Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.
The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
The DOJ says Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases “J.P. Morgan,” “xxx,” and “lansky.”
He was also a member of the Direct Connection cybercrime website between 2011 and 2016, when the site was shut down following the arrest of its administrator.
According to court documents, Silnikau began developing the Ransom Cartel ransomware operation in May 2021 and recruited other cybercriminals through underground forums to participate in attacks.
He supplied members with information and tools used in the intrusions, including stolen credentials for compromised computers and software designed to encrypt victims’ computers.
Silnikau also operated an affiliate website that allowed members of the ransomware operation to manage attacks, communicate with each other, negotiate ransom demands, and distribute revenue shares after a ransom was paid.
Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide, including organizations in California, New York, Nebraska, and countries outside the United States.
During the attacks, the threat actors stole corporate data and demanded payments in exchange for decryption keys or promises that the stolen information would not be publicly leaked.
Federal prosecutors said the ransomware operation attempted to extort at least $5.2 million from its victims.
The United States identified more than $6.7 million in losses suffered by 18 known victims, although prosecutors said the total was likely higher because some victims had not reported their attacks.
In one August 2022 attack, Ransom Cartel reportedly disrupted the operations at a medical technology startup developing robotic surgical technology for two months. In May 2023, the gang also attacked infrastructure used by a group of law firms, causing business disruptions lasting from several days to multiple months.
One law firm paid a ransom worth $125,000 after being disrupted for nearly a month, while another suspended operations for almost a month before paying a $300,000 ransom.
Prosecutors said the combined losses associated with those attacks reached approximately $2.2 million.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor.
However, the lack of some of REvil’s obfuscation features led researchers to believe that it may have been created by a former core member of the operation who did not have access to the complete source code.
Silnikau reportedly held a central role in the ransomware-as-a-service operation, recruiting affiliates, working with initial access brokers who supplied access to compromised corporate networks, communicating with victims, and handling ransom payments.
He also transmitted ransom payments through cryptocurrency mixers to make it harder for law enforcement to trace the funds.
Silnikau was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation. However, he fled while awaiting extradition to the United States and was later captured while attempting to return to Belarus.
“The defendant fled Spanish authorities while awaiting extradition to the United States and was apprehended while trying to cross from Poland to his native Belarus,” prosecutors said in their sentencing filing.
Silnikau ultimately consented to extradition and was sent from Poland to the United States to face prosecution in the Eastern District of Virginia.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You must be logged in to post a comment Login