Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in jail for his function in ransomware assaults in opposition to no less than 18 corporations worldwide.
The U.S. Division of Justice introduced as we speak that the 40-year-old Belarusian nationwide was sentenced for conspiracy to commit offenses in opposition to the US, conspiracy to commit wire fraud, and aggravated id theft.
The DOJ says Silnikau had been energetic on Russian-speaking cybercrime boards since no less than 2005 and used the aliases “J.P. Morgan,” “xxx,” and “lansky.”
He was additionally a member of the Direct Connection cybercrime web site between 2011 and 2016, when the location was shut down following the arrest of its administrator.
In accordance with court docket paperwork, Silnikau started creating the Ransom Cartel ransomware operation in Could 2021 and recruited different cybercriminals via underground boards to take part in assaults.
He equipped members with info and instruments used within the intrusions, together with stolen credentials for compromised computer systems and software program designed to encrypt victims’Â computer systems.
Silnikau additionally operated an affiliate web site that allowed members of the ransomware operation to handle assaults, talk with one another, negotiate ransom calls for, and distribute income shares after a ransom was paid.
Between 2021 and 2023, Ransom Cartel associates attacked no less than 18 corporations worldwide, together with organizations in California, New York, Nebraska, and nations outdoors the US.
In the course of the assaults, the risk actors stole company knowledge and demanded funds in trade for decryption keys or guarantees that the stolen info wouldn’t be publicly leaked.
Federal prosecutors mentioned the ransomware operation tried to extort no less than $5.2 million from its victims.
The US recognized greater than $6.7 million in losses suffered by 18 identified victims, though prosecutors mentioned the entire was seemingly larger as a result of some victims had not reported their assaults.
In a single August 2022 assault, Ransom Cartel reportedly disrupted the operations at a medical know-how startup creating robotic surgical know-how for 2 months. In Could 2023, the gang additionally attacked infrastructure utilized by a bunch of regulation companies, inflicting enterprise disruptions lasting from a number of days to a number of months.
One regulation agency paid a ransom price $125,000 after being disrupted for almost a month, whereas one other suspended operations for nearly a month earlier than paying a $300,000 ransom.
Prosecutors mentioned the mixed losses related to these assaults reached roughly $2.2 million.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor.
Nonetheless, the shortage of a few of REvil’s obfuscation options led researchers to imagine that it could have been created by a former core member of the operation who didn’t have entry to the whole supply code.
Silnikau reportedly held a central function within the ransomware-as-a-service operation, recruiting associates, working with preliminary entry brokers who equipped entry to compromised company networks, speaking with victims, and dealing with ransom funds.
He additionally transmitted ransom funds via cryptocurrency mixers to make it more durable for regulation enforcement to hint the funds.
Silnikau was initially arrested in Spain on July 18, 2023, as a part of a global regulation enforcement operation. Nonetheless, he fled whereas awaiting extradition to the US and was later captured whereas making an attempt to return to Belarus.
“The defendant fled Spanish authorities whereas awaiting extradition to the US and was apprehended whereas making an attempt to cross from Poland to his native Belarus,” prosecutors mentioned of their sentencing submitting.
Silnikau in the end consented to extradition and was despatched from Poland to the US to face prosecution within the Jap District of Virginia.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remaining transfer via your setting unseen.
The Picus whitepaper reveals how breach and assault simulation exams your SIEM and EDR guidelines so threats cease slipping by detection.


