‘Russian Market’ emerges as a go-to shop for stolen credentials

Researchers from ReliaQuest have reported that the ‘Russian Market’ cybercrime marketplace has emerged as one of the most popular platforms for selling credentials stolen by infostealer malware.

Ensar Seker, CISO at SOCRadar, commented:

“The rise of the Russian Market as a post-Genesis powerhouse for credential sales is no surprise. It underscores a growing trend where info-stealer logs are the new currency of access in the cybercrime ecosystem. These logs are often harvested at scale via malware like Raccoon, RedLine, and Vidar, then sold in semi-curated bundles for as little as $2. For threat actors, it’s a low-cost, high-reward model that enables everything from account takeovers to full-blown ransomware deployment.”

“What makes this surge concerning is not just the affordability and volume of stolen credentials, but the quality and contextual richness of the logs—browser session cookies, saved passwords, crypto wallets, VPN configs, and even MFA tokens can be included. The Russian Market has also benefitted from the void left by Genesis Market’s takedown, which previously offered a slick user interface and session replay capabilities. While the Russian Market lacks that level of polish, its availability, persistence, and pricing are drawing in a new wave of threat actors, especially low-skilled affiliates and initial access brokers.”

“The cybersecurity industry needs to stop thinking of stealer logs as a footnote. They are a first-stage breach vector and increasingly weaponized in the earliest stages of intrusions. Organizations must monitor the dark web and infostealer marketplaces to understand whether their attack surface has already been compromised. At SOCRadar, we’ve observed a 30% uptick in stealer log exposure among enterprise assets across our monitored datasets, especially credentials linked to VPNs and SaaS platforms.”

“This also ties back to the larger issue of password reuse and unmanaged credentials. It’s not just about detecting breaches after the fact, but reducing the exploitability of leaked credentials through password managers, device-based authentication, and routine credential rotation. The Russian Market is just one shop in a growing underground mall and unfortunately, business is booming.”

Additionally, SOCRadar recently published an analysis on the prevalence of stealer logs. Here it is in full: https://socradar.io/stealer-logs-everything-you-need-to-know/

My $0.02 worth on this is to not to be a victim. And the best way to avoid being a victim of phished or stolen credentials is to use some form of 2FA or even migrate to a passwordless solution. The former will make it harder for stolen credentials to be used. The latter will make stolen or phished credentials a non-issue as there’s nothing to steal.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading