Free tool · Field guide

The underground has a vocabulary. Here is the translation.

Every term below is used daily in the markets we monitor, in the languages the underground actually speaks and the creole in between. Each entry ends with the part vendors skip: why the word should change what you do on your side of the wall.

71 entries · curated by the research desk · no signup

71 of 71 entries

Terms starting with A

Access listing

The trade

The IAB's ad format: industry, country, revenue, access level and price. Everything except the victim's name, which is disclosed to serious buyers in private.

Why it matters to you"Bank, $500M revenue, AD admin" narrows to very few companies. Fluency in reading listings is how analysts spot their employer without the name.

SEEN IN DRAGNET

Adversary-in-the-middle phishing

AiTM · MitM phishing · reverse proxy phishing

The playbook

A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.

Why it matters to youThis is the technique that makes "we have MFA" an incomplete answer. The second factor is satisfied honestly and the stolen artefact is the session, not the password, so a password reset closes nothing. Revoke sessions and bind tokens to a device or a client certificate. In the logs the shape to look for is a genuine authentication from a hosting range followed immediately by activity from somewhere else on the same token.

SEEN IN SHERLOG

Antidetect browser

ru антидетект

The infrastructure

A browser built to present a consistent, disposable fingerprint per profile: its own canvas, fonts, timezone and proxy. Sold so a stolen session can be replayed from a machine that looks like the victim's.

Why it matters to youFingerprint checks and impossible-travel rules are exactly what this is sold to defeat. Treat them as friction and put the weight on session binding and re-authentication for sensitive actions.

SEEN IN SHERLOG

Terms starting with B

Bank log

ru банк лог

The goods

Access to a compromised online banking account, sold with the balance quoted in the listing. Priced as a fraction of what it holds, because the buyer still has to get the money out.

Why it matters to youThe balance is the advertisement; the account is the asset. Detection tuned to large transfers misses the quiet reconnaissance logins that come first.

SEEN IN DRAGNET

BIN

bank identification number · IIN

The goods

The first six to eight digits of a payment card, identifying the issuing bank, the country and the card product. Not stolen data in itself, but the index the trade is organised around: cards are advertised, sorted and priced by BIN.

Why it matters to youA BIN tells a fraudster which of your controls they are about to meet, because issuer, country and product predict how a transaction will be authorised. A sudden concentration of attempts on a narrow BIN range is somebody testing one issuer's behaviour, and it usually precedes the volume rather than accompanying it.

SEEN IN DRAGNET

Bot shop

bot market · log shop

The trade

A marketplace that sells the output of one infected machine as a single unit: its cookies, saved passwords, browser fingerprint and time zone, packaged so a buyer can load the lot into an antidetect browser and resume the victim's sessions.

Why it matters to youWhat is sold is not a password but a logged-in state, so the account controls that assume a login are never exercised. The buyer arrives already inside. Session revocation and device binding are the controls that matter; password rotation on its own does not touch this.

SEEN IN DRAGNET

Bulletproof hosting

BPH · ru абузоустойчивый хостинг

The infrastructure

Hosting sold on the promise that abuse complaints go unanswered and legal requests go unread. Priced well above ordinary hosting, because that indifference is the entire product.

Why it matters to youAn address that never answers an abuse report is one worth blocking as a range rather than as a host. The provider outlives every campaign that runs on it.

SEEN IN MALVEINE

Business Email Compromise (BEC)

BEC · CEO fraud

The playbook

Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.

Why it matters to youThe control that works is out-of-band verification of any payment change, on a number you already had. Everything upstream of that is detection; this is the step that stops the loss.

SEEN IN DRAGNET

Terms starting with C

C2 panel

ru панель

The infrastructure

The web console an operator uses to run infected machines: victims listed, tasks queued, output collected. Sold with the malware, screenshotted in the advertisement, and often the most revealing artifact a crew produces.

Why it matters to youPanels have their own fingerprints: paths, headers, certificates, response shapes. Blocking a malware family is hard; recognising the panel it reports to is not.

SEEN IN MALVEINE

Callback phishing

TOAD · telephone-oriented attack delivery · vishing callback

The playbook

An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.

Why it matters to youIt is built to defeat mail filtering by containing nothing to filter. The defence is not technical: it is that finance and support staff know the shape of the call, and that a request to install anything during an inbound support conversation is treated as the alarm rather than as the solution.

SEEN IN DRAGNET

Card dump

ru дамп

The goods

The magnetic-stripe data read off a payment card, sold for cloning into a physical one. Distinct from card-not-present data, priced higher, and slowly becoming a legacy good as chip and contactless spread.

Why it matters to youDumps point at a physical compromise: a skimmer, a tampered terminal, a processor. Card-not-present data points at a web breach. The category tells you which team owns the response.

SEEN IN DRAGNET

Carding

ru кардинг

The trade

The trade in stolen payment card data and the craft of turning it into goods: testing cards, choosing merchants, shipping to reshippers. An economy with its own schools, slang and reputations.

Why it matters to youCarding pressure follows the weakest checkout in a sector rather than the biggest brand in it. If your payment flow is being discussed, the fraud arrives well before the chargebacks do.

SEEN IN DRAGNET

Cashout

ru обнал

The trade

The last mile: turning stolen access, cards or balances into money the criminal keeps. Gift cards, crypto, mule accounts, reshipping, each with its own fee and its own specialists.

Why it matters to youCashout is the step with the most friction, which makes it the step with the most leverage. Controls that add delay there cost an attacker more than controls that add delay at login.

SEEN IN DRAGNET

Checker

The playbook

A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.

Why it matters to youA spike in failed logins from distributed IPs is a checker run. If credentials from your domain are circulating, that run is already scheduled somewhere.

SEEN IN SHERLOG

ClickFix

paste and run

The playbook

A lure that tells the visitor the page is broken and asks them to fix it: copy this, press these keys, paste, run. The victim performs the delivery by hand, so nothing was downloaded and nothing was blocked.

Why it matters to youEvery automated control is bypassed by asking the user to be the delivery mechanism. Awareness training that covers only attachments and links does not cover this.

SEEN IN DRAGNET

Cloud of logs

ru облако логов

The trade

A subscription Telegram channel that pours out fresh stealer logs daily to paying members. Bulk access to victims, sold like a streaming service.

Why it matters to youThis is why "we'd know if we were breached" fails: your employee's device can be in a cloud within hours of infection, visible to hundreds of subscribers.

SEEN IN SHERLOG

Combolist

The goods

A recycled email:password list compiled from old breaches and other people's logs, resold in bulk. The fast food of the credential economy: cheap, stale, everywhere.

Why it matters to youCombolist hits inflate exposure numbers without telling you anything new. Insist on knowing whether a record is primary (from a log) or recycled.

SEEN IN SHERLOG

Credential harvesting

credential theft · credential collection

The playbook

The collection stage of an operation, separate from its use: gathering usernames and passwords at scale through phishing pages, infostealers, compromised forms or scraped breaches, with no immediate intention of logging in.

Why it matters to youThe gap between harvest and use is the whole opportunity. Credentials are collected long before anyone tries them, often by a different party entirely, so watching for failed logins finds you the end of the process and never the middle. Watch for your domain appearing in collections instead.

SEEN IN SHERLOG

Credential stuffing

The playbook

Replaying credentials leaked from one service against every other service, at scale, on the assumption that people reuse passwords. The industrial use for every combolist and log ever sold.

Why it matters to youThe failure rate is enormous and irrelevant; the success rate is what pays. Rate limits alone do not stop a run spread across a million residential addresses.

SEEN IN SHERLOG

Crypt / FUD

The playbook

Crypting is the service of repacking malware until antivirus engines stop recognizing it. FUD, "fully undetectable", is the advertised result, sold with a guarantee and re-crypts included.

Why it matters to youA signature is a snapshot of one crypt. This is why detection engineering favors behavior over hashes: the hash changes nightly by design.

Crypto drainer

wallet drainer

The goods

A kit sold to fraudsters that empties a cryptocurrency wallet the moment its owner signs a transaction on a malicious site. The victim believes they are minting, claiming an airdrop or connecting to a service, and the signature they give away authorises transfer of everything.

Why it matters to youThe theft is authorised by the owner, which is what makes it final. There is no chargeback, no issuer to appeal to and no reversal. Defence lives entirely before the signature: what the wallet shows about what is being approved, and whether the person reads it.

