Trending

ee-track">
HomeBlog
Cybercriminals e-tailing on e-commerce storefronts – A Growing Trend
Cybercrime-E-commerce

Cybercriminals e-tailing on e-commerce storefronts – A Growing Trend

Cyble Research and Intelligence Labs analyzes the trend of Threat Actors increasingly embracing retail practices to sell compromised data.

Cyble Research and Intelligence Labs have observed several Threat Actors (TAs) using e-commerce platforms such as Shoppy, Selly, Sellix, Satoshibox, Rocketr, and even WordPress to further their criminal activities.

This has been the natural progression and scaling of the TA’s activities – from single-party sales through a middleman or escrow to automating the payment and delivery process (auto-buy), thereby allowing the buyer instant access to the product once the cryptocurrency payment is confirmed.

While the platforms mentioned above are all otherwise reputable, their misuse by cybercriminals is not new. SatoshiBox has previously been used in extortion scams and continues to be used to sell malware and data (see Figure 1).

Figure 1 TA on a cybercrime forum selling malware using Satoshibox 1
Figure 1: TA on a cybercrime forum selling malware using Satoshibox

Figure 2 Hacking services and malware sold on
Figure 2: Hacking services and malware sold on Sellix

Figure 3 Ransomware builder for sale
Figure 3: Ransomware builder for sale on Sellix

Part of the appeal of these low-contact platforms is that they enable TAs to bypass communication with buyers, as well as the fees required by traditional safeguards of the cybercrime forums, such as middlemen (a role which the administrator takes on typically to oversee transactions) or escrow (a system whereby the payment remains in the forum’s wallet until both the buyer and seller confirm release). Moreover, these platforms, such as forums, offer payment options in various cryptocurrencies.  

It’s been observed that the TAs who are actively selling databases on popular cybercrime forums share the same databases on their online stores.

While these shops allow both buyer and seller to trade instantaneously, significantly reducing their deal closure timeframe, there does remain a risk of buyers not getting what was advertised by the seller. Further, the platform offers no grievance management, which generally forum middlemen do. However, such platforms are observed to be utilized by reputed TAs to move their dealings outside the forums.

report-ad-banner

Unlike cybercrime forums, Sellix offers a free plan for those looking to start their own shop, similar to Shoppy. These shops are becoming lucrative day-by-day among cybercriminals due to no entry restrictions, ease of furthering their activities without detection and economizing their operations.

The goods sold on these storefronts vary from databases and cracked accounts to hacking services. Some TAs also offer “leads” – databases of users with personally identifying information, such as addresses and phone numbers, sorted by industry and country to cater to buyers’ demands.

Other types of data include both corporate and individual email-password combinations (AKA combo lists), commonly used for credential-stuffing attacks.

These platforms also provide the option to list the availability of their data or tools including their numbers to highlight their sales projections.

Figure 4 A TA selling Indonesian datasets with unlimited stock
Figure 4: A TA selling Indonesian datasets with “unlimited” stock

Figure 6 Shoppy storefront of a TA who sells combo lists 1
Figure 5: Shoppy storefront of a TA who sells combo lists

Take the example of KelvinSecurity, a prominent TA group featured in the Ukraine-Russia cyberwar. They have attempted to open three online shops in the past and continue to run a popular marketplace group on Telegram. Recently, KelvinSecurity made its fourth attempt at running a WordPress-based e-commerce site, shown below:

Figure 5 Zer0DaySellers KelvinSecuritys new online shop 1
Figure 6: Zer0DaySellers, KelvinSecurity’s new online shop

Another common type of store identified by Cyble researchers is the account reseller, which peddles accounts of popular online services, including food delivery, at a fraction of the original price for these services. These accounts are obtained using logs from stealer malware (stealer logs/compromised endpoints) or other illegitimate means.

Figure 7 Storefront of a TA reselling popular services
Figure 7: Storefront of a TA reselling popular services

Traditional fraud, like carding, in which illicitly obtained credit card details of various bank users are sold by fraudsters, has also found a home on e-commerce platforms.

Figure 8 Storefront of a cracker carder reselling popular products
Figure 8: Storefront of a cracker/carder, reselling popular products

The adoption of e-commerce stores for cybercrime activities is likely to grow further. These stores are however far from replacing the cybercrime forums because these online stores are fragmented without any centralized directory.

Instead, these will continue to supplement TAs’ existing activity on existing cybercrime venues. Some crime niches such as account resellers, combolist peddlers, malware vendors, and carders may thrive on these e-commerce stores. Still, large database sellers may rely on forums to build a reputation before pursuing their own ventures.

References

https://www.bleepingcomputer.com/news/security/cia-exortion-scams-using-satoshibox-to-sell-alleged-proof-for-500/

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free
CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Stay informed

Subscribe to Cyble

Get the latest threat intelligence, research, and security updates straight to your inbox.

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams
Share the Post:
Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams