Dispossessor was a ransomware and extortion operation active from approximately August 2023 until its disruption by a joint law-enforcement action in 2024. The group operated a dedicated leak site and was associated with ransomware victim postings, including reposting victims attributed to LockBit 3.0. It primarily targeted small and medium-sized businesses globally, with reported victims in Europe, the United Kingdom, and the United States. Authorities from the United Kingdom, Germany, and the United States seized infrastructure associated with the operation, after which Dispossessor was described as defunct.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against fmfcu.org, a U.S.-based organization in the financial services sector.
Associated with healthcare-sector dedicated leak-site postings.
Dispossessor is a ransomware group that was highly active in 2024.
Defunct ransomware/data-extortion brand associated with reposting previously leaked victim data rather than original compromises.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.