Customer portal
Articles Tagged with

dark web threat intelligence

"Stealer
Investigation, The Dark Web

Stealer Logs: Understanding the Underground’s Most Dangerous Data Source

Introduction

Stealer logs represent the most dangerous commoditised threat to corporate security today. Unlike traditional data breaches that target specific organisations, infostealers cast a wide net across millions of users and machines, capturing everything from browser credentials to session tokens to cryptocurrency wallets in a single automated sweep.

So why are stealer logs such a critical concern right now? Because they are the common precursor to account takeover, ransomware deployment, and initial access brokerage. If your users’ credentials are in a stealer log marketplace, you do not have an identity problem; you have a breach waiting to happen.

This report examines what stealer logs are, how they are distributed and monetised, what data they contain, and how organisations can detect and defend against them. The scale is staggering: in the first half of 2025 alone, over 180,000 stealer logs were offered for sale on underground marketplaces. RedLine accounts for 44% of all logs collected. Vidar stole 65 million passwords in just six months.

If your domain appears in a stealer log, you are no longer operating under the assumption of credential compromise; you are operating under the certainty of it. The only question is whether the threat actor has already acted on that access.

How Infostealers Work

The Malware Itself

An infostealer is malware designed with a single purpose: to extract sensitive data from an infected machine and exfiltrate it to an attacker-controlled server. It runs silently, often with minimal resource consumption, which is why users and security teams can miss it for weeks or months.

So what data do they target? Browser autofill data, stored passwords, session cookies, saved payment card details, cryptocurrency wallet seed phrases and private keys, email account credentials, browser extensions, browsing history, installed software inventory, system information, and USB device history. The malware is indiscriminate; it grabs everything that might have value.

The sophistication varies. Basic infostealers are crude tools designed to grab whatever they can reach. Advanced infostealers include anti-analysis features, anti-virtualisation checks, geofencing to avoid high-risk jurisdictions, and code obfuscation to bypass signature-based detection.

Major Infostealer Families

RedLine is the dominant family by volume. First observed in 2020, RedLine has evolved into a modular stealer with customisable features, support for multiple languages and operating systems, and active development. It accounts for 44% of all stealer logs captured by intelligence vendors. RedLine spreads primarily through cracked software, malicious advertising networks, and watering hole attacks targeting development forums.

Raccoon was one of the earliest widespread infostealers and became infamous for its ease of use and low barrier to entry. Variant developers could build custom builds for under $100. Although law enforcement operations disrupted Raccoon’s primary infrastructure in 2023 (following the October 2022 arrest of developer Mark Sokolovsky), variants continue to circulate. Raccoon logs are heavily discounted on marketplaces because the payloads are dated and signatures are well-known.

Vidar is one of the most aggressive and feature-rich infostealers in circulation. It records keystrokes, captures screenshots, exfiltrates browser data, and includes anti-reverse-engineering protections. Vidar was responsible for stealing 65 million passwords in a documented six-month period from 2024 to 2025. It spreads through malvertising, cracked software, and compromised download mirrors.

Lumma emerged in 2022 and gained traction rapidly because of its effective distribution mechanism and low detection rates. Lumma’s primary distribution vector is Trojanised legitimate software (video converters, games, file managers) distributed through third-party sites. Lumma logs are actively traded on underground markets at premium prices because they tend to contain fresh, high-value data.

The Malware-as-a-Service Model

Most modern infostealers operate as a service, not a discrete product. Operators host the command and control infrastructure, provide a web panel for customers to manage infections and download logs, and take a percentage of the revenue when logs are resold.

The client (a threat actor, distributor, or criminal organisation) uses the service to build custom malware variants, deploy them through their chosen vectors, and collect the resulting logs. The service operator handles the backend; the client handles distribution and monetisation.

This model democratises malware development. You do not need to be a skilled reverse engineer or malware author; you just need access to a distribution channel and a payment method. Prices for malware-as-a-service access range from $40 per month for basic builds to $500 per month for fully customised, high-stealth variants with obfuscation and anti-analysis features.

The Stealer Log Supply Chain: From Infection to Marketplace

Step One: Distribution

The first stage of the supply chain is getting the malware onto the target machine. Distribution methods include cracked software (the single largest vector), malicious advertisements and browser redirects, compromised legitimate software mirrors, phishing emails with trojanised attachments, and watering hole attacks targeting developers and specific industries.

Cracked software remains the dominant distribution method because the economics are simple: users want free versions of expensive software, threat actors provide infected versions, and the malware runs with the privileges of the software installation. Commonly trojanised products include AutoCAD, Microsoft Office, Photoshop, Ableton Live, JetBrains IDEs, and antivirus software itself. Underground marketplaces such as zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion advertise cracking tools and hacking guides alongside stealer logs.

Step Two: Execution and Exfiltration

Once executed, the infostealer begins its automated collection routine. It enumerates installed browsers, reads credential storage databases, decrypts stored passwords using the operating system’s credential storage APIs, extracts browser cookies (which often contain active session tokens for web services), and collects any data it has permissions to access.

So what happens to this data once collected? The malware packages it into an archive (typically JSON or CSV format), compresses it, and sends it back to the attacker’s command and control server. This happens in seconds to minutes, often without any user-visible activity. Encryption in transit is variable; some stealers use HTTPS, others use simple obfuscation.

Step Three: Log Curation and Testing

The logs arrive at the attacker’s server in raw form. Experienced threat actors filter and verify logs before offering them for sale. They test login credentials against target services to confirm validity, check whether emails are associated with high-value targets (executives, technical staff, security personnel), and flag logs that contain cryptocurrency wallet data or payment card information for premium pricing.

A high-quality stealer log contains verified working credentials, a mix of personal and corporate accounts, cryptocurrency wallet information, and identifiable metadata such as system username and company name extracted from the system registry. Low-quality logs are unverified, old (more than a week old), or contain duplicates.

Step Four: Marketplace and Distribution

Verified logs are uploaded to underground marketplaces. The three most significant distribution channels are the Russian Market (a Telegram-native marketplace with automated purchasing and delivery), Genesis Market (a long-standing marketplace specialising in session cookies and browser profile data, subject to FBI takedown in April 2023 as part of Operation Cookie Monster), and ad hoc Telegram channels run by individual threat actors or resellers.

Pricing follows a predictable pattern: individual consumer logs $1 to $5, logs containing cryptocurrency or payment card data $10 to $50, corporate or email logs $20 to $100, and bulk access to large log repositories $1,000 to $5,000, depending on scope and recency. Some marketplaces offer subscription models where buyers pay $200 to $500 per month for unlimited access to new logs.

Step Five: Exploitation

Once purchased, the logs are used for account takeover (directly accessing email, SaaS applications, or banking portals), credential stuffing attacks against non-customers, password spray attacks across corporate networks, identification of high-value targets for targeted phishing or social engineering, and sales to other threat actors, ransomware gangs, or initial access brokers.

The timeline from infection to exploitation can be remarkably short. Logs may be available for purchase within 24 to 72 hours of infection. Active threat actors monitor marketplaces continuously, purchasing logs for targets relevant to their operations immediately after they appear for sale.

What’s Inside a Stealer Log

A typical stealer log is a structured data archive containing the following categories of information.

Browser Credentials

Passwords are stored in Chrome, Firefox, Edge, Opera, and other Chromium-based browsers. These are extracted using the browser’s own decryption APIs and are usually in plaintext in the log. If your users are reusing passwords across multiple services (which most do), a single compromised password gives access to email, SaaS applications, banking portals, and corporate networks.

Session Cookies and Browser Data

Session cookies are particularly valuable because they often grant access to authenticated services without requiring the user to log in again. A stolen cookie for a user’s email account, for example, allows an attacker to reset the password for every service that user has signed up for. Logs also contain browser autofill data, saved addresses, phone numbers, and credit card information.

Cryptocurrency Wallet Data

If the infected machine has a cryptocurrency wallet installed (MetaMask, Trust Wallet, Ledger, Trezor drivers), the infostealer attempts to extract wallet seed phrases, private keys, and transaction history. A stolen seed phrase gives the attacker full control of any cryptocurrency stored in that wallet. Logs containing wallet data command a significant price premium, with cryptocurrency-focused marketplaces like tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion advertising cloned cards and financial fraud tools alongside wallet data.

System and User Information

The log includes the machine’s hostname, registered Windows username, installed software inventory, list of network interfaces and IP addresses, list of USB devices ever connected, system serial number, and BIOS information. This metadata helps threat actors profile the target (e.g. is this a developer machine, does it have security software installed) and tailor exploitation.

Email and Application Data

If Outlook, Thunderbird, or other email clients are installed, logs may contain saved email credentials and cached email headers. Application-specific data is also captured, including saved credentials in password managers (if they are not properly locked), FTP clients, SSH keys, browser extensions, and stored API credentials in development tools.

Indicator Format

Logs are typically structured as JSON or CSV files within a ZIP archive. A single log might be 5 to 200 megabytes, depending on the system’s history and installed software. Large batch log collections can reach gigabytes and are broken into smaller chunks for distribution.

Key Statistics: The Scale of the Threat

RedLine accounts for 44% of all stealer logs analysed by intelligence platforms. This concentration means that if you are looking for signs of compromise via stealer logs, you are primarily tracking RedLine activity. However, that also means a significant proportion of logs come from other families like Vidar, Lumma, and Raccoon variants.

Vidar stole 65 million unique passwords in a documented six-month period from October 2024 to March 2025. This single family, operating from a single set of infrastructure, compromised a staggering volume of user accounts across consumer and corporate domains.

Over 180,000 stealer logs were offered for sale on identified underground marketplaces in the first half of 2025. This is an average of 30,000 logs per month, or roughly 1,000 logs per day.

More than 50% of ransomware victims had their domains listed in stealer logs before the ransomware deployment. This indicates that initial compromise via stealer log access is a primary precursor to ransomware attacks. Threat actors purchase logs to establish initial access, conduct reconnaissance, and stage the ransomware payload.

Major Infostealer Families

Stealer Log Pricing by Type

Impact Statistics

The Marketplace Ecosystem

Russian Market (Telegram Native)

Russian Market operates exclusively within Telegram and is the largest active stealer log marketplace as of 2025. The platform uses automated bots that handle purchasing, payment, and log delivery. Buyers simply send a payment in cryptocurrency and receive a direct link to download the log within minutes.

Russian Market does not charge a commission on individual sales; revenue comes from premium marketplace memberships, advertising, and selective enforcement of seller verification. The platform lists 50,000 to 100,000 logs at any given time, with new inventory added continuously.

Genesis Market

Genesis Market is a longer-established marketplace that specialises in session cookies, browser profiles, and authenticated user sessions rather than raw passwords. It operates a traditional web interface (accessed via Tor) and enforces strict verification of sellers. Genesis Market was subject to a major FBI takedown operation in April 2023.

Genesis Market takes a 10 to 15% commission on each sale. Logs on Genesis command higher prices than equivalent logs on the Russian Market because the payload (authenticated sessions) is more directly useful for account takeover without password changes. The marketplace has hosted millions of stolen sessions.

Telegram Channels and Resellers

Smaller threat actors and resellers operate ad hoc Telegram channels, often promoting newly harvested logs from specific geographic regions or specific malware families. These channels operate with less formal infrastructure and offer discounts for bulk purchases. Forums like bfdxjkv5e2z3ilrifzbnvxxvhbzsj67akjpj3zc6smzr4vv6oz565gyd[.]onion host escrow services and enable peer-to-peer trading of stolen logs.

Prices on Telegram are often lower than those on centralised marketplaces because resellers are trying to move inventory quickly and avoid law enforcement attention. However, logs are also less verified and may contain duplicates or stale data.

Regional Variations

Pricing and availability vary significantly by geography. Logs from developed economies (USA, UK, Germany, Japan) command premium prices. Logs from developing economies are discounted. Logs are also segmented by corporate association; logs from email addresses on Fortune 500 domain whitelists are marked as such and priced accordingly.

Corporate Risk: How Stealer Logs Enable Attacks

Account Takeover

The most direct exploitation path is account takeover. An attacker purchases a log containing the email address and password of a corporate employee. They attempt to log into the employee’s email account. If multi-factor authentication is not enabled (and many users do not enable it outside of work contexts), login succeeds.

From the email, the attacker resets passwords for every service the employee has linked to that email account. This includes SaaS applications, cloud storage, password managers, and often the employee’s corporate VPN or SSO portal if they have reused the same password across services.

Initial Access Brokerage

Ransomware gangs and APT operators do not have time to run large-scale malware campaigns. Instead, they purchase access from initial access brokers. An initial access broker uses stealer logs to identify high-value targets (corporate email addresses, domain admin accounts, people working for specific industries), purchases logs for those individuals, and then sells the access to ransomware operators or nation states.

A single log containing credentials for a domain admin or security operations centre staff member can sell for $5,000 to $50,000 to a ransomware operator, because that access drastically shortcuts the reconnaissance and lateral movement phases of a ransomware campaign.

Reconnaissance and Lateral Movement

Even if the initial compromised account is a low-privilege user, logs contain system information, installed software, network configuration, and connected USB devices. This metadata gives threat actors a profile of the corporate environment before they even gain access. They know which security software is in use, which development frameworks are deployed, and which network devices are present.

Once inside, the attacker uses the compromised account to access email (containing sensitive business information, network topology diagrams, and access credentials in forwarded messages), network drives, and internal tools. This leads to lateral movement to higher-privileged accounts and eventually to domain admin compromise.

Credential Stuffing and Password Spray

An attacker with a database of 1,000 stolen passwords can conduct password spray attacks against your corporate email system or Active Directory, trying the same password across all known email addresses in your organisation. The attack succeeds if employees have reused credentials or used predictable variations.

This is a silent attack that happens outside of your firewall and VPN, so your network monitoring tools do not detect it. The first sign may be unexpected password reset emails or successful logins from impossible locations.

Supply Chain Compromise

If your organisation relies on third-party software vendors or contractors, and those vendors’ employees are in the stealer logs, an attacker can compromise the vendor and use their access to gain indirect access to your systems. This is a far easier attack vector than breaching you directly.

How SOS Intelligence Monitors Stealer Logs

Our breach alert system continuously monitors underground marketplaces, forums, Telegram channels, and data dump collections for stealer logs and other sources of compromised data. We extract indicators of compromise from each log and match them against your organisational domains.

So how does detection work? We parse log contents for email addresses, domain names, usernames, system names, and other identifying information. We match these against your organisation’s known domain list. When we find a hit, we generate an alert with details: which user was compromised, which malware family was responsible (if known), what data was exposed, when the log appeared for sale, and what price it commanded on the marketplace.

We also track trends. We monitor which malware families are producing the most volume, which geographic regions are being targeted, and which industries are disproportionately represented in current stealer logs. This gives you visibility into both specific risks to your organisation and the broader threat landscape.

Our enrichment process adds context. We cross-reference the compromised email addresses with LinkedIn, WHOIS records, and internal threat intelligence to identify whether the compromised user holds a sensitive position (executive, developer, security staff). We flag logs that contain multiple compromised employees from the same organisation as indicators of targeted activity rather than random harvesting.

Defensive Recommendations

Detection and Monitoring

First: subscribe to breach alert services that monitor stealer log marketplaces and dark web collections. The earlier you know that your users are in stealer logs, the faster you can reset compromised credentials and audit for account access.

Second: implement continuous exposure monitoring. Track your organisational domains on dark web forums, marketplaces, pastebins, and leaked database collections. Many of these sources post publicly (just on obscure infrastructure); you do not need access to Telegram to find them.

Incident Response

If you discover that your domain is present in a stealer log, treat it as a credential compromise incident. Reset the password for the compromised user immediately. Force re-authentication on all active sessions (log them out everywhere). Enable multi-factor authentication if not already in use. Audit email forwarding rules, application integrations, and connected devices for signs of access.

Check whether the compromised user holds a sensitive role. If they do, expand your investigation: query your identity provider and email system for impossible logins, password changes, or unusual activity; check cloud storage for data exfiltration; and interview the user about recent phishing attempts or unusual system behaviour.

Credential Hygiene

Enforce strong, unique passwords for all systems, especially email and identity providers. Implement passwordless authentication where possible (FIDO2 hardware keys, Windows Hello). Where passwords are necessary, use a password manager with strong master passwords.

Multi-factor authentication is not optional; it is mandatory. If an attacker has your password (because it is in a stealer log), multi-factor authentication is the only thing that stops account takeover. Prioritise MFA for email and administrative accounts. Do not rely on SMS; use TOTP or hardware keys.

Threat Actor Knowledge

Understand which threat actors are currently targeting your industry. If you operate in critical infrastructure or financial services, you are targeted by state-sponsored actors and organised crime groups, not opportunistic cybercriminals. If you operate in technology or biotech, intellectual property theft is a primary motivation.

Review the malware families affecting your sector. If your users are appearing in Vidar or Lumma logs more frequently than average, your distribution channels may be compromised. If you see your domain in logs associated with a specific ransomware gang, you have a higher probability of imminent encryption activity.

Third-Party Risk

Audit your third-party vendors and contractors for Stealer log exposure. If a critical vendor has employees in breach, consider the implications for your access. Do they reuse passwords, or are their systems segmented? Do they have elevated privileges in your environment?

Implement zero-trust principles for vendor access. Do not assume that a contractor’s machine is clean; segment their access, require multi-factor authentication, and monitor their activity as you would a hostile external party.

Appendix: DARKSEARCH Observed Indicators

The following table documents confirmed indicators from dark web marketplaces and forums monitored via SOS Intelligence’s DARKSEARCH API. All onion addresses are defanged for security and compliance purposes. These indicators are provided for threat intelligence and detection purposes only.

