The man who walked out of cybercrime forums in 2021 with a fresh ransomware operation he called Ransom Cartel didn’t come from nowhere. By that point, Maksim Silnikau had already spent a decade turning ransomware into a franchise, flooding the internet with fake police warnings, and quietly running one of the most widely-used exploit kits of the 2010s.
On August 5, 2026, a federal judge in Alexandria, Virginia, sentenced Silnikau to 16 years in prison. He is 40 years old, Belarusian, and according to Britain’s National Crime Agency, one of the most prolific Russian-speaking cybercriminals ever identified.
Most coverage has focused on the Ransom Cartel. That’s fair. It’s the case that sent him to prison. But Ransom Cartel is really the last chapter of a much longer story.
Quick summary: Maksim Silnikau, operating under the aliases “J.P. Morgan,” “lansky,” “xxx,” and “targa,” was sentenced to 16 years in US federal prison on August 5, 2026. He created and ran Ransom Cartel, a ransomware-as-a-service operation that attacked at least 18 companies between 2021 and 2023. Prosecutors say he also co-created Reveton, widely considered the first-ever ransomware-as-a-service product, back in 2011, and was linked to the Angler Exploit Kit, which at its peak generated an estimated $34 million a year.
Who Is Maksim Silnikau?
He was active on Russian-language cybercrime forums from at least 2005, and by 2011 he was building criminal infrastructure rather than just browsing for it. Between 2011 and 2016, he was a member of a forum called Direct Connection, a vetted, closed-door marketplace for serious cybercriminals that only went dark after its administrator was arrested.
His online alias “J.P. Morgan” is a reasonable clue about how he saw himself: less a hacker in the traditional sense, more someone running a financial operation that happened to involve malware.
He Helped Build the First Ransomware-as-a-Service Operation
In 2011, Silnikau, alongside co-conspirators Volodymyr Kadariya and Andrei Tarasov, developed a ransomware strain called Reveton. Prosecutors have described Reveton as the first-ever ransomware-as-a-service business model, meaning it wasn’t just a tool, it was a service that other, less technically skilled criminals could rent and deploy for a fee.
The product worked on fear. When Reveton infected a computer, it locked the screen and displayed a fake message from the FBI, or whichever local law enforcement agency matched the victim’s location, claiming the user had been caught accessing illegal content like child abuse material. Pay a fine, and the computer would unlock. The message even looked authentic because it pulled the victim’s IP address and customized the wording to sound local.
Most victims had no idea it was fake. The group was pulling in roughly $400,000 a month between 2012 and 2014.
Understanding how Reveton worked matters because it set the template for almost everything that came after. The ransomware-as-a-service model Silnikau helped introduce in 2011 is now the standard business structure behind groups like LockBit, Qilin, and BlackCat, the same groups that were, separately, sending money through the AudiA6 laundering service we covered earlier this year. The model has scaled dramatically, but the core idea, build the tool, rent it to affiliates, take a cut, started here.
The Angler Exploit Kit: Half a Billion Victims
Alongside Reveton, Silnikau was linked to the Angler Exploit Kit, a piece of infrastructure used to automatically infect devices by scanning for vulnerabilities in web browsers and plugins when a user visited a legitimate-looking site with a poisoned ad. This technique is called malvertising: hiding malicious code inside digital advertisements that run on real websites.
Silnikau’s use of malvertising was aggressive enough that researchers measured a 325% increase in malvertising campaigns by early 2014. At its peak, Angler represented around 40% of all exploit kit infections globally, targeting roughly 100,000 devices at a time. The UK’s National Crime Agency later estimated these campaigns affected over half a billion victims worldwide, with the operation generating an estimated $34 million annually.
That kind of scale doesn’t happen without infrastructure, the same type of dark web forums and criminal marketplaces where initial access, credentials, and tools are bought and sold every day.
What Ransom Cartel Was and How It Worked
After Reveton and the Angler activity went dormant, Silnikau wasn’t done. He posted an advertisement to a Russian-language cybercrime forum on May 4, 2021, looking for access to corporate networks anywhere outside the Commonwealth of Independent States. His screening criteria were direct: revenue of at least $10 million, prices starting at $100 and up.
He built what prosecutors call a ransomware-as-a-service operation, with Ransom Cartel at its center. Here’s how it was structured:
Silnikau sat at the top, providing the locking software, stolen credentials he sourced from initial access brokers, and a hidden panel where affiliates could log in and manage their own attacks. That panel let participants monitor compromises, send ransom notes, negotiate with victims, and track how the money was split between everyone involved. He even ran a ratings system to reward the more productive affiliates.
Ransom Cartel was a double extortion operation. Attackers didn’t just encrypt the victim’s data. They stole it first. If a company refused to pay for the decryption key, they’d receive a separate threat to publish the stolen data, or send it directly to the victim’s competitors and business partners. Some victims faced threats to notify news organizations. Multiple pressure points at once.
Between 2021 and 2023, Ransom Cartel affiliates hit at least 18 organizations, including companies based in California, New York, and Nebraska, along with targets outside the United States. Ransom payments were pushed through cryptocurrency mixers to obscure the trail, a similar laundering approach to what we covered in the supply chain attack warning signs piece, where criminal groups rely on the same underground financial infrastructure to stay operational.
The REvil Connection: Real or Overstated?
Because Ransom Cartel appeared not long after , REvil largely collapsed under international law enforcement pressure in late 2021, researchers initially speculated the two were linkedpossibly a rebrand or a successor.
