Russian Cybercrime Marketplace Shifting from RDP Access to Malware Stealer Log Exploits
The online marketplace known as Russian Market has transitioned from selling Remote Desktop Protocol (RDP) access to becoming a significant platform for trading information-stealing malware logs. Stolen user credentials are frequently exchanged,…
The online marketplace known as Russian Market has transitioned from selling Remote Desktop Protocol (RDP) access to becoming a significant platform for trading information-stealing malware logs. Stolen user credentials are frequently exchanged, providing potential avenues for unauthorized access to corporate systems.
Threat actors utilize these credentials to initiate credential-based attacks, posing risks to businesses, governments, and individuals by compromising accounts and facilitating further cyberattacks. Numerous high-profile breaches have been linked to credentials acquired from such marketplaces.
Initially, Russian Market focused on selling RDP access and login credentials from compromised computers. This access was exploited for activities like ransomware deployment and cyberespionage. From 2020 until January 2024, RDP sales were a primary offering. In 2021, the marketplace expanded to include stolen credit card data and later introduced the “Bots” product line.
The "bots" are data logs extracted from compromised machines using information-stealing malware, including harvested cookies, credentials, autofill data, and session tokens. By the first half of 2025, more than 180,000 infostealer logs were available for sale, with three main vendors—Nu####ez, bl####ow, and Mo####yf—accounting for nearly 70% of all listings.
Within the “Logs” section, buyers can filter listings by geography, operating system, type of infostealer, and vendor. A typical bot contains credentials for multiple domains, with sizes ranging from 0.05 to 0.3 megabytes, correlating with the number of harvested logins.
These bots predominantly target users in the United States (26%), Argentina (23%), and Brazil. In the first half of 2025, the average bot size was 0.14 megabytes, with prices averaging $10 per bot. Prices have historically ranged from $1 to $100, influenced by factors like geolocation, session quality, and credential validity.
Example SQL-style query used by buyers to locate enterprise credentials:
SELECT * FROM bots WHERE domain LIKE '%examplecorp.com' AND infostealer = 'Lumma' AND country = 'US';
Stolen user credentials are frequently exchanged, providing potential avenues for unauthorized access to corporate systems.
Compromised logins may provide access to webmail portals, cloud services, or VPN connections. These credentials allow threat actors to bypass perimeter defenses and conduct phishing or ransomware attacks while masquerading as legitimate users.
The infostealer ecosystem on Russian Market is supported by a few prolific vendors. Nu####ez, active since January 2024, holds a “Diamond” status with a 4.41 rating and uses Lumma, Rhadamanthys, and Acreed in 2025. Bl####ow relies exclusively on Lumma with a 4.78 rating. Mo####yf, originally a credit card seller, shifted to bots, achieving a 4.50 rating.
New vendors such as sm####ez and co####er have also gained prominence with multi-stealer strategies.
Vendor Market Share Primary Malware Variants
Nu####ez 38% Lumma, Rhadamanthys, Acreed
bl####ow 24% Lumma
Mo####yf 19% Lumma
sm####ez 7% Lumma, Vidar, Stealc
co####er 4% Lumma, Stealc
Information-stealing malware supports a robust underground economy by providing the means for credential-based intrusions. Unlike forums that have been disrupted, Russian Market has maintained operations, highlighting its resilience. Organizations should enhance defenses by enforcing multi-factor authentication, continuous credential monitoring, and integrating threat intelligence to detect anomalous activities.
Profiling key vendors and malware variants offers insights into Russian Market’s operations, emphasizing the need for businesses to prevent credential exposure and mitigate the risk of subsequent attacks.
Based on reporting by GBHackers.