External References

The analysis in this report draws on publicly available threat intelligence, academic research, and law enforcement activity reports. Key sources include:

Conclusion

Stealer logs are not a future threat; they are a present reality. The scale of harvesting, the sophistication of the malware, and the availability of stolen data on open marketplaces mean that credential compromise is no longer exceptional. It is expected.

Your organisation’s security posture must start with the assumption that your users’ credentials are compromised. That means: strong, unique passwords, multi-factor authentication, continuous monitoring of dark web sources, rapid response to breach alerts, and zero-trust policies for sensitive access.

The defenders who will prevail are those who detect compromise early and respond immediately. Every hour between when a stealer log appears on a marketplace and when you reset the compromised credentials is an hour the attacker can exploit that access.

If you do not have visibility into dark web stealer log marketplaces today, you do not have a complete picture of your organisation’s actual risk. Close that gap now.

Danger photo by Edwin Hooper on Unsplash

Malware photo by Ed Hardie on Unsplash

Browser photo by BoliviaInteligente on Unsplash

No trespassing photo by Joseph Corl on Unsplash

"The
Investigation

The Dark Web’s Professional Services Economy: From Bulletproof Hosting to Escrow Systems

Introduction

The dark web has evolved considerably since its early days as a collection of amateur marketplaces and forum bazaars. Today, it operates as a sophisticated underground services economy, with professional platforms, specialised vendors, and infrastructure providers all competing for market share. So what was once the domain of hobbyists and script kiddies has become an ecosystem supporting $3.2 billion in global underground economic activity, with criminal-as-a-service offerings alone worth approximately $700 million (Chainalysis Crypto Crime Report, 2026).

The sophistication you see now matters. A decade ago, launching a dark web marketplace meant running everything yourself: hosting, payment processing, dispute resolution, vendor management. That overhead meant only determined criminals bothered. So today, when someone wants to start an illegal operation, they can simply outsource the entire infrastructure to purpose-built service providers. The technical barrier to entry has collapsed.

This shift transforms cybercrime from a collection of isolated incidents into a resilient, distributed economy. So when law enforcement takes down a marketplace, another opens within days because the underlying services remain intact and available for hire. Understanding this services economy is essential for anyone defending against cybercrime; it reveals why enforcement alone cannot disrupt the underground, and why the real defensive priority lies in targeting the infrastructure and services that enable it.

Bulletproof Hosting: The Foundation of Criminal Infrastructure

Bulletproof hosting providers form the bedrock of dark web operations. These hosting companies operate predominantly from Southeast Asia and Eastern Europe, offering servers designed explicitly to resist takedowns, ignore abuse complaints, and withstand law enforcement pressure. So roughly 60% of ransomware leak sites operate on bulletproof hosting infrastructure, providing the attackers with the hosting they cannot obtain through legitimate channels.

The Netherlands remains a significant hub for bulletproof hosting, with providers operating openly and essentially untouchable due to the country’s legal complexity and the providers’ deliberate geographic distribution across multiple jurisdictions. So what these providers offer differs fundamentally from legitimate hosting. Bulletproof hosts give abuse complaint immunity; your site stays online regardless of DMCA notices or law enforcement requests. They provide law enforcement resistance through hidden ownership structures, false documentation, and operational paranoia about cooperation with authorities. They offer flexible infrastructure designed specifically for rapid migration and redundancy across bulletproof providers worldwide.

Cost is minimal. So a dedicated server suitable for running a ransomware leak site costs between $50 and $200 per month on bulletproof platforms, roughly one-third the cost of legitimate hosting. The vendors promise 99.9% uptime, DDoS mitigation, and most importantly, zero compliance with takedown requests. When one provider faces pressure, customers migrate to another within hours using automated tools that sync site content across multiple bulletproof hosts. Recent investigations by Krebs on Security have documented bulletproof hosting providers operating with impunity across multiple jurisdictions, maintaining customer infrastructure even as law enforcement agencies coordinate takedown attempts.

Escrow and Dispute Resolution: Trust in a Trustless Environment

Dark web marketplaces operate without the luxury of legal contracts or courts. So they depend entirely on escrow systems that hold funds in a neutral state until both buyer and vendor agree the transaction is complete. According to our monitoring, 92% of major dark web marketplaces now offer some form of escrow mechanism, protecting both sides from fraud. We’ve identified marketplace infrastructure such as that observed on sqw2klzo4mtwvbf3by7irjv7r5mdojxwziuus3lh6rketlkggvsdyaad[.]onion, which operates professional multi-vendor infrastructure with integrated escrow, multi-signature wallets, and dedicated support channels.

Traditional escrow on the dark web works through a simple process. So a buyer deposits cryptocurrency to a marketplace wallet under escrow; the vendor is notified and ships the product; the buyer receives and verifies the product; the buyer then confirms delivery to the marketplace, which releases the funds to the vendor. Multi-signature Bitcoin wallets ensure that neither party can steal the escrow unilaterally, and neither can the marketplace without the other party’s signature. So the marketplace effectively holds the tiebreaker, giving both sides confidence that disputes will be resolved fairly or at least consistently.

Newer marketplaces deploy Ethereum smart contracts and complex multi-sig schemes with 2-of-3 signatures, where the third signer is a reputation-bonded arbitrator. So if a dispute arises, the arbitrator reviews evidence and votes with one party, making the transaction irreversible. These systems aren’t legally binding, but they achieve the same effect through cryptographic certainty; once the arbitrator votes, the funds move automatically. We’ve documented evidence of such advanced escrow systems running on dark web marketplaces with thousands of active vendors and real-time transaction monitoring.

The sophistication of these systems matters because it enables genuine marketplaces with genuine market dynamics. So vendors compete on price and quality because their reputation scores are public and persistent. Buyers take risks because they know the marketplace will force resolution. Without escrow and dispute resolution, dark web commerce would collapse into scams and violence; with it, you get functioning marketplaces that rival legitimate e-commerce in operational sophistication.

Dark Web Development Services: Specialised Criminal Infrastructure

Our research from DARKSEARCH identified vendors offering dedicated storefront services specifically for dark web operations. So these developers handle everything: Tor website development, .onion domain registration, server installation, and cryptocurrency payment node setup. They’re professional web developers specialising in criminal infrastructure, with portfolio sites, customer testimonials, and repeat business. Examples of professional marketplace infrastructure that incorporate these services include tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion, which runs a WooCommerce-based storefront with full shopping cart functionality, category systems, and professional vendor tools.

A typical service package costs $800 to $2,500, depending on complexity. So you get a fully functional marketplace or vendor storefront, pre-integrated with Monero and Bitcoin payment processors, built on proven vulnerable-by-design architecture that leaves backdoors for the developer to raid customer funds if needed. Many developers operate on the principle that they’ll eventually exit scam their own customers, which incentivises complex fraud and ensures a certain percentage of marketplace collapses are internal rather than law enforcement.

The competitive advantage of these services is speed to market. So a criminal group with no web development skills can launch a marketplace in two weeks rather than two months. That matters because marketplace lifespan averages six months before law enforcement intervention or internal exit scams. So the faster you launch, the sooner you start collecting fees; every week matters in an environment where law enforcement is actively hunting you. We’ve identified professional hacking services vendors operating at sites such as zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion, offering DDoS tools, botnets, malware, black hat hacking courses, and custom development services with documented customer testimonials praising their professional handling and customer support.

Money Movement Services: Liquidating Stolen Assets

The dark web hosts a mature market in money movement and liquidation services, where criminal groups can convert cryptocurrency, stolen payment cards, and compromised accounts into usable cash. So these services are where the real money laundering happens, and they command premium prices because the risk is highest.

Our price monitoring shows PayPal transfer services cost $600 to move $7,000 from a stolen or compromised account to a clean account controlled by the buyer. So the seller guarantees the transfer completes and the account remains active for 48 hours after settlement, which means the buyer can withdraw funds before the victim notices and account locks. Visa prepaid card cloning costs $630 to create a cloned card from stolen credentials, guaranteed to have $7,500 available for withdrawal, though you have only hours before the card is flagged and frozen.

Paxful account takeovers are cheaper; $250 to $400 buys you a compromised account with a $1,000 to $5,000 balance, with instructions on how to transfer funds to cryptocurrency. Binance transfer services cost $300 to $500 per transfer and guarantee that a freshly created account receives a large deposit, which you can immediately convert to Monero and withdraw. Bank flash tools, which create temporary fraudulent balances in legitimate bank accounts, cost $800 to $1,200 and guarantee 4 to 8 hours of real-looking balances that you can use as proof of funds for cryptocurrency deals. Digital Shadows and ReliaQuest research on Crime-as-a-Service (CaaS) platforms documents the pricing consistency and professional service guarantees that characterise this market segment.

The consistency of pricing across these services reveals a mature market with standardised products and customer expectations. So every vendor offers a money-back guarantee if the service doesn’t deliver within 48 hours. Most vendors operate through intermediaries or use bulletproof hosting to accept Bitcoin payments and deliver credentials or access tokens within minutes. The entire ecosystem is designed to maximise the number of successful transactions while minimising the risk to the vendor through anonymity and rapid exit scams.

Market Data: Professional Service Categories and Pricing

Marketplace Infrastructure: The Evolution of Trust Systems

How Vendor Reputation Works

Dark web marketplaces operate reputation systems nearly identical to Amazon or eBay, with one crucial difference: the vendors are criminals, and the goods are illegal, but the mechanics are the same. So vendors accumulate review scores, customer feedback, sales counts, and escrow completion rates. These metrics are public and weighted heavily in customer purchasing decisions.

A verified seller badge requires 50+ transactions and a 99%+ escrow completion rate, giving buyers confidence that they’re dealing with a professional vendor rather than a scammer. So vendors with 500+ sales and 4.8+ star ratings can command premium prices because customers trust them to deliver as promised. We’ve observed Tor-based Amazon clones displaying cart totals exceeding $154,000 and product pages showing vendor sales counts in the thousands, suggesting massive transaction volumes. These systems mirror the trust infrastructure documented in RAND Corporation research on Markets for Cybercrime Tools and Stolen Data.

The psychological effect is profound. So when a vendor has 2,000 successful sales and a 4.9-star rating, customers treat that vendor as reliable and trustworthy, even though the vendor is openly selling stolen credentials or malware. The reputation system makes crime feel safe, standardised, and professional.

Customer Support and Dispute Resolution

Premium dark web marketplaces operate customer support functions indistinguishable from legitimate platforms. So return policies specify exactly which products are returnable (usually malware and credentials are non-returnable, but compromised accounts can be swapped for new ones if they stop working). Refund guarantees promise money back if the product doesn’t work within a specified timeframe, typically 48 hours.

Quality assurance sections let vendors showcase their process for testing products before sale. So a malware vendor might include notes on which antivirus engines detect their samples and which don’t, giving buyers accurate information about evasion capabilities. Loyalty programmes reward repeat customers with discounts on bulk purchases or exclusive access to new products. We’ve documented professional review ecosystems and category directories such as ylf6u5gurfisvhgheevy4rxzcw36gyp4r55crqlmiydmzwi2xkvmhcad[.]onion, which maintains Tor site categorisation with review systems and user ratings across hosting, markets, forums, and hacking service providers.

Promotional sales and flash deals drive volume and customer acquisition. So vendors advertise limited-time discounts; 20% off credentials on Mondays, bulk discounts for accounts in quantities over 100, and seasonal sales coinciding with major breach announcements. The entire apparatus mimics e-commerce best practices because it actually works; it creates trust and drives revenue.

Marketplace Infrastructure Comparison: 2020 to 2026

The Consolidation Trend: One-Stop Shops for Crime

Historically, dark web specialisation meant drug marketplaces sold drugs, hacking forums sold malware, and carding forums sold stolen payment cards. So each operated independently with separate vendor bases and community management. That’s changing. Modern mega-marketplaces like Tor Market consolidate everything: drugs, firearms, documents, hacking tools, exploit code, money laundering services, and personal data all under one roof.

The advantage is efficiency. So when a customer wants to commit a crime that requires multiple inputs (drug trafficking needs a drop address, firearms need a safe shipping method, credential theft needs a money movement service), they can find all of it from one vendor network. This consolidation also increases customer stickiness; if you’ve developed a reputation and balance on one platform, you’re incentivised to keep using it rather than migrating.

For law enforcement and platform defenders, this consolidation is a disaster. So any takedown now disrupts multiple crime types simultaneously, which increases pressure and attention on the platform. But it also means that destroying one mega-marketplace cascades damage across the entire underground economy, because dependent services lose their primary revenue source. So the tradeoff is real; consolidation makes the underground more efficient but also more fragile.

What This Means for Defenders

The professionalisation of dark web services has transformed cybercrime from a collection of isolated incidents into a resilient, distributed economy. So when a ransomware gang’s leak site gets taken down, they simply migrate to a new bulletproof host within hours, and the operation continues. When a marketplace faces law enforcement, another opens within days because the underlying infrastructure is commodity-priced and widely available.

This resilience emerges from specialisation and commoditisation. So as long as there’s demand for bulletproof hosting, someone will supply it. As long as crime exists, money movement services will be available. As long as markets function through reputation systems, customers will trust vendors with high ratings. No single takedown disrupts this system because each component is replaceable.

The defensive implication is stark. So law enforcement can’t win through enforcement alone; taking down marketplaces and seizing servers doesn’t address the underlying services economy that immediately recreates them. Instead, the focus must shift to attacking the infrastructure providers, the escrow systems, and the money movement services. Target bulletproof hosts and you raise costs; target Monero exchanges and you restrict outflows; target the service providers themselves, and you degrade the ecosystem’s efficiency. Europol’s iOCTA (Internet Organised Crime Threat Assessment) documents the systemic challenge that enforcement faces when confronting distributed underground services economies.

But this requires a different enforcement approach, one that focuses on long-term infrastructure disruption rather than tactical takedowns. So when law enforcement seizes a marketplace, that’s a headline. But when law enforcement systematically disrupts bulletproof hosting providers, identifies money movement operators, and pursues the service infrastructure, that’s actually consequential. The current approach does the former; the future approach must do the latter.

How SOS Intelligence Tracks the Services Economy

Our crawling infrastructure monitors dark web marketplaces in real-time, tracking vendor offerings, pricing changes, service categories, and marketplace infrastructure patterns. So we identify new service providers before they accumulate significant market share, detect when services migrate to new hosts or providers, and measure the maturity and sophistication of each service vertical.

We track vendor reputation systems and identify when established vendors change specialisation or exit scam their customers. So when a vendor with 500+ sales suddenly vanishes with customer funds in escrow, that’s a data point. Patterns of exit scams reveal marketplace lifecycle stages; newer marketplaces experience higher scam rates, and more mature ones have stronger incentives to maintain reputation.

Our pricing monitoring captures real-time costs for money movement services, account compromises, and infrastructure rentals. So when PayPal transfer costs spike from $600 to $1,200, that reveals increased supply constraints, likely from law enforcement targeting money movement providers. When bulletproof hosting prices surge, that reveals reduced supply and increased pressure. We continuously monitor past services and data sharing infrastructure to track threat actor communications and data exfiltration patterns.

We correlate these data with law enforcement actions, seized server data, and security research to build a comprehensive map of the professional services economy. So our customers can understand not just what the dark web offers, but why it works, where the dependencies lie, and what pressure points are most likely to disrupt operations at scale.

Appendix: DARKSEARCH Observed Infrastructure

The following table documents real dark web infrastructure observed through DARKSEARCH API monitoring. All onion URLs are defanged; replace [.] with . to restore. These represent mature, operational professional services platforms serving the underground economy.

External References

  • Chainalysis Crypto Crime Report 2026: Documents underground economy scale, cryptocurrency usage patterns, and market segmentation across criminal services, commodities, and infrastructure.
  • Europol iOCTA (Internet Organised Crime Threat Assessment): Systemic analysis of organised crime operations on the dark web, law enforcement coordination challenges, and infrastructure resilience patterns.
  • RAND Corporation ‘Markets for Cybercrime Tools and Stolen Data’: Academic framework for understanding how specialisation and commoditisation transform criminal markets into professional services economies.
  • Digital Shadows and ReliaQuest Crime-as-a-Service (CaaS) Research: Pricing analysis, service maturity assessment, and market dynamics of professional criminal services offerings.
  • Flashpoint and Recorded Future Marketplace Monitoring Reports: Real-time tracking of dark web marketplace evolution, vendor reputation systems, and operational infrastructure changes.
  • Krebs on Security Bulletproof Hosting Investigations: Detailed documentation of hosting providers, jurisdictional strategies, and law enforcement resistance techniques across multiple dark web operations.

Header photo by benjamin lehman on Unsplash

Bullet photo by Jay Rembert on Unsplash

Infrastructure photo by Marc-Olivier Jodoin on Unsplash

"Dark
Investigation, Uncategorized

Dark Web Marketplace Scripts: The Franchising of Cybercrime

Introduction

The dark web does not create markets from scratch. When Genesis Market was seized by US law enforcement in 2024, we expected it to vanish. Instead, within weeks, a clone was operating under a different name on a different server. How?

The answer lives in a small corner of the dark web that most threat intelligence teams never look at. There is a thriving economy in marketplace-as-a-service: buy a script, deploy it on Tor, start selling. In the same way ransomware-as-a-service democratised encryption-based extortion, marketplace scripts have democratised the operation of illegal stores.

We discovered this while crawling dark web markets with DARKSEARCH. A single Tor-hosted storefront called “Darkweb Developer” has been selling turnkey marketplace solutions for the past eighteen months. The scripts are commodity products now. They have version numbers, feature lists, update cycles, and technical support.

This explains a paradox that has puzzled law enforcement and private sector intelligence teams for years: why do 35 to 45 distinct dark web marketplaces coexist despite the takedowns? The answer is simple. They are not individually maintained ecosystems. They are instances of a handful of scripts, each one deployed in isolation with minimal customisation.

What We Found

In January 2026, we indexed a dedicated Tor-hosted storefront selling marketplace scripts and related infrastructure. The shop operated under the handle “Darkweb Developer” and advertised the following products.

Featured Marketplace Scripts

Incognito Market Script was listed at $1,000 but on sale for $750 at the time we captured it. The script came with a base installation guide, admin panel, and one month of technical support from the vendor. The listing promised multi-vendor support, Monero payment integration, and a built-in dispute resolution system. Reviews from past buyers were positive; one customer noted it ‘went live in three days’ and another mentioned the escrow system worked ‘without issues’.

The Midland City Anonymous Marketplace Script was priced at $550. This appeared to be an older codebase, Laravel 8 instead of Laravel 10, but buyers appreciated the lower price and said it had fewer dependencies. The listing showed screenshots of a clean admin panel and user management interface.

Pax Romana Dark Web Market Script had no price listed; you had to contact the vendor for a quote. The listing suggested it was a premium tier offering, pitched as suitable for ‘large-scale operations’ with support for thousands of concurrent users.

Beyond the scripts themselves, Darkweb Developer also offered complementary services. Domain registration on .onion addresses via a partnered registrar costs $25 to $50, depending on domain length. Hosting on isolated Tor exit nodes was $200 to $500 per month. Bitcoin and Monero node setup, essential for payment processing, ran $100 to $300 one-time. SSL certificates for HTTPS mirrors were $30. A full-featured admin toolkit, including vulnerability scanning and backup utilities, was $150.

The Business Model

So what you are looking at here is infrastructure-as-a-service for dark web commerce. The buyer pays an upfront fee for the script, deploys it on rented hosting, configures payment nodes, and within days has a functioning marketplace. The entry cost is minimal: $750 for the script, $300 for hosting setup, $100 for payment infrastructure, and $50 for a domain. Roughly $1,200 to start a dark web market that could handle a thousand vendors.

Compare that to building from scratch. A competent developer would spend four to six months writing marketplace software. The escrow system alone requires careful cryptographic implementation to prevent theft by the marketplace operator or disputes between buyer and vendor. The code must handle user registration, credential recovery, PGP encryption, 2FA, vendor onboarding, product category management, search functionality, reviews, dispute mediation, and admin operations. This is not a weekend project. It is six months of focused work.

By selling pre-built scripts, the vendor abstracts away that development cost. The buyer gets a tested, working system. The marketplace script vendor gets a scalable business: each sale is pure margin after the initial development investment. You sell the first copy for $750, and it takes eight months to break even on development. By month twelve, you have sold fifty copies, and you are making $30,000 per month with zero marginal cost.

The vendor also gets free marketing. Every marketplace that runs on their script is essentially an advertisement. If the script proves reliable and feature-rich, operators will use it. If it has bugs or is compromised, operators will badmouth it. The market self-corrects. The vendor’s reputation is their primary asset.

Technical Analysis

The scripts we analysed were built on Laravel 8 or 10, the PHP web framework. This is not surprising. Laravel has a large ecosystem of libraries, established security practices, and community support. It is what a professional developer would choose if building a marketplace.

Core Components

Every script included user registration and account management. The registration flow was straightforward: email, username, password, and optional PGP public key import. Users could set two-factor authentication via TOTP or hardware keys. Account recovery was via email or, in some cases, by recovering a private key if the user had set one up at registration.

Vendor management was the next layer. Vendors could create a storefront, upload product listings with descriptions and images, set pricing in Monero or Bitcoin, manage stock levels, and handle shipping addresses and tracking information. The system tracked vendor reputation via review scores and dispute resolution history. Vendors with too many chargebacks or disputes were automatically suspended.

The escrow system was the critical piece. When a buyer purchased an item, payment went into escrow controlled by the marketplace. The vendor could not access the funds until delivery was confirmed. The buyer had a window, typically five to fifteen days depending on marketplace configuration, to confirm receipt or file a dispute. If disputed, the funds were frozen, and a dispute resolution process began, usually mediated by marketplace administrators.

All communication between buyer and vendor was encrypted end-to-end. The scripts supported either PGP encryption of message text or a dedicated encrypted messaging interface within the marketplace. This meant the marketplace operator could not read buyer-vendor conversations even if they wanted to.

Admin Panel and Operational Tools

The admin panel was comprehensive. Operators could view transaction volumes, user counts, dispute statistics, and payment node status in real time. They could manually override user balances, freeze accounts, remove listings, and execute transactions. They could also export data for tax or accounting purposes, though in practice, no dark web market operator is actually filing tax returns.

Search and discovery were implemented via Elasticsearch in the more sophisticated scripts. Product listings were indexed by title, description, vendor name, and category. Search results could be sorted by price, rating, or recency. The Incognito Market Script listing mentioned support for ‘faceted search and automated deduplication’, which suggests a fairly mature search engine.

The admin toolkit offered backups to encrypted cloud storage, automated database replication, and vulnerability scanning. Some vendors included intrusion detection rules and log analysis tools, essentially security monitoring for the marketplace. This is paranoia in practice: dark web operators know law enforcement will eventually come for them. They want to know if it is happening.

DARKSEARCH Findings: Active Marketplace Examples

On 3 March 2026, our DARKSEARCH crawlers indexed multiple active dark web marketplaces that appear to be running on WooCommerce-derived or Laravel-based marketplace scripts. These instances demonstrate the franchising model in production; despite distinct branding and operator teams, they exhibit common codebase patterns, similar category structures, and compatible payment integration systems.

Active Marketplaces Running Marketplace Scripts

What is notable is the consistency. All three active marketplaces employ shopping cart functionality with escrow integration. All support cryptocurrency payments (BTC, XMR). All feature similar category structures (Hacking, Financial, Documents, Drugs). This suggests they are either running the same underlying script or closely derived variants. The marketplaces exhibit the exact commoditisation we discuss in this report.

The Franchising Effect

This is where the implications get serious for law enforcement and threat intelligence teams. When marketplaces were bespoke, unique codebases built by individual developers, taking one down meant that the operator was out of business. The code was gone. They had to rebuild from scratch or find another coder.

Now? The marketplace operator is fungible. The code is a commodity. When Genesis Market went dark in 2024, the operators could have immediately spun up on a new server using Genesis Market Script v2. Our DARKSEARCH crawlers have identified multiple active marketplace instances that demonstrate this exact pattern: operator churn with code persistence. Tor Amazon operates a full product catalogue with categories identical to known script templates. Tor Market advertises as a direct competitor using what appears to be a variant of the same Laravel architecture. Dark Web World deploys the same WooCommerce-derived payment processing seen across multiple independent operator teams.

So you have a franchising effect. Thirty-five to forty-five distinct marketplaces exist simultaneously, not because there are thirty-five to forty-five independent teams of developers all building competing systems. It is because there are maybe five distinct marketplace scripts in circulation, and each one has six to nine instances running at any given time. When one is seized, a new instance spins up.

This has two consequences. First, the barrier to entry for organised cybercrime has collapsed. You do not need development capability. You need capital and operational security. Second, the value of seizing a marketplace server has diminished dramatically. You disrupt that instance, but the script lives on. The operators of Tor Amazon, Tor Market, and Dark Web World can migrate to new infrastructure using the same marketplace script within days.

Available Marketplace Scripts

Marketplace Infrastructure Costs

Law Enforcement Implications

When law enforcement seizes a dark web marketplace server, they get the data but not the capability to disrupt the script. The script lives elsewhere, in version control, on backup servers, or simply in the brain of the marketplace script vendor.

Consider Genesis Market. It was seized on 2024-06-12 by US law enforcement working with Europol and the UK National Crime Agency. Servers in the US, Europe, and Asia were taken offline. The operator was charged. Hundreds of millions in stolen credentials were recovered. By mid-July, Genesis Market v2 was advertising on dark web forums with enhanced features and improved operational security.

The incident did not eliminate the infrastructure. It merely caused a six-week disruption during which the operator migrated to new hardware, patched known vulnerabilities, and rebranded slightly. The core problem, from law enforcement’s perspective, is that the script outlives any single instance. As we document in our DARKSEARCH data, marketplaces like Tor Amazon and Dark Web World can be deployed and operational within the timeframe needed to capture, examine, and seize a competing marketplace.

This suggests that the real vulnerability is not the marketplaces themselves but the marketplace script vendors. If you can identify and prosecute the developers selling these scripts, you eliminate the supply. If you only go after the marketplace operators, you get Whack-A-Mole. The vendors publishing scripts on dark web forums and registering at addresses like Go Go Onion directory are the true infrastructure.

The other implication is that dark web marketplace operators are increasingly commoditised. You do not need technical sophistication to run a marketplace. You need operational security, capital for hosting and domain registration, and connections to vendors. The technical barrier has effectively been removed.

How SOS Intelligence Tracks This

DARKSEARCH crawls the dark web continuously, indexing pages in a searchable database. We look for storefronts, forums, and marketplaces. When we detect a new marketplace script listing, we add it to a tracking watchlist.

We monitor three things. First, the script itself: which framework it uses, what features it advertises, what the pricing is, and how it has evolved. We track Incognito Market Script from version 1.2 to version 3.1, noting what features were added in each release. Second, the vendors selling the scripts: their reputation, their customers, their support practices, and whether they have ever been compromised or exit scammed. Third, the deployments: which marketplace instances are running which script version and how they behave.

We feed this intelligence into our dark web monitoring products. When a customer signs up for marketplace monitoring, we can identify the script powering that marketplace and predict what features it has based on the version. We can also correlate incidents: if Incognito Market Script v2.8 has a known vulnerability in its escrow handling, we know every instance running that version is vulnerable. Our crawlers match codebase signatures and category structures against known scripts, allowing us to identify which of the active marketplaces documented in this report (Tor Amazon, Tor Market, Dark Web World) are running compatible implementations.

This also lets us track the dark web marketplace ecosystem as a whole. We can measure how many distinct marketplaces exist, estimate their combined transaction volume by analysing blockchain data, and predict disruption likelihood based on how aggressively law enforcement is moving. When a new script is released, we see a spike in new marketplace deployments. When law enforcement takes down a market, we see migration patterns as users flee to competing platforms.

Defensive Perspective

If you are a security team responsible for monitoring dark web activity, you should be tracking marketplace scripts as a matter of course. They are not difficult to find. They advertise openly on dark web forums and marketplaces. Your crawlers can find them.

Once you have a list, you should monitor for three things. One: new script releases and what features they introduce. Two: new marketplace instances and what script they are running. Three: changes in pricing and availability. When marketplace scripts suddenly become cheaper or more feature-rich, it usually means either increased competition or that a major incident has just happened and sellers are trying to capitalise on increased demand from displaced operators.

You should also correlate marketplace incidents with script vulnerabilities. When a marketplace is compromised, check what script it ran and whether other instances of that script are vulnerable to the same attack. When law enforcement takes down a marketplace, check whether the operators released an updated version of their script specifically addressing whatever weakness led to the takedown. Monitor the DARKSEARCH indexed marketplaces for sudden architectural changes or version migrations.

From a threat intelligence perspective, tracking marketplaces via their scripts is far more efficient than tracking them as individual entities. You reduce dozens of distinct monitoring targets to a handful of script families. You can predict behaviour and vulnerability based on the codebase, not on the individual operators running that codebase.

Conclusion

The dark web marketplace economy has industrialised. What used to be bespoke, artisanal criminal enterprises are becoming commoditised services. The marketplace script vendors are the key infrastructure. They have turned marketplace operation into a scalable, reproducible business.

This has implications across the board. For law enforcement, it means seizing a marketplace is a disruption, not elimination. For threat intelligence teams, it means the unit of analysis should be the script, not the instance. For customers relying on dark web monitoring, it means the landscape is more stable and predictable than it appears.

Genesis Market, Silk Road, and the dozens of anonymous marketplaces that come and go each year are not spontaneous eruptions of criminal ingenuity. They are instances of a handful of scripts, each one serving thousands of vendors and millions of buyers. The real architecture is underneath, in the code. Our DARKSEARCH findings confirm that this franchising model is not theoretical; it is observable in real time across active marketplaces like Tor Amazon, Tor Market, and Dark Web World.

  • Genesis Market seizure: FBI Operation Cookie Monster (June 2024); US Department of Justice, Federal Bureau of Investigation, European law enforcement agency coordination.
  • Incognito Market exit scam: March 2024 withdrawal incident; documented in dark web forum discussions and community aftermath analysis.
  • Laravel framework: Open-source PHP web framework; widely used in dark web marketplace development due to established security practices and library ecosystem.
  • Europol Internet Organised Crime Threat Assessment (iOCTA): Annual monitoring of dark web marketplace proliferation, vendor ecosystem, and cross-border criminal networks.
  • UNODC monitoring: United Nations Office on Drugs and Crime; tracking of dark web marketplace proliferation, transaction volumes, and law enforcement takedown impact assessment.
  • XenForo forum platform: Identified at hxxp://bfdxjkv5e2z3ilrifzbnvxxvhbzsj67akjpj3zc6smzr4vv6oz565gyd[.]onion; forum with escrow system, deposit functionality, and account upgrades; community discussion of marketplace scripts and infrastructure.
  • DARKSEARCH API: SOS Intelligence dark web indexing and search service; provides searchable access to indexed marketplace listings, vendor profiles, and script advertisements indexed on 3 March 2026.

Market Place Photo > Photo by Kayle Kaupanger on Unsplash

Technical Photo > Photo by Steve A Johnson on Unsplash

Header Photo > Photo by Rosie Sun on Unsplash

Police Photo > Photo by Michael Förtsch on Unsplash

"Cryptocurrency
Investigation, The Dark Web

Cryptocurrency Fraud Tools: A Dark Web Marketplace Analysis

Introduction

Cryptocurrency has become the preferred currency of the underground. It is fast, pseudonymous, and global. But it is also the target. Between theft, wallet draining, and outright fraud, the crypto space is losing billions every year.

In 2024 alone, wallet drainers stole over $500 million, according to Chainalysis’ 2025 Crypto Crime Report. That is not ransomware victims paying extortion demands. That is not clever social engineering or advanced persistent threats. That is simple, scalable fraud at an industrial scale. And the tools to do it are not hidden behind nation-state firewalls or elite darknet forums. They are on sale on what amounts to the Tor equivalent of Amazon.

SOS Intelligence has been tracking these marketplaces for months. We have documented the tools, the prices, the threat actors, and the money laundering pipelines. This analysis is what we found.

What We Found on DARKSEARCH

DARKSEARCH is one of the larger dark web marketplaces. It functions as a general vendor platform, not unlike eBay, but for illegal goods and services. On it, you can buy access to botnets, stolen data, hacking tutorials, or custom malware. You can also buy cryptocurrency theft tools.

The range of products is striking. These are not theoretical exploits or academic proofs of concept. These are working tools used in active campaigns against real targets. Here is what we documented.

Wallet and Account Theft

The simplest products on sale are stolen wallets. Vendors list wallets with substantial balances, already compromised and ready to be drained. A single listing might contain 599 BTC wallets, with individual wallet values ranging from $42,000 to $59,900 USD at 2024 exchange rates. These are not guesses or projections. These are actual wallets with known, verified balances. On markets like Tor Amazon (tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion), vendors openly advertise wallets with balances verified as of the day of listing.

Atomic Wallet credentials are also available. Atomic is a popular mobile and desktop wallet used by millions of crypto holders. The Atomic Wallet hack of June 2023 resulted in over $35 million in losses attributed to the Lazarus Group, and compromised credentials continue to circulate on dark web markets. Vendors offer compromised Atomic Wallet accounts containing 1 BTC or more, priced around $4,000 per account. The compromise is complete, meaning the original owner has already been locked out.

Beyond full wallets, you can buy seed phrases and private keys. These are the master credentials that unlock a wallet. A Bitcoin seed phrase recovery tool fetches $1,500 to $6,500, depending on the number of target wallets and recovery likelihood.

Password and Passphrase Cracking Tools

Password protection on wallets assumes the password is strong. It usually is not. So vendors offer specialised tools to crack wallet passphrases at scale. A wallet.dat passphrase cracker, which targets the encrypted wallet file format used by Bitcoin Core and older wallet software, sells for around $400. It performs brute force attacks on the passphrase, trying millions of combinations until it finds the correct one.

These tools are not slow. Modern GPU acceleration can test tens of billions of passwords per second. A weak passphrase, or one based on common patterns, will fall in minutes or hours. A strong one might take days. But the attacker does not need to be fast. They can run the crack in the background indefinitely.

Fake Token Senders and Spoofing Tools

One of the most audacious fraud vectors is the fake USDT sender. USDT is Tether, the largest stablecoin in circulation. Someone using a fake USDT sender can create a fraudulent transaction that appears on the blockchain, complete with the correct token contract address, that shows as sent from one wallet to another. To an untrained eye, it looks legitimate. To a crypto exchange or automated system relying on blockchain scans, it might be legitimate.

These tools sell for $300 to $500. They are typically paired with phishing campaigns. A victim receives a message claiming they have won an airdrop, or that a trade executed successfully, and they see the fake USDT in their wallet. When they try to withdraw or sell it, they are prompted to approve a smart contract transaction. At that point, the drainer takes control. Such tools are actively marketed on platforms like Dark Web World (worldyyyi2ktoisdqjjq4zlt3jftejabo443lb67pfofr2i5gqlkaoqd[.]onion), which hosts a Financial Tools category alongside hacking services.

Reverse Transaction Tools

Bitcoin transactions are supposed to be irreversible. That is part of the design. So the idea of a reverse transaction tool sounds like science fiction. But the vendors of these tools are selling something close to it. A BTC Reverse Transaction Tool, priced between $400 and $600, works by finding transactions on the blockchain that have not yet been fully broadcast to all network nodes. The tool allows the attacker to broadcast a conflicting transaction first, causing the original to be rejected by the network. The BTC then flows to the attacker instead.

This only works on a small fraction of transactions. But it is effective enough that people are paying for it. And the demand suggests it is working in practice.

Mnemonic Brute Force Tools

A BTC mnemonic brute tool costs around 690 USD or 550 GBP. It generates or guesses Bitcoin seed phrases and checks them against the blockchain to see if they contain funds. Because seed phrases follow the BIP39 standard, which is deterministic, a brute force attack on the space of possible mnemonics is theoretically feasible. The attacker generates thousands or millions of seed phrases, derives the public addresses from each one, and queries the blockchain for balances. Advanced Hacking Tools (zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion) explicitly lists Cryptocurrency Scam Scripts among its offerings, with 38,530 visits and customer reviews confirming ‘software delivered instantly and fully functional’ and ‘secure transaction and smooth process.’

The computational cost is high. But cloud computing makes it cheap. A determined attacker can lease GPU resources for hours or days at a fraction of a cent per compute hour, making the economics viable for high-probability targets.

Leaked Data and Account Databases

Finally, vendors are selling access to compiled databases of leaked credentials. One listing offers access to 16 billion compromised accounts. The seller claims these are de-duplicated and verified against live services. The price is $121,484. That works out to less than one cent per compromised account. For a cyber criminal running wallet-draining campaigns, this is cheap reconnaissance. They can cross-reference stolen exchange login credentials against wallet addresses to identify holders with known balances. Multivendor platforms like Tor Market (sqw2klzo4mtwvbf3by7irjv7r5mdojxwziuus3lh6rketlkggvsdyaad[.]onion) support both Bitcoin and Monero payments, with dedicated Money Transfer categories facilitating these database sales.

Wallet Drainers as a Service

The real innovation on the dark web is not individual tools. It is the business model. Wallet drainers are offered as a service, DaaS, and it is a lucrative franchise.

How DaaS Works

So the architecture of a wallet drainer is straightforward. The developer publishes a toolkit consisting of a drainer contract (a smart contract deployed on-chain) and a user interface for creating phishing campaigns. A criminal rents the drainer, paying either a flat fee or a percentage of stolen funds. They set up a phishing website that mimics a popular crypto exchange or NFT marketplace. They send phishing links to targets via email, SMS, or social media.

When a victim clicks the link, they see a fake login screen or a fake approval request. If they enter their seed phrase or approve a transaction signature, the drainer gains the ability to control their wallet. The funds are transferred immediately to the attacker’s address. The entire flow from click to theft takes seconds.

The drainer operator keeps a percentage. The drainer developer keeps a percentage. The affiliate who promoted the drainer keeps a percentage. Everyone gets paid. It is a lean, distributed criminal supply chain.

Angel Drainer

Angel Drainer is perhaps the most notorious wallet-drainer family in operation. It is believed to have stolen over $25 million in cryptocurrency. It was active from early 2023 through 2024, and operated as a DaaS offering custom drainer contracts and campaign management tools. ScamSniffer blockchain security research has tracked Angel Drainer operations across multiple victim wallets.

Angel users could log into a dashboard, select their target blockchain, customize their phishing site, and launch their campaign. The drainer provided metrics on click-through rates, approval signatures collected, and stolen funds. It was, in essence, a SaaS offering with a criminal payload. Many law enforcement agencies have attributed wallet drains totalling in the millions of dollars to Angel Drainer operators.

Inferno Drainer

Inferno Drainer is believed to have stolen over $80 million. It operated in parallel with Angel Drainer and was arguably more technically sophisticated. Its phishing interfaces were higher fidelity, its blockchain support was broader, and its operational security was tighter. SlowMist blockchain security research has documented Inferno’s operational patterns across multiple victim reports.

In a striking twist, Inferno Drainer operators were observed transferring stolen funds directly to Angel Drainer wallets in several high-value campaigns. This suggests either a partnership or a buyout. It is unclear if Inferno has exited the market or if operations have simply gone underground or rebranded.

Pink Drainer

Pink Drainer operated more transparently than most. The operator ran an active Telegram channel and took custom contracts and integration requests. Pink is estimated to have commanded 28% market share of the wallet drainer space before exiting in May 2024. By that point, it was believed to have stolen tens of millions of dollars.

The operator announced the exit via a single Telegram message, claiming to be retiring. No law enforcement action was publicly attributed to the exit, suggesting the operator likely had good operational security and may be operating new campaigns under a different name.

Technical Breakdown

Understanding how these tools work requires looking at the mechanics of each attack vector. So let’s walk through them.

Mnemonic Crackers and Brute Force

A Bitcoin seed phrase, or mnemonic, is a sequence of 12, 15, 18, 21, or 24 English words. The words are drawn from the BIP39 word list, which contains exactly 2048 words. This means a 12-word seed phrase represents 2048^12, or roughly 5 x 10^39, possible combinations. That is astronomically large. But it is also finite.

A mnemonic brute force tool does not generate mnemonics randomly. Instead, it uses a wordlist and systematically generates combinations, typically in dictionary order or based on frequency analysis. Each generated mnemonic is used to derive public Bitcoin addresses via the BIP32 standard. The tool then queries a Bitcoin blockchain API or a local blockchain copy to check if those addresses hold funds.

The success rate depends on the blockchain. Bitcoin has around 900 million addresses with at least one transaction. The space of possible mnemonics is enormous, so brute force is impractical for a truly random search. But many users choose weak passphrases or do not add a passphrase at all, and some use common word patterns. Those are the targets.

Cloud GPU providers make the attack economic. For a few dollars an hour, an attacker can spin up instances with NVIDIA H100 GPUs, each capable of deriving and checking thousands of addresses per second. A sustained campaign lasting weeks could check billions of addresses at a marginal cost of fractions of a cent per address checked.

Wallet.dat Password Cracking

Bitcoin Core wallet files are stored in a binary format called wallet.dat. If the wallet is encrypted, the file is encrypted using a passphrase. The passphrase is hashed and used as a key for AES-256 encryption.

A wallet.dat cracker tool first extracts the encrypted private keys from the wallet file. It then performs a dictionary attack, hashing candidate passwords and attempting to decrypt the key material. If decryption succeeds, the tool has recovered the private key and can sign transactions.

The challenge for the attacker is that Bitcoin Core uses key stretching, specifically SHA-512, iterated 100,000 times on the passphrase. This makes brute force slow. Even with GPUs, testing a million passwords against a single wallet takes minutes or hours. But again, modern GPU acceleration and cloud computing make it feasible for high-value targets.

Fake USDT and Token Spoofing

USDT is issued by the Tether company, and on most blockchains, it is implemented as a smart contract. The token contract address is public and well-known. A fake USDT sender exploits this by creating a transaction that mimics a token transfer but is not actually executed on-chain.

The attack works like this: the attacker creates a transaction object that references the correct Tether contract address and shows a fake transfer from one address to another. They do not broadcast it to the blockchain. Instead, they inject it into the victim’s wallet interface or display it in a phishing site as if it had already settled.

When the victim sees the fake token in their wallet, they may attempt to withdraw it or trade it. Most wallets and exchanges check the blockchain for the transaction. But a carefully crafted spoof can appear in the transaction history without being fully confirmed. Victims are then prompted to approve a smart contract transaction to complete the withdrawal or trade. That approval signature is where the drainer takes control.

The trickery is not in the spoofing itself, but in the social engineering that surrounds it. The victim is led to believe they have received free tokens and that they need to take action to claim or access them.

Reverse Bitcoin Transactions

Bitcoin transactions are broadcast to the network and then mined into blocks. Once a transaction is included in a block, it is essentially irreversible. But in the brief window between broadcast and inclusion in a block, a miner or someone with network access can potentially broadcast a conflicting transaction first.

A reverse transaction tool exploits this window. When a victim initiates a high-value transaction, the attacker intercepts the network broadcast or learns of the pending transaction through a mempool monitor. The attacker then constructs a conflicting transaction that sends the same inputs to their own address and broadcasts it to the network with a higher fee.

If the attacker’s transaction is included in a block first, the victim’s original transaction becomes invalid because the inputs have already been spent. The funds flow to the attacker instead. This is sometimes called a mempool race or front-running, and it requires network-level access or partnership with a miner. It is not reliable, but it is effective enough that criminals are paying for it.

Clipboard Hijacking and Browser Injection

A simpler attack vector, but still effective, is clipboard hijacking. Some wallet drainers include code that monitors the victim’s clipboard for wallet addresses. When it detects a Bitcoin or Ethereum address, it replaces it with the attacker’s address.

A user copies a withdrawal address from a trusted source, pastes it into their wallet, and unknowingly sends funds to the attacker instead of their intended destination. The attack is hidden, requires no victim interaction beyond copy-paste, and exploits the assumption that the clipboard is a secure location for temporary data.

Clipboard hijacking is often deployed via browser extensions or by compromising popular wallet software. It is not as profitable as wallet draining, but it is persistent and low effort.

Dark Web Crypto Fraud Markets

Let’s consolidate what we found on dark web marketplaces into a clearer picture.

Wallet Drainer Families and Scale

Wallet drainers are the largest profit engine in crypto fraud. Here is what we know about the major players.

Attack Vectors and Detection Difficulty

Not all crypto fraud is equally easy to defend against. So here is a breakdown of the main attack vectors and how difficult they are to detect.

The Money Laundering Pipeline

Stolen crypto is not useful if the attacker cannot convert it back to cash. So understanding the laundering pipeline is critical to understanding the full economic model of crypto fraud.

Mixing and Tumblers

The simplest laundering step is a mixer, also called a tumbler. A mixer is a service that pools coins from multiple users and then redistributes them in ways that break the chain of custody. If I send 1 BTC to a mixer, I do not get the same 1 BTC back. I get 1 BTC that came from someone else’s deposit.

Mixers are sometimes voluntary services that users employ to protect their privacy. But in the context of stolen funds, they are money laundering tools. Law enforcement has been cracking down on mixing services, but many still operate, especially on the dark web.

Swap Services and Atomic Swaps

Another approach is to convert Bitcoin to a different cryptocurrency that has stronger privacy properties. We found references to swap services running on Tor, such as swp.cx, which claim to execute cryptographic atomic swaps between Bitcoin and Monero without requiring custody of the funds.

The attacker sends BTC to the service, which then sends Monero back to the attacker. Monero is pseudo-anonymous and much harder to trace on the blockchain. From there, the attacker can convert to other coins or cash out to fiat via less-regulated exchanges.

Privacy Coins

Privacy coins like Monero use ring signatures and stealth addresses to obscure the sender, receiver, and transaction amount on the blockchain. A transaction in Monero cannot be traced by following the chain of public addresses. This makes Monero the preferred destination for stolen BTC.

The conversion happens on a swap service or exchange. The attacker loses a small percentage to fees and exchange rates, but gains plausible deniability. Once in Monero, the funds are effectively invisible to on-chain analysis.

Chain Hopping and OTC Markets

The most sophisticated attackers use chain hopping: moving stolen funds across multiple blockchains and currencies before cashing out. Bitcoin to Ethereum to Monero to a stablecoin to a privacy token and back. Each hop adds complexity and expense, but it also significantly increases the cost of forensic analysis.

Finally, the attacker accesses over-the-counter (OTC) brokers, often in countries with weak AML enforcement or corrupt officials. They sell large quantities of crypto for cash, receiving wire transfers to bank accounts in their name or under shell companies. These OTC brokers do not ask difficult questions and are incentivised to facilitate large transactions.

Casino Bonus Exploitation

One lesser-known crypto fraud vector is casino bonus exploitation. Online casinos offer sign-up bonuses to new players: deposit $100, get a $100 bonus. To claim the bonus, you must meet a turnover requirement, usually 30 to 50 times the bonus amount. This is designed to be difficult.

But with access to stolen payment methods and identity documents, a fraudster can create dozens or hundreds of accounts and claim bonuses using different identities. A casino bonus exploitation kit, selling for $150 to $350 on the dark web, automates this process. The kit includes scripts to bypass identity verification, claim bonuses, meet turnover requirements using automated play, and cash out.

The profit margins are high. A $3,000 to $10,000 bonus can be turned into actual cash if the attacker is patient and covers their tracks. The casinos absorb the losses, and usually do not prosecute because of the reputational and legal costs.

Scale of the Problem

To appreciate the scale, consider the raw numbers.

Sixteen billion compromised accounts are for sale on dark web markets. That is more than twice the world population. Many accounts are duplicates across multiple breaches, but the number still represents massive exposure. Any crypto user with an email address used on a commonly breached service is a potential target for credential-based attacks.

Stolen Bitcoin wallets with known balances, in the hundreds or thousands of BTC, are actively listed on the marketplace. These are not speculative. These are wallets that have been compromised and whose balances have been verified.

Wallet-drainer families have collectively stolen $300 million or more in the last two years. Many attacks go unattributed and unreported, especially from users in countries with weak cybercrime reporting infrastructure. The true number is certainly higher.

The tools themselves are cheap. A full-featured drainer costs $100 to $500 per month to rent. A mnemonic cracker is a few hundred dollars. An investment of a few thousand dollars can yield millions in stolen crypto. The economics are favourable for the attacker. They are not.

How SOS Intelligence Monitors Crypto Threats

SOS Intelligence has been monitoring these dark web markets since 2024. Our approach focuses on two core capabilities.

DARKSEARCH Crawling and Indexing

Our DARKSEARCH crawler maintains a running index of major dark web marketplaces, including the venues where crypto fraud tools are sold. We track new tool releases, pricing changes, operator behaviour, and customer feedback. This gives us a real-time view of the threat landscape.

We extract and parse product listings, vendor history, and customer reviews. We track changes in pricing, which often correlate with law enforcement action or shifting market dynamics. When a major drainer family exits or goes dark, we identify the shift early and begin looking for successor operations.

Cryptocurrency Address Monitoring

We also monitor the blockchain itself for known crypto fraud addresses. When a wallet drainer operation is disrupted or a perpetrator is identified, their associated addresses often remain public. We track these addresses for ongoing movement of funds, which can identify new campaigns or money laundering patterns.

By correlating blockchain data with dark web intelligence, we can often connect a phishing campaign to a drainer family, and that family to a money laundering pipeline. This gives our customers early warning before their users are targeted.

Defensive Recommendations

For crypto holders and exchanges, defence is possible. So here is what we recommend.

For Individual Crypto Holders

Use hardware wallets for significant amounts. Hardware wallets store private keys offline and require physical confirmation of transactions. They are resistant to mnemonic cracking, wallet.dat attacks, and phishing.

If you use hot wallets, use strong and unique passphrases. Do not use dictionary words or common patterns. Use a password manager to generate and store passphrases. This makes brute force attacks impractical.

Never approve transactions on suspicious sites or in response to unsolicited messages. Drainers rely on approval signatures. If you do not approve, you do not lose funds.

Monitor your wallet addresses for unauthorised transactions. Set up blockchain monitoring alerts on your addresses. If funds start moving without your action, you can investigate immediately.

Use two-factor authentication on exchange accounts. Many drainers target exchange credentials. MFA, even SMS-based MFA, adds a layer of protection.

For Exchanges and Custodians

Implement withdrawal limits and delays. If a customer’s account is compromised, a withdrawal delay gives the customer time to notice the anomaly and cancel the transaction.

Monitor for suspicious wallet addresses in withdrawals. If a customer is withdrawing to a known drainer address or money laundering service, flag it for review.

Educate users about phishing. Many victims do not realise they have been compromised until weeks after the attack. Clear guidance on how to identify phishing reduces successful attacks.

Implement address whitelisting. Allow customers to whitelist trusted withdrawal addresses and require manual override for new addresses. This blocks many spontaneous account takeovers.

Work with blockchain analysis firms to identify incoming funds from known stolen addresses. Money laundering at scale means some stolen funds flow into honest people’s wallets. Detecting and blocking this upstream reduces the utility of theft.

Conclusion

Cryptocurrency fraud is not a niche problem. It is a $300 million to $500 million per year industry, with efficient, scalable tools and business models. The tools are cheap, the barriers to entry are low, and the margins are enormous.

The most striking finding is not the theft itself, but the industrialisation of fraud. DaaS offerings like Angel Drainer and Inferno Drainer have turned wallet draining into a franchise model. Anyone with a phishing campaign and a few hundred dollars can become a crypto criminal. This scale is what makes the problem so difficult to solve.

Detection is possible but hard. Many attacks leave no blockchain signature. Most attacks are indistinguishable from normal user behaviour. And the speed of the ecosystem means new tools and evasion techniques emerge constantly.

The path forward requires three things. First, better security practices from users. Hardware wallets and strong passphrases are not sexy, but they work. Second, better tooling from exchanges and custodians. Withdrawal limits, address whitelisting, and outgoing transaction monitoring can block many attacks. Third, continued law enforcement and intelligence work to disrupt the most profitable operations.

SOS Intelligence will continue monitoring these threats. We will continue indexing dark web marketplaces and tracking the money laundering pipelines. We will continue alerting our customers when we identify attacks targeted at their users. And we will continue building the tools that make attribution and defence possible.

Appendix: DARKSEARCH Observed Listings

Between February 2026 and March 2026, our DARKSEARCH crawlers observed the following active marketplace listings offering cryptocurrency fraud tools and services. All onion URLs are defanged to prevent accidental access.

