Cryptocurrency Theft Detailed Report: Sold for Only $105 on the Dark Web

marsbitXuất bản vào 2025-12-29Cập nhật gần nhất vào 2025-12-29

Tóm tắt

Phishing attacks go beyond stealing credentials through fake links. Stolen data is quickly commodified on the dark web. This report traces how data is collected via email, Telegram bots, and administration panels (like BulletProofLink), then sold and reused in future attacks. Data types range from instantly monetizable information (bank cards, e-wallet logins) to data used for follow-up attacks (account credentials, phone numbers) or targeted schemes (biometric data, ID scans). Analysis shows 88.5% of attacks in early 2025 aimed to steal online account credentials. On dark web markets, data is packaged, validated, and sold—often via Telegram—with prices varying based on account age, balance, and attached services. Old leaked data remains dangerous, as criminals compile comprehensive digital profiles for highly targeted attacks like whaling. Once stolen, it doesn’t disappear. Users must use unique passwords, enable multi-factor authentication, and monitor their digital footprint to reduce risk.

Author: Olga Altukhova Editor: far@Centreless

Compiled by: Centreless X(Twitter)@Tocentreless

Typical phishing attacks often involve users clicking on a fraudulent link and entering their credentials on a fake website. However, the attack is far from over at this point. Once sensitive information falls into the hands of cybercriminals, it immediately becomes a commodity, entering the "pipeline" of the dark web market.

In this article, we will trace the flow path of stolen data: from data collection through various tools (such as Telegram bots and advanced admin panels), to the sale of the data and its subsequent use in new attacks. We will explore how once-leaked usernames and passwords are integrated into vast digital profiles, and why data leaked years ago can still be exploited by criminals to carry out targeted attacks.

Data Collection Mechanisms in Phishing Attacks Before tracking the subsequent whereabouts of stolen data, we first need to understand how this data leaves the phishing page and reaches the cybercriminals.

Through the analysis of real phishing pages, we have identified the following most common data transmission methods:

  • Sent to an email address
  • Sent to a Telegram bot
  • Uploaded to an admin panel

It is worth mentioning that attackers sometimes use legitimate services for data collection to make their servers harder to detect. For example, they may use online form services like Google Forms, Microsoft Forms, etc. Stolen data may also be stored on GitHub, Discord servers, or other websites. However, for the convenience of this analysis, we will focus on the main data collection methods mentioned above.

Email

The data entered by the victim into the HTML form on the phishing page is sent to the attacker's server via a PHP script, which then forwards it to an email address controlled by the attacker. However, due to the many limitations of email services—such as delivery delays, the possibility of the hosting provider banning the sending server, and operational inconvenience when handling large amounts of data—this method is gradually decreasing.

Phishing kit contents

For example, we once analyzed a phishing kit targeting DHL users. The index.php file contained a phishing form for stealing user data (here, email address and password).

Phishing form imitating the DHL website

The information entered by the victim is then sent to the email address specified in the mail.php file via a script in the next.php file.

Contents of the PHP scripts

Telegram Bot

Unlike the method above, scripts using a Telegram bot specify a Telegram API URL containing a bot token and corresponding Chat ID, rather than an email address. In some cases, this link is even hardcoded into the phishing HTML form. Attackers design detailed message templates to be automatically sent to the bot upon successful data theft. A code example is as follows:

Code snippet for data submission

Compared to sending data via email, using a Telegram bot provides phishers with stronger functionality, which is why this method is becoming increasingly popular. Data is transmitted to the bot in real-time, and the operator is notified immediately. Attackers often use disposable bots, which are harder to track and ban. Furthermore, its performance does not depend on the quality of the phishing page hosting service.

Automated Admin Panels

More sophisticated cybercriminals use specialized software, including commercial frameworks like BulletProofLink and Caffeine, often provided as "Platform as a Service" (PaaS). These frameworks provide a web interface (dashboard) for phishing campaigns, facilitating centralized management.

All data collected by the phishing pages controlled by the attacker is aggregated into a unified database and can be viewed and managed through their account interface.

Sending data to the administration panel

These admin panels are used to analyze and process victim data. Specific functions vary depending on the panel's customization options, but most dashboards typically have the following capabilities:

  • Real-time statistics classification: View the number of successful attacks by time, country, and support data filtering
  • Automatic verification: Some systems can automatically verify the validity of stolen data, such as credit card information or login credentials
  • Data export: Support downloading data in various formats for subsequent use or sale

Example of an administration panel

Admin panels are a key tool for organized cybercrime groups.

It is worth noting that a single phishing campaign often employs multiple data collection methods simultaneously.

Data Types Coveted by Cybercriminals

The data stolen in phishing attacks varies in value and purpose. In the hands of criminals, this data is both a means of profit and a tool for carrying out complex multi-stage attacks.

Based on their use, stolen data can be divided into the following categories:

  • Immediate Monetization: Directly selling raw data in bulk, or immediately stealing funds from the victim's bank account or e-wallet
  1. Bank card information: Card number, expiration date, cardholder name, CVV/CVC code
  2. Online banking and e-wallet accounts: Login name, password, and one-time two-factor authentication (2FA) verification codes
  3. Accounts linked to bank cards: Login credentials for online stores, subscription services, or payment systems like Apple Pay/Google Pay
  • Used for subsequent attacks for further monetization: Using stolen data to launch new attacks for more gains
  1. Credentials for various online accounts: Usernames and passwords. It is worth noting that even without a password, just the email or phone number used as a login name has value to attackers
  2. Phone numbers: Used for phone scams (such as tricking users into giving 2FA codes) or phishing via instant messaging apps
  3. Personal Identifiable Information (PII): Full name, date of birth, address, etc., often used for social engineering attacks
  • Used for targeted attacks, extortion, identity theft, and deepfakes
  1. Biometric data: Voice, facial images
  2. Scanned copies and numbers of personal documents: Passport, driver's license, social security card, taxpayer identification number, etc.
  3. Selfies with documents: Used for online loan applications and identity verification
  4. Corporate accounts: Used for targeted attacks against businesses

We analyzed phishing and scam attacks that occurred between January and September 2025 to determine the data types most frequently targeted by criminals. The results showed: 88.5% of attacks aimed to steal various online account credentials, 9.5% targeted personal identity information (name, address, date of birth), and only 2% focused on stealing bank card information.

Selling Data on the Dark Web Market

Apart from being used for real-time attacks or immediate monetization, most stolen data is not used immediately. Let's take a deeper look at its flow path:

1. Data Packaged for Sale

After being consolidated, data is sold on dark web markets in the form of "data dumps"—compressed packages often containing millions of records from various phishing attacks and data breaches. A data dump may sell for as low as $50. The main buyers are often not active scammers, but dark web data analysts, the next link in the supply chain.

2. Classification and Verification

Dark web data analysts filter the data by type (email accounts, phone numbers, bank card information, etc.) and run automated scripts for verification. This includes checking the validity of the data and its potential—for example, whether a set of Facebook account passwords can also log into Steam or Gmail. Since users tend to use the same password on multiple websites, data stolen from a service years ago may still be applicable to other services today. Verified accounts that can still log in normally are sold at a higher price.

Analysts also correlate and integrate user data from different attack incidents. For example, an old social media leaked password, login credentials obtained from a phishing form impersonating a government portal, and a phone number left on a scam website may all be compiled into a complete digital profile of a specific user.

3. Sale on Specialized Markets

Stolen data is usually sold through dark web forums and Telegram. The latter is often used as an "online store," displaying prices, buyer reviews, and other information.

Offers of social media data, as displayed in Telegram

Account prices vary greatly, depending on many factors: account age, balance, linked payment methods (bank card, e-wallet), whether two-factor authentication (2FA) is enabled, and the popularity of the service platform. For example, an e-commerce account linked to an email, with 2FA enabled, a long usage history, and a large number of order records, will be sold at a higher price; for game accounts like Steam, expensive game purchase records increase their value; and online banking data involving high-balance accounts from reputable banks commands a significant premium.

