The criminal market is organised around division of labour. Infostealer malware exfiltrates credentials, session cookies and browser data from infected devices and bundles them into so-called stealer logs, which are traded on marketplaces and in Telegram channels; combolists aggregate email-password combinations from old and new leaks, and the leak sites of ransomware groups publish stolen data sets. Initial access brokers (IABs) turn such raw data into verified network access and sell it on – according to ENISA, with a trend towards low-priced, high-volume offerings in which the majority of accesses trade for under roughly 2,800 euros. The market is also remarkably resilient: after the takedown of the RedLine and META infostealers (Operation Magnus, October 2024), use of the Lumma stealer rose by more than 350 percent between the first and second half of 2024; ENISA continues to assess infostealers as a fixed link in the cybercriminal supply chain.
Dark Web Monitoring as an Early Warning System
How to detect compromised credentials, mentions of your company and data leaks before attackers exploit them – and where the limits of the approach lie.
Stolen credentials are a commodity today: infostealer malware harvests them at scale from infected devices, initial access brokers refine them into ready-made network access, ransomware groups buy in. Dark web monitoring watches the sources of this underground economy – forums, marketplaces, Telegram channels, leak sites – and raises an alert when data related to your own company surfaces there. Used correctly, it creates a window of time between data exfiltration and exploitation in which an incident can still be prevented. This article explains how the underground market works, what monitoring can realistically deliver, what a robust response process looks like, and how the approach fits into NIS2 and DORA.
The Essentials at a Glance
Six topic blocks — tap to expand.
The underground economy at a glance
Three roles in a division-of-labour market — tap a tab.
- Exfiltrate credentials, session cookies and browser data from infected devices and bundle them into stealer logs.
- Stealer logs are traded on marketplaces and in Telegram channels.
- After the takedown of RedLine and META (Operation Magnus, October 2024), Lumma use rose by more than 350 percent — ENISA continues to assess infostealers as a fixed link in the cybercriminal supply chain.
- Turn raw data such as stealer logs into verified network access and sell it on.
- According to ENISA, the trend is towards low-priced, high-volume offerings — the majority of accesses trade for under roughly 2,800 euros.
- The leak sites of ransomware groups publish stolen data sets.
- Combolists aggregate email-password combinations from old and new leaks.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ENISA Threat Landscape 2025
Analyses infostealers as a fixed link in the cybercriminal supply chain, price trends among initial access brokers, and takedowns such as Operation Magnus (reporting period 07/2024–06/2025).
2026 Data Breach Investigations Report
Documents the infostealer-to-ransomware pipeline: 73% of ransomware victims with a preceding infostealer or credential-leak event, half of them within 95 days before the attack.
Die Lage der IT-Sicherheit in Deutschland 2025
Documents, for the reporting period 07/2024–06/2025, a growing number of leak victims and credential thefts; 72 percent of reported ransomware attacks were accompanied by data leaks.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2) with the risk management measures (including risk analysis and incident handling) and Art. 23 with the reporting deadlines of 24 hours/72 hours/one month.
Verordnung (EU) 2022/2554 (DORA)
Art. 13(1) obliges financial entities to gather information on vulnerabilities and cyber threats; Art. 26 governs TLPT; applicable since 17 January 2025.
Verordnung (EU) 2016/679 (DSGVO)
Art. 33 requires notification of personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours.
Related Services
Do you know what is circulating about your company?
VamiSec offers dark web monitoring as a managed service together with our partner Paranoid Lab – from detection through triage to guided response. Contact us for a no-obligation initial consultation.