Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.
Intelligence analysis by Llama

The U.S. Department of Justice announced that Silnikau was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. He was initially arrested in Spain but fled while awaiting extradition to the United States and was later captured while attempting to return to Belarus.
Imagine you're a hacker who creates a program that locks people's computers and demands money to unlock them. This is called ransomware. A man named Maksim Silnikau created a program like this and was caught by the police. He was sentenced to 16 years in prison for his role in locking up 18 companies' computers and demanding money to unlock them.
Analysis
A $60B Vote of Confidence
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases 'J.P. Morgan,' 'xxx,' and 'lansky.' He was also a member of the Direct Connection cybercrime website between 2011 and 2016, when the site was shut down following the arrest of its administrator.
According to court documents, Silnikau began developing the Ransom Cartel ransomware operation in May 2021 and recruited other cybercriminals through underground forums to participate in attacks. He supplied members with information and tools used in the intrusions, including stolen credentials for compromised computers and software designed to encrypt victims' computers.
Silnikau also operated an affiliate website that allowed members of the ransomware operation to manage attacks, communicate with each other, negotiate ransom demands, and distribute revenue shares after a ransom was paid. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide, including organizations in California, New York, Nebraska, and countries outside the United States.
During the attacks, the threat actors stole corporate data and demanded payments in exchange for decryption keys or promises that the stolen information would not be publicly leaked. Federal prosecutors said the ransomware operation attempted to extort at least $5.2 million from its victims. The United States identified more than $6.7 million in losses suffered by 18 known victims, although prosecutors said the total was likely higher because some victims had not reported their attacks.
In one August 2022 attack, Ransom Cartel reportedly disrupted the operations at a medical technology startup developing robotic surgical technology for two months. In May 2023, the gang also attacked infrastructure used by a group of law firms, causing business disruptions lasting from several days to multiple months. One law firm paid a ransom worth $125,000 after being disrupted for nearly a month, while another suspended operations for almost a month before paying a $300,000 ransom.
Prosecutors said the combined losses associated with those attacks reached approximately $2.2 million. Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor. However, the lack of some of REvil's obfuscation features led researchers to believe that it may have been created by a former core member of the operation who did not have access to the complete source code.
Silnikau reportedly held a central role in the ransomware-as-a-service operation, recruiting affiliates, working with initial access brokers who supplied access to compromised corporate networks, communicating with victims, and handling ransom payments. He also transmitted ransom payments through cryptocurrency mixers to make it harder for law enforcement to trace the funds.
Silnikau was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation. However, he fled while awaiting extradition to the United States and was later captured while attempting to return to Belarus.
The defendant fled Spanish authorities while awaiting extradition to the United States and was apprehended while trying to cross from Poland to his native Belarus, prosecutors said in their sentencing filing. Silnikau ultimately consented to extradition and was sent from Poland to the United States to face prosecution in the Eastern District of Virginia.
Why Cursor?
This case highlights the importance of international cooperation in combating cybercrime. The fact that Silnikau was able to flee from Spain to Belarus and then attempt to return to the United States while awaiting extradition is a stark reminder of the challenges that law enforcement faces in pursuing cybercriminals across borders.
The Road Ahead
The sentencing of Silnikau is a significant victory for law enforcement and a reminder that those who engage in ransomware attacks will face consequences. However, the fact that Ransom Cartel was able to operate for several years and cause significant losses to its victims highlights the need for continued vigilance and cooperation between law enforcement agencies and the private sector.
In the wake of this case, it is essential to recognize the importance of investing in cybersecurity measures and working together to prevent and respond to ransomware attacks. By doing so, we can reduce the risk of these attacks and protect the sensitive information of individuals and organizations.
Key points
- Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.
- Silnikau was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
- He was initially arrested in Spain but fled while awaiting extradition to the United States and was later captured while attempting to return to Belarus.
- Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor.
- The combined losses associated with Ransom Cartel attacks reached approximately $2.2 million.
The sentencing of Silnikau is a significant victory for law enforcement and a reminder that those who engage in ransomware attacks will face consequences. This development plays out positively if it leads to a decrease in ransomware attacks and a reduction in the losses suffered by victims.
However, the fact that Ransom Cartel was able to operate for several years and cause significant losses to its victims highlights the need for continued vigilance and cooperation between law enforcement agencies and the private sector. The realistic downside risks or failure modes of this development include the possibility that other ransomware groups may emerge to fill the gap left by Ransom Cartel, leading to a continued threat to individuals and organizations.