SEEN IN DRAGNET

Crypto mixer

tumbler · coin mixer

The infrastructure

A service that pools cryptocurrency from many senders and pays out from the pool, so that the link between an incoming and an outgoing transaction is broken. Charged as a percentage, sometimes with a delay bought separately.

Why it matters to youFor a defender the mixer is usually the end of the trail, not a step in it. Effort spent following funds past one is rarely repaid; effort spent on the addresses immediately before it, which are still attributable, often is.

SEEN IN MALVEINE

CVV

CC

The goods

Card-not-present data: number, expiry, security code and usually the billing address, sold per record for online use. The bulk commodity of card fraud, priced by country, issuer and freshness.

Why it matters to youFresh CVVs mean a live source somewhere: a compromised checkout, a skimmed page, a breached processor. A falling price for your country means that source is large.

SEEN IN DRAGNET

Terms starting with D

Database dump

ru слив

The goods

The raw export of a breached application's tables, traded whole before it is broken up into combolists. Structure intact: emails, hashes, addresses, order history, whatever the schema held.

Why it matters to youA dump ages differently than a credential. The password gets reset; the customer records, security answers and order history stay useful for account-recovery fraud for years.

SEEN IN DRAGNET

Dedik

ru дедик

The infrastructure

A compromised dedicated server or RDP host, rented out as anonymous infrastructure. The underground's cloud computing, billed to someone else.

Why it matters to youYour servers can be inventory. An unexplained RDP listing matching your IP range means the breach already happened.

SEEN IN MALVEINE

Device fingerprint

browser fingerprint · fingerprinting

The infrastructure

The set of attributes a browser or device reveals in ordinary use, combined into an identifier: fonts, screen dimensions, time zone, language, graphics behaviour, extensions. Used by defenders to recognise a returning device, and sold underground as something to wear.

Why it matters to youA fingerprint is a claim the client makes about itself, so it is evidence and never proof. Treating a matching fingerprint as authentication inverts the control: it is useful for spotting a device that should not be here, and worthless for confirming one that should.

SEEN IN SHERLOG

DLS / leak site

DLS

The playbook

A ransomware group's "dedicated leak site": victim announcements, countdown timers and proof packs, published to convert embarrassment into payment.

Why it matters to youGroups increasingly skip encryption and go straight to extortion-by-publication. Monitoring leak sites is now table stakes for breach detection.

SEEN IN DRAGNET

Domain fronting

fronting · domain hiding

The infrastructure

Hiding the real destination of a connection behind a permitted one, by presenting an allowed hostname where the network can read it while the encrypted request asks for something else on the same infrastructure.

Why it matters to youIt defeats blocking that works on names, which is most blocking. What it cannot hide is the shape of the conversation: beacon intervals, payload sizes and session durations survive the disguise, and are what a network defender should be watching once name-based control is known to be insufficient.

SEEN IN MALVEINE

Double extortion

The playbook

Steal the data first, encrypt second, and charge for both: one price to decrypt, another not to publish. Increasingly the theft alone, with no encryption at all, because publication is the half that forces payment.

Why it matters to youBackups answer encryption and answer nothing about publication. If the data left, the incident is a disclosure question from the first hour rather than a recovery one.

SEEN IN DRAGNET

Drop

ru дроп

The trade

A money or goods mule: the recruited (sometimes unwitting) person whose bank account or address launders the proceeds. Recruited openly, in "work" channels, at scale.

Why it matters to youDrop recruitment targeting your country's banks predicts where cashout pressure lands next. Route this feed to your fraud team as well as the SOC.

Terms starting with E

Exit scam

The trade

A market or a trusted vendor takes the escrow balance and disappears. The recurring end state of criminal platforms, and the reason escrow and reputation systems exist at all.

Why it matters to youAn exit scam scatters a market's population into successor venues within days. Monitoring tuned to one forum goes blind at exactly the moment everyone moves.

SEEN IN DRAGNET

Exploit maturity

The playbook

The underground's own CVE lifecycle: PoC posted, "private exploit" for sale, then bundled into kits and partnerkas. Each stage changes the price, and your patch window with it.

Why it matters to youA CVE being traded is a different emergency than a CVE with a CVSS score. Watch the market's pricing alongside the scoring calculators.