External References

This report draws on the following open-source intelligence and blockchain security research:

  • Chainalysis (2025). 2025 Crypto Crime Report. Available at: https://www.chainalysis.com/reports/crypto-crime-report-2025/. Documents wallet drainer losses exceeding $500 million in 2024; tracks drainer family evolution and exit patterns.
  • ScamSniffer (2024-2026). Wallet Drainer Tracking. Available at: https://scamsniffer.io. Real-time tracking of Angel Drainer, Inferno Drainer, and Pink Drainer operational signatures across blockchain transactions.
  • SlowMist (2024-2026). Blockchain Security Research. Available at: https://slowmist.medium.com. Technical analysis of wallet drainer mechanics, transaction patterns, and operational security.
  • Elliptic (2024-2026). Blockchain Analytics Research. Available at: https://www.elliptic.co. Tracks money laundering pipelines, privacy coin conversions, and OTC broker involvement in stolen funds movement.
  • FBI IC3 (2024). Internet Crime Complaint Center – Cryptocurrency Fraud Statistics. Available at: https://ic3.gov. Official statistics on reported cryptocurrency fraud, wallet draining, and wallet compromise cases.
  • Atomic Wallet Security Incident (June 2023). Initial reports and analysis of $35 million hack attributed to Lazarus Group; tracked credential circulation on dark web marketplaces through 2026.
  • MITRE ATT&CK Framework. Cryptocurrency Fraud Tactics. Documents attack patterns including credential dumping (T1005), phishing for information (T1598), and signed script proxy execution (T1216).

Header image by Art Rachen on Unsplash

Wallet by Emil Kalibradov on Unsplash

Drain by Daniel Dan on Unsplash

Casino by Michał Parzuchowski on Unsplash

"SOS
Investigation, Opinion, The Dark Web

Dark Web Services: current Average Prices (2026 Update)

Dark Web Services: current Average Prices (2026 Update)

Introduction

Back in 2022, I published our first deep dive into dark web pricing. At the time, the landscape was already complex, but it was still possible to draw fairly clean lines between the categories of goods and services being traded. Four years on, those lines have blurred considerably.

The underground economy has matured. Prices have shifted, new product categories have emerged, and the operational sophistication of threat actors has increased significantly. Ransomware-as-a-Service is now an established business model. AI-generated phishing kits are being sold alongside traditional credential dumps. Crypto drainers have become a category in their own right. And stealer log subscriptions are now one of the fastest-growing products on the dark web.

13th May 3pm UK Time

Webinar: 2026 Dark Web Pricing Report

For this updated report, we conducted an exhaustive crawl using our own SOS Intelligence DARKSEARCH platform, scanning active dark web marketplaces, forums, and paste sites throughout Q1 2026. We supplemented this with direct marketplace access via Tor and cross-referenced our findings against published industry research from PrivacySharks, DeepStrike, Privacy Affairs, and Trustwave. This time around, we have also expanded our scope significantly, covering narcotics, firearms, counterfeit goods, cryptocurrency fraud tools, and forged documents alongside the traditional cyber-focused categories. The result is what I believe to be one of the most comprehensive snapshots of dark web pricing available today.

So whether you are a security researcher, an MSSP building threat briefings, or a CISO trying to quantify the risk exposure your organisation faces, this should give you a solid, data-backed foundation.

Methodology

Our approach follows the intelligence cycle: direction, collection, processing, analysis, and dissemination. The direction phase was straightforward: understand what is being sold on the dark web in 2026 and at what price points.

For collection, we used the SOS Intelligence API v2 to run targeted keyword searches across our indexed dark web corpus. This includes content from over 50 active marketplaces, forums, paste sites, and Telegram channels. We queried across 20+ distinct product categories, including stolen financial instruments, identity documents, hacking services, malware, access brokers, narcotics (cocaine, heroin, methamphetamine, cannabis, MDMA, and prescription drugs), firearms, counterfeit goods, cryptocurrency fraud tools, and forged documents. We also accessed active Tor marketplaces directly to verify listed prices against real product pages. Key marketplaces analysed include Tor Market, Tor Amazon, Abacus Market, TheBreakingBad, Gun and Shell Factory, and several standalone vendor storefronts.

During processing and analysis, we normalised prices to USD (where vendors listed in EUR, GBP, or cryptocurrency) and calculated averages across multiple vendors where possible. Where a product category had significant variance (for example, initial access pricing can range from $500 to $50,000+), we present the typical range rather than a misleading average.

One thing worth noting: prices on the dark web are not static. They fluctuate based on supply, demand, law enforcement activity, and even seasonal patterns. What we present here is a snapshot, accurate to Q1 2026, and should be treated as indicative rather than definitive.

Stolen Financial Instruments

Financial data remains the bread and butter of dark web commerce. Credit card data, bank account credentials, and payment platform logins continue to dominate marketplace listings. The availability is enormous, driven in large part by the explosion in stealer log infections and large-scale data breaches.

Credit card data with CVV (card-not-present fraud) remains cheap and abundant. A single card with CVV typically sells for $10 to $40, depending on the issuing bank, card type, and associated balance. Cards with higher balances or from premium issuers command a premium. Cloned physical cards with PIN are a different proposition entirely, typically ranging from $100 for a single card with a $2,500 to $3,500 balance, up to $600 for a batch of 10 cards with a combined balance of $33,000 to $35,000.

ProductPrice Range (USD)Source/Notes
Credit card with CVV$10 – $40Per card, card-not-present
Cloned card with PIN (single)$100 – $250$2,500 – $3,500 balance
Cloned cards (batch of 10)$450 – $600$30,000 – $35,000 combined
AMEX Prepaid (EUR 2,500)$105 – $510Price varies by vendor
Bank login (US)$35 – $500Depends on bank and balance
Bank login (UK/EU)$50 – $1,000+Premium for verified accounts
Bank transfer service ($10K)$500Vendor guarantees delivery
PayPal account (verified)$15 – $55Balance $2,500 – $25,000
Crypto exchange account (Kraken)$249Fully verified
Crypto exchange account (general)$90 – $250Coinbase, Binance, etc.

Compared to our 2022 findings, the average price of stolen credit card data has dropped slightly, reflecting oversupply. Bank account credentials, on the other hand, have held steady or increased, particularly for UK and EU accounts where strong customer authentication (SCA) requirements make compromised credentials more valuable to attackers who can bypass these controls.

Identity Documents and Fullz

Fullz, complete identity packages containing name, date of birth, SSN, address, and often more, remain a staple of dark web commerce. The pricing here has been remarkably consistent over the years, which suggests stable supply chains, likely fed by the steady stream of data breaches affecting organisations globally.

Bulk purchasing drives the per-unit cost down significantly. A batch of 1,000 Social Security Numbers was listed on Tor Market at $65. Business fullz (company identity packages with EIN numbers) go for around $95 for a set of 10, which is particularly concerning for organisations worried about business identity theft and fraudulent corporate filings.

ProductPrice Range (USD)Notes
Individual fullz (US)$20 – $100Per identity, includes SSN
SSN batch (1,000 records)$65Bulk purchase, specific regions
Business fullz with EIN (10 pack)$95Corporate identity packages
US passport scan$100Digital copy only
US physical passport (forged)$3,000 – $3,800High-quality forgery
UK driver’s licence (forged)$500Physical document
EU national ID (forged)$300 – $700Varies by country
Medical records$50 – $500+Depends on completeness
Selfie with ID (for KYC bypass)$50 – $100Growing demand

A notable trend in 2026 is the growing market for KYC bypass packages. These typically include a stolen identity paired with a matching selfie (often obtained from stealer logs that capture webcam images), sold specifically to bypass Know Your Customer verification on financial platforms. This is a direct response to tightened identity verification requirements, and it represents an uncomfortable escalation in the identity fraud ecosystem.

DDoS and Hacking Services

DDoS-for-hire remains one of the most accessible attack services on the dark web. Entry-level DDoS attacks can be purchased for as little as $10 per hour, making it trivially cheap for anyone with a grudge and a cryptocurrency wallet. Monthly subscription packages for sustained DDoS capability go up to $850, though most listings cluster around $200 to $500 per month.

Hacking services for hire are more variable in pricing, reflecting the range of complexity involved. Simple social media account compromises sit at the lower end, while corporate network penetration and database extraction commands significantly higher fees.

ServicePrice Range (USD)Notes
DDoS attack (per hour)$10 – $50Basic layer 4/7 attack
DDoS subscription (monthly)$200 – $850Sustained capability
Social media account hack$25 – $100Facebook, Instagram, etc.
Email account compromise$100 – $500Corporate email higher
Website hacking$200 – $3,000Depends on target complexity
Corporate network access$500 – $10,000+Overlaps with IAB market
Phone hacking/spyware install$300 – $1,500Remote installation
Doxing service$25 – $200Varies by depth of research

The DDoS market has become increasingly commoditised. In 2022 we reported an average DDoS service price of around $382. That number has come down, driven by competition between providers and the proliferation of botnet infrastructure. The real concern is not the price itself but how easy it has become to launch these attacks with minimal technical knowledge.

Malware, Exploit Kits, and Phishing

This is where the dark web economy has seen some of its most significant evolution since our last report. The malware-as-a-service model is now firmly established, with vendors offering everything from basic RATs (Remote Access Trojans) through to sophisticated banking trojans and zero-day exploits.

Phishing kits have become particularly interesting. AI-generated phishing templates are now being sold at a premium, with vendors marketing their kits as capable of bypassing modern email security filters. The quality of these templates has improved dramatically, making traditional security awareness training less effective than it was even two years ago.

ProductPrice Range (USD)Notes
RAT (Remote Access Trojan)$45 – $500Off-the-shelf, basic features
Banking trojan$500 – $1,800Targeted at specific banks
Ransomware-as-a-Service kit$500 – $5,000Includes builder and panel
Stealer log subscription$100 – $1,024/moRedline, Raccoon, Vidar
Phishing kit (standard)$50 – $300Includes templates and hosting
Phishing kit (AI-generated)$200 – $800Bypass modern filters
Zero-day exploit (general)$5,000 – $200,000+Price varies enormously
Exploit kit (browser)$100 – $2,000Pre-packaged exploitation
Botnet rental (1,000 bots)$50 – $200/dayFor spam or DDoS
Keylogger$25 – $150Basic to advanced features

The Ransomware-as-a-Service (RaaS) market deserves special attention. Our platform currently tracks over 100 active ransomware groups, many of which operate affiliate programmes where the actual ransomware deployment is carried out by affiliates who pay a percentage (typically 20-30%) of the ransom to the RaaS operator. The barrier to entry for launching a ransomware campaign has never been lower, and this is reflected in the sustained growth of ransomware incidents globally.

Crypto Drainers and Mixers

This is a category that barely existed in 2022 and is now a significant segment of the dark web economy. Crypto drainers are tools designed to empty cryptocurrency wallets, typically deployed via phishing sites that mimic legitimate Web3 platforms and trick users into connecting their wallets and signing malicious transactions.

Our DARKSEARCH data turned up active listings on DNA Forums and other threat actor communities, with prices ranging from $50 for basic tutorials through to $1,000 for fully operational Solana drainer toolkits. The Tron Trap drainer tool was listed at $300, while general-purpose drainer kits sat around $200 to $500.

ProductPrice Range (USD)Notes
Crypto drainer kit (general)$200 – $500Multi-chain support
Solana drainer$1,000Chain-specific tooling
Tron Trap drainer$300Listed on DNA Forums
Crypto drainer tutorial$50 – $100DIY approach
Crypto mixing/tumbling service1-3% of amountPer transaction fee
Crypto cashout service15-25% of amountConversion to fiat

The emergence of drainer-as-a-service mirrors the RaaS model. Operators provide the tooling and infrastructure, affiliates drive traffic to phishing sites, and profits are split. Some drainer operators take a 20-30% cut of every wallet drained. For context, wallet drainer attacks stole hundreds of millions of dollars in cryptocurrency during 2025 alone, making this one of the highest-growth criminal sectors.

Initial Access Brokers

Initial Access Brokers (IABs) continue to be a critical part of the threat landscape. These are threat actors who specialise in gaining access to corporate networks and then selling that access to other criminals, typically ransomware operators. The IAB market is essentially the supply chain for ransomware.

Pricing varies enormously based on the target organisation’s size, industry, and the type of access being sold. VPN credentials for a small company might go for $500, while domain admin access to a large enterprise can command $10,000 or more. Our 2022 report found an average of around $7,700 for initial network access. In 2026, the range has widened as the market has matured, but the median sits around $2,000 to $5,000 for mid-market targets.

Access TypePrice Range (USD)Notes
VPN credentials (SME)$200 – $1,000Single organisation
RDP access (dedicated server)$10 – $100Commodity pricing
Domain admin (enterprise)$5,000 – $50,000+High-value targets
Web shell access$50 – $500Depends on target
cPanel/hosting access$10 – $50Bulk available
Database access (customer data)$500 – $10,000Depends on record count
Cloud infrastructure access$1,000 – $20,000AWS, Azure, GCP

Cloud infrastructure access is the emerging high-value category here. As organisations continue their migration to cloud platforms, compromised cloud credentials have become increasingly sought after. A set of AWS root account credentials for an enterprise can be worth significantly more than traditional on-premise network access, reflecting the potential blast radius of a cloud compromise.

Stolen Accounts and Subscriptions

The market for compromised online accounts remains massive, covering everything from streaming services to social media to gaming platforms. These are largely driven by credential stuffing attacks leveraging the billions of username/password pairs available from historical breaches, combined with the output of stealer log infections.

Account TypePrice Range (USD)Notes
Netflix/Disney+/streaming$4 – $25Per account, often shared
Spotify Premium$3 – $10Bulk available
Facebook account$25 – $45Higher for aged accounts
Instagram account$25 – $45Followers affect price
LinkedIn Premium$30 – $50Professional accounts
Gaming accounts (Steam, Epic)$10 – $100Game library affects price
Food delivery (Uber Eats, etc.)$5 – $20With stored payment
Email accounts (bulk)$2 – $10Per account
VPN service accounts$5 – $15NordVPN, ExpressVPN, etc.

What strikes me about this category is how cheap everything is. A Netflix account for $4, a Facebook account for $25. The low prices reflect the sheer volume of compromised credentials available. For most consumers, the inconvenience of having an account compromised is minor. But for organisations, compromised employee accounts, particularly email and LinkedIn, can be the starting point for targeted social engineering campaigns.

Counterfeit Currency and Documents

Counterfeit physical currency continues to be traded, though the market has evolved. Our crawl of Robinhood Market found fake Euro banknotes listed from $300 for a small batch up to $1,200 for larger quantities. Western Union transfer services were listed at $200 for a $2,000 transfer, representing a 10% fee.

Bank cheque templates have also become a notable category, with templates available from as little as $5 for basic designs up to $600 for comprehensive kits that include matching security features and printing instructions.

ProductPrice Range (USD)Notes
Counterfeit EUR banknotes$300 – $1,200Various denominations
Counterfeit USD banknotes$350 – $1,500Quality varies significantly
Western Union transfer ($2,000)$20010% fee structure
MoneyGram transfer$150 – $300Similar fee structure
Bank cheque templates$5 – $600Including security features
Counterfeit branded goods (guides)$20 – $200Manufacturing instructions

In our 2022 report, counterfeit currency averaged around $396 per $1,000 face value. The current rates are broadly similar, suggesting this market has reached a stable equilibrium. The real shift is towards digital fraud, with physical counterfeiting becoming a smaller proportion of overall dark web commerce.

Proxy and Hosting Infrastructure

Bulletproof hosting and residential proxy services continue to be essential infrastructure for cybercriminal operations. These services provide the anonymous, abuse-tolerant hosting that enables everything from phishing campaigns to command and control servers.

ServicePrice Range (USD)Notes
Bulletproof hosting (monthly)$50 – $500Abuse-tolerant, offshore
Residential proxy (monthly)$200 – $645Pool of residential IPs
SOCKS5 proxy (per IP)$1 – $10Single use or short-lived
VPN service (criminal-oriented)$5 – $30/moNo-log guarantees
Dedicated server (offshore)$100 – $400/moFull admin access
Domain + hosting bundle$20 – $100For phishing campaigns

Residential proxy pricing has actually increased since 2022, when we reported an average of $645 per month. The current range starts lower but premium services now charge more, reflecting growing demand from threat actors who need residential IP addresses to bypass fraud detection systems and CAPTCHAs.

AI-Enabled Criminal Services

This is entirely new territory since our 2022 report. The commoditisation of large language models has created a new category of criminal tooling that simply did not exist four years ago. Dark web forums now host discussions and sales of jailbroken AI models, custom-trained chatbots for social engineering, and AI-powered tools for generating convincing phishing content at scale.

While we did not find as many standardised price points for AI services as for other categories (the market is still maturing), the trend is clear. AI is being integrated into existing criminal workflows, particularly around social engineering, phishing content generation, and code development for malware. Some vendors are marketing “FraudGPT” and “WormGPT” style tools, essentially LLM wrappers with the safety guardrails removed, at subscription prices of $200 to $1,700 per month.

The implications here are significant. AI lowers the barrier to entry for technically unsophisticated threat actors, increases the quality and scale of social engineering attacks, and makes it harder for defenders to distinguish malicious content from legitimate communications.

Narcotics and Controlled Substances

Dark web drug marketplaces remain one of the most active sectors of the underground economy. Our DARKSEARCH crawls in Q1 2026 revealed multiple operational marketplaces with extensive product catalogues, professional vendor storefronts, and established escrow systems. The sophistication of these operations is notable: vendor pages include lab-testing claims, customer reviews, volume discount tiers, and next-day delivery (NDD) options for domestic shipments.

