Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison

A US federal court has sentenced Maksim Silnikau, a 40-year-old Belarusian national, to 16 years in prison for creating and administering the Ransom Cartel ransomware-as-a-service operation. The Department of Justice said Silnikau was convicted of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Prosecutors described him as a longtime fixture of Russian-speaking cybercrime forums, active under aliases including “J.P. Morgan” and “Lansky” since the mid-2000s, and previously a member of the now-defunct Direct Connection cybercrime marketplace.

According to court documents, Silnikau began building Ransom Cartel in May 2021, recruiting affiliates through underground forums and supplying them with stolen network credentials and encryption tools. He also ran the affiliate infrastructure that let members coordinate attacks, negotiate ransoms, and split proceeds. Between 2021 and 2023, the operation is linked to attacks on at least 18 companies across the United States and abroad, including a medical technology startup whose robotic surgery operations were disrupted for two months, and a group of law firms that each paid six-figure ransoms after weeks of business disruption. US authorities estimate victims lost more than $6.7 million, though the real toll is likely higher since not all victims reported the attacks.

Investigators noted that Ransom Cartel’s encryption software shared code with the notorious REvil ransomware, suggesting it may have been built by a former REvil affiliate without full access to the original source. Silnikau was first arrested in Spain in mid-2023 as part of an international law-enforcement action, but fled while awaiting extradition and was later caught trying to cross from Poland into Belarus. He ultimately agreed to extradition and was tried in the Eastern District of Virginia.

The sentencing adds to a string of recent prison terms for ransomware operators, part of a broader push by US and allied law enforcement to pursue not just ransomware infrastructure but the individuals who profit from running these criminal enterprises.

Read the original report →