ZeroFox Intelligence Flash Report - Ransomed[.]vc Sunsets Operations, Auctions Off Infrastructure
|by Alpha Team

ZeroFox Intelligence Flash Report - Ransomed[.]vc Sunsets Operations, Auctions Off Infrastructure
Product Serial: F-2023-11-10b
TLP:CLEAR
In this Intelligence Flash Report, ZeroFox researchers report on the ransomware and digital extortion collective known as Ransomed[.]vc announcing that it no longer wanted to continue running the project and was selling all aspects of its infrastructure.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- The ransomware and data extortion (R&DE) collective known as Ransomed[.]vc announced in its Telegram channel that it no longer wanted to continue running the project and was selling all aspects of its infrastructure.
- At the time of writing, one Ransomed[.]vc leak site has been closed down, and the other hosts a closing note on its home page. However, its ransomware forum (on which Ransomed[.]vc coordinates its ransomware-as-a-service projects) remains active, likely to assist in the sale of its infrastructure and assets.
- Since August 2023, ZeroFox has identified more than 40 R&DE victims of Ransomed[.]vc, almost 60 percent of which are organizations based in Europe.
- These posts very likely represent a legitimate cessation of Ransomed[.]vc’s activity and a fire sale of the operation’s infrastructure. Threat actors will likely be motivated to purchase the infrastructure to target victims, create spin-off extortion operations, or leverage for further malicious activity. However, Ransomed[.]vc’s closure is very unlikely to have any considerable impact on the broader R&DE threat.
Tags: tlp:clear, dark web, all industries, DDW Ransomware