This is not a ransomware group but a data broker Known victims: 344
Objectives
Executive Summary
The 'dispossessor' threat actor, identified as a criminal with medium sophistication, operates primarily for organizational gain but has goals aligned with ransomware and financial exploitation. Unlike traditional ransomware groups, dispossessor is classified as a data broker, suggesting its activities may focus on harvesting and selling sensitive information rather than direct extortion. First seen in February 2020 and last observed in August 2024, the actor remains active but lacks clear targeting preferences for sectors or geographies.
Goals & Targeting
Dispossessor appears to target victims primarily for their ability to generate revenue through data monetization rather than direct ransomware extortion. Its strategic objectives likely include maximizing the volume and value of stolen data, targeting sectors or organizations that possess high-value information, such as financial institutions or e-commerce platforms. The actor's choice of victims may be driven by the ease of compromise and the potential resale value of stolen data on darknet markets.
Enhanced Description
Dispossessor operates as a medium-sophistication criminal threat group primarily motivated by organizational gain. While its goals include ransomware activities and financial exploitation, it is distinct from typical ransomware groups in that it is identified as a data broker rather than an extortionist. This suggests dispossessor's primary modus operandi may involve harvesting sensitive data from victims for resale on the black market or other criminal purposes. The actor has been active since at least February 2020 and was last observed in August 2024, indicating a persistent presence in the cybercriminal landscape. Despite this activity span, dispossessor's targeting patterns remain unclear, with no specific sectors or countries identified as primary targets. Its operations likely involve data collection and exfiltration techniques, aligning with its role as a data broker. Dispossessor's activities represent a blend of traditional cybercrime elements, such as financial exploitation, with the emerging trend of data commodification.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Dispossessor's campaigns likely involve large-scale data collection efforts, targeting hundreds of victims, as evidenced by the 344 known cases. Its operational tempo suggests a focus on long-term campaigns rather than high-profile, short-lived attacks. The actor appears to prefer stealth over speed, possibly to avoid detection while amassing a substantial corpus of stolen data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in dispossessor's attributes is moderate, as limited data exists on its具体 tactics, techniques, and procedures (TTPs). Key gaps include the absence of linked campaigns, specific MITRE ATT&CK techniques, or associated tools. Further intelligence collection efforts are needed to better understand this actor's operational tradecraft and improve defensive measures.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
2
IOCs
0
Observed Data
0
Tactics