Palo Alto Networks’ Unit 42, which published one of the most detailed technical analyses of Ransom Cartel in 2022, found that the operators appeared to possess the original REvil source code but not the obfuscation engine that REvil used. That’s a meaningful technical distinction. Having someone’s source code doesn’t mean you’re the same group, or even that you got it legitimately. Unit 42 noted only that the two groups were “linked at some point” without being more specific.
Neither the indictment nor the official DOJ sentencing announcement mentions REvil. That gap is deliberate. Prosecutors proved what they could prove in court, and speculative connections to a separate defunct group weren’t part of the case they built.
The Arrest, Extradition, and Two Separate Cases
Silnikau’s physical downfall came in July 2023. The Spanish Guardia Civil, working alongside the US Secret Service, FBI, and the UK’s National Crime Agency, arrested him at an apartment in Estepona, Spain. According to the DOJ’s press release, prosecutors say that arrest disrupted Ransom Cartel’s growth trajectory. Poland extradited him to the United States in August 2024.
Here’s something the other coverage mostly glosses over: Silnikau faces two separate federal cases, not one. The Virginia case — now resolved with the 16-year sentence, covered the Ransom Cartel operation specifically. A second case in the District of New Jersey covers the malvertising and Angler Exploit Kit activities from 2013 to 2022, and that case remains open.
The Virginia indictment charged seven counts. He was convicted on three: conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
What About His Co-Conspirators?
Two men were charged alongside Silnikau in the New Jersey case, and both are still free.
Volodymyr Kadariya, 38, a Belarusian-Ukrainian national, remains at large. The US State Department is offering up to $2.5 million for information leading to his arrest or conviction.
Andrei Tarasov, 33, a Russian national, was arrested in Germany but released after roughly six months and returned to Russia. The US Secret Service still lists him as wanted.
This is a common reality with international cybercrime cases: arrest one person, and the network doesn’t disappear. Affiliates scatter, co-conspirators flee to jurisdictions that won’t extradite, and some simply wait. The two people still out there are actively sought, which tells you how seriously prosecutors take the unresolved half of this case.
How Does This Sentence Compare?
At 16 years, this sentence sets a new benchmark for ransomware convictions in the United States.
In May 2024, Yaroslav Vasinskyi, the Ukrainian national behind more than 2,500 REvil attacks and over $700 million in ransom demands, received 13 years and 7 months. REvil attacked more victims and demanded vastly more money. Silnikau’s sentence is longer.
What explains the gap? A few factors: the scope of his entire criminal career, not just Ransom Cartel. The fact that he co-created what prosecutors call the first-ever RaaS model in 2011. The Angler Exploit Kit’s scale and reach. And the deliberate structure of Ransom Cartel as an operation designed to evade detection while maximizing damage. The court appears to have sentenced the full picture, not just the two years of Ransom Cartel attacks.
For context on how ransomware money moves after an attack, and why these operations are so hard to fully dismantle even after the leader is caught, our piece on the AudiA6 crypto laundering takedown breaks down the financial infrastructure that makes ransomware profitable in the first place.
Why This Matters Beyond the Headlines
Silnikau’s arrest and conviction landed after a 15-year career. He was on investigators’ radar from as far back as 2015, when the UK’s NCA opened a parallel investigation alongside the US Secret Service and FBI. That’s a long time between identifying someone and successfully extraditing them.
It also illustrates something important about how RaaS works: even if you shut down Ransom Cartel today, the affiliates who used its infrastructure don’t disappear. They move to the next platform. The model Silnikau helped pioneer in 2011 is now a mature criminal industry, with dozens of competing groups using the same basic structure. Removing one person at the top of one group doesn’t rewrite the economics underneath.
What changed in this case was a combination of Spain’s willingness to arrest, Poland’s willingness to extradite, and years of cross-agency coordination across multiple countries, the same international cooperation structure that took down AudiA6, Archetyp Market, and the REvil infrastructure before it.
If your business was ever a target of ransomware, or you’re concerned your data is circulating somewhere it shouldn’t be, our dark web monitoring guide covers the practical steps that actually matter after an exposure.
Frequently Asked Questions
Who is Maksim Silnikau?
A 40-year-old Belarusian national sentenced to 16 years in US federal prison for creating and running the Ransom Cartel ransomware-as-a-service operation. He is also linked to Reveton ransomware and the Angler Exploit Kit.
What was Ransom Cartel?
A ransomware-as-a-service operation that ran from 2021 to 2023, attacking at least 18 companies. Affiliates rented access to Silnikau’s infrastructure and tools in exchange for sharing ransom payments. It used double extortion: encrypting data and threatening to publish it.
What was Reveton?
An earlier ransomware product developed by Silnikau and co-conspirators around 2011, widely considered the first ransomware-as-a-service business model. It locked victims’ screens with fake law enforcement warnings and generated roughly $400,000 a month at peak.
What is Ransom Cartel’s connection to REvil?
Unit 42 found Ransom Cartel possessed REvil source code but not REvil’s obfuscation engine. Researchers speculate the groups were linked at some point. Prosecutors did not make the REvil connection part of the official case.
Are his co-conspirators in custody?
No. Volodymyr Kadariya remains at large with a $2.5 million US reward on his head. Andrei Tarasov was arrested in Germany but released and returned to Russia. Both face charges in the unresolved New Jersey case.