Profiling CSAM Consumers Using Infostealers Data
ID: 5dd540e1-821b-5f5b-9625-df4b6bc08529
STIX ID: report--5dd540e1-821b-5f5b-9625-df4b6bc08529
Feed Name: infostealers.com
Threat Score
This report presents a reverse-investigation methodology that uses data from InfoStealer logs (credentials, cookies, browser-saved wallets, and hardware serial numbers) to map Dark Web CSAM domains to infected devices, pivot from device identifiers to other leaked sources, and thereby profile and deanonymize site users; the author includes case examples illustrating identification of fake and real identities and discusses limits and scalability of the approach.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
