Cryptocurrency Theft Detailed Report: Sold for Only $105 on the Dark Web

marsbitXuất bản vào 2025-12-29Cập nhật gần nhất vào 2025-12-29

Tóm tắt

Phishing attacks go beyond stealing credentials through fake links. Stolen data is quickly commodified on the dark web. This report traces how data is collected via email, Telegram bots, and administration panels (like BulletProofLink), then sold and reused in future attacks. Data types range from instantly monetizable information (bank cards, e-wallet logins) to data used for follow-up attacks (account credentials, phone numbers) or targeted schemes (biometric data, ID scans). Analysis shows 88.5% of attacks in early 2025 aimed to steal online account credentials. On dark web markets, data is packaged, validated, and sold—often via Telegram—with prices varying based on account age, balance, and attached services. Old leaked data remains dangerous, as criminals compile comprehensive digital profiles for highly targeted attacks like whaling. Once stolen, it doesn’t disappear. Users must use unique passwords, enable multi-factor authentication, and monitor their digital footprint to reduce risk.

Author: Olga Altukhova Editor: far@Centreless

Compiled by: Centreless X(Twitter)@Tocentreless

Typical phishing attacks often involve users clicking on a fraudulent link and entering their credentials on a fake website. However, the attack is far from over at this point. Once sensitive information falls into the hands of cybercriminals, it immediately becomes a commodity, entering the "pipeline" of the dark web market.

In this article, we will trace the flow path of stolen data: from data collection through various tools (such as Telegram bots and advanced admin panels), to the sale of the data and its subsequent use in new attacks. We will explore how once-leaked usernames and passwords are integrated into vast digital profiles, and why data leaked years ago can still be exploited by criminals to carry out targeted attacks.

Data Collection Mechanisms in Phishing Attacks Before tracking the subsequent whereabouts of stolen data, we first need to understand how this data leaves the phishing page and reaches the cybercriminals.

Through the analysis of real phishing pages, we have identified the following most common data transmission methods:

  • Sent to an email address
  • Sent to a Telegram bot
  • Uploaded to an admin panel

It is worth mentioning that attackers sometimes use legitimate services for data collection to make their servers harder to detect. For example, they may use online form services like Google Forms, Microsoft Forms, etc. Stolen data may also be stored on GitHub, Discord servers, or other websites. However, for the convenience of this analysis, we will focus on the main data collection methods mentioned above.

Email

The data entered by the victim into the HTML form on the phishing page is sent to the attacker's server via a PHP script, which then forwards it to an email address controlled by the attacker. However, due to the many limitations of email services—such as delivery delays, the possibility of the hosting provider banning the sending server, and operational inconvenience when handling large amounts of data—this method is gradually decreasing.

Phishing kit contents

For example, we once analyzed a phishing kit targeting DHL users. The index.php file contained a phishing form for stealing user data (here, email address and password).

Phishing form imitating the DHL website

The information entered by the victim is then sent to the email address specified in the mail.php file via a script in the next.php file.

Contents of the PHP scripts

Telegram Bot

Unlike the method above, scripts using a Telegram bot specify a Telegram API URL containing a bot token and corresponding Chat ID, rather than an email address. In some cases, this link is even hardcoded into the phishing HTML form. Attackers design detailed message templates to be automatically sent to the bot upon successful data theft. A code example is as follows:

Code snippet for data submission

Compared to sending data via email, using a Telegram bot provides phishers with stronger functionality, which is why this method is becoming increasingly popular. Data is transmitted to the bot in real-time, and the operator is notified immediately. Attackers often use disposable bots, which are harder to track and ban. Furthermore, its performance does not depend on the quality of the phishing page hosting service.

Automated Admin Panels

More sophisticated cybercriminals use specialized software, including commercial frameworks like BulletProofLink and Caffeine, often provided as "Platform as a Service" (PaaS). These frameworks provide a web interface (dashboard) for phishing campaigns, facilitating centralized management.

All data collected by the phishing pages controlled by the attacker is aggregated into a unified database and can be viewed and managed through their account interface.

