Overview of the Russian-speaking infostealer ecosystem: The logs
ID: 3110d193-6536-55bf-baae-f364f4275c9b
STIX ID: report--3110d193-6536-55bf-baae-f364f4275c9b
Feed Name: Sekoia.com
This Sekoia Threat & Detection Research blog describes the lifecycle of data stolen by infostealers—collection, processing, sale and exploitation—within the Russian-speaking cybercrime ecosystem, detailing centralised marketplaces (e.g., Genesis Market), decentralised Telegram-based clouds and bots, specialised tooling for parsing and validating logs, examples of abuse by criminal and state-linked actors (Lapsus$, Sandworm), and recent law-enforcement takedowns such as Operation Cookie Monster, concluding that the infostealer economy is professionalising and poses significant risk to organisations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
