Access to Active Sessions Instead of Databases: How the Shadow Market in Russia Has Changed

cryptonews.ruОпубліковано о 2026-08-28Востаннє оновлено о 2026-08-28

Анотація

The Russian cybercriminal underground is shifting from selling massive, stolen corporate databases to trading active, short-term access to user accounts, according to a 2026 report. The value of information intercepted directly from infected devices by malware has risen nearly 13% in a year. Attackers now sell packets containing active session tokens (bypassing passwords and two-factor authentication), live email credentials, VPN and cloud storage logins, and corporate network access. A subscription for a steady stream of fresh data costs $250-$300 per month, far exceeding the value of outdated archives. While Russian regulators have successfully penalized companies for data leaks from centralized storage—with no repeat violations recorded after imposing turnover fines—this framework fails against the new threat model. Malware now steals data *after* it leaves the corporate perimeter and is on a user's personal device, a legal grey area. In 2026, 60% of studied web attacks aimed to steal keys for infiltrating corporate infrastructure. The situation mirrors global trends, akin to the Genesis Market shutdown in 2023, and highlights a structural risk: the demand for "fresh" data incentivizes botnet operators to maintain long-term control of infected devices for recurring revenue. This creates a persistent vulnerability layer between personal devices and corporate networks, currently outside the reach of existing regulatory protections.

The shadow market in Russia has shifted its priorities: instead of selling massive databases stolen from corporations, criminals now trade active, short-term access to user accounts. The cost of information intercepted by malware directly from infected computers and phones has increased by almost 13% over the past year. This was reported by BI.ZONE experts in mid-August 2026. The share of Russian users in this segment reaches 14–18%.

Unlike outdated archives, new packages contain tools for instant penetration into a person's digital environment. Such packages are found to contain:

  • active session tokens allowing login to the system without entering a password;
  • current passwords and direct access to email;
  • credentials for VPN services and cloud storage;
  • administrative access to corporate networks.

A retail archive with outdated information is valued at just $10–15. However, a subscription to a private channel with daily uploads of fresh data costs attackers $250–300 per month. The market is willing to pay for relevance, not volume.

Official statistics create an illusion of full control over the situation. In 2024, Roskomnadzor recorded 135 cases of database distribution containing over 710 million records about Russians. After the introduction of strict sanctions, the number of new large arrays indeed decreased. According to researchers from Smart Business Alert, as published by Kommersant on July 13, 2026, only 54 relevant databases with approximately 24.3 million records were discovered in the first half of 2026.

The state successfully punishes companies for leaks from centralized storage. Since May 2025, a turnover-based fine is provided for a repeat incident. Over a year and a half, starting January 1, 2025, the agency conducted 52 administrative investigations and imposed fines totaling 2.6 million rubles, without identifying any repeated violations. This was stated by Deputy Head of Roskomnadzor Milosh Wagner on August 14, 2026. However, this measure is powerless against the new threat model. Malicious software steals data after it has already left the company's secure perimeter and ended up on a person's personal device. Formally, the organization's database is not compromised, and the regulatory mechanism simply does not trigger.

Vulnerability of Corporate Infrastructure

Intercepting data on the end device allows bypassing multi-level protection. A stolen active session token often enables login to the system without re-authentication and bypassing two-factor verification. In the first half of 2026, 6 out of 10 web attacks studied by specialists were aimed precisely at obtaining keys to penetrate companies' internal infrastructure. One infected employee computer can turn a secure network into an open resource, explaining the high demand for fresh data.

A similar gap between regulator intentions and reality is observed in the field of telephone communication. Since September 1, 2025, organizational calls must be accompanied by the sender's name and category. However, already on January 27, 2026, the operators of the "big four" stopped displaying the "bank" label on calls from Sberbank, VTB, and Alfa-Bank due to the absence of contracts for the labeling service. This was reported by RBC. Later, these credit organizations, together with Sovcombank, proposed changing the rules for mass calls, deeming some requirements excessively difficult to implement.

This situation does not indicate a connection between legal marketing and cybercrime. It demonstrates that even the largest market players, interested in customer trust, face the inconvenience of new infrastructure rules. The user is forced to independently navigate the flow of commercial offers, warnings, and fraudulent attempts arriving through the same channels.

Russian regulators have made the mass dumping of databases economically unprofitable for companies. Criminal groups have adapted by switching to the targeted extraction of active access keys. Such an attack exists in the gap between the corporate perimeter and the personal device, where administrative responsibility mechanisms do not apply. As operations move to remote formats, the value of a short-lived token providing access to several services simultaneously will only grow, leaving this vulnerability zone outside the scope of existing protection norms.

AI Opinion

From the perspective of machine data analysis, the current turn of the shadow market in Russia repeats a scenario already experienced by global cybercrime several years ago. A similar model was offered by the darknet marketplace Genesis Market: session tokens, browser "fingerprints," and bypassing two-factor verification—this platform was shut down in April 2023 by Europol and law enforcement from 17 countries, detaining over a hundred buyers. International experience shows: such operations shift the point of sale but do not eliminate the source—device infection by info-stealers continues regardless of the fate of a specific platform, and new channels quickly replace closed ones.

The situation also highlights a structural risk left outside the article's scope: demand for "fresh" data creates an incentive for botnet operators to keep an infected machine operational for as long as possible, turning it into a source of constant income rather than a one-time asset for sale. Will regulators manage to develop a tool to influence this intermediate layer between the personal device and the corporate perimeter, or will it remain outside the control zone?

end-content

Пов'язані питання

QWhat is the new priority on Russia's shadow market, according to the article?

AInstead of selling massive corporate databases, criminals are now prioritizing the trade of active, short-term access to user accounts, such as active session tokens.

QWhat do the new data packages traded on the shadow market typically contain?

AThey contain tools for instant intrusion, including active session tokens, current passwords and direct email access, credentials for VPN services and cloud storage, and administrative access to corporate networks.

QWhat regulatory action has the Russian government taken against data leaks, and why is it ineffective against the new threat model?

ARoskomnadzor has imposed fines on companies for leaks from centralized databases. However, this is ineffective because the new malware steals data after it leaves the company's secure perimeter and is on a user's personal device, meaning the corporate database is not formally compromised.

QWhat specific type of attack was most common in web attacks during the first half of 2026, according to the article?

A6 out of 10 studied web attacks in the first half of 2026 were aimed at obtaining keys (like session tokens) to penetrate companies' internal infrastructure.

QAccording to the AI opinion section, what is a key structural risk highlighted by the shift to this new cybercrime model?

AThe demand for 'fresh' data creates an incentive for botnet operators to keep infected machines operational for as long as possible, turning them into a continuous source of income rather than a one-time asset for sale.

Пов'язані матеріали

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

SlowMist has identified a fake GitHub repository impersonating Alibaba's Qwen 3.8 27B AI model, which contains an information-stealing virus. The repository, created in August 2026, offered a download file of only 487 KB, far smaller than a legitimate 27-billion-parameter model (over 16 GB). The malicious ZIP file contained a Lua-based script disguised as a certificate, which deploys the StealC malware. Once executed, StealC harvests system data, takes screenshots, and steals browser credentials, cryptocurrency wallet information, and more, sending it to attacker-controlled servers. The malware also includes a backup system that can read new server addresses from the Polygon blockchain if the primary server is taken down. This incident is part of a broader campaign called FakeGit, active since March 2025, which has created thousands of malicious repositories. Approximately 800 of these specifically target AI tools using a method called AgentBaiting, sometimes tricking AI assistants into recommending them. Separate reports detail hundreds of other fake GitHub repositories spreading malware like BoryptGrab and campaigns like Megalodon that generate thousands of clones rapidly. Attackers copy legitimate projects, create convincing documentation, and even list them on public AI registries to appear trustworthy. The fake repositories exploit the high demand for open-source AI capabilities, putting users who run models locally at significant risk of data theft.

cryptonews.ru1 год тому

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

cryptonews.ru1 год тому

Торгівля

Спот
活动图片