Sending data to the administration panel

These admin panels are used to analyze and process victim data. Specific functions vary depending on the panel's customization options, but most dashboards typically have the following capabilities:

  • Real-time statistics classification: View the number of successful attacks by time, country, and support data filtering
  • Automatic verification: Some systems can automatically verify the validity of stolen data, such as credit card information or login credentials
  • Data export: Support downloading data in various formats for subsequent use or sale

Example of an administration panel

Admin panels are a key tool for organized cybercrime groups.

It is worth noting that a single phishing campaign often employs multiple data collection methods simultaneously.

Data Types Coveted by Cybercriminals

The data stolen in phishing attacks varies in value and purpose. In the hands of criminals, this data is both a means of profit and a tool for carrying out complex multi-stage attacks.

Based on their use, stolen data can be divided into the following categories:

  • Immediate Monetization: Directly selling raw data in bulk, or immediately stealing funds from the victim's bank account or e-wallet
  1. Bank card information: Card number, expiration date, cardholder name, CVV/CVC code
  2. Online banking and e-wallet accounts: Login name, password, and one-time two-factor authentication (2FA) verification codes
  3. Accounts linked to bank cards: Login credentials for online stores, subscription services, or payment systems like Apple Pay/Google Pay
  • Used for subsequent attacks for further monetization: Using stolen data to launch new attacks for more gains
  1. Credentials for various online accounts: Usernames and passwords. It is worth noting that even without a password, just the email or phone number used as a login name has value to attackers
  2. Phone numbers: Used for phone scams (such as tricking users into giving 2FA codes) or phishing via instant messaging apps
  3. Personal Identifiable Information (PII): Full name, date of birth, address, etc., often used for social engineering attacks
  • Used for targeted attacks, extortion, identity theft, and deepfakes
  1. Biometric data: Voice, facial images
  2. Scanned copies and numbers of personal documents: Passport, driver's license, social security card, taxpayer identification number, etc.
  3. Selfies with documents: Used for online loan applications and identity verification
  4. Corporate accounts: Used for targeted attacks against businesses

We analyzed phishing and scam attacks that occurred between January and September 2025 to determine the data types most frequently targeted by criminals. The results showed: 88.5% of attacks aimed to steal various online account credentials, 9.5% targeted personal identity information (name, address, date of birth), and only 2% focused on stealing bank card information.

Selling Data on the Dark Web Market

Apart from being used for real-time attacks or immediate monetization, most stolen data is not used immediately. Let's take a deeper look at its flow path:

1. Data Packaged for Sale

After being consolidated, data is sold on dark web markets in the form of "data dumps"—compressed packages often containing millions of records from various phishing attacks and data breaches. A data dump may sell for as low as $50. The main buyers are often not active scammers, but dark web data analysts, the next link in the supply chain.

2. Classification and Verification

Dark web data analysts filter the data by type (email accounts, phone numbers, bank card information, etc.) and run automated scripts for verification. This includes checking the validity of the data and its potential—for example, whether a set of Facebook account passwords can also log into Steam or Gmail. Since users tend to use the same password on multiple websites, data stolen from a service years ago may still be applicable to other services today. Verified accounts that can still log in normally are sold at a higher price.

Analysts also correlate and integrate user data from different attack incidents. For example, an old social media leaked password, login credentials obtained from a phishing form impersonating a government portal, and a phone number left on a scam website may all be compiled into a complete digital profile of a specific user.

3. Sale on Specialized Markets

Stolen data is usually sold through dark web forums and Telegram. The latter is often used as an "online store," displaying prices, buyer reviews, and other information.

Offers of social media data, as displayed in Telegram

Account prices vary greatly, depending on many factors: account age, balance, linked payment methods (bank card, e-wallet), whether two-factor authentication (2FA) is enabled, and the popularity of the service platform. For example, an e-commerce account linked to an email, with 2FA enabled, a long usage history, and a large number of order records, will be sold at a higher price; for game accounts like Steam, expensive game purchase records increase their value; and online banking data involving high-balance accounts from reputable banks commands a significant premium.

The table below shows examples of prices for various types of accounts found on dark web forums as of 2025*.

4. High-Value Target Screening and Targeted Attacks

Criminals pay particular attention to high-value targets—users who hold important information, such as corporate executives, accountants, or IT system administrators.

Here is a possible scenario for a "whaling" attack: Company A has a data breach containing information on an employee who previously worked there and is now an executive at Company B. The attackers use Open Source Intelligence (OSINT) analysis to confirm that the user is currently employed at Company B. They then carefully forge a phishing email that appears to be from the CEO of Company B and send it to the executive. To enhance credibility, the email even cites some facts about the user from the previous company (of course, the attack methods are not limited to this). By lowering the victim's vigilance, criminals have the opportunity to further infiltrate Company B.

It is worth noting that such targeted attacks are not limited to the corporate sphere. Attackers may also target individuals with high bank account balances, or users holding important personal documents (such as those required for micro-loan applications).

Key Takeaways

The flow of stolen data is like an efficiently operating pipeline, with each piece of information becoming a commodity with a clear price tag. Today's phishing attacks widely use diverse systems to collect and analyze sensitive information. Once data is stolen, it quickly flows into Telegram bots or the attacker's admin panels, where it is then classified, verified, and monetized.

We must be清醒地认识到清醒地认识到 (clearly aware): Once data is leaked, it does not disappear into thin air. On the contrary, it is constantly accumulated, integrated, and may be used months or even years later to carry out targeted attacks, extortion, or identity theft against the victims. In today's online environment, staying vigilant, setting unique passwords for each account, enabling multi-factor authentication, and regularly monitoring one's digital footprint are no longer suggestions, but necessities for survival.

If you unfortunately become a victim of a phishing attack, please take the following measures:

  1. If bank card information is leaked, immediately call the bank to report the loss and freeze the card.
  2. If account credentials are stolen, immediately change the password for that account, and also change the passwords for all other online services that use the same or similar passwords. Be sure to set a unique password for each account.
  3. Enable multi-factor authentication (MFA/2FA) on all supported services.
  4. Check the account's login history and terminate any suspicious sessions.
  5. If your instant messaging or social media account is stolen, immediately notify friends and relatives, reminding them to be wary of fraudulent messages sent in your name.
  6. Use professional services (such as Have I Been Pwned, etc.) to check if your data has appeared in known data breach incidents.
  7. Be highly vigilant of any unexpected emails, phone calls, or promotional information you receive—they may seem credible precisely because attackers are using your leaked data.

Câu hỏi Liên quan

QWhat are the three most common methods for transmitting stolen data from phishing pages to cybercriminals?

AThe three most common methods are: sending to an email address, sending to a Telegram bot, and uploading to an administration panel.

QWhy are cybercriminals increasingly using Telegram bots over email for data collection?

ATelegram bots provide real-time data transmission, immediate notifications to the operator, are harder to track and block, and their performance is not dependent on the quality of the phishing page hosting service.

QWhat percentage of phishing and scam attacks from January to September 2025 aimed to steal online account credentials?

A88.5% of the attacks aimed to steal various online account credentials.

QWhat is the typical first step in the 'pipeline' of stolen data after it is collected and before it is used in new attacks?

AThe data is packaged and sold as 'dumps' on dark web marketplaces, often for as little as $50.

QAccording to the article, what is one crucial step a victim should take if their online account credentials are stolen?

AThey should immediately change the password for that account and also change the passwords for all other online services where the same or a similar password was used, ensuring a unique password for every account.

