Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem 2026-9-26 14:34:26 Author: securityaffairs.com(查看原文) 阅读量:5 收藏

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Pierluigi Paganini September 26, 2026

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades.

Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement press releases don’t.

The dump contains 9,647 registered members, 13,925 threads, and 80,891 posts. The researcher who analyzed it had been reading Russian-language forums since those years and expected to recognize the layout. What surprised them wasn’t the marketplace threads selling shells and credit cards next to botnet rental offers. It was how many of the people from 2005 are still on the boards twenty years later.

The forum’s section list in 2005 sat malware analysis, spam, carding, and vulnerability testing right next to car tuning, mobile phones, games, and general chat. That wasn’t ironic. It was the actual culture. About a third of everything written on Exploit.in in those years was people talking about their phones and each other. The biggest single section was the marketplace at 10,377 posts, but the car section and the humor board weren’t far behind the technical areas.

“Most writing about Russian cybercrime forums calls them marketplaces, and they were. What the writing tends to leave out is that they were also where a lot of teenagers went to talk about cars and phones.” reads the report published by Ransomnews. “Both things happened in the same place with the same accounts, and nobody on the board seems to have found that strange.”

The post timing confirms this. Activity climbed from nine in the morning Moscow time, held through the afternoon, and peaked at ten at night. Weekends ran about eight percent quieter than weekdays. That’s not a professional criminal operation running shifts. That’s people with school or a job in the day and the forum in the evening.

The membership numbers are also revealing. Of the 9,647 registered accounts, 5,843, or 60.6%, never posted anything. Another 15% posted only once. Just 82 accounts made more than 200 posts, while the top 1% of members were responsible for 52.6% of all posts.

In practice, Exploit.in had around 90 active users and several thousand people who mainly read the content. This helps explain why shutting down a forum may have less impact than it appears. As the researcher points out, those 90 active users could simply move to another forum and register new accounts in a few hours.

The forum’s tiered structure was already in place in 2005, using a standard forum installation. Two password-protected sections were reserved for private material, including stolen credit cards, bank accounts and discussions that users did not want to have in public.

The researcher sees a clear connection between this early structure and today’s ransomware operations, where groups often vet potential affiliates before giving them access to their panels. The basic model was already there in 2005, although it operated on a much smaller scale.

Trust worked differently without escrow. The forum ran two public lists, one for people who had ripped others off, one for people considered reliable enough to do business with. That model breaks down once a forum gets large enough that no one can vouch personally for a handle. In private message archives from later ransomware forums, the researcher found that 11.8% of conversations on RAMP and 8.8% on XSS mention a paid guarantor or escrow service, the modern replacement for those early reputation lists.

The most striking part of the analysis is the continuity. The researcher cross-referenced the full 2005 to 2008 member list against private message archives from five later forums, including XSS, RAMP, and BreachForums. After stripping generic handles that two unrelated people might independently choose, 205 distinctive handles appear in both periods. Twenty-six of those had 20 or more posts on Exploit, meaning they were genuine active members rather than dormant accounts. Thirteen had over a hundred posts.

The researcher isn’t publishing those handles, and the reasoning is worth quoting directly from the piece: the database contains email addresses, IP addresses, and password hashes for 9,647 people, and most of them were kids arguing about Nokia handsets who were never accused of anything. The number is what can be published. Even that number is a ceiling, because a shared handle isn’t proof of a shared person.

“Of 9,647 registered members, 5,843 never posted once.” states the report. “That is 60.6% of the whole forum. Another 15% posted exactly one time. Only 82 accounts ever got past 200 posts, and the top 1% of members wrote 52.6% of everything on the board.”

What it does suggest is that the standard narrative about Russian cybercrime, constant churn, crews forming and collapsing and a younger generation replacing them, is only true at the visible layer. The people who reached the public record were mostly the ones who got caught. Underneath them, a couple of hundred people who were trading ICQ numbers and pay-per-install in 2005 are still on the boards in the ransomware era. They weren’t the famous ones then. They’re not the famous ones now. That’s probably why they’re still there.

The infrastructure evolved with them. Reputation lists became escrow services. Access tiers became affiliate vetting. The section that sold shells and initial accesses became what the industry now calls the initial access broker market. As the researcher puts it, looking at how ransomware-as-a-service is structured today.

“The reputation lists turned into escrow services, the access tiers turned into affiliate vetting, and the section that sold shells and accesses turned into what we now call the initial access market.” Danchev concludes. “I do not think the ransomware-as-a-service model would look unfamiliar to anyone who was on Exploit in 2006. The scale is different. The design is not.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Exploit.in)




文章来源: https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html
如有侵权请联系:admin#unsafe.sh