A federal judge sentenced the creator of a ransomware-as-a-service operation to 16 years in prison for running a criminal enterprise that targeted at least 18 companies across the United States and internationally. Maksim Silnikau, a 40-year-old Belarusian national, received the sentence on August 5 in Alexandria, Virginia, for building and operating Ransom Cartel between 2021 and 2023, according to the Justice Department. His victims included businesses in California, New York, and Nebraska, along with firms in other countries.
Silnikau didn't personally break into most of the networks his operation locked down. Instead, he constructed the infrastructure around the attacks: the encryption software, the stolen credentials he purchased from initial access brokers, and a concealed control panel where partners tracked intrusions, bargained with victims, and divided the money. Working under the aliases "J.P. Morgan," "lansky," and "xxx," he ran a ratings system that rewarded productive affiliates and funneled ransom payments through cryptocurrency mixers. Prosecutors brought seven charges in Virginia and secured convictions on three, though the announcement doesn't specify whether Silnikau pleaded guilty or went to trial, and it lists no restitution or forfeiture amount.
The 16-year term exceeds the 13 years and seven months given to Yaroslav Vasinskyi in 2024 for conducting more than 2,500 REvil attacks that demanded over $700 million in ransoms. But it resolves only part of Silnikau's legal trouble—a separate federal case in New Jersey remains open, and the two men charged with him there are still fugitive. According to the indictment returned in June 2023 and unsealed in 2024, Silnikau launched the operation under a different name in May 2021, rebranded it "Ransom Cartel" in late 2021, and then tried to promote it through security news websites. The charging document includes the advertisement his group posted to a Russian-language cybercrime forum on May 4, 2021, soliciting access to corporate networks anywhere outside the Commonwealth of Independent States and setting minimum thresholds: "Revenue: from $10 million. Prices from $100 and up." The final charged act occurred on April 25, 2023, when he negotiated terms for supplying computers to be encrypted, three months before his July 2023 arrest in Poland, which prosecutors say halted Ransom Cartel's expansion. Poland extradited him to the United States in August 2024.
The sentence reflects how seriously courts now treat ransomware orchestration, even when the defendant doesn't personally execute the attacks. The report explains that Silnikau's business model—buying stolen credentials, providing locking tools, and taking a cut of affiliate ransoms—allowed less-skilled criminals to launch sophisticated intrusions they couldn't manage alone. Palo Alto Networks' Unit 42 found in its 2022 analysis that Ransom Cartel operators possessed the original REvil source code but apparently lacked the obfuscation engine that gang used, speculating only that the groups were connected at some point. Neither the indictment nor the sentencing release mentions REvil. Silnikau faces a separate charge in New Jersey alongside Volodymyr Kadariya and Andrei Tarasov over the Angler Exploit Kit malvertising scheme, which operated from 2013 to 2022. The Secret Service still lists Tarasov as wanted, and the State Department is offering up to $2.5 million for information leading to Kadariya's arrest or conviction, though the Virginia announcement says nothing about that case. The steep sentence suggests prosecutors will continue pursuing the architects of ransomware platforms as aggressively as the attackers themselves. As ransomware-as-a-service models proliferate, courts may view platform operators as more culpable than individual affiliates, since they enable entire ecosystems of crime rather than isolated incidents.

