Russian Market has emerged as the dominant force in the cybercriminal underground, establishing itself as what security experts describe as “the Amazon of stolen credentials.”
This notorious marketplace has fundamentally transformed how threat actors acquire and exploit compromised account information, creating an ecosystem where even low-skilled attackers can launch devastating credential-based attacks with minimal investment.
The scale of Russian Market’s operations is staggering, with the platform hosting over five million logs by February 2023, each containing tens to hundreds of individual credentials.
This massive inventory translates to hundreds of millions, potentially billions, of compromised accounts available for purchase at prices as low as two dollars per log.
The marketplace’s streamlined interface and one-click purchasing system have democratized cybercrime, making sophisticated attacks accessible to a broader range of malicious actors.
ReliaQuest analysts identified that the platform generated over 136,000 customer alerts in 2024 alone, highlighting its significant impact on global cybersecurity.
The researchers found that Russian Market’s success stems from its convenience, reliability, and advanced filtering options that allow cybercriminals to target specific industries, geographic regions, or credential types with surgical precision.
The marketplace’s influence extends far beyond simple credential sales, as it has created an entire pipeline that fuels waves of breaches across industries.
Professional services and information sectors face disproportionate targeting due to their high digital engagement and complex supply chains.
The platform’s longevity and perceived reliability have cemented its position at the forefront of the credential theft ecosystem, even amid growing concerns about law enforcement attention.
The effectiveness of Russian Market lies not just in its marketplace functionality but in the sophisticated infection techniques employed by the infostealers it hosts.
Analysis of over 1.6 million posts reveals that Lumma (LummaC2) dominated the landscape, accounting for nearly 92 percent of credential log alerts in Q4 2024 before its takedown in May 2025.
These infostealers employ five primary compromise techniques that form a robust attack toolkit. Attackers systematically abuse writable directories, particularly the Temp folder, to create staging areas for malicious operations.
They leverage obfuscation through AutoIt scripts and compressed files to disguise malware as legitimate software, effectively bypassing antivirus detection systems.
The malware conceals payloads in less-monitored directories such as “C:/Windows/Fonts/” or exploits legitimate tools like Mavinject32.exe for process injection.
Living-off-the-land techniques utilizing pre-installed utilities like MSBuild.exe allow attackers to execute malicious scripts while blending seamlessly with legitimate system processes.
Finally, persistence mechanisms through registry keys, scheduled tasks, and startup directory implants ensure the malware survives system reboots and user interventions.
Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…