrency mixers. Sixteen years run past the 13 years and seven months handed to Yaroslav Vasinskyi in 2024 for more than 2,500 REvil attacks and over $700 million in ransom demands. It also settles only half the case: a second federal prosecution in New Jersey is unresolved, and the two men charged alongside him there remain at large. Prosecutors charged seven counts in Virginia and announced convictions on three. The announcement carries no restitution or forfeiture figure and does not say whether he pleaded guilty or was convicted at trial. Accounts of when Ransom Cartel began have never lined up: prosecutors date the operation to May 2021, while Palo Alto Networks' Unit 42 did not observe it until mid-January 2022. The indictment, returned in June 2023 and unsealed in 2024, closes the gap. Silnikau ran the operation under another name from May 2021, renamed it "Ransom Cartel" in late 2021, then tried to publicize it on security news sites. The same document preserves the advertisement his conspiracy posted to a Russian-language cybercrime forum on May 4, 2021, seeking access to corporate networks anywhere outside the Commonwealth of Independent States. They screened by victim size and set a floor on what they would pay: "Revenue: from $10 million. Prices from $100 and up." The last charged act falls on April 25, 2023, when he negotiated terms for supplying computers to be locked, three months before the July 2023 arrest that prosecutors say stalled Ransom Cartel's growth. Poland extradited him to the United States in August 2024. Unit 42 has never called Ransom Cartel a rebrand of REvil. Its 2022 analysis found the operators held the original REvil source code but apparently not the obfuscation engine that gang used. The researchers speculated only that the groups were linked at some point. Neither the indictment nor the sentencing release mentions REvil. Silnikau was separately charged in New Jersey alongside Volodymyr Kadariya and Andrei Tarasov over the Angler Exploit Kit malvertising scheme, which ran from 2013 to 2022. The Virginia announcement says nothing about it. The Secret Service still lists Tarasov as wanted, and the State Department is offering up to $2.5 million for information leading to Kadariya's arrest or conviction. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cryptocurrency, Cyber Attack, Cybercrime, dark web, exploit kit, Initial Access, law enforcement, malvertising, Malware, ransomware ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders

Indicators of Compromise

  • malware — Ransom Cartel
  • malware — Angler Exploit Kit

Entities

Maksim Silnikau (threat_actor)Ransom Cartel (campaign)Angler Exploit Kit (product)Yaroslav Vasinskyi (threat_actor)Volodymyr Kadariya (threat_actor)Andrei Tarasov (threat_actor)