Full Report
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.
Analysis Summary
# Threat Actor: Maksim Silnikau (Ransom Cartel)
## Attribution & Identity
* **Name:** Maksim Silnikau
* **Nationality:** Belarusian
* **Aliases:** "J.P. Morgan," "lansky," "xxx"
* **Known Associations:**
* **Ransom Cartel:** Founder and operator of the Ransomware-as-a-Service (RaaS) group.
* **REvil (Sodinokibi):** Linked via shared source code; researchers speculate the groups were connected, though Ransom Cartel lacked the REvil obfuscation engine.
* **Angler Exploit Kit:** Silnikau is linked to this malvertising scheme alongside co-conspirators **Volodymyr Kadariya** and **Andrei Tarasov**.
## Activity Summary
Silnikau operated the Ransom Cartel RaaS from approximately May 2021 until his arrest in July 2023. Under his leadership, the group attacked at least 18 major companies globally. He was responsible for the business infrastructure, including the encryption software, affiliate management, and ransom negotiations. He was extradited from Poland to the U.S. in August 2024 and sentenced to 16 years in prison in August 2026.
## Tactics, Techniques & Procedures
* **Ransomware-as-a-Service (RaaS) Model:** Developed locking software and provided a centralized management panel for affiliates.
* **Initial Access:** Purchased stolen credentials from Initial Access Brokers (IABs) to facilitate intrusions.
* **Affiliate Management:** Implemented a ratings system to reward the most productive cybercriminal affiliates.
* **Financial Laundering:** Used cryptocurrency mixers to process and distribute ransom payments.
* **Double Extortion:** Negotiated with victims via a hidden panel to release data or provide decryption keys.
* **Exploit Kits:** Historically associated with malvertising via the **Angler Exploit Kit**.
## Targeting
* **Sectors:** Large corporate networks (revenue minimum of $10 million).
* **Geography:** Global (California, New York, Nebraska, and international locations). Specifically excluded the **Commonwealth of Independent States (CIS)**.
* **Victims:** At least 18 companies (specific names not disclosed in the article).
## Tools & Infrastructure
* **Malware:** Ransom Cartel ransomware (derived from REvil source code).
* **Infrastructure:**
* Hidden affiliate panel for monitoring attacks and splitting proceeds.
* Cryptocurrency mixers.
* **Angler Exploit Kit** (historical malvertising infrastructure).
## Implications
The sentencing of Silnikau represents a significant blow to the RaaS ecosystem, particularly groups utilizing legacy REvil code. However, his co-conspirators (Kadariya and Tarasov) remain at large, suggesting that portions of the infrastructure or operational knowledge may still be accessible to the cybercrime underground. The 16-year sentence sets a high legal precedent for RaaS operators, exceeding recent sentences for REvil affiliates.
## Mitigations
* **Credential Hygiene:** Implement Multi-Factor Authentication (MFA) to mitigate the risk of stolen credentials purchased from access brokers.
* **Vulnerability Management:** Patch systems against vulnerabilities commonly targeted by exploit kits like Angler.
* **Network Segmentation:** Restrict lateral movement to prevent ransomware from spreading from the initial point of entry to critical data stores.
* **Offline Backups:** Maintain immutable, offline backups to ensure recovery without paying ransoms.
* **Geographic Blocking:** While not a total solution, blocking traffic from regions where these actors operate (outside CIS) can reduce the attack surface.