SEEN IN CVEKIT

Terms starting with F

Fast flux

The infrastructure

Rotating the addresses behind a domain within minutes, so blocking an address never removes the service. A resilience technique, applied to infrastructure that expects to be reported.

Why it matters to youAddress-based blocking decays fast against flux. Blocking at the name, and watching how quickly a name's answers change, holds up better than any single indicator.

SEEN IN MALVEINE

Formjacking

web skimming · digital skimming · e-skimming

The playbook

Injecting script into a checkout or login page so that what the visitor types is copied to the attacker as they type it. The form still works, the transaction still completes, and nothing on the page looks wrong.

Why it matters to youServer logs will not show this, because the theft happens in the browser and never touches your backend. The controls that see it are client side: subresource integrity, a content security policy that names what may execute, and a record of which scripts your checkout page actually loads today.

SEEN IN MALVEINE

Friendly fraud

chargeback fraud · first party fraud · first-party misuse

The playbook

A cardholder disputing a charge they genuinely made, keeping both the goods and the refund. Sometimes deliberate, sometimes a household member who does not recognise the entry, and from the merchant's side the two are indistinguishable at the moment of the claim.

Why it matters to youThis is the fraud your fraud tooling is worst at, because the transaction was legitimate by every signal it checks. The device was right, the address was right, the card was present. Defence is evidential rather than preventive: delivery proof, session records and a dispute process that can produce them quickly.

Fullz

The goods

A complete identity kit for one person (name, national ID, date of birth, address, banking details) packaged for fraud. Sold per record, priced by country and completeness.

Why it matters to youFullz trading in your customer base signals a data leak upstream of the fraud you're seeing. The chargebacks are the symptom; the breach happened earlier.

SEEN IN DRAGNET

Terms starting with G

Garant

ru гарант

The trade

A forum-appointed escrow who holds payment until the goods check out. Criminal marketplaces run on reputation systems and dispute arbitration: trust infrastructure for people who trust no one.

Why it matters to youEscrowed deals are the serious ones. A garant thread about access to your sector deserves more attention than ten braggarts.

SEEN IN JABBERNAUT

Terms starting with I

Infostealer

stealer · information stealer

The playbook

Commodity malware that runs once on a machine, empties every credential store it can reach, and leaves. Browser passwords, session cookies, crypto wallet files, VPN and messaging configs, then a screenshot and a file listing. The output is a stealer log.

Why it matters to youThe malware is not the incident, the log is. By the time anyone finds the infection the credentials have been sold, and cleaning the endpoint changes nothing about that. Assume every secret that machine could reach is public and rotate on that basis, sessions included.

SEEN IN SHERLOG

Initial Access Broker (IAB)

IAB

The trade

A specialist who breaks into organizations and sells the access (VPN, RDP, domain admin) instead of using it. The wholesale layer between opportunistic infection and targeted ransomware.

Why it matters to youThe listing appears days or weeks before the ransomware does. Catching your name in an IAB post is the cheapest incident response you will ever run.

SEEN IN DRAGNET

Invite-only server

The infrastructure

A private Discord server run as a market or a crew's back office: vetted entry, a channel per function, and a history that does not exist for anyone who was not in the room.

Why it matters to youNothing here is retrievable after the fact. Unlike a forum thread, a server that closes takes its record with it, so an investigation that starts later starts with nothing.

SEEN IN GUILDWIRE

Terms starting with J

Jabber

ru жаба · XMPP

The infrastructure

The underground's legacy messenger of choice for closing deals. Forums are the storefront; price, samples and delivery move to Jabber, which is federated, self-hostable and off the platforms' radar.

Why it matters to youIf your monitoring stops at forums, you see the advertisement and miss the transaction. The deal-closing layer is where intent becomes concrete.

SEEN IN JABBERNAUT

Terms starting with K

KYC pack

The goods

A set of identity documents assembled to pass a verification check: ID scans, a selfie holding the document, a utility bill, sometimes a short video. Sold to open accounts in someone else's name.

Why it matters to youDocument-based verification assumes the document is in its owner's hands. Where a KYC pack exists, the check has to rest on liveness and device signals rather than on the scan.

SEEN IN DRAGNET

Terms starting with L

Leaked API key

API key

The goods

A cloud, payment or messaging credential lifted out of a config file, a repository or a stealer log and traded on its own. No password reset touches it, and most carry no expiry.

Why it matters to youKey material rarely shows up in login telemetry, because it does not log in. Inventory what each key can reach and rotate on a schedule rather than on suspicion.

SEEN IN SHERLOG

Lookalike domain

typosquat

The infrastructure

A domain registered to be misread as someone else's: a swapped character, an extra hyphen, a different suffix. The cheapest piece of infrastructure in this economy and the one most often pointed at a brand.

Why it matters to youRegistration usually precedes use by days. Watching the namespace around your own domains buys you the interval between someone preparing and someone sending.

SEEN IN MALVEINE

Terms starting with M

Mailbox access

The goods

A working login to a corporate or personal mailbox, sold as access rather than as a password. The buyer reads, replies and resets other accounts from inside a mailbox its owner is still using.

Why it matters to youA mailbox is the recovery channel for everything else, so its compromise is not one account, it is all of them. Forwarding and rule audits catch what a login alert does not.

SEEN IN DRAGNET

Malvertising

The playbook

Buying advertising to deliver the lure: a paid result above the real one, pointing at a page that looks like the software the visitor searched for. Distribution with a budget and a targeting console.

Why it matters to youThe victim searched for your product and clicked an ad. Brand monitoring that watches only domains misses the placement entirely.

SEEN IN DRAGNET

MFA fatigue

push bombing · MFA bombing · push fatigue

The playbook

Repeatedly triggering push approval prompts against an account whose password the attacker already holds, until the owner approves one to make the phone stop. Often paired with a call claiming to be IT and asking them to accept.

Why it matters to youThis is a design consequence, not a user failure. A factor that can be satisfied by a single tap has no way to express "I did not start this", so blaming the person who tapped fixes nothing. Number matching, or a factor bound to the login itself, removes the option. The signature in the logs is a run of denials inside a few minutes followed by one approval, and the denials are the incident rather than its footnote.

Mirror channel

The infrastructure

The replacement a Telegram market opens before the original is banned, announced in advance and linked from everywhere the crew operates. Continuity as an operating procedure rather than an accident.

Why it matters to youMonitoring pinned to a channel identifier goes blind the day the ban lands, and the market does not. Follow the operators and the naming convention rather than the address.

SEEN IN TELEPATHY

Mobile proxy

4G proxy · LTE proxy · carrier proxy

The infrastructure

Traffic routed through a real mobile network so that it arrives from a carrier-assigned address. Sold by the port or by the gigabyte, usually with a control to force a new address on demand.

Why it matters to youCarrier address space is the hardest kind to block, because thousands of ordinary subscribers share it and rotate through it. A block here costs real customers, which is the property being sold. Judge the session by its behaviour, because the address will not tell you anything: an ordinary subscriber changes address when the network decides, while a session that rotates on a schedule or straight after a failure is being driven.

SEEN IN MALVEINE

Money mule

mule · money transfer agent

The trade

A person whose bank account is used to receive and forward stolen funds, breaking the direct path between the victim and the fraudster. Recruited knowingly through underground channels, or unknowingly through fake job adverts and romance approaches.

Why it matters to youThe institution's word for a role the underground calls a drop. The distinction matters in practice: a mule is a real person with a real account and a real explanation, which is why account opening controls catch so few of them and why the pattern of movement catches more.

SEEN IN DRAGNET

Terms starting with O

Onion mirror

The infrastructure

The Tor address a leak site or market publishes alongside its clear-web one, so that seizing a domain does not remove the service. Usually several, listed together, rotated as they are found.

Why it matters to youA takedown that removes only the clear-web name changes the address rather than the availability. Judge a disruption by whether the mirrors went with it.

SEEN IN DRAGNET

OTP bot

The playbook

An automated calling service that impersonates a bank or provider to trick victims into reading out their one-time codes. MFA bypass, sold as a subscription.

Why it matters to you"We have MFA" is a mitigation rather than an immunity. Codes that humans can read out, humans can be talked out of, so prefer phishing-resistant factors for crown jewels.

Terms starting with P

Partnerka

ru партнёрка

The trade

An affiliate program: the franchise model behind ransomware and stealer operations. The operator supplies malware and infrastructure; affiliates supply victims and split the revenue.

Why it matters to youAffiliate drama is intelligence gold: payment disputes leak internal manuals, victim lists and builder versions into the open.

SEEN IN DRAGNET

Password spraying

spraying · low and slow brute force

The playbook

Trying one common password against many accounts, rather than many passwords against one. Each account sees a single failed attempt, which is below the threshold that would lock it or raise an alert.

Why it matters to youPer account lockout is the control this technique is designed around, and having it does not help. The signal is horizontal: one password, one source, many usernames, all just under the limit. If your alerting is scoped to a single account it cannot see the attack by construction.

SEEN IN SHERLOG

Proof pack

The playbook

The sample of stolen files a ransomware crew publishes or shows a victim to prove the breach is real: file trees, contracts, ID scans, released ahead of the full dump.

Why it matters to youThe proof pack tells you what was actually taken, which is often narrower (or broader) than the attacker claims. Analyze it before negotiating.

SEEN IN DRAGNET

Terms starting with Q

Quishing

QR phishing · QR code phishing

The playbook

Phishing delivered as a QR code, so the malicious address never appears as text anywhere a filter can read it. The code sits in an email attachment, a poster, a parking meter sticker or an invoice, and the victim resolves it with a device the organisation may not control.

Why it matters to youThe point of the technique is that it moves the click onto a phone. Mail security never sees a URL, the endpoint agent is not installed, and the browser showing the address bar is four inches wide. Treat any authentication that begins on an unmanaged device as a separate risk rather than as the same login from a different screen.

SEEN IN DRAGNET

Terms starting with R

Ransomware-as-a-Service (RaaS)

RaaS

The trade

Ransomware sold as a product: the operator builds the encryptor, the panel and the leak site, affiliates bring the victims, and the ransom splits between them. The reason a small crew can run an enterprise-grade extortion campaign.

Why it matters to youThe brand on the ransom note is not the crew in your network. A RaaS name tells you the tooling, not the operator, and the tradecraft you are facing belongs to whichever affiliate bought in this month.

SEEN IN DRAGNET

Refunder

refund service · refunding

The trade

A specialist who obtains refunds for goods that were delivered and kept, by exploiting a retailer's returns process rather than its payment systems. Sold as a service, priced as a share of the order value, with different operators known for different merchants.

Why it matters to youThis is a customer service exploit wearing a fraud costume, and it lands in a team that has no fraud tooling. The loss shows up as returns, not as chargebacks, so the fraud dashboards stay clean while margin drains through the support queue.

SEEN IN DRAGNET

Remote access trojan

RAT · remote administration tool

The goods

Malware that gives an operator interactive control of a machine: file access, keystrokes, screen, camera, and the ability to run anything the logged in user could. Sold with a control panel, often on a subscription, sometimes with support.

Why it matters to youThe distinction that matters operationally is that a human is at the other end. It waits, it watches, and it reacts to what your responders do, which is why containment that announces itself gives the operator time to move. Plan the response before touching the host.

SEEN IN MALVEINE

Residential proxy

ru резидентские прокси

The infrastructure

Traffic routed through consumer devices so it arrives from an ordinary home address. Sold by the gigabyte, sourced from paid panels and from software that enrolled the device without saying so clearly.

Why it matters to youReputation-based blocking fails here by construction: the address belongs to a real subscriber, who may be your customer tomorrow. Behaviour beats geography.

SEEN IN MALVEINE

Terms starting with S

Session cookie

ru куки · session token

The goods

The token that proves a browser is already logged in, copied straight out of a victim's browser by an infostealer. Replayed elsewhere it opens the account without the password and without a second factor.

Why it matters to youA password reset does not invalidate a stolen session; only revoking the session does. If a device turns up in a log, the response is to kill the sessions, not just rotate the credential.

SEEN IN SHERLOG

SIM farm

SIM box · SIM bank

The infrastructure

Racks of SIM cards driven by software, so that one operator controls hundreds or thousands of real mobile numbers. Used to receive verification codes, register accounts in bulk and originate messages that arrive as ordinary person to person traffic.

