Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Ransomware

Ransom Cartel’s Creator Gets 16 Years for Building the Business Behind the Malware

A federal judge in Virginia has sentenced Maksim Silnikau to 16 years in prison for his role in Ransom Cartel. The court records describe something far more organized than the familiar picture of a ransomware operator sitting at a keyboard and breaking into companies one by one. Ransom Cartel worked as a service. Silnikau, 40, created and administered it while affiliates carried out attacks against at least 18 companies between 2021 and 2023, according to the Justice Department.

Silnikau supplied locking tools and bought stolen credentials from initial access brokers, according to The Hacker News. Affiliates used a hidden site to monitor attacks, speak with victims, and divide the proceeds. Silnikau even rated affiliates by performance and rewarded the most productive.

Ransom payments moved through cryptocurrency mixers. It starts to look like management software for extortion, which is grimly efficient when you think about it. The market for victims began before the ransomware appeared on their systems. An advertisement posted to a Russian-language cybercrime forum in May 2021 sought access to corporate networks outside the Commonwealth of Independent States. The buyers wanted companies with at least $10 million in revenue and offered prices starting at $100 for access. A corporate network could already be inventory long before anybody encrypted a file.

For defenders, that moves the interesting part of the attack earlier. Unit 42 saw Ransom Cartel rely on compromised credentials for initial access, including credentials for remote services. Waiting for the ransomware payload means arriving late in the process. The sale of access has already happened by then, and somebody else may simply be buying the right to use it.

The timeline shows how easily the brand can distract from the operation underneath it. Prosecutors trace Silnikau’s activity to May 2021 and say the Ransom Cartel name came later that year. Unit 42 first observed the group around January 2022. The researchers also found technical overlap with REvil and assessed that Ransom Cartel had access to earlier REvil source code. Its samples appeared to lack REvil’s later obfuscation engine, so Unit 42 left the relationship as a possible historical link. Malware names look tidy on a threat report. The people and code behind them tend to travel.

Prosecutors say Silnikau’s July 2023 arrest disrupted Ransom Cartel’s growth. Poland extradited him to the US in August 2024. The Virginia sentence leaves another prosecution pending in New Jersey, where Silnikau was separately charged with Volodymyr Kadariya and Andrei Tarasov over the Angler Exploit Kit malvertising scheme. Tarasov remains on the Secret Service wanted list. The State Department is offering up to $2.5 million for information leading to Kadariya’s arrest or conviction.

The hidden admin site is probably the detail that best explains what Silnikau actually built. By the time an encryptor ran on a victim’s machine, stolen access had already moved through a service built to turn it into extortion. Encryption gets the attention because victims can see it. The system around it is what allowed Ransom Cartel to keep doing it again.

 

 

Share on

More News