// THREAT ACTOR
RAMP_
ActiveRAMP is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of RAMP — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Leak site mirrors
4 mirrors tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
wavbeudogz6byhnardd2lkp2jafims3j7tj6k6qnywchn2csngvtffqd.onionsnapshot · 2021-05-01 00:00 -
rampjcdlqvgkoz5oywutpo6ggl7g6tvddysustfl6qzhr5osr24xxqqd.onionThis Site Has Been Seized snapshot · 2026-02-24 17:24 -
ramp4u5iz4xx75vmt6nk5xfrs5mrmtokzszqxhhkjqlk7pbwykaz7zid.onion -
ramp4u.ioThis Website Has Been Seized snapshot · 2026-08-06 21:14