Why it matters to youEvery control that treats a phone number as proof of a person is defeated by hardware. If your onboarding trusts SMS verification as identity, it is trusting that numbers are scarce, and a farm is the argument that they are not. Rate limit on the behaviour, not on the number.

SEEN IN MALVEINE

SIM swap

SIM swapping

The playbook

Moving a victim's phone number onto an attacker's SIM, usually by persuading or paying someone at the carrier. Every code sent to that number now arrives at the attacker instead.

Why it matters to youSMS is a recovery channel as often as it is a second factor, and this defeats it as both. Where an account matters, bind the factor to a device rather than to a number.

SEEN IN DRAGNET

SMTP access

mailer access · SMTP shop

The goods

Working credentials for a mail server or a mail sending service, sold so that phishing and invoice fraud can be delivered from an organisation with a clean reputation. Priced on the sending reputation of the domain rather than on the size of the mailbox.

Why it matters to youThe damage is done to a third party using your name. Your users see nothing, your inbox stays quiet, and the first symptom is usually somebody else's abuse report or a sudden fall in your own deliverability. Watch outbound volume and authentication failures, not inbound.

SEEN IN SHERLOG

Stealer log

ru лог · ru стилер

The goods

The complete output of an infostealer infection: every saved browser password, session cookie, autofill record and crypto-wallet file from one victim machine, zipped into a single bundle.

Why it matters to youOne log means one compromised device, with cookies that outlive the password reset. Treat a log hit as an incident rather than a leaked password.

SEEN IN SHERLOG

Synthetic identity

synthetic ID · Frankenstein identity

The goods

An identity assembled from real fragments and invented ones: a genuine national identifier belonging to somebody who does not use it, paired with a fabricated name, date of birth and address. Built to pass verification rather than to impersonate anyone.

Why it matters to youThere is no victim to call, which is why these survive so long. Nobody disputes a charge, nobody reports a stolen identity, and the account behaves perfectly for months while it builds a credit history. It is found by looking for identities with no history before a certain date, not by looking for complaints.

SEEN IN DRAGNET

Terms starting with T

Traffer

ru траффер

The trade

The distribution worker of the stealer economy: drives victims to infected downloads via malvertising, fake installers, cracked software and phishing. Organized into teams with quotas and payout shares.

Why it matters to youTraffer team chatter is a leading indicator. The lures they brag about today are the infections you triage next week.

SEEN IN DRAGNET

Traffic distribution system (TDS)

TDS

The infrastructure

A filtering layer in front of a malicious page that decides who gets to see it: the right country, the right browser, not a sandbox, not a crawler. Everyone else is sent somewhere harmless.

Why it matters to youThis is why a reported link looks clean when your analyst opens it. A single fetch from a research address proves nothing about what the victim was served.

SEEN IN MALVEINE

Terms starting with V

Vouch

ru отзыв

The trade

A public endorsement from an established member that a seller delivered. Vouches accumulate into standing, standing sets price, and a lost reputation is the only real penalty most of these markets can impose.

Why it matters to youVouch history is how you tell a capable seller from a loud one. A listing about your organization from a vouched broker deserves a different response than the same claim from a new account.

SEEN IN DRAGNET

Terms starting with W

Wallet file

The goods

The wallet database and key material an infostealer copies off a victim machine, sold on the chance that the passphrase is weak, reused, or sitting in the same log.

Why it matters to youA wallet leaves with the log and cannot be reset. If a device that held keys was ever infected, the funds move on the attacker's schedule rather than yours.

SEEN IN SHERLOG

Web shell

shell · backdoor script

The infrastructure

A small script left on a compromised web server that turns an ordinary HTTP request into command execution. Often a single file, often named to blend into the application around it, and reachable by anyone who knows the path and the password.

Why it matters to youIt is a door, not a payload, and it usually outlives the vulnerability that installed it. Patching the entry point closes the way in and leaves the way back, so an intrusion that involved one is not over until the filesystem has been compared against a known-good state.

SEEN IN MALVEINE

Published for defenders. Definitions describe how the criminal economy operates. Deliberately, none of them describe how to participate in it.

You can read the menu now.

The platform shows you the kitchen: your name, in these markets, as it happens.

NDA-friendly briefings · global coverage · no slideware