Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

04:55 PM
Connect Directly

Meet the Middlemen Who Connect Cybercriminals With Victims

An analysis of initial access brokers explains how they break into vulnerable organizations and sell their access for up to $10,000.

Ransomware operators looking for victims can find them on the Dark Web, where initial access brokers publish listings containing vague descriptions of businesses they've managed to breach.

Initial access brokers, the "middlemen" of ransomware attacks, have noticed demand for their services surge as ransomware-as-a-service (RaaS) gains popularity. Their listings have steadily increased over the past two years, with a significant spike in the past six months, according to Digital Shadows researchers who today published an analysis of these threat actors.

Related Content:

Ransomware Red Flags: 7 Signs You're About to Get Hit

Special Report: Computing's New Normal, a Dark Reading Perspective

New on The Edge: Next-Gen Firewalls 101: Not Just a Buzzword

The job of an initial access broker is to handle the initial requirements of an attack and streamline the process so RaaS operators can launch a successful infection. The growing reliance on RaaS has created a market for initial access brokers to flourish, explains threat intelligence team lead Alec Alvarado.

"There is a lot of pressure placed on ransomware affiliates to feed ransomware developers with victims to generate cash flow," he says. "If an affiliate does not meet the developer's needs, they will be booted from the affiliate program, losing money." 

The process starts with identifying vulnerable targets, which brokers often do indiscriminately with open source port scanning tools like Shodan or Masscan. They also may use vulnerability scanning tools to look for their gateway into a target organization, Alvarado adds. 

In most cases, attackers identify victims who have Remote Desktop Protocol (RDP) exposed to the Internet. Researchers have also observed access to Citrix gateways and domain controller accesses in initial access listings on the Dark Web. Citrix access can be obtained by brute forcing the Citrix gateway to provide remote access or exploit known vulnerabilities in Citrix products.

Once they find their initial foothold, initial access brokers carefully explore the network. They may attempt to escalate privileges or move laterally to see how much data they can access. With this complete, they organize their access information, package it into a presentable product, and figure out how much money it can earn them on the criminal underground. 

These listings can be found across all criminal forums, such as Russian language forums XSS and Exploit, Alvarado says. Some forums have begun to create dedicated sections for access listings.

The price of each listing can range from $500 to $10,000 USD, researchers report, depending on the level of access obtained and organization compromised. Access to large businesses with higher revenues will drive access price. The higher the revenue, the higher a ransom demand.

"Considerably organized and tailored accesses that require minimal effort to complete an attack will typically go for a higher cost as most of the work has been completed at that point," Alvarado explains. "Additionally, if the access encompasses a large portion of the network with multiple hosts, this will drive the access cost."

The buyers of initial access can do far more than launch a ransomware attack. They may also conduct corporate espionage, move laterally, escalate privileges, or stay on the network long-term to take advantage of living-off-the-land techniques.

How Much Information Is Too Much?
Brokers must strike a delicate balance in writing an access listing. They could detail the value of their access to gain more attention and drive the price tag; however, more information may tip off security researchers, who can identify the victim and remove access before it's exploited.

Some brokers play it safe by limiting the description to vague data found on Zoominfo, a site with business information such as company revenue and employee count. This tells potential buyers how lucrative an attack could be without sharing too much information. Brokers have also included portions of a company's stock ticker symbol or the country where it operates.

The subtle nature of their activity and lack of detail in listings make it difficult to catch an initial access broker. Red flags may include evidence of brute-force attempts against RDP servers, multiple failed authentication attempts, or evidence of privilege escalation attempts or lateral movement, Alvarado says. Overall, these brokers can operate without much risk because they don't launch the final campaign and are likely to see a payout. 

"They do not carry out attacks and are more passive," he notes. "From a risk vs. reward perspective, the reward is likely and the risk is low."


Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Author
9/10/2020 | 9:28:31 PM
A Little is Worth a Lot
Incredible analysis of how brokers must adopt a passive approach in order to evade security researchers. This just means both blue and red teams will have to increase vigilance! 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can ...
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one....
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and ...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices f...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `outpu...