Federal prosecutors in the Eastern District of Virginia have sentenced Maksim Silnikau, the Ransom Cartel ransomware creator and operation administrator, to 16 years in prison. The 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. His sentencing concludes an international law enforcement effort that tracked his illicit activities across several years and multiple jurisdictions.
Longstanding Cybercrime History and Operation Setup
Silnikau maintained an active presence in underground Russian-speaking cybercrime communities starting in at least 2005, operating under prominent aliases including “J.P. Morgan,” “xxx,” and “lansky.” Between 2011 and 2016, he was a key participant on the cybercrime website Direct Connection, which was ultimately taken offline following the arrest of its administrator.
In May 2021, Silnikau began engineering the Ransom Cartel ransomware platform, which formally launched operations in December 2021. Acting as the core orchestrator, Silnikau recruited affiliates on underground forums, provided them with custom encryption software, and supplied initial access materials, including stolen network credentials. He also established and managed an affiliate management portal that allowed members of the operation to track compromises, communicate with co-conspirators, negotiate ransom demands with victims, and automatically divide extorted cryptocurrency payouts.
To mask the flow of illicit profits, Silnikau processed ransom payments through cryptocurrency mixers, attempting to break the transaction trail before distributing funds to affiliates and access brokers.
Lineage to REvil and Technical Characteristics
When Ransom Cartel emerged in late 2021, malware analysts noted significant code overlaps with the REvil (Sodinokibi) ransomware strain. The Ransom Cartel encryptor shared core routines and structural components with REvil binaries. However, Ransom Cartel lacked some of the sophisticated code obfuscation and anti-analysis mechanisms present in late-stage REvil builds.
This technical gap led researchers to conclude that Ransom Cartel was likely created by a former REvil core developer or high-level affiliate who had access to portions of the original REvil source code but lacked the full, unredacted codebase. Silnikau effectively leveraged this baseline code to establish a fresh operation, stepping into the market void left when law enforcement disrupted REvil’s core infrastructure in late 2021.
Impact on Critical Sectors and Financial Blast Radius
Between 2021 and 2023, Ransom Cartel affiliates hit at least 18 organizations globally, targeting enterprises across California, New York, Nebraska, and several foreign countries. Operating under a double-extortion model, threat actors stole sensitive corporate files before deploying the ransomware payload, threatening to publish confidential records online if victims refused to pay for decryption keys.
Prosecutors established that the syndicate attempted to extort at least $5.2 million from its victims, generating documented losses of over $6.7 million across the 18 identified targets. Given the underreporting common to cyber extortion, federal authorities noted the true financial impact is significantly higher.
The operational blast radius of Ransom Cartel’s campaigns disrupted critical business functions across key sectors:
- Medical Technology: In August 2022, an attack paralyzed a medical technology startup developing robotic surgical tools, halting the company’s operational and development activities for two full months.
- Legal Services: In May 2023, Ransom Cartel compromised shared infrastructure used by a group of law firms, triggering outages that lasted from several days to multiple months. One firm paid a $125,000 ransom after suffering nearly a month of complete disruption, while a second firm paid $300,000 after shutting down operations for almost four weeks. Total financial losses for the law firm incidents alone reached approximately $2.2 million.
International Apprehension and Extradition
Silnikau was initially arrested in Spain on July 18, 2023, as part of a coordinated international law enforcement action. However, while awaiting extradition proceedings to the United States, Silnikau escaped Spanish custody and fled toward Eastern Europe.
Authorities apprehended him while he was attempting to cross from Poland into his native Belarus. Facing prosecution in the US, Silnikau ultimately consented to extradition and was transferred from Polish custody to the Eastern District of Virginia to face federal trial and sentencing.
Reducing Exposure to Ransomware-as-a-Service Operations
The conviction of Silnikau highlights the ongoing reliance of Ransomware-as-a-Service (RaaS) operations on initial access brokers, stolen credentials, and weak edge security. To limit exposure to similar ransomware threats:
- Enforce multi-factor authentication (MFA) using phishing-resistant methods across all remote access services, VPNs, and administrative portals.
- Isolate and restrict Remote Desktop Protocol (RDP) access, ensuring external endpoints are protected behind secure access gateways or zero-trust network architectures.
- Implement strict credential protection controls, such as Windows Credential Guard, to prevent initial access tools from dumping domain credentials from memory.
- Maintain offline, immutable backup solutions for domain controllers and critical data repositories, ensuring recovery capabilities are regularly validated under simulated attack conditions.
Related content
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call