FBI Seizes RAMP Ransomware Forum Linked to Cybercrime Operations

RAMP ransomware forum FBI cybercrime ransomware takedown cybersecurity law enforcement
Brandon Woo
Brandon Woo

System Architect

 
February 23, 2026 3 min read
FBI Seizes RAMP Ransomware Forum Linked to Cybercrime Operations

TL;DR

  • The FBI, in collaboration with the US Attorney's Office and the DoJ, has seized RAMP, a significant dark web forum used by numerous ransomware groups. This takedown disrupts criminal infrastructure, particularly affecting lower-tier actors, though top-tier groups may migrate to other platforms like Telegram. The operation provides valuable intelligence for law enforcement, highlighting ongoing efforts against cybercrime.

FBI Shuts Down RAMP Ransomware Forum

The FBI has seized the Russian Anonymous Marketplace (RAMP), a notorious cybercrime forum known for allowing ransomware-related discussions. The seizure was a collaborative effort involving the US Attorney’s Office for the Southern District of Florida and the US Justice Department’s (DoJ) Computer Crime and Intellectual Property Section (CCIPS).

FBI Seized Banner

Image courtesy of Infosecurity Magazine

The seizure is highlighted by a banner stating "This site has been seized," accompanied by a taunt directed at RAMP operators: "The Only Place Ransomware Allowed!" and an image of Masha from the Russian cartoon "Masha and the Bear." Domain names linked to RAMP now redirect to seizure notices with FBI and DoJ seals, and the nameservers have been updated to ns1.fbi.seized.gov and ns2.fbi.seized.gov.

RAMP's Role in the Cybercrime Landscape

RAMP gained prominence in 2021 after other major dark web forums like XSS and Exploit, as well as BreachForums, banned ransomware discussions. RAMP became a hub for new and low-to-mid-tier ransomware groups to promote themselves and offer services.

According to Yelisey Bohuslavskiy, co-founder of Red Sense, RAMP was created by individuals affiliated with Russian security services as a response to the ransomware-as-a-service (RaaS) sprawl. Tammy Harper, a senior threat intelligence researcher at Flare, described RAMP as “one of the most trusted ransomware-adjacent forums in the cybercrime ecosystem.” The forum supported the entire attack chain, offering a marketplace for stolen credentials, malware promotion, and ransomware services, as noted by Ben Clarke, a security operations center (SOC) manager at CybaVerse.

Several notorious ransomware groups, including LockBit, ALPHV/BlackCat, Conti, DragonForce, Qilin, Nova, Radiant, and RansomHub, reportedly operated on the forum.

Key Individuals Behind RAMP

One of the individuals behind RAMP was Mikhail Matveev, a Russian national known as Orange, Wazawaka, and BorisElcin. Matveev was arrested in Russia in 2024. Another key operator, known as ‘Stallman,’ was the forum’s administrator at the time of the takedown.

Stallman's Message

Image courtesy of Rebecca Taylor, Sophos

Rebecca Taylor, a threat intelligence researcher at Sophos, noted that Stallman "played a central role in maintaining trust, enforcing rules and managing the platform’s technical operations.” Stallman confirmed the takedown on the XSS forum, stating that it had “destroyed years of my work” and that there were no plans to rebuild.

Impact of the Takedown

The RAMP takedown is considered a significant disruption to criminal infrastructure. Giomar Salazaar, a threat intelligence analyst at Outpost24, called the takedown “another major blow to the infrastructure supporting the digital extortion ecosystem." Daniel Wilcock, a threat intelligence analyst at Talion, described it as "a big win for law enforcement," providing access to valuable information such as emails, IP addresses, and financial transactions.

However, Bohuslavskiy noted that the takedown will primarily impact low-tier actors and cause disruption to underground sellers, with minimal impact on top-tier groups. He also predicted that Telegram will absorb some of the displaced activity. Wilcock added that while RAMP's operator claims no plans to rebuild, other criminals are likely to turn to alternative underground markets.

The seizure of RAMP highlights the ongoing efforts of law enforcement to disrupt cybercriminal activities. However, the cybercrime ecosystem is resilient, and threat actors will likely adapt by migrating to other platforms or adopting new tactics.

As the cyber landscape evolves, Gopher Security remains dedicated to providing cutting-edge cybersecurity solutions. Our AI-powered, post-quantum Zero-Trust architecture converges networking and security across all environments, ensuring robust protection against emerging threats.

Explore our advanced cybersecurity solutions at https://gopher.security and contact us to learn how we can help safeguard your organization.

Brandon Woo
Brandon Woo

System Architect

 

10-year experience in enterprise application development. Deep background in cybersecurity. Expert in system design and architecture.

Related News

Google Dismantles IPIDEA, Major Proxy Network for 550+ Threats
Ipidea proxy network

Google Dismantles IPIDEA, Major Proxy Network for 550+ Threats

Google has disrupted Ipidea, a massive residential proxy network used by cybercriminals. Learn how this action impacts online security and what it means for threat actors. Read now!

By Brandon Woo February 27, 2026 4 min read
common.read_full_article
Pentagon Leaders Anticipate Cybercom 2.0 to Counter Chinese Threats
Cybercom 2.0

Pentagon Leaders Anticipate Cybercom 2.0 to Counter Chinese Threats

The Pentagon is overhauling its cyber defenses with Cybercom 2.0. Discover how specialization, AI, and innovation are reshaping the fight against threats like China's Volt Typhoon. Learn more!

By Jim Gagnard February 26, 2026 3 min read
common.read_full_article
New Britain Ransomware Attack Disrupts City Services, FBI Involved
New Britain cyberattack

New Britain Ransomware Attack Disrupts City Services, FBI Involved

New Britain faces a major ransomware attack disrupting city services. Learn about the ongoing investigation, impact on operations, and essential services. Discover how to enhance your cybersecurity.

By Alan V Gutnov February 20, 2026 3 min read
common.read_full_article
New Britain Ransomware Attack and Fire Disrupt City Operations
New Britain ransomware attack

New Britain Ransomware Attack and Fire Disrupt City Operations

New Britain faces network disruption from a ransomware attack, impacting city departments. Meanwhile, a major fire damages a downtown factory. Learn how to protect your city.

By Brandon Woo February 10, 2026 3 min read
common.read_full_article