In April 2023, a coordinated international law enforcement operation dismantled Genesis Market, one of the largest marketplaces for stolen credentials on the dark web. The operation involved agencies across seventeen countries and was widely reported as a landmark victory. Within weeks, Genesis Market was back online.
That pattern has repeated itself across the criminal credential ecosystem. In May 2026, law enforcement announced the disruption of a relaunched marketplace with 22,000 registered users and €3.6 million in revenue. Within days, successor forums began absorbing its traffic. Takedowns disrupt the market. They do not end it.
This article looks inside the stealer logs marketplace ecosystem: how these shops work, which platforms have emerged after Genesis Market, and why the underlying problem for any organization is not the platform but the data being sold on it.
What Happened to Genesis Market — and What Replaced It
Genesis Market operated from 2018 until its takedown in April 2023, in a coordinated operation involving Europol and the FBI. At the time of its disruption, the platform held data from more than 1.5 million compromised devices, offering buyers ready access to stolen credentials, session cookies, and browser fingerprints packaged as complete device profiles.
What distinguished Genesis Market was its business model. Rather than selling raw credentials, it sold access. Each listing represented a specific infected device, complete with all stored passwords, active session tokens, and the browser configuration data needed to impersonate the victim. Buyers could effectively sidestep fraud detection systems by presenting a device fingerprint that matched that of the account owner’s.
The takedown removed the platform but not the community it served. Several alternatives absorbed its user base, adapting or expanding the model. Disrupting a large marketplace consistently produces the same outcome: the community migrates rather than dissolves.
How the Stealer Logs Markets Work
The raw material of these marketplaces is infostealer logs: packages of data harvested from infected devices, containing credentials, cookies, and system metadata. Once a device has been compromised and its data extracted, that data enters a supply chain ending on a marketplace listing.
Platform operators aggregate logs from multiple sources, including infostealer operators under revenue-sharing arrangements, bulk resellers, and direct purchases. They process the raw data into searchable inventory. Buyers can query the database by target domain, country, or credential type, filtering for data relevant to a specific company or service.
A typical listing includes:
- Credentials: Usernames and passwords stored in the victim’s browser, covering every service they accessed.
- Session cookies: Active authentication tokens that allow immediate account access without requiring a password, bypassing two-factor authentication.
- Device fingerprint: Identifiers including operating system, screen resolution, browser configuration, and installed fonts. This lets buyers present a login that looks legitimate to fraud detection systems.
- Metadata: The date the data was collected, the country of the infected device, and the infostealer malware family that produced the log.
Prices vary by data quality and target. A package containing valid VPN or remote desktop credentials for a corporate network commands significantly more than a bundle of consumer accounts. High-value listings are sometimes offered by auction or reserved for buyers with established reputations on the platform.
Transactions are settled in cryptocurrency. Many platforms implement seller ratings, dispute resolution processes, and responsive support channels, mirroring the structure of legitimate e-commerce.
The Most Prominent Active Platforms
Russian Market has established itself as one of the most active successors to Genesis Market. It operates as a high-volume logs marketplace with searchable filtering by domain and credential type. Unlike Genesis Market’s browser extension model, Russian Market focuses on raw data sales at scale. The platform has migrated across domains multiple times following law enforcement attention but maintained continuity of service through each transition.
Criminal Telegram channels have become an increasingly important distribution layer. Channels broadcast stolen credential batches directly to subscribers, sometimes freely as advertising for paid services, sometimes as outright sales. The ease of creating and recreating Telegram channels makes this layer particularly resistant to disruption. For context on how criminal ecosystems use Telegram, see our article on how illicit channels are transforming cybercrime.
Dark web forums such as Exploit and XSS continue to host both direct credential sales and the recruitment activity that feeds the broader monetization of stolen data. Initial access brokers, ransomware affiliates, and credential resellers operate within the same environments, creating a vertically integrated criminal marketplace.
Why Takedowns Are Not a Solution
Law enforcement operations against credential marketplaces have achieved notable successes, including the arrest of platform operators and the seizure of infrastructure. The effect on the availability of stolen credentials has been limited. Several structural factors explain why.
“Law enforcement may shut these sites down, but they regularly re-appear,” says Stuart Holder, Senior Analyst at Cybercheck. “Large forums and channels tend to have backups in place — from hosting sites and TOR networks, to administrators ready to take over in case the current host is arrested. New servers and domains circulate quickly, and communities grow again.”
In other words, these platforms do not depend on infrastructure that cannot be quickly rebuilt. Domain migrations, mirror sites, and rapid hosting changes absorb disruptions within days. The underlying community — the buyers, sellers, and operators who gave the platform its value — moves together.
The supply side is entirely unaffected by takedowns. Infostealer malware continues infecting devices regardless of which marketplace processes the resulting logs. A platform seizure addresses the distribution layer; it does not affect the volume of stolen credentials entering the ecosystem. As long as new data continues to flow in at scale, established and emerging platforms will continue finding buyers.
This is why the credential theft event itself — not the marketplace that eventually lists the data — is the critical intervention point for any organization trying to protect its employees and systems.
How Cybercheck Helps
Cybercheck’s intelligence draws on fifteen years of continuous infiltration of criminal forums, marketplaces, and Telegram channels by human analysts. This sustained presence across the credential trading ecosystem gives the platform visibility extending well beyond known breach dumps, covering the active, fast-moving markets where stolen data is listed and traded between takedowns.
When employee credentials belonging to a monitored corporate domain appear on any of these platforms, the platform raises an alert immediately. That early warning gives your organization the opportunity to revoke compromised passwords and close exposed accounts before buyers can act on the data.
If cybercriminals are trading information about you or your organization, we alert you immediately, so you can respond before attackers do.
Sources
- Europol: Genesis Market disrupted — Operation Cookie Monster — Genesis Market takedown in April 2023, 17 countries involved, 1.5 million compromised devices in the platform’s database.







