Ransom Cartel Leader Sentenced to 16 Years for Global Ransomware and Exploit Kit Operations
A Belarusian cybercriminal, identified as the architect behind the notorious **Ransom Cartel** ransomware-as-a-service operation and the **Angler** exploit kit, has been sentenced to 16 years in a U.S. prison. **Maksim Silnikau**, 40, known by aliases such as "J.P. Morgan" and "targa," faced justice for orchestrating attacks against numerous organizations worldwide and pioneering early ransomware business models.
# Ransom Cartel Kingpin Receives 16-Year Sentence
**Maksim Silnikau**, a 40-year-old Belarusian national and a prominent figure in the Russian-speaking cybercrime underworld, has been sentenced to 16 years in a U.S. prison. Silnikau was convicted for his role as the creator and leader of the **Ransom Cartel** ransomware operation, which targeted businesses globally.
His online activities, spanning nearly two decades, saw him described by Britain's National Crime Agency as one of the most prolific Russian-speaking cybercriminals.
## The Rise of Ransom Cartel
**Ransom Cartel** emerged in late 2021 as a sophisticated ransomware-as-a-service (RaaS) platform. Silnikau developed and administered this platform, leveraging underground forums to recruit accomplices. He provided them with essential tools: stolen credentials, access to compromised networks, and the ransomware itself, which was used to encrypt victim systems.
Prosecutors highlighted Silnikau's operational control, including managing the group's hidden online infrastructure. This allowed members to coordinate attacks, negotiate ransom payments, and distribute illicit proceeds.
Between 2021 and 2023, **Ransom Cartel** affiliates launched attacks against at least 18 organizations, including businesses in California, New York, and Nebraska. These attacks involved exfiltrating sensitive data before encrypting systems, with demands for decryption keys or pledges not to publish stolen information.
Cybersecurity researchers noted that **Ransom Cartel** shared technical similarities with the now-defunct **REvil** ransomware, suggesting a possible lineage or reuse of malware components following **REvil**'s disappearance in 2021 under international law enforcement pressure.
## Angler Exploit Kit and Early RaaS Models
Beyond **Ransom Cartel**, Silnikau is also believed to be the developer of the **Angler** exploit kit. This notorious cybercrime tool, widely used in the mid-2010s, silently infected visitors to legitimate websites via malicious online advertisements, generating tens of millions of dollars annually.
Silnikau's criminal enterprise extends further back. Alongside alleged co-conspirators, Belarusian-Ukrainian **Vladimir Kadariya**, 38, and Russian national **Andrei Tarasov**, 33, he pioneered what prosecutors described as the first ransomware-as-a-service business model in 2011. This product, named **Reveton**, enabled low-skilled cybercriminals to execute ransomware attacks for a fee.
Using **Reveton**, the group extorted approximately $400,000 a month from victims between 2012 and 2014.
## Arrest and Disruption
Silnikau was arrested in Spain in July 2023 and subsequently extradited to the U.S. via Poland to face charges in the Eastern District of Virginia. Prosecutors assert that his arrest significantly disrupted **Ransom Cartel**'s operations. His alleged co-conspirators, **Kadariya** and **Tarasov**, have been charged in absentia in the U.S.