100,000 Hackers Exposed from Top Cybercrime Forums
Using Hudson Rock’s cybercrime intelligence database, which consists of over 14,500,000 computers infected by info-stealing malware, we analyzed 100 of the leading cybercrime forums. Here’s what we discovered:
Researchers found that a staggering 120,000 infected computers, many of which belong to hackers, had credentials associated with cybercrime forums.
The substantial amount of data that is retrieved for each compromised computer when it is infected with an info-stealing malware enables the real identities of the hackers to be discovered based on indicators such as:
- Additional credentials found on the computers (additional emails, usernames).
- Auto-fill data containing personal information (names, addresses, phone numbers).
- System information (computer names, IP addresses).
Furthermore, researchers discovered that the cybercrime forum with highest amount of infected users is the infamous “Nulled.to” with over 57,000 of the compromised users.
In second place are “Cracked.io” and “Hackforums.net”
By analyzing passwords of users from the various forums, researchers determined that the forum with the strongest user passwords is “Breached.to” while the one with the weakest user passwords is the Russian site “Rf-cheats.ru”.
“Strong” are passwords with at least 10 characters and 4 type of characters https://www.hudsonrock.com/password-hygiene?domain=breached.to
Overall, passwords from Cybercrime forums are stronger than passwords used for Government websites, and exhibit fewer “very weak” passwords than industries like the military.
The vast majority of info-stealer infections are attributed to Redline, followed by Raccoon and Azorult.
Researchers also observed that the top 5 countries (Normalized) from which hackers were infected and had at least 1 credential to a cybercrime forum are:
- Tunisia (7.55% of total infections in the country)
- Malaysia (6%% of total infections in the country)
- Belgium (5.14% of total infections in the country)
- Netherlands (4.8% of total infections in the country)
- Israel (4.43% of total infections in the country)
Info-stealer infections as a cybercrime trend surged by an incredible 6000% since 2018, positioning them as the primary initial attack vector used by threat actors to infiltrate organizations and execute cyberattacks, including ransomware, data breaches, account overtakes, and corporate espionage.
To learn more about how Hudson Rock protects companies from imminent intrusions caused by info-stealer infections of employees, partners, and users, as well as how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here: https://www.hudsonrock.com/schedule-demo
We also provide access to various free cybercrime intelligence tools that you can find here: www.hudsonrock.com/free-tools
Thanks for reading, Rock Hudson Rock!
Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock