Ransom Cartel is a ransomware-as-a-service (RaaS) operation publicly identified in December 2021. It conducted double-extortion attacks, exfiltrating corporate data and encrypting victim systems before demanding payment for decryption and/or nonpublication of stolen data. The operation targeted at least 18 organizations in the United States and other countries between 2021 and 2023, including organizations in education, manufacturing, utilities and energy, legal services, and medical technology.
Ransom Cartel commonly obtained access through compromised credentials for external remote services and through initial-access brokers. Observed intrusions included credential recovery and credential dumping, network and host discovery, remote-access tooling, SSH and RDP-based lateral movement, archive creation, data exfiltration, event-log clearing, and ransomware deployment. It encrypted Windows systems and Linux-based VMware ESXi environments; activity against ESXi included stopping virtual machines prior to encryption. Observed persistence activity on ESXi included enabling SSH and creating privileged accounts.
The operation was created and administered by Belarusian national Maksim Silnikau, who recruited affiliates through Russian-speaking cybercrime forums, supplied stolen credentials and encryption tooling, and operated infrastructure for attack management, victim negotiations, and revenue distribution. U.S. authorities stated that Silnikau's July 2023 arrest disrupted the operation, and he was subsequently sentenced in the United States to 16 years' imprisonment. Ransom Cartel ransomware has substantial technical overlap with REvil, particularly in configuration and encryption-related functionality, although analysts assessed that its operators likely lacked REvil's obfuscation engine.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TA0004 Privilege Escalation T1068. Exploitation for Privilege Escalation Exploits Print Nightmare vulnerability. | Executive Summary Ransom Cartel is ransomware as a service (RaaS) that surfaced in mid-December 2021. This ransomware performs double extortion attacks and exhibits several similarities and technical overlaps with REvil ransomware.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Silnikau, along with alleged co-conspirators ... are charged with cybercrime offenses associated with a scheme to transmit the Angler Exploit Kit, other malware, and online scams to the computers of millions of unsuspecting victim internet users through online advertisements — so-called “malvertising” — and other means
Он активно вербовал других киберпреступников на русскоязычных хак-форумах для участия в атаках и партнерской RaaS-программе ..., снабжал их инструментами и украденными учетными данными для доступа к корпоративным системам.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor. However, the lack of some of REvil's obfuscation features led researchers to believe that it may have been created by a former core member of the operation...
The hackers removed confidential data without authorization and demanded a monetary payment to refrain from releasing the victim’s data.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned only as a comparison to other U.S. prosecutions; the article provides no technical or operational details.
Named ransomware operation mentioned only as a separate, comparative criminal-sentencing case; no technical behavior is described.
Suspected REvil spinoff ransomware operation with tooling similarities to REvil's original codebase.
Ransomware used by the Ransom Cartel group to steal corporate data, encrypt systems, and extort victims for decryption or to prevent publication of stolen information. The operation also provided tooling, stolen credentials, and an affiliate panel for managing attacks and ransom negotiations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.