The Russian-speaking cybercrime forum XSS banned all ransomware-related topics, including affiliate program advertisements, ransomware rentals, and sales of ransomware software. The forum’s administrator said ransomware had brought excessive publicity and law-enforcement attention to the site, with scrutiny intensifying after the DarkSide attack on Colonial Pipeline. Researchers cited in the reports said XSS had been one of the main underground venues used by ransomware groups to recruit affiliates and promote ransomware-as-a-service operations.
The move drew negative reactions from representatives linked to REvil and LockBit, underscoring how important major forums were to the ransomware ecosystem. A day later, Exploit, another major Russian-language cybercrime forum, reportedly imposed a similar ban on ransomware advertisements. The back-to-back restrictions suggested that pressure from high-profile attacks, political fallout, and increased law-enforcement focus was forcing prominent underground platforms to distance themselves from overt ransomware promotion.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
In early 2020, the Cracked and Nulled forums banned Zoom-related content associated with Zoom-bombing activity. The article presents this as another precedent for forum administrators removing topics that attract unwanted attention.
In 2016, HackForums banned advertisements for DDoS-for-hire services after Mirai source code was published and amid FBI scrutiny of Mirai-related attacks. The article cites this as a prior example of cybercrime forums restricting risky content under law-enforcement pressure.
One day after XSS announced its restriction, the Exploit forum also banned ransomware advertisements. With Exploit's move, both of the two major hacking forums hosting ransomware ads had prohibited such promotions.
Representatives of the REvil and LockBit ransomware operations expressed displeasure after XSS posted its ransomware ban. Their reactions underscored XSS's importance as a recruiting and advertising venue for ransomware groups.
The Russian-speaking hacking forum XSS announced a ban on ransomware-promoting topics, including affiliate program ads, ransomware rentals, and sales of ransomware software. The administrator said ransomware had become too dangerous, noisy, and attention-grabbing for the forum.
DarkSide carried out a ransomware attack that encrypted Colonial Pipeline's network and disrupted the fuel pipeline's operations. The incident is described as a major trigger for heightened scrutiny of ransomware forums and actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.