US law enforcement seized the RAMP (Russian Anonymous Marketplace) cybercrime forum’s infrastructure, taking over both its Tor and clearnet presence and replacing them with a “This Site Has Been Seized” banner attributed to the FBI, coordinated with the US Attorney’s Office for the Southern District of Florida and the DOJ’s Computer Crime and Intellectual Property Section (CCIPS). RAMP was a key marketplace for ransomware-as-a-service (RaaS) promotion and related criminal services, including activity by extortionists and initial access brokers; the seizure banner also taunted operators with the forum’s slogan, “THE ONLY PLACE RANSOMWARE ALLOWED!,” alongside an image of Masha from the Russian children’s cartoon.
While authorities had not publicly detailed the operation at the time of reporting, technical indicators supported the takeover, including DNS changes consistent with prior FBI seizures (e.g., nameservers set to ns1.fbi.seized.gov / ns2.fbi.seized.gov). Reporting also cited an alleged operator (“Stallman”) acknowledging law enforcement control, and noted the seizure could expose forum user data (e.g., email addresses, IP addresses, and private messages), increasing identification and arrest risk for actors with poor OPSEC. Background context indicates RAMP emerged after other Russian-language forums restricted ransomware promotion under increased law-enforcement pressure.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Following the seizure, researchers assessed the takedown as a meaningful disruption but not a permanent blow to the cybercrime ecosystem. Reports indicated some actors, including Nova and DragonForce, were shifting activity toward other forums such as Rehub.
A user identified as 'Stallman,' described as an alleged RAMP operator or prospective owner, posted on XSS that law enforcement had seized the forum. The user said they would not rebuild RAMP but would continue buying network access.
WHOIS and DNS changes on RAMP's clearnet domain showed an update on January 28, with nameservers changed to ns1.fbi.seized.gov and ns2.fbi.seized.gov. These technical changes corroborated that the domain had been taken over through a standard U.S. seizure process.
U.S. law enforcement seized the RAMP cybercrime forum's clearnet domain and Tor site, replacing them with an FBI seizure notice. The action was attributed to the FBI in coordination with the U.S. Attorney’s Office for the Southern District of Florida and the DOJ’s Computer Crime and Intellectual Property Section.
RAMP emerged in July 2021 as a Russian-language cybercrime forum and marketplace after Exploit and XSS banned ransomware promotion under increased law-enforcement pressure following the Colonial Pipeline incident. The platform became a venue for ransomware operators, affiliates, brokers, and malware sellers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcedatabreaches.net
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.