HomeSecurityGenesis Market administrators sold the store to a hacking forum

Genesis Market administrators sold the store to a hacking forum

The administrators of Genesis Market announced on a hacking forum that they had sold the store and that a new owner would take over “next month.”.

This announcement comes about three months after the seizure of certain market domains on the clearnet as part of the “Cookie Monster” operation.

See also: TeamTNT's Cloud Credential Theft Campaign Now Targets Azure and Google Cloud

Genesis Market Sold

On June 28, the “GenesisStore” account, used by a “Genesis Market” operator for announcements on a hacking forum, posted that the team behind the store had decided to sell the platform.

See also: Fake PoC for a Linux Kernel vulnerability on GitHub contains malware

In a post shared by cybersecurity firm Flare with BleepingComputer, the vendor stated that the package included “the full-blown store,” a full database without any details about customers, source code, scripts, and server infrastructure.

Genesis Market administrators sold the store to a hacking forum

The deal will also include the inventory that has made the market a thriving business for cybercriminals.

  • device fingerprints (e.g. cookies, IP addresses, time zones, device information)
  • cookies
  • the form grabber that collected all the data (custom JavaScript)
  • saved passwords
  • other persona data from networked computers

GenesisStore enticed potential buyers by saying that acquiring the platform would significantly increase the profits of those who already have “traffic flow.”.

On Thursday, GenesisStore announced that a customer had made the deposit and the deal is expected to close “next month,” with the new owner assuming full control.

The market administrators also noted that they would not hand over the accounts to the forum, so the new owner would have to create new ones if they wanted this section of the community.

Genesis Market administrators sold the store to a hacking forum

See also: Gamaredon hackers steal data in less than an hour after breach

The history of Genesis Market

Genesis Market launched in late 2017. After three years, it became the most popular store selling account credentials for online services, device fingerprints, and cookies.

Part of the success was the development of custom JavaScript code to collect all the data necessary to create a device fingerprint, which allowed the victim's machine to be impersonated when logging into a service.

To the service provider, it appeared as a normal login from the legitimate account holder using their usual machine from a normal geographic location.

The JavaScript was distributed through various information-stealing malware, including RedLine, DanaBot, Raccoon, and AZORult.

Genesis Market rented bots that provided customers with stolen account credentials in real time. This way, if the credentials were changed on the victim's machine, the bot would replicate almost immediately.

Depending on the type of account, the price of a bot ranged from 70 cents for consumer accounts (Gmail, Facebook, Netflix, Spotify, WordPress, PayPal, Reddit, Amazon, LinkedIn, Cloudflare, Twitter, eBay) to hundreds of dollars for online banking services.

When law enforcement seized Genesis Market's clearnet domains, the platform reportedly offered around 80 million credentials and digital fingerprints, according to the National Crime Agency in the United Kingdom.

Despite this action, the platform remained operational on the dark web. ZeroFox researchers said at the time that the market had increased its stock of new bots following law enforcement's Operation Cookie Monster crackdown on clear web domains.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS