Notorious Russia-based RAMP cybercrime forum apparently seized by FBI
好的,我现在要帮用户总结这篇文章的内容,控制在100字以内。首先,我需要通读整篇文章,抓住主要信息。 文章开头提到FBI查封了RAMP论坛的网站,并替换成了Splash页面。接着提到司法部还没有公开声明,有人质疑查封的真实性。然后提到2024年AlphV/BlackCat集团被关闭的事件,以及DNS记录显示RAMP的网站重定向到FBI常用域名。查封通知只提到了美国司法部和佛罗里达南区检察官办公室,没有其他国际机构的标志。 RAMP主要用于俄罗斯、中国和英语国家的网络犯罪分子,特别是勒索软件集团。管理员Mikhail Matveev在2022年将所有权转交给Stallman。Stallman在XSS论坛上宣布论坛被执法部门接管,并表示不会重建论坛,而是继续通过购买访问潜在受害者网络来进行犯罪活动。 Laura Galante提到,这类干扰行动是重塑网络犯罪生态系统的策略之一,但没有单一行动能永久破坏勒索软件活动。她认为频繁的干扰行动可以防止某个集团或工具集主导市场,使生态系统保持分散和混乱。 总结下来,关键点包括:FBI查封RAMP论坛网站的真实性存疑;该论坛被多个勒索软件集团使用;管理员Stallman回应;以及专家对干扰行动的看法。 现在需要将这些信息浓缩到100字以内。要确保涵盖主要事件和影响。可能需要省略一些细节,如具体人物或历史事件。 最终总结应包括:FBI声称查封RAMP论坛网站;该论坛用于勒索软件和网络犯罪;真实性存疑;管理员Stallman回应;以及专家观点。 </think> FBI声称已查封RAMP论坛网站,该平台曾被勒索软件团伙和网络犯罪分子广泛使用。尽管DNS记录显示重定向至FBI常用域名,但真实性仍存疑。管理员Stallman证实执法部门接管,并表示将不再重建论坛。专家指出此类干扰行动有助于重塑网络犯罪生态系统并防止单一集团主导市场。 2026-1-29 13:46:50 Author: therecord.media(查看原文) 阅读量:1 收藏

Websites for the RAMP cybercrime forum, a notorious Russian marketplace widely used by ransomware groups and initial access brokers, have been replaced with a splash page declaring they have been seized by the FBI.

The U.S. Department of Justice has not yet made a public statement about any actions targeting the Russian marketplace. Questions have been raised about the authenticity of the seizure. Back in 2024, the AlphV/BlackCat group claimed to have been shuttered by U.S. law enforcement in an elaborate exit scam intended to defraud its criminal affiliates.

Domain name server (DNS) records reportedly initially showed RAMP’s clearnet site redirecting to an FBI domain regularly used in takedowns.

The seizure notice does not feature the logos of any other international law enforcement agencies, as is typical for similar operations. It states: “This action has been taken in coordination with the United States Attorney’s Office for the Southern District of Florida and the Computer Crime and Intellectual Property Section of the Department of Justice.”

RAMP was used by Russian, Chinese and English-speaking cybercriminals and particularly catered to ransomware groups and their affiliates.

Among its administrators was a man called Mikhail Matveev, who was interviewed by Recorded Future’s Dmitry Smilyanets in 2022. At the time, Matveev said ownership of the forum would be transferred to a hacker known as Stallman.

In a post on the XSS hacking forum this week, Stallman announced that law enforcement had “taken control of the RAMP forum.”

“This event has destroyed years of my work creating the freest forum in the world, and although I hoped that this day would never come, deep down I always understood that it was possible. This is the risk we all take,” stated Stallman.

They added they would not be creating a new forum from scratch, but would continue to operate as a cybercriminal by purchasing access to the networks of potential victims.

One of many

Laura Galante, the former director of the cyberthreat intelligence integration center at the Office of the Director of National Intelligence (ODNI), told journalists in 2024 that disruption operations such as domain seizures were part of a strategy to reshape the cybercrime ecosystem.

“There is no one operation that’s going to disrupt ransomware permanently. Instead, we have to increase the frequency and increase the breadth of these operations by taking down infrastructure regularly, designating the exchanges that are facilitating money laundering and ransomware activity regularly,” she added.

Galante explained the intention was to prevent the emergence and success of a  single, dominant group. The “disruption operations, especially the frequent cadence, does help keep any one group or any one specialization of toolsets from really holding on.”

This lack of market dominance “is one of the ways that this [the ransomware ecosystem] has remained decentralized,” said Galante.

“Disruption operations have been really key to making this harder for certain groups to really get deeper and more specialized and mature, and makes the organizations a little bit more chaotic, which ends up being helpful because it takes more time for them to reconstitute and have successful operations in the future.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.


文章来源: https://therecord.media/notorious-russia-based-ramp-forum-seized
如有侵权请联系:admin#unsafe.sh