A U.S. federal court has sentenced the alleged founder and operator of the Ransom Cartel ransomware group to 16 years in prison, concluding a case that prosecutors say involved years of cyber extortion against organizations in multiple countries.
The U.S. Department of Justice (DOJ) announced that Maksim Silnikau, a 40-year-old Belarusian national, was convicted on charges including conspiracy to commit offenses against the United States, conspiracy to commit wire fraud and aggravated identity theft. Prosecutors described Silnikau as the central figure behind the ransomware operation, responsible for building the group’s infrastructure and coordinating attacks carried out by affiliated cybercriminals.
According to court records, Silnikau had participated in Russian-speaking cybercrime communities for nearly two decades, using online aliases including “J.P. Morgan,” “xxx,” and “lansky.” Investigators also linked him to the now-defunct Direct Connection cybercrime forum, where he was active for several years before the platform was dismantled by law enforcement.
Authorities say Silnikau established the Ransom Cartel operation in 2021, adopting the increasingly common ransomware-as-a-service model. Instead of conducting every attack himself, he allegedly recruited affiliates through underground forums and supplied them with tools needed to compromise corporate networks. Those resources reportedly included stolen login credentials, ransomware software and access to a dedicated online portal where members could coordinate attacks, negotiate with victims and divide ransom proceeds.
Between 2021 and 2023, investigators identified attacks against at least 18 organizations located in the United States and other countries. Victims included businesses in California, New York and Nebraska, as well as companies outside the U.S. During the intrusions, attackers allegedly stole sensitive corporate information before encrypting systems and demanding payment in exchange for decryption tools or promises not to publish the stolen data.
Federal prosecutors said the group sought to collect more than $5.2 million in ransom payments. Known victims reported losses exceeding $6.7 million, although investigators believe the true financial impact was significantly higher because some incidents were never disclosed to authorities.
Court filings describe several attacks that caused prolonged operational disruption. One ransomware incident reportedly forced a medical technology company developing robotic surgical systems to operate under disruption for approximately two months. Another attack targeted infrastructure supporting multiple law firms, leaving some organizations unable to function for weeks. Two firms ultimately paid ransoms of $125,000 and $300,000 respectively after extended outages, with prosecutors estimating that the combined financial impact of those incidents reached approximately $2.2 million.
Researchers have previously noted that Ransom Cartel, which emerged publicly in late 2021, shared technical characteristics with the notorious REvil ransomware family. Although the malware appeared similar in several respects, security analysts concluded it lacked some of REvil’s more advanced protections, leading to speculation that it may have been developed using only part of the original codebase. That assessment has not been officially confirmed.
Prosecutors also alleged that Silnikau played an active role throughout the criminal enterprise beyond developing the ransomware itself. According to the DOJ, he recruited affiliates, worked with brokers who sold access to compromised corporate networks, participated in ransom negotiations, and used cryptocurrency mixing services in an effort to obscure the movement of illicit payments.
Silnikau’s arrest followed an international law enforcement investigation. He was initially detained in Spain in July 2023 pending extradition to the United States. Authorities say he later escaped while awaiting transfer but was subsequently captured while attempting to cross from Poland into Belarus. He eventually agreed to extradition and was transported to the United States, where he was prosecuted in the Eastern District of Virginia.
The sentencing marks another significant prosecution targeting operators of ransomware-as-a-service platforms, a criminal model that has enabled cybercriminal groups to expand attacks by providing malware and infrastructure to affiliates in exchange for a share of ransom payments.