On August 12, 2024, the U.S. Department of State announced a reward of up to $2.5 million for information leading to the arrest or conviction of Volodymyr Kadariya, whom U.S. prosecutors charged in an alleged international malvertising and malware-distribution scheme. The announcement was made through the State Department’s Transnational Organized Crime Rewards Program. The available official material establishes that Kadariya was charged, not convicted; it does not establish a later arrest or confirm that the reward remains available in 2026.
Who is Volodymyr Kadariya?
The Justice Department describes Kadariya as a Belarusian and Ukrainian dual national. Documents and reporting also use the spellings Volodymyr Kadaria and Vladimir Kadaria. BleepingComputer reported the aliases “Stalin,” “Eseb” and “baxus.”
According to the indictment, Kadariya allegedly participated in malicious advertising and malware distribution and helped manage infrastructure used in the campaigns. Prosecutors named him alongside Maksim Silnikau and Andrei Tarasov in a New Jersey case. The Justice Department’s account distinguishes Kadariya’s alleged role from Silnikau’s: it identifies Silnikau as a leader associated with Angler and as the creator and administrator of the separate Ransom Cartel ransomware strain. The available charges do not establish that Kadariya created Angler.
The Justice Department’s August 12, 2024 announcement and the indictment describe allegations, not findings of guilt.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
How the alleged malvertising operation worked
Malvertising uses online advertising as a route to malicious content. The indictment alleges that the defendants presented themselves as legitimate advertising businesses, using numerous online identities and fictitious entities to place or manage campaigns. Traffic-distribution systems and related code helped determine what a visitor would see.
- Reach users through advertising. The alleged campaigns used online ads distributed through legitimate advertising channels.
- Sort traffic. The infrastructure could assess incoming devices and decide whether to show ordinary advertising or redirect a visitor. Prosecutors allege that users not selected for an attack could receive normal ads, while devices considered susceptible were sent malicious content.
- Deliver an attack or scam. Selected users could be directed to exploit infrastructure, malware, scareware, phishing pages or fraudulent offers.
- Monetize access and data. Prosecutors allege that the operation sold access to compromised devices and information stolen from them, and used infected devices for further malware delivery and scams.
This selective routing could make a campaign harder to spot: a reviewer or security system might see a benign ad while a targeted visitor received a malicious redirect. The indictment and the District of New Jersey’s filed-case document describe the alleged infrastructure and delivery method.
What the alleged criminals sold or delivered
- Malware: software intended to compromise or misuse a device.
- Scareware: false warnings that a device has a virus or other problem, used to pressure a victim into buying software or taking another harmful action.
- Phishing and fraudulent offers: pages designed to obtain personal or financial information or defraud users.
- “Loads” or “bots”: alleged sales of access to compromised devices.
- “Logs”: alleged sales of stolen information, including credentials or banking details.
The Justice Department said the campaigns allegedly delivered malware and scams to millions of internet users. That describes the alleged reach of the operation; it is not a verified count of devices successfully infected.
What was the Angler Exploit Kit?
An exploit kit is a criminal web platform that checks for vulnerable software and attempts to exploit it to install malware. Angler targeted web-facing vulnerabilities in browsers and associated plug-ins. During its prominent mid-2010s period, older technologies such as Adobe Flash, Java, Silverlight and Internet Explorer were among the kinds of software exploit kits could target.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Malvertising could funnel a user to an exploit kit without requiring the user to deliberately visit a known criminal site. If the browser or plug-in was vulnerable, the exploit could try to install malicious software. Keeping software updated reduces exposure to known vulnerabilities, but that general security advice does not mean Angler is operating today.
Angler is a historical exploit kit associated with the 2013–2016 era and is generally regarded as inactive by the end of 2016. The alleged scheme in the U.S. case spans October 2013 through March 2022, a broader period than Angler’s peak. The case’s mention of Angler should not be read as evidence that its old infrastructure remains active in 2026. For background on its history, see BleepingComputer’s coverage.
Rank #4
How Silnikau and Tarasov fit into the case
Silnikau was arrested in Poland and extradited to the United States in August 2024. The Justice Department describes him as a leader of two multiyear cybercrime schemes and associates him with the aliases “J.P. Morgan,” “xxx” and “lansky.” It links him to Angler and separately to Ransom Cartel. Tarasov and Kadariya were named as alleged co-conspirators in the New Jersey case. The reward announcement concerned Kadariya, not Silnikau.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What charges did Kadariya face?
The New Jersey indictment charged Kadariya, Silnikau and Tarasov with conspiracy to commit wire fraud, conspiracy to commit computer fraud and abuse, and two substantive counts of wire fraud. The Justice Department stated these counts carried statutory maximum penalties of up to 27 years for wire-fraud conspiracy, up to 10 years for computer-fraud conspiracy, and up to 20 years for each wire-fraud count.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
Those are maximum penalties set by statute, not a prediction of a sentence. Any outcome would depend on the case’s legal proceedings and factors including conviction and sentencing rules. A charge is an allegation; it is not proof of guilt.
What the $2.5 million reward means
The State Department offered up to $2.5 million for information leading to Kadariya’s arrest or conviction. The Justice Department announcement says the qualifying arrest or conviction could occur in any country. “Up to” is a maximum, not a guaranteed payment for submitting a tip; eligibility and any award depend on the program’s decision and the information’s value in achieving the stated result. This is a law-enforcement reward, not a cybersecurity vulnerability bounty or bug-bounty program.
The DOJ announcement gave this reporting email: [email protected]. Use the official channel rather than social-media accounts or intermediaries claiming they can secure payment. The announcement does not establish that the reward is still active today, so check current official U.S. government information before acting on it.
What is known about the case now?
The verified announcement is dated August 12, 2024. The official material cited here records charges against Kadariya and Silnikau’s extradition, but does not establish that Kadariya was later arrested, extradited or convicted, or that the reward was withdrawn. Without a newer official status update, none of those outcomes should be assumed.
Practical protection against malvertising
The case describes alleged activity from 2013 to 2022; it is not evidence of a current Angler campaign. The underlying delivery methods remain useful security lessons. Keep browsers, operating systems and software updated, avoid downloading programs from pop-up warnings, and treat unexpected redirects or urgent virus alerts as suspicious. Reputable browser protections, endpoint security and DNS filtering may help reduce exposure to malicious sites, but no single control guarantees safety.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




