Uptime Hamster: 12d 19h 58mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ramp

ramp

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Russian Anonymous Marketplace, como Holy Water, Godlike12, SweetAlerts, Strategic web compromise (watering hole), Holy Water, APT RAMPANTKITTEN
Ver en IntelTracker → APTTrail →
RAMP, also referred to as Russian Anonymous Marketplace, was a prominent Russian-speaking cybercrime forum that emerged in July 2021, positioning itself as a central hub for ransomware operations after other major forums banned such discussions. It functioned as a marketplace that facilitated the entire ransomware supply chain, connecting ransomware groups, affiliates, and initial access brokers. Founded by Mikhail Matveev, a Russian national known by aliases such as Orange, Wazawaka, and BorisElcin, the forum was assessed with high confidence to be of Russian origin. Its primary motivation was to serve as a safe haven and commercial platform for various ransomware actors, enabling the recruitment of affiliates, the sale of initial access to compromised networks, and the exchange of tools and stolen data. What uniquely set RAMP apart was its explicit policy of allowing and promoting ransomware activities, a stance that differentiated it from its predecessors and attracted a wide array

Aliases del actor

Russian Anonymous Marketplacecomo Holy WaterGodlike12SweetAlertsStrategic web compromise (watering hole)Holy WaterAPT RAMPANTKITTEN

Actores similares

HolyWaterapt · 0apt-rampantkittenactor · 1Rampant Kittenapt · 0apt-rusticwebactor · 1MuddyWaterapt · 1Water Labbuapt · 0Water Gamayunapt · 0Water Saciapt · 0Water Barghestapt · 0Water Kuritaapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownotx.alienvault.comAPT RAMPANTKITTEN indicators and references
Webunknownresearch.checkpoint.comAPT RAMPANTKITTEN indicators and references
Repositoriounknowngithub.comAPT RAMPANTKITTEN indicators and references
Webunknownraw.githubusercontent.comAPT RAMPANTKITTEN indicators and references
Webunknownotx.alienvault.comAPT RAMPANTKITTEN indicators and references
DLS / onionunknownramp4u5iz4xx75vmt6nk5xfrs5mrmtokzszqxhhkjqlk7pbwykaz7zid.onionramp
DLS / onionunknownrampjcdlqvgkoz5oywutpo6ggl7g6tvddysustfl6qzhr5osr24xxqqd.onionramp
Foroseizedransomware.anggipradana.comRansomware Group: ramp
Tecnicas MITRE
T1176, T1110, T1547, T1486, T1083, T1496
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBrazilCanadaChinaGermanyFranceUnited KingdomGreeceIndia

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingSoftware PublishersEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationOil & GasEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com