Over 120,000 computers infected with info-stealing malware, many of which belong to malicious actors, had credentials associated with cybercrime forums, new research conducted by cybersecurity firm Hudson Rock has found.
An analysis of the data collected from computers compromised between 2018 to 2023, revealed that the credentials used for logging into cybercrime forums were generally stronger than credentials for government websites.
Data retrieved from systems infected by info-stealers is often expansive, allowing to determine the real-world identities of hackers based on indicators such as additional credentials, email addresses, phone numbers, computer names, and IP addresses.
The researchers also discovered that the cybercrime forum with the highest amount of infected users is the infamous “Nulled.to” with over 57,000 of compromised users, followed by “Cracked.io" (19, 062) and "Hackforums.net" (13,366).
It was also found that “Breached.to” was the forum with the strongest user passwords, while the one with the weakest user passwords was the Russian site “Rf-cheats.ru”.
The vast majority of info-stealer infections were attributed to Redline, followed by Raccoon and Azorult. The top 5 countries from which hackers were infected and had at least 1 credential to a hacker forum include Tunisia (7.55%), Malaysia (6%), Belgium (5.14%), the Netherlands (4.8%), and Israel (4.43%).