The January 2026 seizure of RAMP disrupted a major ransomware coordination hub, but it did not destroy the ecosystem behind it. It just scattered. Now ransomware actors spreading across gated forums like T1erOne and Rehub.
Inside Darknet spoke with T1erOne in an exclusive interview.
For our listeners (and readers of course) who don't know you yet - who are you and what is T1erOne?
Привет, я один из администраторов Тиер1. Тиер1 - это форум для людей, которые интересуются заработком (в основном через рансом), обсуждают вопросы связанные с этой тематикой. От непосредственного входа в сеть, до монетизации данных, ну и безопасность при всём этом.
Hi, I'm one of the administrators of Tier1. Tier1 is a forum for people interested in making money (primarily through ransomware) and discussing topics related to this field - from gaining direct access to networks to monetizing data, and of course, security throughout the process.
T1erOne launched in early February 2026, right after RAMP got seized by the FBI. Was T1erOne created as a direct response to the RAMP takedown, or was it already in the works?
Тиер1 развивался медленно и постепенно но после того как РАМП закрыли процесс очень ускорился, потому что возникла пустота в пространстве, нужна была надёжная площадка где можно обсуждать рансом и сопутствующие тематики.
Tier1 developed slowly and gradually, but after RAMP shut down, the process really picked up speed because a void had opened up in the space - there was a need for a reliable platform where people could discuss ransomware and related topics.
Some people in the community are calling T1erOne "RAMP's successor." Do you see yourself that way? Or is T1erOne trying to be something different?
Преемником, я бы так не сказал. Но можно использовать другую картинку, мы подхватили флаг Рансома- как направление для работы пощадки. Если бы не мы, то чуть позже это сделал бы ктото другой, пологаю. Преемником Рампа мы не будем, история рансома развивается, и мы движемся с нею. Рамп - прошел свою историю, оставил свой след. Теперь мы постараемся объединить людей и идти дальше, посмотрим что из этого выйдет. Да мы стараемся быть другими. Мы слушаем юзеров и постоянно работаем с командой чтобы внедрять новые функции и улучшать форум
I wouldn't call us a successor. But you could use a different framing: we picked up the ransomware flag as a direction for the platform. If not us, someone else would have done it a little later, I think. We won't be a successor to RAMP - the history of ransomware keeps evolving and we move with it. RAMP ran its course and left its mark. Now we'll try to bring people together and move forward, we'll see what comes of it. Yes, we try to be different. We listen to users and constantly work with the team to implement new features and improve the forum.
Your forum requires either $450 payment or proof of activity on another forum to join. Why did you choose this model?
Сейчас есть только хсс и эксп где регистрация закрыта но там не разрешён рансом. Мы хотели разрешить рансом но при этом оставить регистрацию закрытой чтобы держать ресерчеры подальше.
Сейчас есть площадки, как ХСС или эксп, где регистрация закрыта, но там не разрешён рансом. Мы же даём место для рансома но отсеиваем школьников, стараемся модерировать аудиторию форума через маленькое интервью и пруф оф ворк так сказать. Ещё мы решили выделить отдельный вход на площадку для ресерчеров, ведь они всёравно попадают на любую площадку, но их аккаунты лимитированы и под пристальным наблюдением. ОпСек - важная тематика на нашем форуме. стараемся напоминать и поднимать этот раздел чаще.
Right now there's XSS and Exploit where registration is closed, but ransomware isn't allowed there. We wanted to allow ransomware while keeping registration closed to keep researchers away. There are platforms like XSS or Exploit where registration is closed but ransomware isn't permitted. We provide a space for ransomware but filter out script kiddies — we try to moderate the forum's audience through a small interview and proof of work, so to speak. We also decided to create a separate entry point for researchers, since they find their way onto any platform anyway, but their accounts are limited and under close observation. OpSec is an important topic on our forum — we try to bring it up and highlight that section more frequently.
Maybe you know a bit about RAMP. It was the only major forum that allowed ransomware since 2021. When it got seized, Stallman said "this destroyed years of my work to create the most free forum in the world." Why do so many forums not allow ransomware?
Да, Рамп, навсегда останется в истории рансома. А на счёт того почему другие не разрешают - спросите у них, наверное у каждого будет свой ответ.
Yes, RAMP will forever remain in the history of ransomware. As for why others don't allow it - ask them, I imagine everyone will have their own answer.
And your forum allows Ransomware just like RAMP?
Да. Скажу даже больше, это наша основная аудитория.
Yes. I'll say even more: that's our primary audience.
Ransomware has hit hospitals, schools, critical infrastructure. Some groups have ethics rules (like not hitting hospitals), others don't. Does T1erOne have any ethical guidelines? Or is it purely business?
Единственное правило нашего форума для пп - Работа по странам СНГ и УА СТРОГО ЗАПРЕЩЕНА! Моментальный бан
The only rule on our forum for affiliates: Operations targeting CIS countries and Ukraine are STRICTLY PROHIBITED. Instant ban.
This is common on Russian forums. Why is this rule so important? What happens if someone breaks it?
Ну это довольно очевидное правило - не сри там где живёшь, как говорится. Наш форум в основнове своей рускоязычный. Поэтому такое правило, мы любим страны откуда мы родом. А еще работать против своих, вредно для здоровья, думаю это объяснять не надо. Да это правило очень важно, если кто-то его не соблюдает - то он ставит под угрозу не только себя но и всех окружающих людей. Таким людям не место у нас на площадке.