The table below shows examples of prices for various types of accounts found on dark web forums as of 2025*.

4. High-Value Target Screening and Targeted Attacks

Criminals pay particular attention to high-value targets—users who hold important information, such as corporate executives, accountants, or IT system administrators.

Here is a possible scenario for a "whaling" attack: Company A has a data breach containing information on an employee who previously worked there and is now an executive at Company B. The attackers use Open Source Intelligence (OSINT) analysis to confirm that the user is currently employed at Company B. They then carefully forge a phishing email that appears to be from the CEO of Company B and send it to the executive. To enhance credibility, the email even cites some facts about the user from the previous company (of course, the attack methods are not limited to this). By lowering the victim's vigilance, criminals have the opportunity to further infiltrate Company B.

It is worth noting that such targeted attacks are not limited to the corporate sphere. Attackers may also target individuals with high bank account balances, or users holding important personal documents (such as those required for micro-loan applications).

Key Takeaways

The flow of stolen data is like an efficiently operating pipeline, with each piece of information becoming a commodity with a clear price tag. Today's phishing attacks widely use diverse systems to collect and analyze sensitive information. Once data is stolen, it quickly flows into Telegram bots or the attacker's admin panels, where it is then classified, verified, and monetized.

We must be清醒地认识到清醒地认识到 (clearly aware): Once data is leaked, it does not disappear into thin air. On the contrary, it is constantly accumulated, integrated, and may be used months or even years later to carry out targeted attacks, extortion, or identity theft against the victims. In today's online environment, staying vigilant, setting unique passwords for each account, enabling multi-factor authentication, and regularly monitoring one's digital footprint are no longer suggestions, but necessities for survival.

If you unfortunately become a victim of a phishing attack, please take the following measures:

  1. If bank card information is leaked, immediately call the bank to report the loss and freeze the card.
  2. If account credentials are stolen, immediately change the password for that account, and also change the passwords for all other online services that use the same or similar passwords. Be sure to set a unique password for each account.
  3. Enable multi-factor authentication (MFA/2FA) on all supported services.
  4. Check the account's login history and terminate any suspicious sessions.
  5. If your instant messaging or social media account is stolen, immediately notify friends and relatives, reminding them to be wary of fraudulent messages sent in your name.
  6. Use professional services (such as Have I Been Pwned, etc.) to check if your data has appeared in known data breach incidents.
  7. Be highly vigilant of any unexpected emails, phone calls, or promotional information you receive—they may seem credible precisely because attackers are using your leaked data.

Câu hỏi Liên quan

QWhat are the three most common methods for transmitting stolen data from phishing pages to cybercriminals?

AThe three most common methods are: sending to an email address, sending to a Telegram bot, and uploading to an administration panel.

QWhy are cybercriminals increasingly using Telegram bots over email for data collection?

ATelegram bots provide real-time data transmission, immediate notifications to the operator, are harder to track and block, and their performance is not dependent on the quality of the phishing page hosting service.

QWhat percentage of phishing and scam attacks from January to September 2025 aimed to steal online account credentials?

A88.5% of the attacks aimed to steal various online account credentials.

QWhat is the typical first step in the 'pipeline' of stolen data after it is collected and before it is used in new attacks?

AThe data is packaged and sold as 'dumps' on dark web marketplaces, often for as little as $50.

QAccording to the article, what is one crucial step a victim should take if their online account credentials are stolen?

AThey should immediately change the password for that account and also change the passwords for all other online services where the same or a similar password was used, ensuring a unique password for every account.

Nội dung Liên quan

Sau ba quý liên tiếp suy giảm, thị trường tiền điện tử có thể đón cửa sổ ổn định trong quý III?

