Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors dispossessor

Description

This is not a ransomware group but a data broker Known victims: 344

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The 'dispossessor' threat actor, identified as a criminal with medium sophistication, operates primarily for organizational gain but has goals aligned with ransomware and financial exploitation. Unlike traditional ransomware groups, dispossessor is classified as a data broker, suggesting its activities may focus on harvesting and selling sensitive information rather than direct extortion. First seen in February 2020 and last observed in August 2024, the actor remains active but lacks clear targeting preferences for sectors or geographies.

Goals & Targeting

Dispossessor appears to target victims primarily for their ability to generate revenue through data monetization rather than direct ransomware extortion. Its strategic objectives likely include maximizing the volume and value of stolen data, targeting sectors or organizations that possess high-value information, such as financial institutions or e-commerce platforms. The actor's choice of victims may be driven by the ease of compromise and the potential resale value of stolen data on darknet markets.

Enhanced Description

Dispossessor operates as a medium-sophistication criminal threat group primarily motivated by organizational gain. While its goals include ransomware activities and financial exploitation, it is distinct from typical ransomware groups in that it is identified as a data broker rather than an extortionist. This suggests dispossessor's primary modus operandi may involve harvesting sensitive data from victims for resale on the black market or other criminal purposes. The actor has been active since at least February 2020 and was last observed in August 2024, indicating a persistent presence in the cybercriminal landscape. Despite this activity span, dispossessor's targeting patterns remain unclear, with no specific sectors or countries identified as primary targets. Its operations likely involve data collection and exfiltration techniques, aligning with its role as a data broker. Dispossessor's activities represent a blend of traditional cybercrime elements, such as financial exploitation, with the emerging trend of data commodification.

Key Capabilities

  • Data collection and exfiltration
  • Spear-phishing campaigns
  • Compromise of web applications
  • Lateral movement within networks
  • Custom scripts or tools for data extraction

MITRE ATT&CK Tactics

Initial Access
Execution
Exfiltration

Software / Tooling

Phishing emails with malicious attachments
Exploitation frameworks (e.g., custom or known)
Implants for persistence and data collection

Campaigns & Victims

Dispossessor's campaigns likely involve large-scale data collection efforts, targeting hundreds of victims, as evidenced by the 344 known cases. Its operational tempo suggests a focus on long-term campaigns rather than high-profile, short-lived attacks. The actor appears to prefer stealth over speed, possibly to avoid detection while amassing a substantial corpus of stolen data.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Lateral movement using compromised credentials
  • Data exfiltration via encrypted channels
  • Network reconnaissance activities
  • Staging infrastructure for data storage and transfer

Recommended Actions

  • Implement robust phishing detection mechanisms to mitigate spear-phishing attempts.
  • Monitor network traffic for suspicious lateral movement patterns and data exfiltration attempts.
  • Enhance access controls and implement multi-factor authentication to prevent credential theft.
  • Conduct regular security audits to identify and patch potential vulnerabilities in web applications.
  • Educate employees on recognizing and reporting phishing attempts to reduce the success of social engineering attacks.

Suggested Tags

APT
ransomware
espionage
finance-sector

Confidence Assessment

The confidence level in dispossessor's attributes is moderate, as limited data exists on its具体 tactics, techniques, and procedures (TTPs). Key gaps include the absence of linked campaigns, specific MITRE ATT&CK techniques, or associated tools. Further intelligence collection efforts are needed to better understand this actor's operational tradecraft and improve defensive measures.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
APT
ransomware
espionage
finance-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 3, 2020
Last Seen
Aug 11, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.