CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Ransom Cartel Creator Sentenced to 16 Years in Prison for Ransomware-as-a-Service Operation

August 6, 2026

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau, a 40-year-old Belarusian national, to 16 years in prison on August 5, 2026, for creating and operating Ransom Cartel, a ransomware-as-a-service (RaaS) operation active from 2021 to 2023. The operation targeted at least 18 companies, including firms in California, New York, and Nebraska, as well as international victims.

Silnikau, who used handles such as “J.P. Morgan,” “lansky,” and “xxx,” did not personally conduct most intrusions. Instead, he built a business model around affiliates, providing them with locking software, stolen credentials purchased from initial access brokers, and a hidden panel to monitor attacks, negotiate with victims, and split proceeds. He implemented a ratings system to reward productive affiliates and routed ransom payments through cryptocurrency mixers.

The Justice Department charged Silnikau with seven counts in Virginia, with convictions on three. The sentence exceeds the 13 years and seven months given to Yaroslav Vasinskyi in 2024 for REvil attacks. However, a separate federal prosecution in New Jersey remains unresolved, with two co-defendants, Volodymyr Kadariya and Andrei Tarasov, still at large. The State Department is offering up to $2.5 million for information leading to Kadariya’s arrest or conviction.

Prosecutors date Ransom Cartel’s start to May 2021, though Palo Alto Networks’ Unit 42 first observed it in mid-January 2022. The indictment, unsealed in 2024, reveals Silnikau ran the operation under another name before renaming it “Ransom Cartel” in late 2021. He advertised on a Russian-language cybercrime forum, seeking access to corporate networks outside the Commonwealth of Independent States, with revenue thresholds starting at $10 million and prices from $100.

The last charged act occurred on April 25, 2023, when Silnikau negotiated terms for supplying computers to be locked. Poland extradited him to the United States in August 2024. Unit 42’s analysis found Ransom Cartel operators held original REvil source code but not the obfuscation engine, suggesting only a possible link. The sentencing release does not mention REvil.

Silnikau was also charged in New Jersey over the Angler Exploit Kit malvertising scheme (2013–2022). The Secret Service lists Tarasov as wanted. This case highlights the ongoing efforts of law enforcement to dismantle RaaS operations and bring cybercriminals to justice.

CVEs: CVE-2026-50522

Attack groups: Ransom Cartel, REvil

Malware: Angler Exploit Kit

Companies: Palo Alto Networks