Close Menu
geekfence.comgeekfence.com
    What's Hot

    Instagram looks to take on streaming services with longer-form, episodic and live formats for its TV app

    June 22, 2026

    EchoStar to change stock ticker to ‘ECHO’

    June 22, 2026

    SpaceX wants to build AI data centers in space. Will it work?

    June 22, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»A Glimpse into the “Search Your Target” Market for Stolen Credentials
    Cyber Security

    A Glimpse into the “Search Your Target” Market for Stolen Credentials

    AdminBy AdminJune 22, 2026No Comments7 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    A Glimpse into the “Search Your Target” Market for Stolen Credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A Glimpse into the “Search Your Target” Market for Stolen Credentials

    Threat actors are increasingly turning massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for a specific company, platform, domain, geography, or account type.

    Flare researchers analyzed 470 underground forum posts published between January 2025 and June 2026, across different sources, related to actors offering to search for and extract stolen credentials from their databases. The dataset included advertisements, reposts, buyer feedback, pricing references, and disputes around quality and validity.

    The findings show a dedicated service layer sitting between infostealer infections, raw logs trading and account takeover activity. The profile of the threat actors who offer these services is divided between the Malware-as-a-Service (MaaS) providers and the MaaS consumers.

    In many cases, they function as credential brokers or data processors, monetizing the vast number of logs and their ability to search, filter, format, and deliver targeted results from large stolen credential collections.

    Key Points

    • Analysis of 470 underground posts illustrates a pinpointed service that offers targeted extraction, filtering, deduplication, formatting, and freshness, from large infostealers databases containing tens of billions of lines. It is functioning as an alternative to combo lists, where instead of purchasing a bulk dump, buyers query a seller’s existing data and receive only the results that match their target.

    • The market overlaps with the Initial Access Broker (IAB) ecosystem, but is not identical to it, when the common output formats included URL:LOGIN:PASS, MAIL:PASS, LOGIN:PASS, PHONE:PASS, MAIL:PHONE, and MAIL:LOGIN.

    • Interestingly buyer feedback showed there’s a gap between what is advertised and the actual results in terms of in reality the volume is lower, the credentials are often invalid, duplicated and generally usable.

    How Does the “Search Your Target” Service Work

    The “search your target” market sits in the middle of the account takeover chain.

    First, infostealers infect devices and collect credentials, cookies, autofill data, and browser artifacts. Then logs are aggregated and inserted into private clouds, ULP databases, public dumps, or exchange-based collections. Next, the “search-service” threat actors extract rows based on buyers’ requests. Buyers then validate the credentials and use them for account takeover, fraud, spam, phishing, crypto theft, or corporate intrusion.

    This means the sellers in this dataset are often neither the first nor final step. They are the processing layer that turns stolen credential noise into targeted attack material.

    Figure 1 – the
    Figure 1 – the “search your target” flow

    From a threat intelligence framework perspective, this service model represents a practical example of T1589.001 (Gather Victim Identity Information: Credentials), where adversaries actively research and acquire credentials prior to exploitation, and potentially T1650 (Acquire Access), given that some sellers deliver results indistinguishable from direct access provisioning.

    From GitHub access sales to leaked vendor repositories, the warning signs exist — they’re just buried in forums and marketplaces most teams aren’t watching.

    Flare surfaces them before they become incidents.

    Start Monitoring for Supply-Chain Exposure For Free

    The “Search Your Target” Market Economy

    Much like in the DDoS market, where the buyer submits a domain and the service provider attacks it, the service is duplicated and offers the same pipeline. 

    1. A buyer sends a target

    2. The seller returns matching credentials

    That target can be a company domain, login URL, ecommerce site, gaming platform, application, geographic market, or a list of emails. The output is usually delivered in formats such as URL:LOGIN, URL:LOG, MAIL, LOGIN, PHONE, or other combinations depending on the request.

    Several sellers in the underground specify the size of their database as a selling point. One actor advertised an “ULP 5kkk+ lines” database (5,000,000,000), quick access within 10–15 minutes, daily updates, and sources that allegedly included private logs, private clouds, personal streams, and public data. Another actor promoted a 10kkk+ line, 1TB+ URL:LOG database, while others claimed access to collections ranging from hundreds of millions to tens of billions of records.

    Screenshot taken from Flare’s platform.
    Sign up for the free trial to access if you aren’t already a customer.

    The size of the database isn’t the only selling point. Threat actors also indicate  other capabilities, as part of their sales pitch. The sellers are also advertising their search capabilities, freshness, formatting, and relevance.