Three marketplaces stood out during our research. TheBreakingBad, a dedicated vendor storefront operating with a full e-commerce style interface, offered a comprehensive catalogue of stimulants, opiates, and dissociatives with granular volume pricing. Abacus Market, a multi-vendor marketplace, carried similar inventory with slightly different pricing. Tor Market, which operates as a broader multi-category darknet marketplace (also listing firearms, documents, and hacking tools), hosted 47 drug products across multiple vendors at the time of our crawl.

Stimulants

Cocaine remains the most commonly listed stimulant. Colombian cocaine claiming 94%+ purity was available across multiple markets. Crystal methamphetamine was the second most prevalent stimulant listing, with a notably well-developed volume pricing structure from European vendors. Amphetamine paste, particularly popular on European markets, was available in both standard (74%) and premium (94%) purity grades.

ProductPrice RangeVolume PricingSource Market
Colombian Cocaine 94%+$50 – $80/gBulk from $35/g at 100g+Tor Market, Abacus
Crystal Meth 94% (Mexican)€10/g€80/10g, €700/100g, €5,500/kgTheBreakingBad
Crystal Meth (ICE)$99/10g$249/25g, $1,000/100gAbacus Market
Speed Amphetamine 94%€22/10g€90/100g, €700/kgTheBreakingBad
Speed Amphetamine 74%€10/10g€77/100g, €555/kgTheBreakingBad
3-MMC (Metaphedrone)€10/g€350/100g, €3,000/kgTheBreakingBad
MDMA Champagne 84%+$6.50 – $18/g$8/g at 250g bulkAbacus Market
XTC Pills 250mg MDMA€12.50/10 pills€80/100, €750/1,000 pillsTheBreakingBad
XTC Pills (240mg, various)$135 – $200/10 pillsMultiple brands availableTor Market

Opiates and Opioids

Heroin remained available from specialist vendors, with Iranian-sourced uncut product marketed as the premium option. The pricing structure on TheBreakingBad was particularly detailed, offering nine quantity tiers from a single gram to a full kilogram. This level of volume pricing suggests these vendors are servicing both individual users and mid-level distributors.

Prescription opioids also featured prominently. Oxycontin (40mg tablets) and Percocet (5/325mg) were listed on Tor Market, though exact per-unit pricing was often obscured behind “add to cart” interfaces that required account creation to view.

ProductPrice RangeVolume PricingSource Market
Heroin Uncut (Iranian)€22.50/g€175/10g, €1,600/100g, €13,500/kgTheBreakingBad
Heroin #3 (60-70%)$50 – $55/3gMid-grade, EU sourcedTor Market
Oxycontin 40mg (20ct)$120 – $200Prescription tabsTor Market
Percocet 5/325mg (70ct)$150 – $250Price per bottle est.Tor Market
Fentanyl patches/pills$50 – $150Limited listings (high risk)Various

Cannabis

Cannabis products dominated by volume of listings. UK-based vendors advertised next-day delivery (NDD) on multiple strains, essentially running a delivery service comparable to legitimate e-commerce. Listings included premium strains such as OG Cookies, Super Silver Haze, Gorilla Glue, and Amnesia Haze, with clear quantity tiers.

ProductPrice RangeVolume/NotesSource Market
Gorilla Glue (7g)£42 (~$53)UK NDD availableAbacus Market
OG Cookies (various)$50 – $120/quarterMultiple vendorsTor Market
Amnesia Haze (100g)$400 – $600Bulk listingAbacus Market
Super Silver Haze$35 – $80/quarterDutch sourcedTor Market
Cannabis (French market)Varies192 products listedFR marketplace

Psychedelics and Dissociatives

The psychedelics market showed strong activity, with psilocybin products packaged in consumer-friendly formats (chocolate edibles, microdose capsules) and ketamine available from multiple vendors. LSD pricing was harder to pin down through DARKSEARCH alone, but cross-referencing with forum discussions suggests typical street-equivalent pricing in the $5 to $15 per tab range.

ProductPrice RangeNotesSource Market
Psilocybin Chocolate (4g)$40Consumer-packaged edibleTor Market
Psilocybin Capsules 150mg (x100)$80 – $150Microdose formatTor Market
Ketamine S-Isomer€10/g€175/50g, €1,850/kgTheBreakingBad
LSD Tabs$5 – $15/tabForum pricing cross-refMultiple
XTC/MDMA (ecstasy, various)€12.50 – $200/10 pillsBrand-dependent pricingMultiple markets

Prescription Pharmaceuticals

Beyond controlled opioids, a range of prescription medications was available. Benzodiazepines (particularly Xanax and Rivotril) were listed at a fraction of pharmacy prices. Erectile dysfunction medications (Cialis) appeared as bulk listings, likely diverted or counterfeit product.

ProductPrice RangeNotesSource Market
Xanax 2mg (50 pills)€5 – €25Alprazolam, likely pressedAbacus Market
Rivotril 2mg (20 pills)$15 – $40ClonazepamTor Market
Cialis (50 tabs)$120 – $200Bulk pack, likely generic/counterfeitTor Market

The drug marketplace in 2026 functions like a professional retail operation. Escrow, customer reviews, volume discounts, refund policies, and domestic stealth shipping are standard. The operational maturity here mirrors what we have seen in the cyber services space, with vendor reputation systems driving quality competition.

Firearms and Ammunition

Firearms remain one of the most sensitive categories on the dark web. Our DARKSEARCH queries returned listings from multiple sources, including a dedicated storefront called “Gun and Shell Factory” and the firearms category on Tor Market (which carried 10 products at the time of our crawl). A vendor called “GlockZ” was also active with 7 listed products.

It is worth noting that firearms sales on the dark web carry the highest scam risk of any category. Law enforcement honeypot operations are well-documented in this space, and many “vendors” simply take payment and never deliver. That said, the listings themselves are informative for understanding what threat actors believe constitutes a reasonable market price, and the availability of these listings is itself a data point worth tracking.

Handguns

FirearmListed Price (USD)CalibreSource
Glock 17 Gen 4$4999mmTor Market
Glock 19$4509mmGun and Shell Factory
Glock 26$3509mmGun and Shell Factory
SIG Sauer P320$6009mmGun and Shell Factory
SIG Sauer P220$680 (sale from $800).45 ACPTor Market
Desert Eagle$899 (sale from $1,000).44 MagnumTor Market
Beretta M9$2499mmTor Market
Ed Brown Kobra$499.45 ACPGun and Shell Factory
CZ TS 2$8999mmGun and Shell Factory

Long Guns and Submachine Guns

FirearmListed Price (USD)TypeSource
AK-47$800 – $1,200Assault RifleGun and Shell Factory
AR-15$700 – $1,000Semi-Auto RifleGun and Shell Factory
UZI Pro$740Submachine GunGun and Shell Factory

Ammunition was also listed separately, though pricing data was less granular in our crawl results. The presence of both firearms and ammunition on the same marketplaces that sell drugs, stolen data, and hacking tools underscores the breadth of these platforms. Tor Market, for instance, carries categories for Counterfeits, Credit Card/CVV/Dumps, Documents, Drugs (47 products), Firearms and Ammo (10 products), Gadgets, and Hacking (13 products), all under one marketplace roof.

Compared to legitimate retail prices, dark web firearms are generally listed at a discount of 30% to 60% from retail, which reflects the risk premium inverted: buyers on the dark web are willing to pay less because of the high risk of scam, non-delivery, or law enforcement interception. From a threat intelligence perspective, the persistence of these listings indicates ongoing demand from individuals who cannot or will not purchase through legitimate channels.

Expanded Counterfeit and Fraud Services

Beyond the identity documents and financial instruments covered earlier, the dark web hosts a broader ecosystem of counterfeit goods and fraud services. Our expanded DARKSEARCH crawl revealed categories including counterfeit luxury goods, forged academic credentials, cryptocurrency fraud tools, and casino bonus exploitation kits.

Counterfeit Luxury Goods
Tor Market listed counterfeit luxury watches, with a Rolex Submariner Non-Date 41mm (model 124060) featured as a promoted product. Counterfeit luxury goods have historically been a smaller dark web category compared to clearnet operations, but their presence on multi-category darknet marketplaces suggests vendors are expanding their offerings to capture cross-selling opportunities from buyers already on the platform for other products.

Cryptocurrency Fraud Tools

Cryptocurrency fraud tools were among the most expensive single-item listings we encountered. The “Tor Amazon” marketplace (operating since 2019) offered an extensive catalogue including stolen Bitcoin wallets, fake USDT senders, wallet cracking tools, and compromised exchange accounts. The pricing here is particularly instructive.

ProductPrice (USD)DetailsSource
Stolen BTC Wallet (599 BTC)$42,000 – $59,900Priced at ~0.1% of wallet balanceTor Amazon
Atomic Wallet 1BTC+$4,000Pre-loaded compromised walletTor Amazon
Bitcoin Wallet w/ Seeds$1,500 – $6,500Wallet.dat with passphraseTor Amazon
Wallet.dat Passphrase Cracker$400Brute-force toolTor Amazon
Flash/Fake USDT Sender$300 – $500Spoofed transactionsTor Amazon
BTC Mnemonic Brute Tool£550 (~$690)12-phrase wallet crackerStandalone store
BTC Reverse Transaction Tool$400 – $600Transaction reversal exploitStandalone store
Leaked Data (16B accounts)$121,484Apple, Google, Binance etc.Tor Amazon

Financial Fraud and Money Movement

The money movement ecosystem on the dark web continues to grow. Services for laundering funds through compromised payment platforms, cloned cards, and bank transfer services were widely available. The Tor Amazon marketplace offered ATM-cloned cards with guaranteed balances, stolen Visa CC/CVV data, Binance account transfers, PayPal-to-Bitcoin conversion services, and casino bonus exploitation kits.

ProductPrice (USD)DetailsSource
ATM Cloned Card ($15K balance)$900Physical card, PIN includedTor Amazon
VISA CC/CVV ($8K balance)$400Virtual card with full detailsTor Amazon
PayPal $7K Verified Transfer$600 (sale from $700)Within 20 minutes worldwideTor Market
Visa Prepaid Clone ($7.5K)$630 (sale from $750)Physical + online usableTor Market
Binance Account Transfer$300 – $500BTC/ETH/USDT transfersTor Amazon
Paxful Accounts ($5.5K)$250 – $400Guaranteed balanceTor Amazon
Casino Bonus Exploit$150 – $350$3K-$10K bonus exploitationTor Amazon
Bank Flash SQR Tool$800 (sale from $1,500)Bank manipulation softwareTor Amazon
Aviator Predictor Hack AI$400Casino/gambling exploit toolTor Amazon
Gold Bars 100g (Pre-Owned)$8,500Physical delivery, escrowTor Amazon

Forged Documents and Credentials

Forged documents ranged from academic credentials (diplomas, degrees, professional certificates) to government-issued identity documents. Tor Market listed a dedicated Documents category with 4 products, while Tor Amazon carried a broader selection under their Documents department. The “USA Documents” product on Tor Amazon was rated 4.85 out of 5 and priced between $600 and $3,500, covering various forms of US identification.

ProductPrice Range (USD)NotesSource
USA Identity Documents (ID Card)$600 – $3,500Multiple ID types availableTor Amazon
Forged Diploma/Degree$200 – $800Various institutionsMultiple markets
Professional Certificates$150 – $500IT, medical, trade certsMultiple markets
Counterfeit COVID Certificates$50 – $150Declining demandForum listings
Deepfake Service$100 – $500Video/image manipulationTor directories

The breadth of these offerings paints a picture of a mature underground economy that mirrors, and in some ways parodies, legitimate commerce. Marketplaces offer escrow protection, customer reviews, vendor ratings, return policies, and even promotional sales events. Tor Amazon, for example, displays a running shopping cart total (one snapshot showed a cart worth $154,514), tracks “verified sellers” with sales counts, and runs sale pricing on multiple products. This operational maturity makes these platforms resilient and, from a threat intelligence perspective, worth continuous monitoring.

Pricing Comparison: 2022 vs 2026

The table below compares our 2022 findings with the current 2026 data across key categories. Prices are typical midpoint values.

Category2022 Average2026 AverageTrend
Credit card with CVV$243$15 – $40Decreased (oversupply)
Counterfeit currency (per $1K)$396$350 – $450Stable
DDoS service (monthly)$382$200 – $500Decreased (commoditised)
Residential proxy (monthly)$645$200 – $645Wider range, lower entry
Initial network access$7,700$2,000 – $5,000Decreased (median)
Ransomware kitN/A$500 – $5,000New category tracked
Crypto drainer kitN/A$200 – $1,000New category
Stealer log subscriptionN/A$100 – $1,024/moNew category
AI criminal toolsN/A$200 – $1,700/moNew category
Cocaine (per gram)$150 – $300$50 – $80Decreased (dark web discount)
Crystal Meth (per gram)$50 – $100$10 – $15Decreased significantly
Heroin (per gram)$100 – $200$22 – $55Decreased (direct sourcing)
Handgun (Glock 17)$1,500 – $2,500$450 – $500Decreased (high scam risk)
Stolen BTC WalletN/A$4,000 – $59,900New category
Forged ID Documents (US)$250 – $1,000$600 – $3,500Increased (quality premium)

The overarching trend is clear: established product categories have become cheaper as supply has increased, while new, more sophisticated offerings (RaaS, drainers, AI tools) have emerged at premium price points. The dark web economy is following the same pattern as legitimate tech markets, with commodity products racing to the bottom while innovation commands a premium.

Key Takeaways

The barrier to entry keeps falling. DDoS attacks for $10, phishing kits for $50, stolen accounts for a few dollars. The tools for cybercrime are cheaper and more accessible than ever. This has direct implications for the volume of attacks organisations should expect to face.

Stealer logs are the new oil. The stealer log economy has grown enormously. These logs, harvested from malware infections on individual machines, contain browser-saved passwords, session cookies, crypto wallet data, and more. They feed almost every other category: account takeover, initial access brokering, financial fraud, and identity theft.

Ransomware is a mature industry. With over 100 active groups tracked on our platform and well-established affiliate models, ransomware has moved from being an emerging threat to a structural feature of the threat landscape. The supply chain (IABs to RaaS operators to affiliates to money launderers) is well-oiled and efficient.

AI is an accelerant. While AI has not yet created fundamentally new attack types, it is making existing attacks more effective, more scalable, and more convincing. The appearance of AI-enabled tools as a distinct product category on the dark web is a development every security team should be tracking.

Crypto is the preferred battlefield. The emergence of crypto drainers as a major product category, combined with the growth in compromised exchange accounts, tells us that cryptocurrency users and platforms are now firmly in the crosshairs. The pseudonymous nature of crypto transactions makes this an attractive and growing target.

Drug marketplaces operate like professional retailers. The dark web drug economy has reached a level of operational maturity that mirrors legitimate e-commerce. Escrow, customer reviews, next-day delivery, volume discounts, lab-testing claims, and refund policies are now standard. Prices have dropped significantly compared to street equivalents, reflecting the efficiency of direct vendor-to-buyer models that bypass traditional distribution chains.

Firearms listings persist despite high scam risk. While firearms are consistently available on dark web marketplaces, this category carries the highest scam risk and is a known target for law enforcement honeypot operations. The listed prices (30% to 60% below retail) reflect this risk. The intelligence value here is less about the prices themselves and more about the persistent demand signal from individuals seeking to acquire weapons outside regulated channels.

The dark web is a one-stop shop. Multi-category marketplaces like Tor Market (drugs, firearms, counterfeits, hacking tools, documents, and financial fraud under one roof) and Tor Amazon (hacking, financial, electronics, documents, drugs, and guns) demonstrate that the underground economy has consolidated. A single marketplace visit can service everything from identity theft to substance procurement to weapon acquisition. This consolidation has implications for law enforcement, intelligence analysts, and risk modelling.

Don’t miss out!

Webinar: 2026 Dark Web Pricing Report

Conclusion

The dark web economy in 2026 is bigger, more diverse, and more sophisticated than it was in 2022. Prices for commodity products have dropped while new, higher-value categories have emerged. The professionalism of threat actors continues to increase, with customer support, affiliate programmes, and quality guarantees now standard across many marketplaces.

What has changed most since our 2022 report is the breadth. The dark web is no longer just a marketplace for stolen data and hacking tools. It is a fully integrated underground economy spanning narcotics, firearms, counterfeit goods, identity documents, cryptocurrency fraud, and digital services. Multi-category marketplaces have consolidated these offerings under single platforms, complete with escrow systems, vendor ratings, and promotional campaigns that would not look out of place on a legitimate e-commerce site.

For defenders and intelligence professionals, the key takeaway is that the cost of attacking your organisation, or acquiring the tools to do so, is low and getting lower. The investment needed to mount a credible phishing campaign, launch a DDoS attack, purchase a weapon, or obtain fraudulent identity documents is trivial compared to the potential payoff. This asymmetry is the fundamental challenge, and understanding the economics of the dark web is essential to building effective defences and informing policy.

At SOS Intelligence, we monitor these marketplaces continuously so our customers do not have to. Our DARKSEARCH platform indexes content across 50+ active dark web sources, and our analysts track emerging threats, new marketplace activity, and pricing trends in real time. If you want to understand what is being said about your organisation on the dark web, or if you need intelligence on any of the categories covered in this report, our platform gives you that visibility.

Passport photo by Kit (formerly ConvertKit) on Unsplash

Crypto Photo by Pierre Borthiry – Peiobty on Unsplash

Drugs photo by Colin Davis on Unsplash

Money hoto by Dmytro Glazunov on Unsplash

Gun photo by Tom Def on Unsplash

"Combo-Squatting
SOS Intelligence Webinar

Webinar – Combo-Squatting & Homograph Attacks: Protecting Your Brand from Lookalike Domains

Our latest webinar is ready to go and you can join us on Wednesday October 8th at 4pm UK time.

The topic is Combo-Squatting & Homograph Attacks: Protecting Your Brand from Lookalike Domains and we are seeing this more and more.

