FBI disrupts the Dispossessor ransomware operation, seizes servers

Share:

The FBI announced on Monday that it seized the servers and websites of the Radar/Dispossessor ransomware operation following a joint international investigation.

The joint operation was carried out in collaboration with the U.K.’s National Crime Agency, the Bamberg Public Prosecutor’s Office, and the Bavarian State Criminal Police Office (BLKA).

Law enforcement seized three U.S. servers, three U.K. servers, 18 German servers, eight U.S.-based domains, and one German-based domain, including radar[.]tld, dispossessor[.]com, dispossessor-cloud[.]com, cybershare[.]app, readteamcr[.]com, redhotcypher[.]com, cybernewsint[.]com (fake news site), and cybertube[.]video (fake video site).

Since August 2023, Dispossessor—led by a threat actor known as Brain—has targeted small to mid-sized businesses in various sectors worldwide, claiming attacks against dozens of companies (the FBI identified 43 victims) from the U.S., Argentina, Australia, Belgium, Brazil, Honduras, India, Canada, Croatia, Peru, Poland, the United Kingdom, the United Arab Emirates, and Germany.

The FBI says the ransomware gang breaches networks through vulnerabilities, weak passwords, and the lack of multi-factor authentication configured on accounts. After gaining access to the victim’s network, they steal data and deploy the ransomware to encrypt the company’s devices.

“Once the criminals gained access to the systems, they obtained administrator rights and easily gained access to the files. The actual ransomware was then used for encryption. As a result, the companies could no longer access their own data,” the FBI said in a press release shared with BleepingComputer.

“Once the company was attacked, if they did not contact the criminal actor, the group would then proactively contact others in the victim company either through email or phone call. The emails also included links to video platforms on which the previously stolen files had been presented.”

The FBI also asked past victims or those targeted to share information on the Dispossessor gang by contacting the Internet Crime Complaint Center at ic3.gov or 1-800-CALL FBI.

When the cybercrime group initially launched, it acted as an extortion group, reposting old data stolen during LockBit ransomware attacks, from which they claimed to be affiliates. Dispossessor has also been reposting leaks from other ransomware operations and attempting to sell them on various breach markets and hacking forums like BreachForums and XSS.

“Dispossessor initially announced the renewed availability of the data from some 330 LockBit victims. This was claimed to be reposted data from previously available LockBit victims, now hosted on Dispossessor’s network and thus not subject to LockBit’s availability restrictions,” SentinelOne said in an April report.

“Dispossessor appears to be reposting data previously associated with other operations with examples ranging from Cl0p, Hunters International, and 8base. We are aware of at least a dozen victims listed on Dispossessor that have also been previously listed by other groups.”

Starting in June 2024, the threat actors began utilizing the leaked LockBit 3.0 encryptor [VirusTotal] for use in their own encryption attacks, significantly escalating the scope of their attacks.

Over the past year, law enforcement operations have targeted many other cybercrime activities, including cryptocurrency scams, malware development, phishing attacks, credential theft, and ransomware operations.

For instance, they have used hack-back tactics to infiltrate, disrupt, and dismantle ALPHV/Blackcat ransomware, a ransomware group deploying LockerGoga, MegaCortex, HIVE, and Dharma, the Ragnar Locker ransomware operation, and Hive ransomware.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:37 am, May 9, 2025
weather icon 8°C
L: 7° | H: 8°
overcast clouds
Humidity: 89 %
Pressure: 1021 mb
Wind: 6 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:17 am
Sunset: 8:35 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
7° | 8°°C 0 mm 0% 12 mph 89 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 20°°C 0 mm 0% 12 mph 86 % 1021 mb 0 mm/h
Sun May 11 10:00 pm
weather icon
11° | 23°°C 0.98 mm 98% 12 mph 85 % 1015 mb 0 mm/h
Mon May 12 10:00 pm
weather icon
12° | 22°°C 1 mm 100% 12 mph 93 % 1015 mb 0 mm/h
Tue May 13 10:00 pm
weather icon
12° | 20°°C 1 mm 100% 7 mph 88 % 1022 mb 0 mm/h
Today 7:00 am
weather icon
8° | 8°°C 0 mm 0% 6 mph 89 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
10° | 14°°C 0 mm 0% 8 mph 78 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
14° | 17°°C 0 mm 0% 12 mph 50 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
17° | 17°°C 0 mm 0% 12 mph 31 % 1020 mb 0 mm/h
Today 7:00 pm
weather icon
15° | 15°°C 0 mm 0% 10 mph 41 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
12° | 12°°C 0 mm 0% 8 mph 61 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
9° | 9°°C 0 mm 0% 5 mph 86 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,453.19
3.88%
Ethereum(ETH)
€1,968.80
16.48%
Tether(USDT)
€0.89
-0.03%
XRP(XRP)
€2.04
4.92%
Solana(SOL)
€144.66
7.96%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.173354
8.14%
Shiba Inu(SHIB)
€0.000012
7.49%
Pepe(PEPE)
€0.000010
25.53%
Scroll to Top