A Belarusian national who built and ran the Ransom Cartel ransomware operation has been sentenced to 16 years in prison for orchestrating a scheme that struck at least 18 companies across the United States and abroad, the Justice Department announced.
Maksim Silnikau, 40, received the sentence after pleading guilty to conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft, according to the Justice Department. Federal prosecutors said Silnikau had operated under the online aliases “J.P. Morgan,” “xxx,” and “lansky” on Russian-language cybercrime forums since 2005, and that he belonged to the Direct Connection cybercrime website from 2011 until its closure in 2016 following the arrest of its administrator.
Court records show Silnikau began building the Ransom Cartel ransomware network in May 2021, drawing recruits from underground forums to carry out intrusions on his behalf. He furnished those affiliates with stolen network credentials and encryption tools, and he built a companion platform that let members coordinate attacks, negotiate with victims and split the proceeds once ransoms were collected.
From 2021 through 2023, affiliates tied to the operation breached at least 18 companies, including firms in California, New York and Nebraska as well as targets outside the United States. In each case, prosecutors said, the attackers exfiltrated corporate data and demanded payment either for a decryption key or for a promise not to leak the stolen files publicly. The Justice Department put the attempted extortion total at more than $5.2 million, while confirmed losses among the 18 identified victims exceeded $6.7 million — a figure prosecutors said likely understates the true toll because not every victim came forward.
Among the documented incidents, a medical technology startup working on robotic surgical systems saw its operations disrupted for two months after an August 2022 breach. In May 2023, the group also knocked out systems shared by several law firms, causing outages that stretched from a few days to several months. One affected firm paid $125,000 after nearly a month offline, while another halted operations for close to a month before handing over $300,000. Prosecutors estimated the combined damage from those two incidents at roughly $2.2 million.
Ransom Cartel first appeared publicly in December 2021, and researchers noted its code bore similarities to the REvil ransomware strain. The absence of several obfuscation techniques found in REvil led analysts to suspect the tool was built by a former REvil affiliate who lacked access to the group’s full source code.
Investigators described Silnikau as the operation’s central figure, responsible for recruiting affiliates, coordinating with brokers who sold access into breached corporate networks, communicating directly with victims and managing ransom collection. He also routed the resulting cryptocurrency payments through mixing services in an effort to obscure the money’s origin from investigators.
Spanish authorities arrested Silnikau on July 18, 2023, as part of a coordinated international law enforcement action. He later fled while his extradition to the United States was pending and was apprehended while trying to cross from Poland into his native Belarus. “The defendant fled Spanish authorities while awaiting extradition to the United States and was apprehended while trying to cross from Poland to his native Belarus,” prosecutors wrote in their sentencing filing. Silnikau subsequently agreed to extradition and was transferred from Poland to the United States, where he was prosecuted in the Eastern District of Virginia.
Click Here For The Original Source.
