Actor Profile

Maksim Silnikau is a 40-year-old Belarusian national who created and administered the Ransom Cartel ransomware-as-a-service (RaaS) operation. Active on Russian-speaking cybercrime forums since at least 2005, Silnikau operated under aliases including "J.P. Morgan," "xxx," and "lansky." He was a member of the Direct Connection cybercrime website from 2011 to 2016. Motivated by financial gain, Silnikau developed Ransom Cartel beginning in May 2021, recruiting affiliates through underground forums and providing them with stolen credentials, encryption tools, and an affiliate management platform. He held a central role in the operation, coordinating with initial access brokers, negotiating with victims, and laundering ransom payments through cryptocurrency mixers. Arrested in Spain in July 2023, he fled while awaiting extradition but was later captured attempting to cross from Poland to Belarus.

TTPs (Tactics, Techniques, Procedures)

Silnikau's Ransom Cartel operation employed classic ransomware-as-a-service TTPs. Initial access was obtained through partnerships with initial access brokers who supplied compromised corporate network credentials (T1078: Valid Accounts). The operation provided affiliates with custom ransomware encryptors sharing code similarities with REvil (T1486: Data Encrypted for Impact). Threat actors conducted data exfiltration prior to encryption (T1041: Exfiltration Over C2 Channel) to enable double extortion tactics. Silnikau operated centralized affiliate infrastructure for attack coordination and victim communication. Post-compromise, ransom payments were laundered through cryptocurrency mixers (T1027: Obfuscated Files or Information) to evade financial tracking by law enforcement. The operation distributed revenue shares among affiliates following successful extortion.

Targets & Patterns

Ransom Cartel targeted at least 18 companies worldwide between 2021 and 2023, with confirmed victims in California, New York, Nebraska, and multiple countries outside the United States. The operation demonstrated opportunistic targeting across diverse sectors including healthcare technology and legal services. Notable attacks include an August 2022 compromise of a medical technology startup developing robotic surgical systems, causing two months of operational disruption, and a May 2023 attack on law firm infrastructure resulting in business disruptions lasting days to months. Two law firms paid ransoms of $125,000 and $300,000 respectively after extended operational suspensions. The targeting pattern suggests a focus on organizations with high operational dependencies and financial capacity to pay ransoms, with combined losses from the law firm attacks alone reaching approximately $2.2 million.

Historical Context

Ransom Cartel launched publicly in December 2021, emerging during the post-REvil landscape. The ransomware encryptor shared code similarities with REvil but lacked some of REvil's obfuscation features, leading researchers to theorize it was created by a former REvil core member without access to complete source code. Silnikau's cybercrime career predates Ransom Cartel significantly—he was active on Russian-speaking forums since 2005 and participated in the Direct Connection cybercrime marketplace from 2011 until its 2016 shutdown following administrator arrests. The Ransom Cartel operation ran from May 2021 through at least May 2023, attempting to extort at least $5.2 million and causing over $6.7 million in documented losses across 18 known victims. Silnikau's July 2023 arrest in Spain was part of an international law enforcement operation, though he briefly evaded custody before recapture.

Defensive Recommendations

  • Monitor for use of valid accounts from unusual geographic locations or at abnormal times, particularly privileged credentials obtained through initial access brokers (T1078)
  • Implement network segmentation and restrict lateral movement capabilities to limit ransomware spread following initial compromise
  • Deploy behavioral detection for data exfiltration patterns, including large file transfers to external destinations and unusual compression activity preceding encryption events (T1041)
  • Establish offline, immutable backups with regular testing of restoration procedures to enable recovery without ransom payment
  • Monitor cryptocurrency transactions and implement controls to detect ransom payment preparation, while establishing incident response procedures that involve law enforcement early in ransomware incidents