Thị trường tiền mã hóa vừa trải qua quý tồi tệ nhất kể từ năm 2022, với vốn hóa giảm 12.6% xuống 2.1 nghìn tỷ USD, khối lượng giao dịch sụt giảm và dòng tiền rút mạnh khỏi các quỹ ETF Bitcoin. Bitcoin và Ethereum lần lượt giảm 14.2% và 25.4% trong quý, đánh dấu sự đảo ngược so với mối tương quan trước đây với các tài sản rủi ro như Nasdaq. Dòng vốn ETF chứng khoán Mỹ ghi nhận dòng ròng rút khoảng 46.7 tỷ USD trong quý II, báo hiệu áp lực bán. Tuy nhiên, dấu hiệu tích cực ban đầu xuất hiện khi các nhà đầu tư dài hạn bắt đầu tích lũy trở lại và dòng ETF có đợt thu hút ngắn hạn. Toàn bộ thị trường hiện tập trung vào cuộc họp của Cục Dự trữ Liên bang Mỹ (FOMC) vào cuối tháng 7. Các tín hiệu chính sách tiền tệ sẽ quyết định xu hướng: tín hiệu ôn hòa có thể đẩy Bitcoin lên vùng 68,000-84,000 USD, trong khi lập trường cứng rắn có thể kéo giá về vùng 50,000-56,000 USD. Tiến trình pháp lý của Đạo luật CLARITY gần như đình trệ, làm giảm kỳ vọng và gia tăng phí rủi ro cho toàn ngành. Trong bối cảnh ảm đạm, hai lĩnh vực nổi bật là thị trường dự đoán (tăng trưởng 48.7%) và bộ sưu tập kỹ thuật số được mã hóa (tăng ~143%), cho thấy sự chuyển dịch nhu cầu thực tế. Nhìn chung, thị trường thiếu động lực cho một đợt tăng trưởng mạnh dựa trên tâm lý. Các quyết định giao dịch trong quý III sẽ chủ yếu xoay quanh diễn biến giá, lựa chọn chính sách và kỳ vọng lãi suất.

marsbitHôm qua 08:39

Sau ba quý liên tiếp suy giảm, thị trường tiền điện tử có thể đón cửa sổ ổn định trong quý III?

marsbitHôm qua 08:39

Giao Dịch SpaceX, Đã Mở Khóa: SPCXON Được Giao Dịch Trên WEEX

SpaceX đã thực hiện đợt IPO lớn nhất lịch sử vào tháng 6/2026, nhưng nhiều nhà giao dịch không thể tiếp cận do các rào cản như hạn chế môi giới và khu vực. Sàn giao dịch tiền điện tử WEEX đã giới thiệu SPCXON/USDT, một công cụ token hóa cho phép tiếp cận biến động giá của SpaceX thông qua tài khoản crypto được quyết toán bằng USDT, mà không cần môi giới Mỹ hay tài khoản ngân hàng. Sản phẩm này, xây dựng trên nền tảng cổ phiếu token hóa của Ondo, dành cho các nhà giao dịch bên ngoài Hoa Kỳ. Trường hợp đầu tư dựa trên đà tăng doanh thu Starlink và các cột mốc Starship, trong khi các yếu tố cần thận trọng bao gồm định giá cao, lượng cổ phiếu lưu hành công chúng ít và sự kiện mở khóa cổ phiếu nội bộ sắp tới. Lưu ý quan trọng: SPCXON cung cấp mức tiếp xúc với hiệu quả kinh tế, không phải quyền sở hữu cổ phiếu trực tiếp, và có thể giao dịch ở mức cao hơn hoặc thấp hơn giá trị tài sản ròng. WEEX tích hợp SPCXON cùng các sản phẩm TradFi token hóa khác như MicroStrategy (MSTRON) và Micron (MUON) vào một tài khoản thống nhất, cho phép luân chuyển giữa crypto và cổ phiếu dễ dàng. Sàn cũng đang chạy chiến dịch TradFi Trading Challenge với quỹ thưởng $50,000.

TheNewsCryptoHôm qua 08:32

Giao Dịch SpaceX, Đã Mở Khóa: SPCXON Được Giao Dịch Trên WEEX

TheNewsCryptoHôm qua 08:32

BIT Trading Hours: BTC Vẫn Chịu Áp Lực Từ Đường MA 200 Tuần, Bị Từ Chối Có Thể Tái Khởi Động Đợt Giảm, Ngành Lưu Trữ và Bán Dẫn Tăng Mạnh Đêm Qua Bắt Đầu Giảm Trong Khung Giờ Giao Dịch Ban Đêm

Bitcoin (BTC) hiện giao dịch quanh mức $66,000, đối mặt với vùng kháng cự mạnh gần $68,000 - nơi tập trung nhiều lệnh mua trước đó có thể chốt lời. Về mặt kỹ thuật, BTC đang nằm giữa đường trung bình động 200 tuần (MA ~$63,333) và đường trung bình động hàm mũ 200 tuần (EMA ~$68,328). Việc không thể vượt qua mức $68,000 có thể kéo giá về kiểm tra lại vùng hỗ trợ $63,000. Thị trường hiện có tính thanh khoản thấp và được xem là đang trong đợt phục hồi nhẹ. Trên thị trường chứng khoán Mỹ, các chỉ số tương lai giảm nhẹ. Nhóm cổ phiếu bán dẫn và lưu trữ, vốn tăng mạnh vào đêm trước, đã điều chỉnh giảm trong phiên giao dịch ngoài giờ. Tuy nhiên, Super Micro Computer (SMCI) tăng mạnh sau báo cáo doanh thu và đơn đặt hàng tích cực. Dầu thô tăng (trên $91) và lợi suất trái phiếu kho bạc Mỹ tăng cao tiếp tục gây áp lực lên thị trường cổ phiếu và làm dấy lên lo ngại lạm phát. Tại châu Á, thị trường Hàn Quốc phục hồi nhẹ cùng với cổ phiếu công nghệ, trong khi Nhật Bản thận trọng do đồng Yên yếu kỷ lục. Các sự kiện quan trọng sắp tới bao gồm báo cáo thu nhập từ các gã khổng lồ công nghệ như Alphabet, Tesla, IBM; sự kiện AI của AMD; và cuộc họp chính sách tiền tệ của Ngân hàng Trung ương châu Âu.

marsbitHôm qua 08:31

BIT Trading Hours: BTC Vẫn Chịu Áp Lực Từ Đường MA 200 Tuần, Bị Từ Chối Có Thể Tái Khởi Động Đợt Giảm, Ngành Lưu Trữ và Bán Dẫn Tăng Mạnh Đêm Qua Bắt Đầu Giảm Trong Khung Giờ Giao Dịch Ban Đêm

marsbitHôm qua 08:31

Chủ tịch CFTC cũ, Chủ tịch Circle Tarbert: Một mặt khuyên bạn chủ nghĩa dài hạn, mặt kia tự mình thoái vốn 30 triệu USD

Tác giả: Zen, PANews Trước tình cảnh cổ phiếu Circle (CRCL) giảm 70% so với đỉnh và bị hạ xếp hạng, Chủ tịch Heath Tarbert - cựu Chủ tịch CFTC - trong một cuộc phỏng vấn ngày 14/7 đã kêu gọi các nhà đầu tư kiên nhẫn và tập trung vào tầm nhìn dài hạn của công ty. Tuy nhiên, hành động của ông lại trái ngược hoàn toàn. Kể từ khi Circle IPO, Tarbert đã không ngừng bán cổ phiếu CRCL thông qua kế hoạch giao dịch 10b5-1 được lập trước, thu về tổng cộng khoảng 30 triệu USD. Ông chưa từng mua lại cổ phiếu trên thị trường mở, ngay cả khi giá cổ phiếu lao dốc. Bài viết nêu bật sự mâu thuẫn giữa lời nói "chủ nghĩa dài hạn" và hành động "thoái vốn" mạnh tay của Tarbert. Sự nghiệp của ông được mô tả là điển hình của "cánh cửa xoay" chính trị-thương mại Mỹ: từ các vị trí cấp cao tại Bộ Tài chính và CFTC, ông nghỉ hưu chỉ 27 ngày trước khi gia nhập Citadel Securities - một nhà tạo lập thị trường lớn - vào thời điểm công ty này đang đối mặt với cuộc điều tra của Quốc hội sau sự kiện GameStop. Sau đó, ông chuyển sang Circle, nơi ông được cho là đã sử dụng kinh nghiệm và quan hệ quản lý để giúp công ty vượt qua các rào cản pháp lý và niêm yết thành công. Bài báo đặt câu hỏi liệu Tarbert có thực sự tin vào tương lai dài hạn của Circle hay không, khi mà ông liên tục chốt lời trong khi lại khuyên các cổ đông nhỏ lẻ giữ vị thế. Nó gợi ý rằng mô hình của ông là tận dụng tối đa kiến thức về chu kỳ chính sách và cơ hội thị trường để biến các nguồn lực và uy tín tích lũy được thành lợi thế nghề nghiệp và tài chính cá nhân, trong khi rủi ro dài hạn được chuyển sang cho các nhà đầu tư tin tưởng vào những tường thuật công khai của ông.

marsbitHôm qua 08:08

Chủ tịch CFTC cũ, Chủ tịch Circle Tarbert: Một mặt khuyên bạn chủ nghĩa dài hạn, mặt kia tự mình thoái vốn 30 triệu USD

marsbitHôm qua 08:08

Gate Research: Làn sóng "phố Wall hóa" trong các sản phẩm tài chính tiền điện tử - Cạnh tranh hay Hội tụ?

Gate Research Institute: Sự hòa hợp hay cạnh tranh trong làn sóng "phố Wall hóa" các sản phẩm tài chính tiền mã hóa? Từ tầm nhìn ban đầu về một hệ thống tài chính phi tập trung, loại bỏ trung gian của Bitcoin, thị trường tiền mã hóa đang chứng kiến sự hội tụ mạnh mẽ với tài chính truyền thống (TradFi). Các quỹ ETF Bitcoin, tài sản thế giới thực được mã hóa (RWA) và trái phiếu chính phủ trên chuỗi cho thấy các tổ chức như BlackRock, Fidelity đang đưa tài sản mã hóa vào hệ thống phát hành, định giá, lưu ký và phân phối truyền thống. Tuy nhiên, đây không phải là một trò chơi tổng bằng không. Xu hướng này thể hiện sự bổ sung lẫn nhau: TradFi cung cấp khung pháp lý, mạng lưới phân phối rộng và sự tin cậy, trong khi Crypto mang lại tính mở, thanh khoản toàn cầu 24/7 và khả năng thanh toán lập trình được. Hai hướng đi tiêu biểu minh chứng cho sự hội tụ hai chiều: các sàn giao dịch tiền mã hóa (CEX) như Gate mở rộng sang giao dịch cổ phiếu thực, ETF thông qua cơ sở hạ tầng môi giới truyền thống; trong khi các công ty môi giới truyền thống như Robinhood tích hợp tài sản mã hóa và phát triển tài sản mã hóa (như cổ phiếu mã hóa) để thu hút người dùng. Mục tiêu chung của cả hai hướng là tranh giành "tài khoản tài chính tổng hợp" thế hệ tiếp theo - một điểm vào duy nhất nơi người dùng có thể giao dịch đa dạng tài sản từ cổ phiếu, tiền mã hóa đến RWA. Sự tăng trưởng mạnh mẽ của thị trường RWA, đặc biệt là cổ phiếu mã hóa, bất chấp xu hướng thị trường giảm, cho thấy đây là một xu hướng cấu trúc thực sự. Kết luận, "phố Wall hóa" không có nghĩa là thị trường tiền mã hóa bị TradFi thôn tính. Thay vào đó, đây là một sự chuyển đổi hai chiều, nơi cả hai hệ thống đang cùng nhau định hình lại thị trường vốn thành một cấu trúc hỗn hợp hiệu quả và toàn cầu hơn, với trải nghiệm người dùng liền mạch cho nhiều loại tài sản khác nhau.

marsbitHôm qua 08:06

Gate Research: Làn sóng "phố Wall hóa" trong các sản phẩm tài chính tiền điện tử - Cạnh tranh hay Hội tụ?

marsbitHôm qua 08:06

Giao dịch

Giao ngay
活动图片