Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Architect of Ransomware-as-a-Service Model Extradited to U.S. After More than a Decade on the Run

    Architect of Ransomware-as-a-Service Model Extradited to U.S. After More than a Decade on the Run

    August 13, 2024

    The suspected architect of the Ransomware-as-a-service model, who called himself the “J.P. Morgan” of the underground cybercrime world, has been arrested and extradited from Poland to the U.S., where he faces multiple charges of wire fraud, identity theft and hacking.

    Maksim Silnikau, a 38-year-old Belarusian and Ukrainian dual national, is believed to be the mastermind behind a vast criminal network responsible for developing and deploying some of the most damaging ransomware and exploit kits of the past decade.

    The U.S. District Court for the Eastern District of Virginia and the District of New Jersey unsealed two separate indictments on Monday that revealed a plethora of cybercriminal activities connected to Silnikau. Apart from him, the District of New Jersey’s indictment charged two other individuals, Andrei Tarasov, 33, from Russia, and Volodymyr Kadaria, 38, from Belarus, as co-conspirators in Silnikau’s alleged activities.

    (Source: UK NCA)

    The National Crime Agency (NCA) of the United Kingdom spearheaded the investigation, working alongside the U.S. Secret Service (USSS), the FBI, and other international partners across Poland, Ukraine, Spain, Portugal and Germany, to unearth Silnikau’s cybercrime ring and associates.

    Ransomware-as-a-Service Model Pioneer

    Silnikau, who also used aliases like “xxx” and “lansky,” is accused of playing a key role in the creation of Reveton, a pioneering ransomware strain credited with introducing the Ransomware-as-a-Service (RaaS) model in 2011. RaaS simplifies ransomware attacks, allowing even low-skilled criminals to launch them for a small fee.

    Reveton used scare tactics, falsely accusing victims of downloading illegal content and demanding hefty fines to regain access to their devices. Investigators estimate the scam netted the group roughly $400,000 per month from 2012 to 2014.

    In the Eastern District of Virginia, Silnikau is also charged for his role as the creator and administrator of the Ransom Cartel ransomware strain. Launched in May 2021, this ransomware targeted companies in the U.S., including a New York-based company in November 2021 and another California-based firm in March 2022. The perpetrators not only encrypted data but also stole sensitive information, using it as leverage to extort their victims.

    The Justice Department’s unsealed indictment alleges that Silnikau recruited participants from cybercrime forums and provided them with the tools and information needed to carry out these ransomware attacks.

    The takedown of “J.P. Morgan” and his network represents a significant victory in the fight against cybercrime. NCA Deputy Director Paul Foster emphasized the group’s far-reaching impact, stating: “As well as causing significant reputational and financial damage, their scams led victims to suffer severe stress and anxiety. Their impact goes far beyond the attacks they launched themselves. They essentially pioneered both the exploit kit and ransomware-as-a-service models.”

    Angler Exploit Kit and Scareware Dissemination

    Silnikau’s network didn’t stop there. They also developed and distributed the notorious Angler Exploit Kit, a tool used in “malvertising” campaigns. The Angler Exploit Kit targeted web-based vulnerabilities in Internet browsers and associated plug-ins. These malvertising campaigns impacted over half a billion victims worldwide, the NCA said.

    The modus operandi of these campaigns involved injecting malicious code into legitimate online advertisements, infecting unsuspecting users with malware – like ransomware variants Reveton, CryptXXX, CryptoWall, Ransom Cartel, etc. – after clicking on the ad. Angler, at its peak, infected an estimated 100,000 devices and generated a staggering $34 million annually.

    The NCA linked British national Zain Qaiser to J.P. Morgan’s Angler malvertising campaigns and said the two shared profits. Qaiser was convicted on three counts of blackmail, Computer Misuse Act and money laundering offenses and sentenced to six years and five months prison time in the U.K. in 2019.

    The conspirators also allegedly deployed “scareware” ads that displayed hoax messages claiming a system was infected with a virus or was facing Internet troubles. The messages then attempted to deceive the victim into buying or downloading malicious software that acted as backdoor and gave remote access to the device. In some cases, infostealers were also deployed, which siphoned the victims’ personal identifying or financial data.

    The Intricate Web of J.P Morgan’s Operations

    The investigation revealed a complex web of operations, with Silnikau’s network using various aliases and even operating physical offices in Ukraine under the name “Media Lab.” International collaboration proved crucial. The NCA shared information with Ukrainian authorities, leading to raids on Media Lab locations. Additionally, the Singapore Police Force assisted in taking down the infrastructure behind the Ransom Cartel.

    Silnikau’s extradition marks a turning point for law enforcement’s ability to track down and prosecute even the most sophisticated cybercriminals operating across international borders. The investigation remains ongoing, with authorities urging anyone with relevant information to come forward.

    Deputy Attorney General Lisa Monaco said this case represented a crucial step in holding cybercriminals accountable. “Today’s actions demonstrate our commitment to disrupting ransomware actors and those who use the anonymity of the internet to prey on victims worldwide,” she said.

    Authorities hope that Silnikau’s extradition and the charges against his co-conspirators will serve as a deterrent to others engaged in similar activities.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleThird-Party Risk Scoring for CEOs
    Next Article The AI Fix #11: AI gods, a robot dentist, and an angry human

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4831 – TOTOLINK HTTP POST Request Handler Buffer Overflow Vulnerability

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Prioritizing your developer experience roadmap

    Development

    Exact Nearest Neighbor Vector Search for Precise Retrieval

    Databases

    New macOS Malware “Cthulhu Stealer” Targets Apple Users’ Data

    Development

    Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised

    Development

    Highlights

    Simplifying Dev Tool Design: From Concept to Execution

    May 10, 2024

    While that arrangement may make sense given the close relationship between software development and interface…

    Prioritizing your developer experience roadmap

    August 22, 2024

    SwiftUI Views & Layouts [SUBSCRIBER]

    June 25, 2024

    CVE-2025-46780 – Apache HTTP Server Denial of Service

    April 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.