Threat intelligence firm Hudson Rock has discovered credentials associated with cybercrime forums on roughly 120,000 computers infected with various information stealer malware. The experts discovered that many of these computers, compromised between 2018 to 2023, belong to threat actors.
The researchers analyzed a database of more than 14.5 million computers infected with info-stealers.
The researchers were able to uncover the real identities of the hackers based on indicators such as additional credentials found on the computers (additional emails, usernames), auto-fill data containing personal information (names, addresses, phone numbers), and system information.
The researchers discovered that the cybercrime forum with the highest number of infected users is “Nulled.to” (57,203), followed by “Cracked.io” (19,062) and “Hackforums.net” (13,366).
The analysis of the passwords of users revealed that forum with the strongest user passwords is “Breached.to.”
The expers noticed that the passwords from Cybercrime forums are stronger than passwords used for Government websites.
Most of the infections are attributed to Redline, followed by Raccoon and Azorult. The top 5 countries (Normalized) from which hackers were infected and had at least 1 credential to a cybercrime forum are:
“Info-stealer infections as a cybercrime trend surged by an incredible 6000% since 2018, positioning them as the primary initial attack vector used by threat actors to infiltrate organizations and execute cyberattacks, including ransomware, data breaches, account overtakes, and corporate espionage.” concludes the report published by Hudson Rock.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, cybercrime forums)
Security Affairs Malware newsletter includes a collection of the best articles and research on malware…
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
This website uses cookies.