A Belarusian cybercriminal widely considered one of the most prolific Russian-speaking threat actors of the past two decades was sentenced to 16 years in federal prison on August 5, 2026, for operating the Ransom Cartel ransomware-as-a-service (RaaS) platform and a sprawling malvertising network.
The Defendant: Maksim Silnikau
Maksim Silnikau, 40, operated under the aliases "J.P. Morgan," "targa," "xxx," and "lansky" — names that became notorious across underground cybercriminal forums beginning in 2005. The UK's National Crime Agency previously described him as one of the most dangerous cybercriminals active today.
Silnikau was arrested in Spain in July 2023 and extradited from Poland before being convicted in the Eastern District of Virginia (Alexandria). He was found guilty of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
What Was Ransom Cartel?
Ransom Cartel was a ransomware-as-a-service operation Silnikau built and launched in May 2021. The operation shared notable technical similarities with the infamous REvil ransomware group and followed the standard RaaS playbook:
- Affiliate recruitment through underground criminal forums
- Initial access sourced from credential brokers and infostealer malware
- Hidden affiliate panel for monitoring active attacks and negotiating ransoms
- Ratings system rewarding the most productive affiliates
- Cryptocurrency mixing to launder ransom payments
Between 2021 and 2023, Ransom Cartel struck at least 18 companies in California, New York, Nebraska, and internationally. Victims faced dual extortion — paying for decryption keys and/or to prevent publication of stolen data.
The Angler Exploit Kit Connection
In a separate case filed in New Jersey, Silnikau and co-conspirators Volodymyr Kadariya and Andrei Tarasov were charged for operating the Angler Exploit Kit, a malvertising platform that ran from approximately 2013 to 2022. The Angler EK was one of the most sophisticated drive-by download frameworks of its era, compromising millions of systems via malicious ads served on legitimate websites.
The US State Department is offering a $2.5 million reward for information leading to the arrest of Kadariya, who remains at large.
Significance of the Sentence
The 16-year sentence is one of the most substantial handed down for ransomware-related offenses. It reflects a broader push by US authorities to pursue and extradite major cybercriminal figures regardless of national borders. Silnikau's case involved coordination between US, UK, Spanish, and Polish law enforcement — a multi-year international operation that ultimately succeeded in bringing one of the web's most active threat actors to justice.
Key Takeaways
- Ransom Cartel operated from 2021–2023 and hit 18+ organizations across multiple US states
- Silnikau was extradited from Poland after arrest in Spain in July 2023
- The Angler Exploit Kit charges cover a decade of malvertising activity (2013–2022)
- Cryptocurrency mixing does not guarantee anonymity from determined law enforcement
- International cooperation between US, UK, Spain, and Poland enabled the prosecution