HomeYoutubeRussian Market: Increasingly popular for buying and selling stolen credentials

Russian Market: Increasingly popular for buying and selling stolen credentials

The cybercrime marketplace “Russian Market” is emerging as one of the most important hubs for buying and selling stolen credentials originating from info-stealer malware infections. Although it has been operating for about six years, the platform is becoming increasingly popular, especially after the dismantling of Genesis Market, one of its main competitors on the dark web.

According to ReliaQuest analysis , Russian Market has exploited the created vacuum, attracting more and more threat actors. At the same time, it offers them a wide variety of products at very low prices , with logs starting at just $2 .

See also: New InfoStealer Delivers EDDIESTEALER via Fake CAPTCHA

Although about 85% of the credentials circulating there come from old leaks that can be found from other sources, the amount and type of data that the so-called logs is impressive. An infostealer log is usually a text file or multiple files created by infostealer malware and may include:

  • Usernames and passwords
  • Session cookies
  • Credit card information
  • Data from crypto wallets
  • Technical information about the target device

Each log can contain tens to thousands of credentials. Once collected from infected devices, the logs are uploaded to the attackers’ servers and then either used in new attacks or sold on platforms like Russian Market, feeding the global cybercrime.

Russian Market credentials info-stealer

Info -stealer malware continues to be a key tool in the cybercriminal arsenal, with attackers increasingly turning to corporate targets. Their primary goal: collecting session cookies and corporate credentials from popular business platforms.

According to the ReliaQuest, data from Russian Market confirms this shift:

  • 61% of the recorded logs contain credentials from services such as Google Workspace, Zoom and Salesforce.
  • 77% include Single Sign-On (SSO) credentials, which typically provide access to multiple corporate systems through a single login.

"Compromised cloud accounts are extremely dangerous entry points, allowing attackers to infiltrate critical infrastructure and extract sensitive data," the researchers warn.

See also: Katz Stealer targets Chrome, Edge, Brave and Firefox

Change of scenery: Lumma retreats, Acreed rises

An analysis of more than 1.6 million Russian Market posts (by ReliaQuest) reveals the constant changes in the info-stealing malware space. Until recently, Lumma Stealer held the lead, with 92% of logs available on the market having been collected through it. Lumma’s rise came as a natural consequence of the collapse of Raccoon Stealer, following an international law enforcement operation. However, Lumma now seems to be facing the same fate: a recent international operation led to the seizure of 2,300 domains, severely damaging its distribution infrastructure. Its developers are said to be working to rebuild and restore their business.

This has created room for new players. For example, a new malware called, Acreed, seems to be rapidly emerging as the next big name in the infostealer space, gaining market share and popularity among cybercriminals.

Within the first week of its release, over 4,000 stolen data records on the Russian Market.

Although a newcomer, Acreed follows the well-known action model of infostealers:
its goal is to steal data stored in browsers such as Chrome, Firefox , etc. This data includes passwords, cookies, digital wallets , and credit card information.

Acreed is transmitted through widely used tactics, such as:

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Phishing emails,
  • ClickFix attacks,
  • Malicious ads offering "premium" software,
  • as well as misleading videos on YouTube and TikTok.

Protection from info-stealer malware

Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.

See also: New Chihuahua Infostealer targets browser data

Russian Market: Increasingly popular for buying and selling stolen credentials

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS