U.S. law enforcement has seized the RAMP cybercrime forum, a long-running hub used to advertise and facilitate ransomware operations, malware distribution, and other illicit services. Both the forum’s Tor presence and clearnet domain (reported as ramp4u[.]io) were replaced with an FBI seizure banner indicating coordination with the U.S. Attorney’s Office for the Southern District of Florida and the DOJ’s Computer Crime and Intellectual Property Section; the forum’s administrator reportedly acknowledged the takedown publicly on the XSS forum. Reporting notes RAMP emerged as a dedicated venue for ransomware promotion after other major forums restricted such activity, and that criminal communities are already attempting to migrate to alternative platforms.
Separate reporting also highlighted other cybercrime enforcement actions (including indictments tied to Ploutus-based ATM jackpotting and other marketplace disruptions), but those are distinct from the RAMP seizure. A different, unrelated incident involved a supply-chain compromise of eScan antivirus update infrastructure in which attackers briefly pushed a backdoor via a trojanized Reload.exe that altered update settings, established persistence via a scheduled task, and contacted a C2 to retrieve additional payloads; this event is not connected to the RAMP takedown and should be tracked independently as a vendor update-channel compromise affecting customer environments.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
SentinelLABS and Censys reported that about 175,000 self-hosted or open-source AI systems across 130 countries were exposed without basic security controls. They warned the exposed systems could be abused for spam, phishing, disinformation, and other malicious activity.
CISA added the actively exploited Office flaw CVE-2026-21509 to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline of 2026-02-16. The move signaled urgent government concern over ongoing exploitation.
Microsoft released out-of-band updates for CVE-2026-21509, an actively exploited Office security feature bypass involving COM/OLE controls that affects multiple Office versions and Microsoft 365 Apps for Enterprise. The company also provided a registry-based mitigation for defenders unable to patch immediately.
The alleged operator of the darknet marketplace Kingdom Market entered a guilty plea, according to reporting summarized in the weekly roundups. The plea added to a series of recent enforcement actions targeting darknet market operators.
Law enforcement seized the RAMP cybercrime forum as part of a broader crackdown on cybercrime infrastructure. Multiple references highlighted the takedown as a significant disruption of a known criminal platform.
U.S. authorities announced charges against 31 defendants allegedly involved in an ATM jackpotting scheme using Ploutus malware and linked to Venezuela’s Tren de Aragua. The action marked a major law-enforcement move against a cross-border cash-out operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.