Dispossessor is a ransomware group that emerged in August 2023, gaining notoriety for targeting various sectors with sophisticated tactics. They specialize in a double extortion strategy, encrypting victims' data and threatening to leak it unless ransom is paid. Their aggressive approach includes direct contact with victims and the use of advanced malware.
Key insights
•Uses double extortion tactics with threats of data leakage.
•Employs spear-phishing as an initial attack vector.
•Targets sectors like healthcare and construction, especially during crises.
•Utilizes custom ransomware such as Babyk for file encryption.
•Exploits supply chain vulnerabilities to increase impact.
•Adopts techniques such as living-off-the-land binaries to evade detection.