It's a pretty obvious rule — don't shit where you eat, as they say. Our forum is primarily Russian-speaking, so that's why the rule exists — we love the countries we come from. And working against your own is bad for your health, I think that goes without saying. Yes, this rule is very important. If someone doesn't follow it, they put not only themselves but everyone around them at risk. People like that have no place on our platform.
There are ransomware groups on your forum ShadowByt3$, Qilin. How do you verify these groups are legitimate and not law enforcement honeypots or scammers?
У нас есть прямой контакт с администраторами. По сути мир рансома не такой уж и большой, большинство людей, кто серьёзно этим занимается, друг друга знает если не напрямую, то через 1 контакт, или через 1 старый ник.
We have direct contact with administrators. The ransomware world isn't actually that big - most people who are serious about this know each other, if not directly then through one contact, or through one old alias.
RAMP eventually got seized and parts of its database leaked - including emails, IPs, and allegedly LockBit's registration email. What lessons did you learn from that? How are you protecting T1erOne users differently?
Урок - не юзать ксенофоро. Он старый, на пхп, у ФБР скорее всего есть несколько 0 дней для него. Поэтому мы написали всё с нуля. Мы не собираем ни айпи, ни имейлы. Так же мы работает над очень интересными решениями для усиления безопасности пользователей, но пока публично не хочу это анонсировать, думаю скоро мы выкатим пару новых фич, об этом вы прочитаете и увидите на самом форуме.
The lesson: don't use XenForo. It's old, built on PHP, and the FBI probably has several zero-days for it. That's why we wrote everything from scratch. We don't collect IPs or emails. We're also working on some very interesting solutions to strengthen user security, but I don't want to announce that publicly yet. I think we'll roll out a couple of new features soon, and you'll read about them and see them on the forum itself.
There's a lot of paranoia after the seizures. Some people in the community think T1erOne, XSS and Rehub could be honeypots. How do you respond to that?
Мы стараемся быть максимально прозрачными и ненавязчивыми. Например мы не собираем имейлы и айпи. Кто то может сказать что мы всё равно собираем дата аккаунтов но если человек параноит он может зарег через хмр - простое решение, Некоторые могли видеть «претензии» от одного блогера, мы на те выпады чётко ответили, обосновали всё. Есть вопросы, пишите, мы ответим.
We try to be as transparent and unobtrusive as possible. For example, we don't collect emails or IPs. Some might say we still collect account data, but if someone is paranoid they can register via XMR as a simple solution. Some people may have seen "complaints" from a certain blogger; we responded clearly to those attacks and justified everything. If you have questions, write to us and we'll answer.
If T1erOne gets seized tomorrow - do you have a backup plan? Would you rebuild? Or would you follow Stallman's example and just continue your core business elsewhere?
Мы делаем ежедневные бэкапы сервера дата так что если что то удалят или ФБР вмешается мы сможем всё восстановить и продолжить работу. Также мы работаем над E2EE чатами чтобы никто не мог читать сообщения юзера и ещё некоторыми интересными решениями которые точно усилят безопасность пользователей нашего форума.
We do daily server data backups, so if something gets deleted or the FBI intervenes we can restore everything and continue operating. We're also working on E2EE chats so no one can read user messages, plus some other interesting solutions that will definitely strengthen the security of our forum's users.
Do you think it's scary to run a forum with all the law enforcement pressure? Are you worried?
Лично я доверяю себе и своей команде, так что давления особо не чувствую. Если бы был один - возможно уже бы обосрался. Своего рода децентрализация- помогает в этом.
Personally I trust myself and my team, so I don't really feel the pressure. If I were alone I'd probably have already cracked. A kind of decentralization helps with that.
Do you think it is possible to get rich from running cybercrime forums, or is this for the sake of hacking communities, and reputation?
Ну да может ты и заработаешь 500к за 4 года если повезёт. Но это то чего ты хочешь? Обычную зарплату? Лично для меня это больше про сообщество и развитие. А вместе всегда и интересней и проще.
Sure, maybe you'll earn 500k over four years if you're lucky. But is that what you want? A regular salary? For me personally it's more about the community and development. And together it's always more interesting and easier.
One way to make money is escrow. Your forum has an escrow system?
У нас эскроу делается вручную на форуме. Но мы работаем над авто гарантом, чтобы это можно было делать быстрее
We do escrow manually on the forum. But we're working on an automatic guarantor system so it can be done faster.
Are there any interesting stories you'd like to share about the forum?
В первые дни офф. открытия форума и появления чата... ктото из юзеров написал чтото вроде: ну что забьёмся какой первый блэк будет? ну и буквально через день последовало первое разбирательство, которое закончилось баном известного юзера, который нарушил одно из немногих правил что у нас есть. И такое бывает.
Но мы пока молоды, так что интересное еще в переди
In the first days of the forum's official opening and the launch of the chat, one of the users wrote something like: "So, any bets on which will be the first blacklisting?" And literally a day later there was the first dispute, which ended in the ban of a well-known user who violated one of the few rules we have. That happens. But we're still young, so the interesting stuff is still ahead.
Thank you for joining us. Do you have any final words?
Кто в теме подтягивайтесь, кто заинтересован, тоже заходите, читайте, знакомьтесь, развивайтесь. Что ещё сказать, Всем успехов могу пожелать, что там ещё свободы и здоровья.
Спасибо за интервью, надеюсь всем слушателям и читателям понравилось наше любимое и супер крутое интервью )
If you're in the know, come join. If you're interested, come in, read, get acquainted, develop yourself. What else can I say. I wish everyone success, freedom, and good health. Thanks for the interview, I hope all listeners and readers enjoyed our beloved and super cool interview.
