HomeSecurityDark web market "2easy": Selling stolen data at very low prices

Dark web market “2easy”: Selling stolen data at very low prices

A relatively new dark web marketplace called “2easy” appears to be becoming a major player in the sale of stolen data “Logs,” which have been collected from around 600,000 devices via information-stealing malware.

“Logs” are data files stolen from compromised browsers or systems infected with malware, and what makes them particularly important to cybercriminals is that they usually include account credentials, cookies, and credit card information.

See also: “All in One” SEO WordPress plugin: Critical vulnerabilities put thousands of sites at risk

2easy logs

The dark web marketplace 2easy emerged in 2018 and has seen rapid growth since last year, when it sold stolen data from 28,000 infected devices.

Based on an analysis by researchers at Israeli company KELA, 2easy's sudden growth is related to the platform's development and the consistent quality of its offerings, which led to positive reviews.

Cheap and valid logs

The 2easy dark web marketplace is fully automated, meaning that anyone can create an account, add funds to their wallet, and make purchases without interacting directly with sellers.

Stolen data available for purchase can cost as little as $5, about five times less than the average prices on the dark web market Genesis and three times less than the average cost of bot logs on the Russian Market.

2easy Dark web

Furthermore, according to the comments of several cybercriminals on dark web forums, the logs sold by 2easy contain valid credentials, which provide access to the network of many organizations.

In addition to its low cost and validity, 2easy has a GUI that is both user-friendly and “powerful,” allowing criminals to perform various operations on the site, such as viewing all URLs to which infected machines were connected, searching for URLs of interest, browsing a list of infected machines from which credentials were stolen, etc.

The only downside compared to other platforms is that the 2easy dark web marketplace does not provide prospective buyers with a preview of a sold item, such as the IP address, etc.

See also: Microsoft fixes two Active Directory bugs

RedLine

Every item purchased on 2easy comes in an archive file containing the stolen logs from the selected bot.

The content depends on the info-stealing malware used and its capabilities, as each malware can focus on stealing specific data.

However, in 50% of cases, sellers use RedLine, a malware that can steal passwords, cookies, credit card information stored in browsers, FTP credentials, and more:

Dark web market "2easy": Selling stolen data at very low prices

Five of the 18 vendors operating on 2easy use RedLine exclusively, while another four use it in combination with other types of malware such as Raccoon Stealer, Vidar, and AZORult.

Dark web marketplace 2easy: Why is it so dangerous?

The logs sold on 2easy contain, among other things, credentials that can allow access to online accounts, financial information or even entry into corporate networks.

Criminals are selling this information for as little as $5 a piece, but the damage caused to targeted organizations could be in the millions.

“ One such example is the attack on Electronic Arts that was revealed in June 2021 ,” explains the KELA report

See also: FBI: Hackers exploit critical Zoho zero-day bug

“The attack was allegedly started by hackers who purchased stolen cookies, which were being sold online for as little as $10, and continued by hackers who used those credentials to gain access to a Slack channel used by EA“.

“Once inside the Slack channel, these hackers successfully tricked one of EA's employees into obtaining a multi-factor authentication token, which allowed them to steal source codes for EA games“.

The problem with dark web marketplaces selling stolen data is huge. Millions of account credentials are offered for sale on the dark web, so proper security measures to protect accounts (multi-factor authentication, frequent password changes, etc.).

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS