Maksim Silnikau, the creator and administrator of the malicious organization, was arrested in July of 2023 and faced his sentencing in August of 2026.
What happened
Maksim Silnikau, 40, was sentenced on August 5th to 16 years in prison. His charges included conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
According to the United States’ Attorney General’s Office, Silnikau was the administrator of Ransom Cartel, a ransomware group created by him in May 2021. At that time, Silnikau began recruiting participants from cybercrime forms, at times distributing tools and information. He also maintained a website used by his organization to monitor and control ransomware attacks. The website allowed the perpetrators to communicate with each other as well as their victims. The site was also involved in payment administrator, like distributing ransomware payments among the conspirators. Ransom Cartel no longer seems to be operating. Silnikau was arrested in 2023 for his involvement in Ransom Cartel and was extradited to the US through Poland. He faced his charges for cybercrime in the Eastern District of Virginia.
In the know
It’s believed that Ransom Cartel conspirators participated in attacks on approximately 18 companies worldwide. States impacted in the US included California, New York, and Nebraska. Hackers stole data and received ransom payments in exchange for unlocking the encrypted data or agreeing not to sell it. According to the Record, Ransom Cartel shared several similarities in attack strategies with another ransomware organization, REvil, which disappeared in 2021 following international law enforcement pressure. It’s possible, although not confirmed, that some members of Ransom Cartel had previously been part of REvil.
Going deeper
Silnikau has had a long career in cybercrime. He was known to also be part of Russian-speaking cybercrimes forums since at least 2025. He was a member of the cybercrime website Direct Connection from 2011 to 2016, when the site was shut down following the administrators arrest.
According to The Record, in Silnikau's most recent conviction, he has several co-conspirators, Belarusian-Ukrainian Vladimir Kadariya, and Russian national Andrei Tarasov. It’s believed those three individuals created the first ever ransomware-as-a-service business model in 2011. Their product was called Reveton and allowed low-skilled cybercriminals to launch ransomware attacks for a few. It’s believed the group extorted approximately $400,000 a month from victims between 2012 and 2014.
The big picture
The arrest and sentence of Silnikau’s points to how interconnected the world of cybercrime is, and that there are many different groups, some of which splinter and spread information. In 2024, IBM tracked an increase in ransomware organizations by approximately 50% each year. The multitude of different groups means organizations have to prepare for different attack strategies, evolving tools, and unique threats. With so many groups, eliminating one person doesn’t stop the spread of tools and criminal knowledge. It’s unlikely that other individuals Silnikau worked with are done with cybercrime, even if Ransom Cartel’s operations are halted. Nevertheless, successfully arresting and charging criminals is a step in the right direction. While Silnikau’s sentencing won’t stop cybercrime, it could have a chilling effect on other criminals who want to avoid his fate.
FAQ
What types of tools and information did Silnikau give his accomplices?
He provided information about compromised computers, like stolen credentials, and gave out tools like software that could encrypt compromised computers.
How has Ransomware-as-a-Service (Raas) changed ransomware attacks?
RaaS’ effect on ransomware attacks has been extreme. These services have resulted in more ransomware groups and attacks, because ransomware tools come to lower-skilled criminals ready to deploy. Attacks are now easier than ever. In exchange for the tool, the creators (or higher-skilled criminals), often receive proceeds from the attack. While Reveton may have been one of the first RaaS tools, there have now been many since.