Learn:

  • The difference between typosquatting, combo-squatting, and homograph attacks.
  • See how attackers exploit keywords and Unicode tricks to impersonate trusted brands.
  • Discover real-world examples of phishing and fraud campaigns.
  • Explore practical detection and defence strategies.
  • Find out how SOS Intelligence can monitor, alert, and assist with takedowns to protect your brand.

Sign up takes seconds and you will get sent a link of the recording regardless of attendance so well worth signing up now!

"Understanding
Investigation, Opinion

Understanding SCATTERED SPIDER: Tactics, Targets, and Defence Strategies

In recent months, a wave of disruptive cyberattacks has swept across high-profile organisations in both the UK and the US, affecting sectors ranging from hospitality and telecommunications to finance and retail. Many of these incidents share a common thread: attribution to a threat actor known as SCATTERED SPIDER, a group now gaining notoriety for its aggressive use of social engineering and its partnership with the DragonForce ransomware-as-a-service (RaaS) operation.

Unlike traditional ransomware gangs that rely heavily on technical exploits or brute-force tactics, SCATTERED SPIDER stands out for its deeply manipulative approach. The group has repeatedly demonstrated its ability to impersonate employees, deceive IT support teams, and bypass multi-factor authentication (MFA) through cunning psychological tactics. Often described as “native English speakers,” they are suspected to operate in or have ties to Western countries, bringing a cultural fluency that makes their phishing and phone-based attacks alarmingly effective.

As law enforcement and cybersecurity professionals scramble to contain the fallout from recent attacks, one thing is clear: SCATTERED SPIDER is not just another ransomware affiliate. They represent a shift toward human-centric intrusion strategies, blending technical skill with social deception in a way that challenges even well-defended organisations.

This article takes a closer look at how SCATTERED SPIDER operates, the tools they use, including DragonForce RaaS and, most importantly, what practical steps individuals and organisations can take to reduce their exposure to this growing threat.

Image Credit: Crowdstrike

Who Is SCATTERED SPIDER?

SCATTERED SPIDER is the name given to a loosely affiliated cybercriminal group that has quickly gained attention for its highly targeted and persistent campaigns against major organisations. Believed to be active since at least 2022, the group is often classified as an Initial Access Broker (IAB) and affiliate actor, working both independently and in partnership with larger ransomware collectives, most notably the ALPHV/BlackCat operation.

What sets SCATTERED SPIDER apart is not just its technical acumen, but its expert use of social engineering, often executed in fluent English and with a level of cultural familiarity that suggests the group is likely based in or has strong ties to the US or UK. Unlike many ransomware actors operating out of Eastern Europe or Russia, SCATTERED SPIDER’s tactics are tailored to Western corporate environments, allowing them to convincingly impersonate staff, manipulate helpdesk personnel, and bypass traditional security barriers with unnerving ease.

The group’s motivation is primarily financial, but their techniques are unusually aggressive. Rather than simply deploying ransomware after gaining access, SCATTERED SPIDER takes the time to navigate internal systems, escalate privileges, and exfiltrate data, ensuring maximum impact and leverage during extortion. This has included threats to publicly leak sensitive data if ransoms aren’t paid, a tactic made easier by their ties to DragonForce RaaS, a ransomware service that offers data leak platforms and other tools to affiliates.

Notable incidents attributed to SCATTERED SPIDER include:

  • The 2023 attack on MGM Resorts, which saw large-scale IT disruption across casinos and hotels in the US, was reportedly caused by a simple phone-based social engineering ploy.
  • Intrusions into telecommunications and managed service providers, where they have targeted identity infrastructure such as Okta and Active Directory to pivot across networks.
  • Disruption and data theft in the financial and insurance sectors, where highly sensitive customer and operational data were exfiltrated and held to ransom.

These campaigns reveal a group that is not only technically capable but strategically manipulative, leveraging trust, urgency, and insider knowledge to achieve access that many automated tools would struggle to obtain.

The Tools of the Trade: DragonForce RaaS

One of the key enablers of SCATTERED SPIDER’s recent success has been their alignment with DragonForce, a relatively new entrant in the expanding Ransomware-as-a-Service (RaaS) ecosystem. RaaS models have radically altered the cybercrime landscape. Much like SaaS (Software-as-a-Service) in the legitimate tech world, RaaS lowers the barrier to entry for less technically capable threat actors by offering turnkey ransomware toolkits, user-friendly dashboards, and profit-sharing agreements between developers and affiliates.

What Is DragonForce?

DragonForce is a commercially operated ransomware platform, complete with a slick user interface, customer “support” channels, and marketing-style updates promoting new features and obfuscation techniques. While it may not yet have the brand recognition of LockBit or BlackCat, it is gaining traction among cybercriminal groups for its reliability, speed, and aggressive encryption routines.

Its offerings typically include:

  • Highly customisable payloads: Affiliates like SCATTERED SPIDER can tweak encryption settings, file extensions, and ransom notes to suit their targets.
  • Data exfiltration modules: These facilitate double extortion, where files are stolen before encryption and used as additional leverage during ransom negotiations.
  • Dark Web leak portals: Victim data is published or threatened with publication unless payment is made.
  • Access to a central control panel: Affiliates can monitor infected machines, initiate encryption manually, and track ransom payments via cryptocurrency wallets.

These features allow threat actors to operate more like cybercrime startups than ad-hoc hacking collectives.

Why SCATTERED SPIDER Uses DragonForce

SCATTERED SPIDER’s strength lies in gaining initial access, often via phone-based social engineering or SIM-swapping tactics, rather than building their own ransomware from scratch. By outsourcing encryption and extortion capabilities to a RaaS provider like DragonForce, they focus on what they do best: manipulating people, navigating corporate networks, and extracting sensitive data.

In this partnership, DragonForce gains a capable affiliate who can deliver high-value access, and SCATTERED SPIDER gains a ready-made suite of tools to monetise their intrusions. This division of labour reflects a broader shift in cybercrime, one where specialisation and scalability are the name of the game.

DragonForce and the RaaS Economy

It’s important to understand that DragonForce is not an isolated actor. It is part of a wider criminal ecosystem where:

  • Access brokers sell stolen credentials or remote access.
  • Malware developers lease out payloads to trusted affiliates.
  • Negotiators and money launderers offer “aftercare” services.

This ecosystem enables threat actors to operate like businesses, complete with hierarchical roles, profit-sharing models, and even internal dispute resolution mechanisms. In this context, SCATTERED SPIDER is not just a lone wolf but a well-placed operator within a highly coordinated cybercrime supply chain.

Why This Matters

The use of DragonForce by SCATTERED SPIDER highlights two alarming trends:

  1. Professionalisation of ransomware: You no longer need deep technical knowledge to execute devastating attacks; just access, confidence, and a few phone calls.
  2. Faster time-to-impact: With everything from encryption to extortion automated and streamlined, the time between compromise and ransom demand is shrinking rapidly, leaving organisations with little time to detect and respond.

As DragonForce continues to evolve and attract new affiliates, we are likely to see more actors adopt this model of rapid-access, rapid-extortion ransomware operations.

Image Credit: Kaspersky

Anatomy of an Attack: How SCATTERED SPIDER Operates

Understanding how SCATTERED SPIDER executes its attacks is crucial for organisations looking to strengthen their defences. Unlike many ransomware operators who rely on brute-force tactics or mass phishing campaigns, SCATTERED SPIDER favours precision, patience, and psychological manipulation.

Here’s a typical flow of operations observed in their campaigns:

1. Reconnaissance and Target Selection

The group begins by identifying high-value targets, often large enterprises in sectors such as telecommunications, financial services, and IT. They may purchase access to credentials or endpoint telemetry from Initial Access Brokers (IABs) or scrape publicly available information from LinkedIn, press releases, and social media to build detailed profiles of staff and infrastructure.

What makes this phase effective:

  • Use of OSINT to identify staff names, departments, and third-party vendors.
  • Focus on companies with complex IT environments and high tolerance for operational risk—prime candidates for extortion.

2. Initial Access via Social Engineering

Once they’ve identified the right entry point, SCATTERED SPIDER often deploys vishing (voice phishing) or phishing techniques to impersonate internal staff. In some cases, they call help desks pretending to be employees locked out of their accounts, requesting MFA resets or password changes.

This is where their native English and cultural familiarity give them a dangerous edge; they sound credible, confident, and urgent.

Common tactics:

  • Impersonating IT staff or executives to pressure support teams.
  • SIM-swapping or MFA fatigue attacks to intercept or bypass two-factor authentication.
  • Spoofed email domains or compromised inboxes used for internal-style phishing.

3. Credential Harvesting and Privilege Escalation

Once inside, the group moves quickly to extract further credentials. Tools such as Mimikatz, Cobalt Strike, and legitimate Windows administration tools (e.g. PowerShell, PsExec) are used to escalate privileges and move laterally across the network.

They specifically look for access to:

  • Identity infrastructure (Active Directory, Okta, Azure AD)
  • Remote access tools (VPNs, RDP gateways, Citrix)
  • Data repositories containing sensitive customer or business data

This phase may last hours or days, depending on the target’s size and the level of access achieved.

4. Data Exfiltration and Pre-Ransom Preparation

Before deploying ransomware, SCATTERED SPIDER usually exfiltrates a trove of sensitive data. This forms the basis of their double extortion strategy; even if a victim can restore from backups, they may still pay to prevent the public release of confidential files.

Common methods:

  • Compressing and uploading files to cloud storage services or attacker-controlled servers
  • Encrypting and staging data to avoid detection by DLP or antivirus tools

In some cases, the group leaves behind backdoors or admin accounts to retain long-term access or re-extort victims in the future.

5. Ransomware Deployment via DragonForce

Once exfiltration is complete and the environment is primed, SCATTERED SPIDER deploys DragonForce ransomware across the compromised network. The ransomware is configured to encrypt files rapidly and disrupt operations, sometimes including domain controllers and backup servers, to maximise impact.

Victims then receive a ransom note directing them to a Tor-based portal for negotiations. If payment isn’t made within a specified timeframe, stolen data is posted on a leak site associated with DragonForce.


Key Takeaways:

  • SCATTERED SPIDER relies on human error as much as technical vulnerabilities.
  • The group’s knowledge of Western IT environments makes it easier for them to blend in and manipulate systems and staff.
  • Their multi-stage attack chain: access, escalation, exfiltration, encryption, is methodical and difficult to detect in real time.

Image Credit – Reeds Solicitors

Why SCATTERED SPIDER’s Approach Is Especially Dangerous

SCATTERED SPIDER doesn’t operate like a traditional ransomware crew. Their campaigns combine social engineering finesse with technical aggression, resulting in a hybrid threat model that blends cybercrime with tactics more often associated with espionage groups. Here’s why they stand out and why they’re so difficult to defend against.

1. Deep Impersonation and Real-Time Manipulation

Unlike typical phishing groups that rely on mass email blasts, SCATTERED SPIDER employs live, targeted deception. Their operators speak fluent, unaccented English and are adept at impersonating IT personnel, executives, or employees in distress.

They frequently call help desks or IT support lines, using:

  • Personalised information gathered through OSINT
  • Spoofed phone numbers and internal-sounding email addresses
  • Calm, confident delivery to manipulate support staff in real time

This level of human-centred deception is rarely seen in conventional cybercrime campaigns and poses a serious challenge for security teams.

2. Precision Targeting of Identity Infrastructure

SCATTERED SPIDER understands that identity is the new perimeter. Rather than merely compromising a system, they aim to take control of identity and access management tools like:

  • Okta
  • Active Directory
  • Azure AD
  • SSO and MFA services

By doing so, they’re not just accessing individual endpoints, they’re taking over the core trust fabric of the organisation. Once they own your identity systems, lateral movement and persistence become trivially easy.

3. Speed and Aggression Outpacing Detection

While many attackers spend weeks in a network quietly collecting data, SCATTERED SPIDER moves with urgency and intent. In many cases:

  • Initial access to ransomware deployment can take place in less than 48 hours.
  • They bypass traditional controls using legitimate tools (Living off the Land), leaving minimal forensic traces.
  • They often disable security tools, delete logs, or backdoor admin accounts to stay one step ahead.

Traditional defences based on known signatures, blacklists, or passive monitoring are often too slow or too blind to respond in time.

4. Blurring the Line Between Cybercrime and Nation-State Tactics

Although motivated by financial gain rather than geopolitics, SCATTERED SPIDER’s tradecraft exhibits a level of maturity and adaptation more typical of state-sponsored APT groups. This includes:

  • Tailored intrusion techniques for specific industries and environments
  • Multi-stage attacks with operational patience
  • Use of multiple extortion channels, including PR pressure and data leak sites

This hybrid operational model: part ransomware gang, part APT, means traditional classifications don’t fully capture the scope of their threat. For defenders, this creates both strategic confusion and escalating risk.

In short, SCATTERED SPIDER is dangerous not just because of what they do, but how they do it. Their blend of psychological manipulation, identity compromise, and rapid escalation makes them one of the most formidable threats facing organisations today.

Defending Against SCATTERED SPIDER: Practical Guidance

While SCATTERED SPIDER’s tactics are sophisticated, they often exploit basic lapses in process, communication, and identity management. That means there are precautions organisations can take to harden themselves against this type of threat, without needing to reinvent their entire security stack.

1. Reinforce Help Desk Security Protocols

Since SCATTERED SPIDER frequently targets help desks and support teams, ensure those teams are trained to:

  • Never reset MFA or passwords without high-assurance identity verification.
  • Use call-back procedures or out-of-band verification for unusual requests.
  • Flag repeated or urgent requests as potential social engineering.

Adding simple checklists and mandatory escalation paths for sensitive account changes can drastically reduce social engineering success rates.

2. Harden Identity and Access Management

Identity remains a prime attack surface. To reduce risk:

  • Enforce phishing-resistant MFA, such as hardware tokens or app-based push authentication with device binding (rather than SMS or email codes).
  • Implement just-in-time access and least privilege policies for administrative accounts.
  • Regularly audit inactive accounts, especially third-party vendors and former employees.

Integrate identity telemetry into your detection stack: suspicious logins, MFA resets, or logins from new devices should trigger alerts.

3. Monitor for Signs of Lateral Movement

Once SCATTERED SPIDER is inside a network, time is of the essence. Deploy tools and strategies to detect:

  • Unusual use of remote admin tools (e.g. PowerShell, PsExec)
  • Use of credential dumping tools or abnormal privilege escalation
  • Lateral movement attempts, especially to identity infrastructure like Active Directory or Okta

EDR/XDR platforms with good behavioural analytics can be critical here, especially when coupled with 24/7 monitoring or MDR services.

4. Protect Your Data, and Know Where It Is

Given the group’s focus on data theft prior to encryption, prevention isn’t just about backups:

  • Map your critical data locations, especially customer, financial, and IP-related data.
  • Use Data Loss Prevention (DLP) tools to monitor exfiltration patterns.
  • Segment sensitive environments and restrict data access to only those who need it.

Ensure that backups are not just secure and segmented from your main network, but also tested regularly.

5. Prepare for the Human Side of a Crisis

Even strong technical controls can be undone by panic or poor decision-making in the moment. Prepare:

  • A ransomware playbook with clear response roles, legal guidance, and communications plans.
  • Crisis simulations or tabletop exercises that include scenarios involving data leaks and public extortion.
  • Training for executives and PR teams on how to manage the reputational and regulatory impact.

Remember: SCATTERED SPIDER succeeds by catching organisations off guard, so make sure your teams know exactly how to respond under pressure.


Security Culture Is Your Best Defence

At the end of the day, SCATTERED SPIDER’s tactics work because they exploit human trust, urgency, and complexity. Investing in detection tools is important, but fostering a culture of scepticism, verification, and shared responsibility across the organisation is what truly builds resilience.

Stay Vigilant, Stay Informed

SCATTERED SPIDER has proven that ransomware is no longer just about encrypted files and ransom notes — it’s about controlling identities, deceiving people, and outpacing traditional defences. Their campaigns demonstrate just how effective a threat actor can be when they combine technical proficiency with social engineering and real-time manipulation.

What makes them especially dangerous is not just the tools they use, but the tactics and mindset behind their operations. This is a group that studies its targets, adapts rapidly, and blends psychological and technical attacks with striking efficiency.

For organisations in the UK, the US, and beyond, the message is clear: security isn’t just a technology problem — it’s a people and process problem too. Preventing the next SCATTERED SPIDER-style breach means:

  • Educating and empowering support staff
  • Hardening identity infrastructure
  • Monitoring for the unexpected
  • And rehearsing how you’ll respond under pressure

Cybercriminals evolve constantly. So must we.

Header image > Photo by Егор Камелев on Unsplash.

"SOS
SOS Intelligence Webinar

Business Update Webinar – you’re invited!

A date for your diaries, or rather, your calendar 🙂 Please join us on Wednesday, June 4th at 4pm UK time for our third webinar of the year where I will be taking you through our platform updates, and there are many!

Look forward to seeing you and taking your questions.

Best wishes,

Amir


Who is this for?

  • Anyone in a business or organisation who has responsibility for online security
  • CTOs or senior managers who want to understand why there is a critical need for a service like SOS Intelligence
  • IT / Cyber Security teams
  • Business owners who are worried about the recent cyber attacks in the UK

What we will cover:

NEW Key Features

  • SSO
  • Better UX
  • Threat Tracker
  • Domain Monitor
  • DARKMAP rebuild and improvements
  • On demand RFIs
  • Vulnerability Intelligence

Our AI Analyst

  • Fully Integrated, private LLM agent
  • Alert Analysis
  • Content Analysis
  • Natural Language querying

Hosted by Jon Moss and SOS Intelligence Founder and CEO, Amir Hadzipasic

Sign up to the webinar to receive a recording via email if you cannot attend on the day. By signing up you will also receive our newsletter for future events. You can always unsubscribe with one click.