Nội dung Liên quan

Mô hình "Ox Alpha" bí ẩn gây sốt, miễn phí có hạn

Vào tháng 8, cộng đồng mô hình lớn (LLM) xuất hiện một trò chơi đoán tên đầy thú vị. Một mô hình ẩn danh tên "Ox Alpha" (được người dùng Trung Quốc gọi vui là "Ngưu Lai" - "Trâu đến") đột ngột xuất hiện trên OpenRouter, gây chú ý với khả năng lập trình ấn tượng. Mô hình này sở hữu ngữ cảnh lên tới 1 triệu token, hỗ trợ đa phương thức (văn bản, hình ảnh, video), có thể gọi công cụ và hiện đang miễn phí. Trong các bài kiểm tra năng lực kỹ thuật phần mềm thực tế DeepSWE, Ox Alpha đạt tỷ lệ hoàn thành nhiệm vụ từ 63% đến 80%, cho thấy tiềm năng mã hóa tầm xa, sánh ngang các mô hình hàng đầu hiện tại. Nguồn gốc của "Ngưu Lai" hiện vẫn là bí ẩn. Nhiều bằng chứng gián tiếp, như tokenizer văn bản và cách mã hóa video tương đồng, hướng đến khả năng đây là phiên bản GLM-5.3 Flash hoặc phiên bản đa phương thức chưa công bố của công ty Trí Phổ (Zhipu AI). Tuy nhiên, chưa có xác nhận chính thức. Cùng thời điểm, một mô hình ẩn danh khác tên "korrine" xuất hiện trên Code Arena càng khiến bức tranh thêm phần hấp dẫn, với nhiều phỏng đoán liên quan đến Kimi, Qwen hay MiMo. Việc các hãng công nghệ "giấu mặt" khi thử nghiệm mô hình giúp thu thập đánh giá khách quan từ người dùng, thực hiện các bài kiểm tra áp lực trước khi chính thức ra mắt, và đồng thời cũng tạo ra hiệu ứng marketing thu hút sự chú ý và thảo luận từ cộng đồng.

marsbit44 phút trước

Mô hình "Ox Alpha" bí ẩn gây sốt, miễn phí có hạn

marsbit44 phút trước

Matt Hougan, CIO của Bitwise: Nếu bạn hiện tại có 0% cấu hình crypto, đồng nghĩa với việc chủ động bán khống thị trường

Matt Hougan, Giám đốc đầu tư (CIO) của Bitwise Asset Management, nhận định rằng việc cấu hình danh mục đầu tư 0% tiền mã hóa hiện nay tương đương với việc chủ động kỳ vọng thị trường giảm sâu. Ông chỉ ra rằng trong bối cảnh tổng tài sản toàn cầu là 670 nghìn tỷ USD, với vốn hóa thị trường crypto khoảng 2,5 nghìn tỷ USD, một tỷ trọng trung lập sẽ rơi vào khoảng 2%. Do đó, cấu hình 0% là một lựa chọn cực kỳ bi quan. Hougan nêu bật sự nghịch lý: thị trường crypto đã giảm 50% từ đỉnh, nhưng các tổ chức Phố Wall như BlackRock, Morgan Stanley, Wells Fargo, UBS lại đang tăng cường tham gia. Họ xem đây là một lớp tài sản hình thành trong 10 năm tới, không quan tâm nhiều đến biến động ngắn hạn. Bằng chứng là BlackRock công bố quỹ mã hóa trên Ethereum ngay khi Đạo luật CLARITY bị trì hoãn, còn Morgan Stanley phê duyệt ETF Solana ngay trong đợt suy giảm thị trường. Ông cho rằng thị trường gấu kết thúc trong sự thờ ơ, và Bitcoin hiện không còn phản ứng với tin xấu (như AI stocks lao dốc, Saylor bán BTC hay xác suất thông qua CLARITY giảm). Điều này cho thấy những người muốn bán đã bán xong, số còn lại là những người tin tưởng lâu dài. Sự đi ngang của BTC hiện tại là tích cực, vì độ biến động bị nén và có thể bùng nổ mạnh khi tăng trở lại. Về chiến lược đầu tư, Hougan đề xuất mức cấu hình 5% cho crypto. Ở tỷ trọng này, danh mục nhận được lợi ích đa dạng hóa rõ rệt, cải thiện lợi nhuận mà hầu như không làm tăng thêm rủi ro tổng thể (biến động vẫn chủ yếu do cổ phiếu chi phối). Ông nhấn mạnh rằng con số 5% này dựa trên phân tích lợi nhuận/rủi ro, chứ không phải vì lợi ích kinh doanh của Bitwise. Cuối cùng, Hougan lạc quan về triển vọng dài hạn. Ông dự báo giá ETH có thể đạt 8.000 USD, được thúc đẩy bởi làn sóng mã hóa tài sản thế giới thực (RWA) và stablecoin, đồng thời cho rằng không gian quản lý tài sản trên chuỗi sẽ phát triển mạnh mẽ trong 3-6 tháng tới.

