A report details "search your target" (SYT) services, a market where cybercriminals pay to search stolen credential databases for specific targets. These services aggregate data from multiple breaches, enabling buyers to find compromised accounts for individuals or organizations.
Background
- Russian cybercriminal marketplaces (often on Telegram or darknet forums) openly sell stolen login credentials — usernames, passwords, cookies, and browser fingerprints — for specific targets like corporate employees, executives, or high-value individuals.
- "Search your target" refers to a service where a buyer names a person or company, and the seller checks if they have that target's stolen data on hand, or obtains it via infostealer malware infections.
- Infostealers (e.g., RedLine, Vidar, Raccoon) are malware that silently siphons saved browser credentials, cookies, and autofill data from infected computers, which are then aggregated and sold.
- These stolen credentials are often used for initial access to corporate networks, enabling ransomware attacks, data breaches, or financial fraud.
- The article provides a look at how these markets operate, pricing, and the scale of available data — a growing concern for enterprise security teams.