    Some offer simple domain extraction, while others offer more customized services, such as extracting email accounts for a requested shop, website, app, or game. De-facto, attackers are advertising their technical capabilities of indexing data inside databases, updating and enabling quick and convenient search on it.

    As an example, one of the sellers advertised that customers could submit a request for only $20 per request, and add additional payment based on the returned results.

    Screenshot taken from the forum of one of the posts in the dataset
    Screenshot taken from the forum of one of the posts in the dataset

    The dataset also showed more advanced forms of credential enrichment. One actor claimed access to separate email, password, login, phone, and URL:Login collections, and described how those records could be combined.

    For example, a buyer with only an email list could request matching login pairs, or a buyer looking for a specific geography could receive results built from country codes, domains, URLs, cities, and password patterns.

    This further indicates that threat actors are using data best practices (e.g. labeling, slicing), much like ordinary legitimate businesses around the world.

    Customers Feedback Shows a Gap Between Ads and Reality

    Customer feedback indicates that the sellers are over-promising and under-delivering. They claim that some sellers aren’t credible. Some claim that the credentials are invalid, and sellers answer in return that they didn’t ever check if the credentials were valid. Some said that this is the same data that appears in large combo lists published for free across the underground.

    Others claim that these databases contain many duplications (one even claimed that out of 3,000 records only 200 were unique).

    While the concept of large combo lists or aggregated credential files, isn’t new. This service is still something unique that can eventually, if operated correctly,  put a lot of businesses and organizations at risk.

    Developed Alongside the Infostealers Market

    Over the past several years, infostealer families and log marketplaces produced enormous quantities of records that include browser-stored credentials, cookies, autofill data, and device information. These collections are constantly growing and create a challenge for buyers to sort it out for profit.

    The operation to more easily extract value was an opportunity for commercialization. Therefore, a buyer who usually has a specific pinpointed goal can save time and money with this service.

    Comparison Between the “Search Your Target” Market and the IAB Market

    The “search your target” market is often tied to a  general search for an email or business or person, the validity and “freshness” of access isn’t guaranteed, and you are basically paying for search, find, and results. This market partially overlaps with the initial access broker’s (IAB) market.

    When buyers are looking for access to corporate VPNs, SaaS platforms, email accounts, cloud environments, admin panels, or remote access systems, the output can become initial access if these markets overlap.

    Nevertheless, the IAB market is often more expensive, prestigious and serves as a “white glove service” when they sell validated access, which often can bypass MFA, and ultimately  get into an organization.

    What Defenders Should Learn

    The “search your target” market shows that attackers no longer need to manually process massive dumps to find what matters. They can outsource that work to sellers who specialize in turning noisy credential collections into focused target lists. For defenders, the challenge is to identify and close those exposed paths before a buyer turns them into access.

    Flare helps by giving security teams visibility into these underground markets and by monitoring exposed employee credentials, corporate domains, login portals, SaaS applications, and related indicators across deep and dark web sources.

    This allows organizations to detect when their access points appear in credential collections or search-service advertisements, prioritize the most relevant exposures, and respond faster with password resets, session revocation, MFA enforcement, and investigation of possible account misuse.

    Learn more by signing up for our free trial.

    Sponsored and written by Flare.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    June 21, 2026

    ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security

    June 20, 2026

    Inside Gentlemen’s EDR killer framework

    June 19, 2026

    Jeff Bezos’ Blue Origin Targets 2026 Rocket Launch After Cape Canaveral Explosion

    June 18, 2026

    Lean IT, future-ready: Why adopting WPA3 for Wi‑Fi 7 is easier than you think

    June 17, 2026

    Maine forced to take down data breach portal after fake notices filed with authorities

    June 16, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202555 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202630 Views

    Redefining AI efficiency with extreme compression

    March 25, 202627 Views
    Don't Miss

    Instagram looks to take on streaming services with longer-form, episodic and live formats for its TV app

    June 22, 2026

    Instagram is exploring new formats in an apparent effort to bring its platform to more…

    EchoStar to change stock ticker to ‘ECHO’

    June 22, 2026

    SpaceX wants to build AI data centers in space. Will it work?

    June 22, 2026

    Google Spent $2.7 Billion to Keep Noam Shazeer, OpenAI Got Him Anyway |

    June 22, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Instagram looks to take on streaming services with longer-form, episodic and live formats for its TV app

    June 22, 2026

    EchoStar to change stock ticker to ‘ECHO’

    June 22, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.