marsbit50 phút trước

Matt Hougan, CIO của Bitwise: Nếu bạn hiện tại có 0% cấu hình crypto, đồng nghĩa với việc chủ động bán khống thị trường

marsbit50 phút trước

Ngay lúc này, trận đấu quần vợt đầu tiên trên thế giới giữa người và máy bắt đầu, robot cứu bóng cực hạn khiến Trịnh Khiết sửng sốt

"Lần đầu tiên trên thế giới: Trận đấu quần vợt người-máy trực tiếp với sự tham gia của robot hình người Trung Quốc Ngày 22/8, tại Đại hội Thể thao Robot hình người Thế giới lần thứ hai, một khoảnh khắc lịch sử đã diễn ra: trận đấu quần vợt đơn đầu tiên trên thế giới giữa huyền thoại quần vợt Trịnh Khiết và robot hình người 'Ngân Hà Tinh Tử' do Ngân Hà Thông Dụng phát triển. Robot đã thể hiện khả năng ấn tượng: di chuyển linh hoạt, thực hiện các cú đánh thuận tay, trái tay, phát bóng với tốc độ trên 100km/h, và thậm chí tự đứng dậy sau khi ngã. Đặc biệt, trong trận đấu đôi hỗn hợp, robot đã phối hợp nhịp nhàng với đối tác con người. Đằng sau màn trình diễn đột phá này là mô hình trí tuệ thể hiện 'Ngân Hà Tinh Não' (AstraBrain). Khác với kiến trúc phân tầng truyền thống (não bộ ra lệnh, tiểu não điều khiển vận động), AstraBrain tích hợp cả tư duy chiến thuật và điều khiển vận động toàn thân vào trong một mô hình thống nhất, giúp giảm thiểu độ trễ và tổn thất thông tin. Mô hình được huấn luyện qua hai giai đoạn chính: đầu tiên học từ dữ liệu chuyển động không hoàn hảo của con người để có hiểu biết cơ bản, sau đó tiến vào thế giới ảo để hàng triệu trí tuệ nhân tạo tự đấu với nhau, tiến hóa và 'tự nảy sinh' các kỹ năng phức tạp như cứu bóng hay đứng dậy sau ngã, trước khi được chuyển giao nguyên vẹn sang robot thật. Trận đấu không đơn thuần là một màn trình diễn thể thao. Nó đánh dấu một bước tiến lớn trong trí tuệ thể hiện, nơi AI không chỉ tư duy trong thế giới số như AlphaGo mà còn có thể hoạt động, ra quyết định và thích nghi trong môi trường vật lý đầy biến động và áp lực thời gian thực. Khoảnh khắc 'AstraTennis' này chứng minh sức mạnh công nghệ của Trung Quốc trong kỷ nguyên mới, nơi carbon và silicon cùng tồn tại."

marsbit1 giờ trước

Ngay lúc này, trận đấu quần vợt đầu tiên trên thế giới giữa người và máy bắt đầu, robot cứu bóng cực hạn khiến Trịnh Khiết sửng sốt

marsbit1 giờ trước

Bất ngờ, DeepSeek thông báo áp dụng giá thấp cả ngày cuối tuần, từ nay làm việc cuối tuần sẽ có lợi hơn?

Sáng nay, DeepSeek thông báo điều chỉnh quy tắc tính phí API theo giờ cao điểm và giờ thấp điểm. Từ 00:00 ngày 23/8 theo giờ Bắc Kinh, các ngày cuối tuần (Thứ Bảy và Chủ Nhật) sẽ không còn phân biệt giờ cao điểm, mà toàn bộ thời gian sẽ được tính theo mức giá thấp điểm. Thông báo này lập tức gây xôn xao trong cộng đồng nhà phát triển. Với các nhà phát triển, đây là tin tốt vì họ có thể yên tâm chạy các tác vụ hàng loạt vào cuối tuần để tiết kiệm chi phí, do giá cao điểm trước đây cao gấp đôi giá thấp điểm. Một số người dùng thậm chí nói rằng họ có thể hoàn thành công việc cả tuần trong hai ngày cuối tuần và hóa đơn giảm một nửa. Tuy nhiên, người lao động bắt đầu lo ngại rằng các công ty có thể điều chỉnh lịch làm việc theo khung giờ tính phí này, chẳng hạn như bố trí làm việc vào cuối tuần và nghỉ bù vào ngày thường. Trên thực tế, xu hướng này đã xuất hiện trong ngành công nghiệp phim ngắn, nơi các nhiệm vụ kết xuất tốn kém thường được lên lịch vào ban đêm để tận dụng giá tính toán rẻ hơn. Gần đây, một lập trình viên đã chia sẻ rằng công ty của họ áp dụng chế độ chấm công mới, yêu cầu làm việc một ngày cuối tuần và điều chỉnh giờ nghỉ trưa theo khung giờ tính phí token, nhằm mục đích tiết kiệm chi phí. Có nhiều suy đoán về lý do điều chỉnh. Một số cho rằng giá cao điểm có thể tương ứng với thời gian DeepSeek huấn luyện mô hình nội bộ, và cuối tuần nhân viên nghỉ làm nên chuyển sang giá thấp điểm. Những người khác nghi ngờ lý do này, cho rằng quá trình huấn luyện mô hình hoàn toàn tự động. Dù nguyên nhân là gì, quy tắc tính phí mới đã chính thức có hiệu lực.

marsbit1 giờ trước

Bất ngờ, DeepSeek thông báo áp dụng giá thấp cả ngày cuối tuần, từ nay làm việc cuối tuần sẽ có lợi hơn?

marsbit1 giờ trước

Con ngựa ô lớn nhất của AI thanh toán, có lẽ là Coinbase đã cho Agent một chiếc ví

Trong lĩnh vực thanh toán AI, mọi người thường chú ý đến các gã khổng lồ như Visa hay OpenAI, nhưng Coinbase đã âm thầm trở thành nền tảng vận hành thực tế lớn nhất cho giao dịch Agent. Dữ liệu cho thấy hơn 90% giao dịch Agent trên chuỗi xảy ra trên Base - mạng lưới Layer 2 của Coinbase, 99% giao dịch thương mại Agent sử dụng USDC và hơn 97% sử dụng giao thức x402. Điểm khác biệt then chốt: Coinbase không chỉ cung cấp giao thức thanh toán, mà tạo ra "ví riêng" cho Agent. Vào tháng 2/2026, họ ra mắt Agentic Wallets - cơ sở hạ tầng ví được thiết kế riêng để Agent có thể tự nắm giữ tài sản, chuyển tiền và thực hiện giao dịch một cách tự chủ dưới sự kiểm soát rủi ro được lập trình. Điều này giải quyết các vấn đề của thanh toán thẻ thông thường trong các giao dịch vi mô, tần suất cao giữa các máy với nhau: phí cao, cần xác nhận thủ công và khó truy vết. Coinbase sở hữu một vòng tròn khép kín hiếm có: ví (Agentic Wallets), chuỗi (Base), giao thức (x402) và tài sản (USDC, cbBTC). Điều này cho phép trải nghiệm thanh toán hoàn chỉnh trong hệ sinh thái của họ. Vị thế dẫn đầu này hình thành một phần do sự chuẩn bị sẵn có từ trước: Base ban đầu được xây dựng để mở rộng hệ sinh thái on-chain, x402 là giao thức thanh toán máy-máy, và chúng tình cờ phù hợp hoàn hảo cho nhu cầu của nền kinh tế Agent khi nó bùng nổ. Bài học rút ra là: việc triển khai thanh toán AI không chỉ phụ thuộc vào tiêu chuẩn nào hợp lý nhất, mà còn vào việc cơ sở hạ tầng nào đã sẵn sàng ngay khi nhu cầu xuất hiện. Coinbase có thể không phải là người chiến thắng cuối cùng, nhưng hiện tại họ là người dẫn đầu nhờ nắm bắt được làn sóng nhu cầu đầu tiên này.

marsbit2 giờ trước

Con ngựa ô lớn nhất của AI thanh toán, có lẽ là Coinbase đã cho Agent một chiếc ví

marsbit2 giờ trước

Giao dịch

Giao ngay
活动图片