Dispossessor was a ransomware group active from at least August 2023 until a joint law-enforcement disruption in 2024. It was described as primarily targeting small to mid-sized businesses worldwide and was notable for reposting victims associated with LockBit 3.0, indicating overlap with or dependence on the broader ransomware affiliate ecosystem rather than a wholly distinct operational model. By victim volume, it was counted among the more active ransomware groups in 2024 before becoming defunct following server seizures. The group conducted financially motivated ransomware and extortion activity against organizations in multiple countries, including Belgium, Croatia, Germany, Poland, and the United Kingdom. Its operations fit the standard ransomware lifecycle of gaining initial access to victim environments, conducting post-compromise activity, stealing data, and using extortion pressure through victim publication. Public reporting specifically characterizes it as a ransomware operation and notes infrastructure seizures by a joint action involving the FBI, the UK National Crime Agency, and German authorities. No high-confidence attribution to a nation-state or a specific country of origin is established here. No additional confirmed sub-groups or widely used aliases beyond Dispossessor are available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dispossessor is a ransomware group that was highly active in 2024.
Defunct ransomware/data-extortion brand associated with reposting previously leaked victim data rather than original compromises.
Dispossessor is a ransomware group active since 2023, targeting small to mid-sized businesses globally with ransomware attacks.
Ransomware group disrupted by FBI per excerpt.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.