Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Kingpin Silnikau Gets 16 Years in Prison

Federal courthouse interior with judge's bench, US flag, and law enforcement hint, conveying justice and authority.

On August 5, a federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison for creating and running Ransom Cartel, the ransomware-as-a-service operation prosecutors say he established in 2021.

Maksim Silnikau — sentence, identity, and procedural facts

Silnikau, a 40-year-old Belarusian national who used the online handles "J.P. Morgan," "lansky" and "xxx," received the 16‑year prison term after a Justice Department prosecution in Alexandria. Prosecutors charged seven counts in Virginia and announced convictions on three; the public announcement does not state whether Silnikau pleaded guilty or was convicted at trial, nor does it list any restitution or forfeiture figures.

According to the record, Polish authorities extradited Silnikau to the United States in August 2024. Prosecutors say his arrest in July 2023 stalled Ransom Cartel's growth. The last charged act in the Virginia case occurred on April 25, 2023, when Silnikau allegedly negotiated terms for supplying computers to be locked.

How Ransom Cartel operated as a business

Prosecutors portray Ransom Cartel not as a single attacker but as a commercial platform: Silnikau built the locking software, purchased stolen credentials from initial access brokers, and hosted a hidden affiliate panel where third‑party affiliates monitored attacks, negotiated with victims and split proceeds. He operated a ratings system that rewarded productive affiliates and directed ransom payments through cryptocurrency mixers.

The indictment preserved an advertisement posted by the conspiracy to a Russian‑language cybercrime forum on May 4, 2021, seeking access to corporate networks anywhere outside the Commonwealth of Independent States. The ad screened by victim size and set a floor on target revenue — "Revenue: from $10 million. Prices from $100 and up." The public record says Silnikau ran the operation under another name from May 2021, renamed it "Ransom Cartel" in late 2021, and attempted to publicize it on security news sites.

Victims and the timeline of attacks

Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms located in California, New York and Nebraska and others abroad, according to the Justice Department. Cybersecurity researchers at Palo Alto Networks' Unit 42 did not observe Ransom Cartel until mid‑January 2022, while prosecutors date the operation to May 2021; the indictment and its timeline bridge that gap.

Unit 42's 2022 analysis reported that the operators held the original REvil source code but apparently did not possess the obfuscation engine REvil used; the researchers speculated only that the groups were linked at some point. Neither the indictment nor the Virginia sentencing release mentions REvil.

Related prosecutions, wanted suspects, and comparative sentences

The 16‑year sentence in Virginia "runs past" the 13 years and seven months imposed on Yaroslav Vasinskyi in 2024 for more than 2,500 REvil attacks and over $700 million in ransom demands. But the Virginia judgment resolves only part of the legal picture: a second federal prosecution in New Jersey is unresolved, and two men charged alongside Silnikau in New Jersey remain at large.

Silnikau was separately charged in New Jersey with Volodymyr Kadariya and Andrei Tarasov over an Angler Exploit Kit malvertising scheme that prosecutors say ran from 2013 to 2022. The Secret Service still lists Tarasov as wanted, and the State Department is offering up to $2.5 million for information leading to Kadariya's arrest or conviction. The sentencing announcement in Virginia does not address the New Jersey case.

What this means for technologists, prosecutors, and affected enterprises

  • Technologists and security teams will watch for operational features highlighted in the case record: affiliate panels that centralize monitoring and negotiations, ratings systems that incentivize prolific affiliates, use of stolen credentials from initial access brokers, and routing ransom proceeds through cryptocurrency mixers.
  • Prosecutors and law enforcement will point to the cross‑border elements reported here — an advertisement on a Russian‑language forum, extradition from Poland in August 2024, and an unresolved New Jersey prosecution — as evidence of the international dimensions and the continued challenges of bringing all participants to justice. The State Department's $2.5 million reward for information on one accused co‑conspirator underscores that challenge.
  • Affected enterprises should note the profile of targets in the indictment: companies with revenues starting at $10 million and locations including California, New York and Nebraska were among those hit, illustrating the range of victims named in the Justice Department account.

The sentence handed to Maksim Silnikau closes a significant chapter in the Ransom Cartel story but not the book: prosecutors say the Virginia case addresses only half the prosecutions tied to his alleged schemes, two co‑defendants in New Jersey remain at large, and the public record leaves open how the broader set of affiliates and infrastructure will be disrupted going forward.

Original story