Cyber Security News

Russian Dark Web Markets Most Popular Tools Fuels Credential Theft Attacks

Russian Market has emerged as the dominant force in the cybercriminal underground, establishing itself as what security experts describe as “the Amazon of stolen credentials.”

This notorious marketplace has fundamentally transformed how threat actors acquire and exploit compromised account information, creating an ecosystem where even low-skilled attackers can launch devastating credential-based attacks with minimal investment.

The scale of Russian Market’s operations is staggering, with the platform hosting over five million logs by February 2023, each containing tens to hundreds of individual credentials.

Russian Market ‘LOGS’ page (Source – Reliaquest)

This massive inventory translates to hundreds of millions, potentially billions, of compromised accounts available for purchase at prices as low as two dollars per log.

The marketplace’s streamlined interface and one-click purchasing system have democratized cybercrime, making sophisticated attacks accessible to a broader range of malicious actors.

ReliaQuest analysts identified that the platform generated over 136,000 customer alerts in 2024 alone, highlighting its significant impact on global cybersecurity.

The researchers found that Russian Market’s success stems from its convenience, reliability, and advanced filtering options that allow cybercriminals to target specific industries, geographic regions, or credential types with surgical precision.

The marketplace’s influence extends far beyond simple credential sales, as it has created an entire pipeline that fuels waves of breaches across industries.

Professional services and information sectors face disproportionate targeting due to their high digital engagement and complex supply chains.

The platform’s longevity and perceived reliability have cemented its position at the forefront of the credential theft ecosystem, even amid growing concerns about law enforcement attention.

Sophisticated Infection Mechanisms Drive Market Success

The effectiveness of Russian Market lies not just in its marketplace functionality but in the sophisticated infection techniques employed by the infostealers it hosts.

Analysis of over 1.6 million posts reveals that Lumma (LummaC2) dominated the landscape, accounting for nearly 92 percent of credential log alerts in Q4 2024 before its takedown in May 2025.

Post by cybercriminal forum user SGL claiming Russian Market is full of public logs (Source – Reliaquest)

These infostealers employ five primary compromise techniques that form a robust attack toolkit. Attackers systematically abuse writable directories, particularly the Temp folder, to create staging areas for malicious operations.

They leverage obfuscation through AutoIt scripts and compressed files to disguise malware as legitimate software, effectively bypassing antivirus detection systems.

The malware conceals payloads in less-monitored directories such as “C:/Windows/Fonts/” or exploits legitimate tools like Mavinject32.exe for process injection.

Living-off-the-land techniques utilizing pre-installed utilities like MSBuild.exe allow attackers to execute malicious scripts while blending seamlessly with legitimate system processes.

Finally, persistence mechanisms through registry keys, scheduled tasks, and startup directory implants ensure the malware survives system reboots and user interventions.

Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago