A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau, 40, to 16 years in prison on August 5 for creating and operating Ransom Cartel, a ransomware-as-a-service scheme he launched in 2021. Silnikau, a Belarusian national, was convicted of conspiracy to commit offenses against the United States, wire fraud conspiracy, and aggravated identity theft.
According to court documents, Silnikau built the Ransom Cartel platform and recruited affiliates through cybercrime forums. He supplied conspirators with stolen credentials and details on compromised networks, along with tools used to encrypt victim systems. He also maintained a hidden website that served as the operation’s command center, used to monitor attacks, coordinate with affiliates and victims, and distribute ransom proceeds among participants.
Between 2021 and 2023, Ransom Cartel affiliates targeted at least 18 organizations in the United States and abroad, including companies in California, New York, and Nebraska. The group stole victim data and demanded payment in exchange for decryption keys or a promise not to leak the stolen information. The operation was disrupted following Silnikau’s arrest in 2023.
Ties to the Angler Exploit Kit
In a separate case, prosecutors charged Silnikau with helping distribute the Angler exploit kit, a malware delivery framework that was widely used before it was disrupted in 2016. Court documents allege that between 2013 and 2022, Silnikau worked with Volodymyr Kadariya, a Belarusian and Ukrainian national, and Andrei Tarasov, a Russian national, to spread malware and run online scams through malvertising campaigns.
Silnikau was arrested in Spain and extradited to the United States from Poland in 2024. Tarasov was detained in Germany but was released after six months and returned to Russia. The US government has offered a $2.5 million reward for information leading to Kadariya, who remains at large.
Why It Matters
The sentencing marks one of the more significant law enforcement outcomes against a ransomware-as-a-service operator, highlighting continued international cooperation in extraditing and prosecuting cybercriminals who build the infrastructure enabling affiliate-driven ransomware campaigns. The case also underscores how exploit kit distribution and ransomware operations can be run by overlapping networks of threat actors over long periods.
