← Blog · · df00tech

Ransom Cartel Creator Sentenced to 16 Years for Global Ransomware Attacks

security-news campaign

Maksim Silnikau, identified as the creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide, according to BleepingComputer.

Why It Matters

Ransom Cartel emerged as a ransomware-as-a-service (RaaS) operation believed to share code lineage with the earlier REvil (Sodinokibi) family, and it was used in double-extortion attacks against organizations across multiple sectors and regions. A sentencing of this length for an operator/developer is notable — successful prosecutions of ransomware operation leaders remain relatively rare, and this case underscores continued law enforcement pressure on the RaaS ecosystem. For defenders, it's a reminder that even when specific operators are taken off the board, the tooling, affiliate networks, and tradecraft associated with a RaaS brand can persist or resurface under new names.

What Defenders Should Watch For

  • Organizations previously targeted by Ransom Cartel or related affiliate infrastructure should review historical incident data for indicators tied to this operation, as legal proceedings sometimes surface additional victim or infrastructure details over time.
  • Given reported ties to REvil-derived code, defenders should maintain detections and hunting rules for known REvil/Sodinokibi-family behaviors (mass file encryption patterns, shadow copy deletion, and known ransom-note artifacts) rather than assuming the threat is fully retired.
  • General ransomware hygiene remains the priority: monitor for precursor activity such as credential-stuffing/RDP brute-forcing, suspicious use of remote management tools, and unusual privilege escalation or lateral movement preceding mass file modification events.
  • Maintain offline, tested backups and validate incident response playbooks for double-extortion scenarios (encryption plus data theft/leak-site pressure).

Developing Story

This is a legal/law-enforcement development rather than a new technical threat disclosure, and specific technical details of the sentencing (e.g., full scope of victims or infrastructure) may still emerge. This item does not correspond to a specific CVE or new malware variant. For the full report, see the original source at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.