dispossessor
This is not a ransomware group but a data broker
dispossessor is a financially motivated data broker group known for selling stolen corporate data on the dark web.
dispossessor is a financially motivated cybercrime data broker group, not ransomware. They primarily target organizations globally to steal and sell or leak sensitive data. Their main TTPs involve data theft, extortion without encryption, and selling stolen data on dark web platforms, relying on compromised credentials rather than custom malware or C2 infrastructure. Defenders should focus on data loss prevention (DLP), credential monitoring, and searching for their organization's data leaks on dark web forums.
This is not a ransomware group but a data broker
No, dispossessor is not a ransomware group. They are a financially motivated data broker group that engages in data theft, extortion without encryption, and selling stolen sensitive data on dark web platforms.
Their main TTPs include data theft, extortion, and selling data on the dark web. The group relies on compromised credentials rather than custom malware or C2 infrastructure.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.