
Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia handed the 40-year-old Belarusian 16 years in prison for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.
“According to court documents, Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware strain, created in 2021.” reads the press release published by DoJ. “Silnikau had been a member of Russian-speaking cybercrime forums since at least 2005 and was a member of the notorious cybercrime website Direct Connection from 2011 to 2016, when the site was shuttered after the arrest of its administrator.”
Silnikau wasn’t new to this world when he launched it. He’d been active on Russian-speaking cybercrime forums since at least 2005, and spent five years, from 2011 to 2016, embedded in Direct Connection, one of the more notorious cybercrime sites of that era, until police arrested its administrator and shut it down. Ransom Cartel, in other words, was the work of someone who’d already spent over a decade learning how this economy runs.
What he actually built was infrastructure, not intrusions. He supplied participants with stolen credentials and locking software, then ran a hidden site where affiliates monitored ongoing attacks, negotiated ransom demands with victims, and split the proceeds among themselves. That hidden panel was the real product: Silnikau wasn’t selling malware, he was selling a functioning business.
Between 2021 and 2023, Ransom Cartel conspirators hit at least 18 companies, spanning California, New York, Nebraska, and targets outside the US entirely. The pitch to would-be affiliates, preserved in the indictment, set a floor on what kind of victims were worth their time: “Revenue: from $10 million. Prices from $100 and up.” That’s not a hacker fishing for any target that’ll bite; that’s someone running numbers on which victims can actually afford to pay.
“From 2021 to 2023, Silnikau’s Ransom Cartel conspirators executed ransomware attacks on at least 18 companies around the world, including companies based in California, New York, Nebraska, and countries other than the United States.” continues the press release. “The hackers stole data and demanded monetary payments in exchange for the key to unlock the stolen data, or in exchange for a promise not to publish the victim’s data. Ransom Cartel’s growth was disrupted by the arrest of Silnikau in July 2023.”
Silnikau’s arrest in July 2023 is what stalled the operation’s growth, according to prosecutors. Poland extradited him to face charges in the Eastern District of Virginia roughly a year later, in August 2024.
Sixteen years sounds like a lot until you set it against Yaroslav Vasinskyi’s 13 years and seven months for running over 2,500 REvil attacks worth more than $700 million in demands back in 2024. Ransom Cartel’s scale was smaller, but the sentence landed heavier, which says something about how prosecutors and judges are calibrating these cases as the pattern repeats.
This Virginia case is only half the story, and the DOJ’s own announcement doesn’t mention the other half. Silnikau faces a separate, unresolved prosecution in New Jersey over the Angler Exploit Kit malvertising scheme, which ran from 2013 to 2022 alongside two co-defendants, Volodymyr Kadariya and Andrei Tarasov, both still at large. The Secret Service still lists Tarasov as wanted, and the State Department has a $2.5 million reward out for information leading to Kadariya.
There’s also a lingering question researchers never fully resolved: whether Ransom Cartel was connected to REvil at all. Palo Alto Networks’ Unit 42 found the operators holding REvil’s original source code but apparently missing the obfuscation engine that gang relied on, and speculated the two groups crossed paths at some point without ever calling it a rebrand. Neither the indictment nor this week’s sentencing announcement brings up REvil once, so that thread stays exactly where it’s always been: interesting, unresolved, and somebody else’s problem to chase down.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Ransom Cartel)