A hacker typing on a laptop keyboard.
© Dmytro Tyshchenko/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

In an ironic turn of events, a tool often wielded by cybercriminals — info-stealing malware — has exposed the identities of thousands of hackers.

On Monday, researchers at Israeli cyberintelligence company Hudson Rock said while analyzing a database of about 14.5 million devices infected with info-stealing malware, they found about 120,000 devices with credentials for cybercrime forums.

“The substantial amount of data that is retrieved for each compromised computer when it is infected with an info-stealing malware enables the real identities of the hackers to be discovered,” Hudson Rock researchers said in a blog post.

Cybercriminals often use info-stealers to obtain the personal information of their targets and then trade this stolen data on the dark web.

“A vast majority of [the] info-stealer infections are attributed to Redline, followed by Raccoon and Azorult,” Hudson Rock said. In a report in December 2022, NordVPN listed these same info-stealers among the top malware cybercriminals use to obtain the personal information of their targets.

‘Real Identities of Hackers’ Exposed

The info-stealers allowed Hudson Rock researchers to uncover various information about the hackers, including the credentials of their other accounts (like their usernames and email addresses), names, phone numbers, addresses, IP addresses, and more.

A large percentage of the infected devices (about 57,000) had credentials for one cybercrime forum, Nulled[.]to — where cybercriminals buy and sell hacking tools, stolen data, and other illegal items. Nulled, which currently has nearly 40 million registered members, also suffered a data breach in 2016 that exposed its users’ identities, messages, invoices, and other details.

Hudson Rock researchers also found credentials for other cybercrime forums, like
Cracked[.]io, Hackforums[.]net, Leak[.]sx, Nulled[.]bb, and Raidforums[.]com.

Interestingly, the passwords used on these cybercrime forums were much stronger than passwords on government sites, the researchers said. Breached[.]to users had the strongest passwords, while Rfucheats[.]ru, a Russian cybercrime forum, had comparatively weaker passwords.

Another key discovery was the regional distribution of affected hackers. The highest concentration of hackers with at least one credential linked to a cybercrime forum originated from Tunisia (7.55%), Malaysia (6%), Belgium (5.14%), the Netherlands (4.8%), and Israel (4.43%).

Protecting Your Device From Info-Stealers

Hudson Rock’s report shows how much info-stealers can reveal about a target. Often, victims don’t know their devices have been compromised.

“Info-stealer infections as a cybercrime trend surged by an incredible 6000% since 2018, positioning them as the primary initial attack vector used by threat actors to infiltrate organizations and execute cyberattacks, including ransomware, data breaches, account overtakes, and corporate espionage,” Hudson Rock said.

According to threat intelligence firm Accenture, the price of info-stealer malware varies between $100 to $1000 on cybercrime forums.

To limit your exposure to info-stealers and other dangerous malware, we recommend using antivirus software with real-time protection.

We also recommend investing in dark web monitoring. Dark web monitoring tools notify you when your data appears on cybercrime forums and recommend ways to secure your privacy and limit the fallout of such a breach.

For more dark web news, follow us on Twitter, Threads, and Mastodon!

Leave a comment