FBI Disrupts Dispossessor Ransomware Network, Seizes and Takes Down Key Domains

Law enforcement agencies have been intensively targeting cybercriminals for a while, with recent actions highlighting their commitment. The FBI has successfully dismantled several servers linked to various cybercriminal entities, aiming to impede their illicit activities.

Recently, the FBI announced the dismantling of a ransomware operation known as “Radar/Dispossessor.” This group was allegedly led by an individual identified as “Brain.” In a coordinated effort, authorities have shut down servers across multiple locations: three in the U.S., three in the UK, eighteen in Germany, and several criminal domains both in the U.S. and Germany.

Radar/Dispossessor emerged on the radar in August 2023 and quickly gained infamy due to its aggressive targeting of small and medium-sized enterprises across various sectors, including production, development, education, healthcare, finance, and transportation. Initially focused on U.S. entities, the group expanded its reach globally, impacting over 43 companies across countries like Argentina, Australia, Belgium, Brazil, Honduras, India, Canada, Croatia, Peru, Poland, the UK, the UAE, and Germany.

This ransomware employs a dual-extortion strategy, involving both the encryption and theft of files. Victims face threats of having their sensitive data leaked or destroyed if they do not comply with payment demands.

Radar/Dispossessor typically gains initial access by exploiting system vulnerabilities, weak passwords, and the absence of two-factor authentication. After breaching the target’s system, the attackers gain administrator privileges, allowing them to access and encrypt sensitive files while exfiltrating them to their own servers. This encryption prevents the victims from accessing their data.

Victims will find a ransom note left on their systems, detailing instructions for engaging with the attackers. If initial contact is not made, the attackers will escalate their efforts by reaching out to other individuals within the victim organization through emails or phone calls. These communications often include a video link showcasing the stolen data to heighten pressure.

Negotiations usually take place on a separate leak site with a countdown timer indicating when the data will be publicly released if the ransom is not paid. The total number of affected businesses is still being assessed.

The FBI urges anyone with information about “Brain” or the Radar Ransomware operation, or those who have been targeted by ransomware, to reach out to the Internet Crime Complaint Center at ic3.gov or call 1-800-CALL-FBI. Tips can be submitted anonymously. The FBI also advises organizations to keep their software and systems updated and to avoid paying ransom, as there is no guarantee of data recovery.

More Articles & Posts