Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actioncybercrime-service-ecosystemunderground-data-leakransomware-group-operation

Law enforcement actions against darknet marketplaces and cybercrime forums

Updated 3mo agoFirst seen Jan 29, 20264 sources

US and international law enforcement continued disrupting illicit online marketplaces and forums used to trade ransomware services, malware, stolen data, and drugs. The FBI seized the dark web and clear web domains for RAMP, a long-running, predominantly Russian-language cybercrime forum that marketed itself as the “only place ransomware allowed,” and which hosted vetted users, tutorials, and a marketplace for malware and criminal services; the seizure was coordinated with the US Attorney’s Office for the Southern District of Florida and DOJ’s Computer Crime and Intellectual Property Section.

Separately, US prosecutors announced guilty pleas tied to major darknet markets that also sold cybercrime tools and stolen information alongside narcotics. A Virginia man, Raheim Hamilton (aka Sydney/ZeroAngel), co-creator of Empire Market, pleaded guilty to federal drug conspiracy charges related to facilitating roughly $430M in transactions (2018–2020) and designing the market to evade law enforcement using cryptocurrency. A Slovakian national, Alan Bill (aka Vend0r/KingdomOfficial), pleaded guilty for helping operate Kingdom Market (2021–2023), which authorities previously seized in December 2023; investigators linked him to the operation after his arrest with devices and a crypto hardware wallet allegedly containing evidence tying him to the marketplace.

Share:
Law enforcement actions against darknet marketplaces and cybercrime forums
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
May 5, 20262mo ago

Alan Bill sentencing is scheduled

Bill is scheduled to be sentenced on May 5 and faces significant prison time and financial penalties in the Kingdom Market case.

Jan 28, 20265mo ago

FBI seizes RAMP cybercrime forum domains

The FBI seized both the dark web and clear web domains of RAMP, with seizure banners citing coordination with the U.S. Attorney's Office for the Southern District of Florida and DOJ's Computer Crime and Intellectual Property Section.

Raheim Hamilton pleads guilty in Empire Market case

Virginia man Raheim Hamilton pleaded guilty to federal drug conspiracy charges tied to co-creating and operating Empire Market, and agreed to forfeit cryptocurrency and properties.

Alan Bill pleads guilty in Kingdom Market case

Alan Bill pleaded guilty to helping operate Kingdom Market and to conspiracy to distribute controlled substances, while agreeing to surrender two domains and forfeit cryptocurrency.

Thomas Pavey pleads guilty in Empire Market case

Co-defendant Thomas Pavey previously pleaded guilty in the Empire Market investigation and faces the same mandatory minimum 10-year federal prison sentence as Raheim Hamilton.

Jan 1, 20242y ago

RAMP administrator claims forum earns $250,000 annually

In 2024, the administrator of RAMP claimed the cybercrime forum generated about $250,000 per year.

Dec 15, 20233y ago

Alan Bill is arrested at Newark airport

On December 15, 2023, Slovakian national Alan Bill was arrested at Newark Liberty International Airport after investigators linked devices and a hardware wallet to Kingdom Market.

Dec 1, 20233y ago

German authorities seize Kingdom Market infrastructure

In December 2023, Germany's BKA seized Kingdom Market's domains and infrastructure, reporting about 42,000 items for sale along with large seller and customer bases.

Jul 1, 20224y ago

Undercover investigators make purchases on Kingdom Market

Around July 2022, U.S. federal undercover investigators purchased methamphetamine, fentanyl, and a fraudulent U.S. passport through Kingdom Market, advancing the investigation.

Mar 1, 20215y ago

Kingdom Market starts operating

Kingdom Market began operating in March 2021 as a darknet marketplace selling narcotics, cybercrime tools and services, fake IDs, and stolen personal information for cryptocurrency.

Jan 1, 20215y ago

RAMP rebrands and continues cybercrime operations

RAMP rebranded in 2021 and continued operating as a prominent forum for ransomware and other cybercrime services, eventually amassing more than 14,000 users.

Dec 31, 20205y ago

Empire Market ceases operations after major illegal trade run

Empire Market's operation period ended in 2020 after facilitating roughly $430 million in illegal transactions between thousands of vendors and hundreds of thousands of buyers.

Jan 1, 20188y ago

Empire Market begins operating on Tor

Empire Market launched in 2018 as a Tor hidden service promoted as an AlphaBay clone, facilitating illegal sales with drugs as the dominant category.

Jan 1, 201214y ago

RAMP cybercrime forum is founded

According to Rapid7, the Russian-language cybercrime forum RAMP was founded and later grew into a major venue for ransomware-related products, tutorials, and services.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Organizations
6 linked
BleepingComputerRapid7Microsoft CorporationRedVDSAlphaBayEmpire Market
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.