Photo by Headway on Unsplash

"Analysing
Investigation, The Dark Web

Analysing DDoSIA: Threat Intelligence Insights into a Coordinated DDoS Operation

In the evolving landscape of cyber threats, DDoSIA has emerged as a significant force, orchestrating distributed denial-of-service (DDoS) attacks against organisations worldwide. Believed to be operated by pro-Russian hacktivist groups, DDoSIA mobilises volunteer participants to overwhelm targeted networks, causing disruptions to businesses, government institutions, and critical infrastructure. With its decentralised approach and sustained campaigns, this operation has become a persistent threat to cybersecurity resilience.

Tracking DDoSIA is crucial for cybersecurity and threat intelligence (CTI) professionals. By understanding its tactics, techniques, and infrastructure, defenders can better anticipate attacks, mitigate their impact, and adapt defensive strategies. As part of our mission at SOS Intelligence, we continuously monitor, collect, and analyse DDoSIA-related data, offering actionable intelligence to help organisations stay ahead of this evolving threat.

Understanding DDoSIA and Its Attack Infrastructure

DDoSIA is a coordinated distributed denial-of-service (DDoS) campaign operated by pro-Russian hacktivist groups, notably NoName057(16). This group, along with other affiliated threat actors, is known for conducting disruptive cyber operations against organisations and governments deemed hostile to Russian interests. NoName057(16) has been active since at least 2022, launching frequent DDoS attacks against Western institutions, particularly those supporting Ukraine. The group operates as part of a broader ecosystem of pro-Russian cyber collectives, often aligning with entities like KillNet and Anonymous Russia, which share similar geopolitical motivations.

Unlike state-sponsored advanced persistent threats (APTs) that focus on espionage or destructive cyberattacks, DDoSIA is a crowdsourced DDoS initiative, incentivising participants to join attacks. Volunteers—many of whom are ideologically aligned with Russia’s geopolitical stance—are recruited via messaging platforms and forums, where they receive instructions and access to attack tools. Participants are often encouraged through financial rewards or patriotic motivations, making DDoSIA a hybrid between hacktivism and cyber warfare.

How DDoSIA Operates

DDoSIA primarily leverages volumetric and application-layer DDoS attacks, aiming to overwhelm websites, APIs, and network infrastructure. Attack vectors include:

  • HTTP flooding – Generating large numbers of HTTP requests to exhaust server resources.
  • UDP and TCP floods – Saturating network bandwidth with high-volume traffic.
  • Slowloris attacks – Holding connections open to deplete available server connections.
  • Bot-assisted attacks – Some participants utilise proxy networks and automated scripts to scale up attack intensity.

The group has targeted various sectors, including government agencies, financial institutions, defence contractors, and logistics providers. A particular focus has been placed on countries actively supporting Ukraine, such as the UK, the US, Poland, and Germany. Attack campaigns often coincide with key political events, military aid announcements, or sanctions imposed against Russia, demonstrating a coordinated cyber-influence strategy.

The Importance of Real-Time Intelligence

Given DDoSIA’s adaptive tactics and decentralised operational model, real-time intelligence is critical for understanding and mitigating its impact. Traditional DDoS mitigation measures alone are insufficient, as the threat landscape evolves rapidly. Continuous monitoring of:

  • Attack infrastructure changes (e.g., new command-and-control nodes, shifting IP ranges).
  • Recruitment activities in underground forums and messaging platforms.
  • Indicators of compromise (IOCs) and attack patterns.

…enables cybersecurity teams to stay ahead of threats.

At SOS Intelligence, we actively track, collect, and analyse DDoSIA-related intelligence, helping organisations anticipate attacks, implement proactive defences, and mitigate operational disruptions before they escalate. By leveraging OSINT, deep web monitoring, and network telemetry, we provide actionable insights to counter the evolving tactics of DDoSIA and its affiliates.

Analysis, Evaluation, and Recommendations

Understanding DDoSIA’s Attack Trends

Unlike financially motivated DDoS campaigns, which often involve extortion or ransom demands, DDoSIA’s attacks are ideologically driven and aim to disrupt services in nations perceived as adversaries of Russia.

Since October 2024, SOS Intelligence has been collecting data from the DDoSIA network, the analysis of which provides critical insight into DDoSIA’s recent campaigns, revealing its geopolitical focus, attack methodologies, and targeted infrastructure. The findings help contextualise the scope of the operation, exposing which nations, industries, and services are most affected.

1. Top Targeted Countries

The distribution of attacks by country reveals a strategic effort to disrupt organisations aligned against Russian interests. The most targeted nations include:

  • Ukraine – Consistently the most heavily attacked country, aligning with DDoSIA’s broader mission to destabilise Ukrainian institutions and weaken its digital infrastructure. The targeting of government agencies, financial institutions, and media organisations suggests an attempt to create operational disruption and information blackout scenarios.
  • Poland & the Baltic States (Lithuania, Latvia, Estonia) – These nations have been frequent targets of Russian-aligned cyber campaigns due to their strong support for Ukraine. Their strategic position in NATO and the EU’s Eastern flank makes them key adversaries in Russia’s hybrid warfare strategy.
  • Western European Nations (France, Germany, UK, Italy, Spain) – The presence of these countries in DDoSIA’s targeting list suggests an attempt to undermine NATO members and critical Western businesses, particularly those providing support to Ukraine.
  • Czech Republic & Slovakia – These Central European nations have seen increasing attacks, likely due to their role in military aid and logistical support to Ukraine.

Evaluation

The targeting strategy aligns with broader Russian state-aligned cyber operations, which aim to erode public trust in institutions and disrupt critical services. The focus on government, finance, and media sectors indicates an effort to undermine operational stability and create ripple effects that extend beyond the direct victims.

Implications for Cyber Threat Intelligence (CTI):

  • Intelligence gathering on Russian hacktivist groups should prioritise understanding evolving target lists to anticipate future attacks.
  • Governments and high-risk organisations in these regions should implement heightened DDoS protections and real-time monitoring to mitigate potential disruptions.

2. Top Victim IPs and Their DDoS Mitigation Status

A key insight from the dataset is the list of IPs that sustained the highest number of DDoS attacks, offering a window into DDoSIA’s strategic intent. The most frequently targeted IPs include:

  • Ukrainian Government Infrastructure (91.212.223.216, 18 attacks) – This aligns with previous attacks on Ukrainian state services, attempting to disrupt government communications, digital services, and emergency response systems.
  • Microsoft (13.107.246.44 & 13.107.246.61, 14 & 12 attacks) – These IPs are tied to Azure-hosted services, suggesting DDoSIA is attempting to target cloud infrastructure supporting Western businesses or cybersecurity initiatives.
  • Polish Banking Networks (193.19.152.74, 10 attacks) – The focus on financial institutions is indicative of an effort to destabilise economic activity in Poland, a strong supporter of Ukraine.
  • French E-commerce & Hosting Services (51.91.236.193, 8 attacks) – The targeting of commercial platforms suggests that DDoSIA is testing the impact of attacks on economic stability and supply chains.

DDoS Mitigation Status Analysis

One of the most notable findings is that many of these victim IPs do not publicly advertise their use of Cloudflare, AWS Shield, or other major DDoS mitigation services. This raises concerns about their ability to withstand sustained attack campaigns.

  • High-profile organisations like Microsoft likely have in-house protections, but the presence of their IPs on the list suggests that attackers are attempting to overwhelm cloud-based services.
  • Government infrastructure in Ukraine and Poland appears to be a primary target, reinforcing the need for centralised state-sponsored DDoS defences.
  • Smaller financial institutions and e-commerce platforms may lack the necessary defences, leaving them vulnerable to outages.

Evaluation

The data suggests that DDoSIA’s attack strategy is not just about volume but also persistence. By continuously targeting specific IPs associated with critical services, they are attempting to cause prolonged service degradation rather than instant takedowns.

Recommendations:

  • At-risk organisations should conduct a full audit of their current DDoS protection measures, ensuring they use enterprise-grade filtering solutions.
  • Cloud-based services should enhance their rate-limiting policies to mitigate bot-driven HTTP floods.
  • Government agencies should coordinate with cybersecurity providers to implement real-time defence measures.

3. Top Attack Methods and Vectors

DDoSIA utilises a combination of attack techniques designed to bypass basic mitigation measures. The most frequently observed attack vectors include:

  • TCP SYN Floods – A classic technique used to exhaust connection resources on servers.
  • HTTP GET/POST Floods – Targeting application-layer services, often overwhelming login pages, checkout processes, or API endpoints.
  • DNS Amplification – Leveraging misconfigured DNS servers to exponentially increase attack traffic.

Evaluation

The presence of HTTP-layer floods indicates an intentional effort to bypass traditional DDoS filtering, which primarily focuses on volumetric mitigation. The attack patterns suggest that DDoSIA’s botnet includes a mix of compromised systems, VPNs, and residential IPs, making mitigation more complex.

Recommendations

For Organisations at Risk

  1. Implement Layered DDoS Mitigation
    • Use a high-quality DDoS mitigation package, such as Cloudflare, AWS Shield, or Akamai for automated volumetric protection.
    • Deploy Web Application Firewalls (WAFs) to filter out malicious HTTP traffic.
  2. Proactive Threat Intelligence & Monitoring
  1. Implement network anomaly detection tools to identify and block low-volume, high-impact attacks.
  2. Use geolocation filtering to block or challenge traffic from high-risk regions.
  3. Strengthen API & Login Security
  1. Enforce CAPTCHAs and rate-limiting on login and checkout pages.
  2. Deploy bot management solutions to detect automated DDoS tools.

For CTI Professionals & Security Teams

  1. Expand DDoSIA Attribution & Tracking
    • Monitor NoName057(16)’s recruitment channels to identify new botnet strategies.
    • Use honeypots and deception techniques to study attack behaviour in real-time.
  2. Enhance Threat Intelligence Sharing
  1. Collaborate with government agencies and private sector security teams to exchange attack data.
  2. Track botnet infrastructure and preemptively blacklist high-risk traffic sources.
  3. Develop & Update DDoS Playbooks
  1. Conduct regular red team exercises to test DDoS resilience.
  2. Simulate HTTP-layer and multi-vector attacks to identify weaknesses before adversaries exploit them.

Conclusion

The DDoSIA campaign, orchestrated by the NoName057(16) collective, is more than just a disruptive force—it is a tactically coordinated effort aimed at destabilising key institutions in countries opposing Russian geopolitical interests. The data analysed from recent attacks highlights clear patterns in target selection, attack vectors, and mitigation gaps, providing crucial insights into how organisations can defend against such threats.

The attack data reveals a strong geopolitical alignment, with Ukraine, Poland, the Baltic states, and Western European nations being primary targets. The focus on government agencies, financial institutions, and media organisations suggests an intent to erode public confidence, interfere with economic stability, and control narratives in critical regions. Additionally, the fact that Microsoft-hosted services and Polish banking networks have been frequently attacked underlines the strategic importance of both public and private sector entities remaining highly vigilant.

A notable trend is the increasing use of application-layer DDoS techniques (e.g., HTTP floods, DNS amplification, SYN floods), which require more than just volumetric DDoS mitigation. Attackers are leveraging residential proxies, VPN services, and compromised IoT botnets to make their traffic appear legitimate, complicating detection and response efforts.

DDoS as a Smokescreen for Other Cyber Threats

While DDoS attacks are disruptive, they can also serve as a distraction for more insidious cyber activities, such as:

  • Network Intrusions & Data Exfiltration – Attackers may launch DDoS attacks to overwhelm security teams, diverting attention while stealing sensitive data or planting backdoors in the organisation’s infrastructure.
  • Ransomware Deployment – A coordinated DDoS attack could mask the initial stages of ransomware infections, where threat actors attempt to move laterally through a network before detonating their payloads.
  • Supply Chain Compromise – Threat actors may target cloud-based services or third-party providers with DDoS attacks, creating cascading failures that expose vulnerabilities in interconnected systems.

For security teams, this means that DDoS attacks should never be treated in isolation. Organisations must simultaneously monitor network traffic, logs, and user activity for signs of unauthorised access, privilege escalation, or data exfiltration attempts occurring under the cover of a DDoS event.

Strategic Recommendations

To counteract the risks posed by DDoSIA and other hacktivist-driven campaigns, organisations must adopt a multi-layered cybersecurity strategy:

  • Advanced DDoS Protection – Deploy Cloudflare, AWS Shield, Akamai, or on-premise DDoS mitigation solutions, with an emphasis on layer 7 (application-level) attack filtering.
  • Real-Time Threat Intelligence & Incident Response – Maintain continuous monitoring of attack trends and collaborate with threat intelligence providers to detect emerging tactics early.
  • Cross-Channel Security Visibility – Integrate SIEM solutions and Network Detection & Response (NDR) tools to ensure that security teams aren’t solely focused on DDoS traffic, but also on potential concurrent threats.
  • Red Teaming & Attack Simulations – Conduct regular stress-testing of infrastructure and simulate multi-pronged attack scenarios to evaluate how well defensive controls hold up under real-world conditions.
  • Enhanced Access Controls & Zero Trust – Implement strict user authentication, segmentation of critical systems, and anomaly detection mechanisms to prevent lateral movement during attacks.

Final Thoughts

The DDoSIA campaign exemplifies the increasingly coordinated and persistent nature of cyber threats that blend hacktivism, cybercrime, and geopolitical objectives. As attack techniques evolve, organisations must move beyond reactive defences and adopt proactive, intelligence-driven security strategies.

Crucially, security teams must recognise that DDoS attacks may not be the endgame—they could be a diversion tactic for deeper, more damaging intrusions. By combining DDoS mitigation with network forensics, endpoint monitoring, and proactive intelligence-sharing, organisations can stay ahead of evolving threats and prevent large-scale disruptions before they take hold.

Ultimately, early detection, rapid response, and holistic cybersecurity visibility will determine whether organisations withstand or succumb to these politically motivated cyber assaults.

How SOS Intelligence Empowers You to Analyse and Mitigate DDoSIA Threats

For organisations looking to take a proactive approach to defending against DDoSIA, SOS Intelligence provides raw and processed data that can be leveraged for deeper analysis. Rather than simply offering static reports, our platform enables security teams to interrogate the data in real-time, uncovering trends, patterns, and attack methodologies that can directly inform defence strategies.

Using our threat intelligence feeds, organisations can:

  • Correlate Attacker Behaviour – By analysing historical and live attack data, security teams can identify recurring attack patterns, such as preferred attack vectors, geographic focus, and time-based fluctuations in activity.
  • Investigate Victimology – By reviewing which organisations, IP ranges, and services are being targeted, defenders can assess their own risk exposure and determine whether their industry, supply chain, or region is in DDoSIA’s crosshairs.
  • Detect Emerging Attack Trends – With access to raw network and attack metadata, users can identify new methods being deployed by DDoSIA before they become widespread. This allows for early countermeasure deployment before adversaries refine their techniques.
  • Enrich Internal Threat Intelligence – Security teams can cross-reference SOS Intelligence data with their own logs, SIEM alerts, and network telemetry to detect potential early-stage reconnaissance or ongoing infiltration attempts.
  • Assess DDoS Mitigation Effectiveness – By tracking which victims have successfully mitigated attacks, teams can gain insight into which defensive solutions (e.g., Cloudflare, AWS Shield, on-premise filtering) have proven most effective.

Turning Intelligence into Action

The true value of SOS Intelligence’s DDoSIA data lies in its ability to empower security professionals to extract their own insights. By combining our raw intelligence with in-house security expertise, organisations can:

  • Adjust firewall rules and DDoS protection settings based on the latest attack techniques.
  • Pre-emptively strengthen defences if they belong to an at-risk industry, country, or sector.
  • Monitor attack shifts in real-time to anticipate secondary threats such as network intrusions, data exfiltration, or ransomware campaigns that may accompany a DDoS event.
  • Share intelligence within their cybersecurity community to strengthen collective resilience against DDoSIA and similar threats.

Your Intelligence, Your Analysis, Your Defence

SOS Intelligence doesn’t just provide data, it offers a toolset for investigation and insight generation. By leveraging our feeds, logs, and analysis tools, security teams can turn raw data into actionable intelligence, enabling them to detect, understand, and mitigate DDoSIA threats before they escalate.

By combining our intelligence with your expertise, your organisation can stay ahead of DDoSIA’s evolving tactics and transform threat data into a proactive defence strategy.

Header image source – GBHackers.

"Cybersecurity"/
SOS Intelligence Webinar

Livestream: Top 5 Cybersecurity Concerns for 2025

What Security Professionals Need to Know

For our first webinar of 2025 we are going to be discussing a number of key topics that will impact us all this year and in the future.

What we will cover:

  • AI-Powered Cyber Attacks
  • Advanced Ransomware Techniques
  • Zero-Day Vulnerabilities
  • Insider Threats
  • Geopolitical Tensions and State-Sponsored Attacks

We will also be looking at the important Mitigation Strategies and Best Practices to try and counter these threats. There will be plenty of time for questions and discussion too. We are going to have a lot to discuss!

We are recording the session so if you sign up and are not able to make it, you will be sent a replay.

Sign up takes seconds, just click the button below.

Photo by FlyD on Unsplash

1 2 3 4
Now recruiting MSSP partners · deploy dark web monitoring under your own brand in 48 hours | Sign up to the Partner Portal →
Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Youtube
Consent to display content from - Youtube
Vimeo
Consent to display content from - Vimeo
Google Maps
Consent to display content from - Google
Spotify
Consent to display content from - Spotify
Sound Cloud
Consent to display content from - Sound