HackMyIP
← Back to News
2026-08-06 The Hacker News

Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years

RansomwareMalwareThreat Intel

A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years in prison on August 5, 2026, for building and operating Ransom Cartel, a ransomware-as-a-service (RaaS) operation that ran from 2021 to 2023. According to the Justice Department, Silnikau — who operated under the aliases "J.P. Morgan," "lansky," and "xxx" — oversaw a conspiracy that attacked at least 18 companies across California, New York, Nebraska, and several international targets. The 16-year sentence exceeds the 13 years and seven months handed to REvil affiliate Yaroslav Vasinskyi in 2024 for over 2,500 attacks and more than $700 million in ransom demands, underscoring the increasing severity courts are imposing on RaaS operators.

Rather than executing intrusions himself, Silnikau built the infrastructure around them: he developed the locking software, purchased stolen credentials from initial access brokers — the kind of compromised logins that security teams can cross-reference against an online password strength checker — and maintained a hidden affiliate panel where partners monitored attacks, negotiated with victims, and split the proceeds. He ran a ratings system that rewarded the most productive affiliates and funneled ransom payments through cryptocurrency mixers to obscure the trail. Prosecutors charged seven counts in Virginia and secured convictions on three, though the announcement omitted both a restitution figure and any indication of whether Silnikau pleaded guilty or was convicted at trial. A second federal prosecution in New Jersey remains unresolved, with co-defendants Volodymyr Kadariya and Andrei Tarasov still at large.

The timeline of Ransom Cartel has long been contested. Prosecutors date the operation to May 2021, while Palo Alto Networks' Unit 42 first observed it in mid-January 2022. The indictment, returned in June 2023 and unsealed in 2024, closes that gap: Silnikau ran the operation under another name from May 2021, rebranded it as Ransom Cartel later that year, and attempted to publicize it on security news sites. The same filing preserves an advertisement the conspiracy posted to a Russian-language cybercrime forum on May 4, 2021, soliciting access to corporate networks outside the Commonwealth of Independent States — with a stated floor of $10 million in victim revenue and access prices starting at $100. Unit 42 has stopped short of calling Ransom Cartel a REvil rebrand, noting that its operators held the original REvil source code but apparently not the gang's obfuscation engine, and neither the indictment nor the sentencing release references REvil directly. Polish authorities extradited Silnikau to the United States in August 2024, three months after his July 2023 arrest stalled Ransom Cartel's growth.

Silnikau was separately charged in New Jersey alongside Kadariya and Tarasov over the Angler Exploit Kit malvertising scheme, which ran from 2013 to 2022 — a long-running operation that investigators say generated revenue by redirecting legitimate web traffic to malicious payloads. For organizations that may have been swept up in either scheme, verifying exposure through an email breach checker and reviewing public-facing infrastructure with a port scanner remain baseline defensive steps. With one prosecution closed and another still pending, the Ransom Cartel case illustrates how ransomware operators who never touch a keyboard themselves can still face the heaviest sentences under U.S. law.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →