Like a real life video game, the online stores on Hydra employ drug dealers known as kladmen (“treasuremen” or “droppers”), whose job is to stash drugs in GPS-tagged hiding spots ready for pick up by online buyers. It’s a street-tech workaround in a country where the postal system is slow and unreliable and regular street drug dealing is highly risky. Hydra has a strict way of doing business and code of conduct overseen by a central hub.
Top Cybersecurity Discord Servers To Join
There aren’t many barriers to registration on XSS—new users simply select credentials, input a valid email, answer a basic cybersecurity question, and await approval from the site’s admin. This forum is a predominantly Russian language forum with a marketplace section where cybercriminals trade in stolen credit card details, malware, and even zero-day exploits. Interestingly, this forum is accessible via both standard Internet browsers on the clear web and via the dark web using the Tor browser. Nemesis Market is a relatively new wallet-less shop on dark web where you don’t need to deposit any amount in your wallet before buying products from here. The platform allows buyers to review the vendor’s products and services, so it’s easy for them to decide if the vendor is reputable or just scamming them. You can see all the product categories the marketplace deals with on the homepage.
Bonus: The Silk Road
There are several similar projects including HYDRA and Russian Silkroad (now a part of HYDRA) RuTor, WayAway, Bazaar, Anthill, as well as several other smaller sites. “Make your business successful with RAMP! Immediate sales!” the site’s advertisement to potential dealers reads in Russian. “Sellers of quality hashish, amphetamine, and cocaine in Moscow, we’re waiting for you.” But after every law enforcement crackdown shakes the dark web, one Russian black market always seems to survive.
Automated High-Risk Exposure Monitoring
As part of these activities, numerous agencies, such as the Federal Bureau of Investigation (FBI), the Drug Enforcement Administration (DEA), and Europol, collaborate to share intelligence, carry out investigations, and make arrests. In the weeks following RAMP’s closure, this reporter also noticed a surge in individual shops selling drugs to Russian-speaking users. RAMP’s sudden closure most likely drove the rise in new Russian shops for illegal products on the Dark Web.

649,096,027 (2465 Billion) Account Usernames And Passwords Have Been Leaked By Cyber Criminals Till Now In 2022
This breach was part of a wider cluster of four breaches that targeted various underground cybercrime forums within a short time span. The conversations align with the widely held view that threat actors running major cybercrime operations need to have a “krysha” (“roof”—that is, protector) in law enforcement. The forum is a predominantly Russian-language forum with a marketplace section where cybercriminals trade stolen credit card information, malware, and even zero-day exploits.

Russian Authorities Announce Takedown Of RAMP Dark Web Marketplace
Dread, founded in 2018 by a threat actor known as HugBunter, is often referred to as the “Reddit of the dark web” due to its similar interface. While Dread is one of the largest forums on the dark web, it is somewhat unique in that discussions on drug sales often overshadow those on hacking and cybercrime. However, recent trends have shown an increase in hacking-related topics, making Dread more relevant to the cybercrime community. In 2016, Nulled made headlines when it suffered a massive data breach that exposed the personal information of its users. This incident underscored the inherent risks of participating in such forums, but it didn’t diminish Nulled’s popularity.
Infostealer Unmasker: Turning Digital Traces Into Real World Identities
- Yes, some can use the dark web for good reasons, like whistleblowers and journalists, and the dark web offers them anonymity.
- Many of the tools sold on Russianmarket, such as phishing kits or ransomware, have been linked to major cybercrime syndicates that target individuals, corporations, and even governments.
- Despite the arrest of Pompompurin in March 2023, the forum was revived under the leadership of ShinyHunters, a group notorious for major data breaches targeting companies like Microsoft’s GitHub and Tokopedia.
- The French subforum, in particular, is the most active, highlighting the forum’s international reach.
- The site used to be known as DaMaGeLaB from 2013 until the arrest of an administrator in 2018, at which point it was rebranded as XSS.
Also, it provides users with an escrow service, which adds an extra layer of trust when they conduct transactions on this notorious platform. Over time, BHF has become a notable forum in the Russian cyber landscape because of its seemingly technically skilled community and an organized structure (hence, authorities aren’t able to seize it yet). Despite all the attacks, blocks, and the constant pressure from the authorities, the forum remains active. Not only do cybercriminals use it, but Dread has also become a go-to source for cybersecurity professionals to spot emerging threats, track criminal groups, and even understand the trends in the dark web market. Never miss a development across illicit communities and protect your assets, stakeholders, and infrastructure by identifying emerging vulnerabilities, security incidents, and ransomware attacks. Sign up for a free trial and see Flashpoint’s extensive collections platform, deep web chatter, and dark web monitoring tools in action.
When RAMP disappeared, legendary Russian marketplace, Hydra witnessed an increase in user registrations and vendor activity while and near clone of RAMP, called MEGA surfaced only earlier this year. For several years, Yahoo was at the apex as the internet’s best web service provider, offering… We review and list tools and products without bias, regardless of potential commissions. Dropmen are charged under article 228 of the Russian criminal code (drug trafficking) and can get slapped with jail terms of up to 20 years, even for relatively small amounts. Sergey was first hit with a seven year sentence, then another court raised it to 13 years.
Easy Steps To Access Dark Web On Your Phone Safely In 2024

In that scenario, it makes it harder to tell where it originated from, its seriousness, and the speed at which it’s spreading when you focus only on one forum – significant info for cybersecurity professionals. The forum suffered a blow in 2018 when the creator was arrested, but despite that, Altenen has soldiered on and remains active today. It has a strict and shady (as you’d expect from such a forum) onboarding process for new members, whereby users must promote the platform by sharing domain links on various platforms like YouTube, X, and several other social networks.
Monitor For Exposed Credentials
Besides, its expertise database expands constantly and covers hacking methods and tools that threat actors can use. Besides, it has a huge and highly active user community that discusses credential lists, hacking tools, email and password combos, vulnerable software, and several other things. It’s so well managed that the platform is multilingual as it features up to 12 language-specific sections, with the French sub-forum being the most active. Moreover, Exploit dark web forum features a highly organized structure as well as membership policies that make it attractive to most threat actors. The controlled and professional landscape has led many people to view the forum as the most reliable source. Its popularity can be as a result to the ease of use on it, as the forum features a clean and accessible design with enhanced moderation and a wider scope of the leak topics and sources.

This article takes a look at the top Russian cybercrime forums worth keeping an eye on in 2023. Originally launched as Payload.bin, it operated as a marketplace for illegal goods—mainly drugs—within Russia. It was also known for offering access to FortiNet VPNs and sharing hacking tools for infiltrations.
Use Cryptocurrency For Transactions
In the case of Maza, forum members logging in were greeted with a message about their data being leaked and the forum being compromised. Verified suffered a similar fate, with unnamed operators hijacking the forum. Exploit is one of the longest-running underground hacking forums, having been launched way back in 2005. As the name suggests, the site’s initial purpose was to provide a place for malicious actors to discuss working exploits for various vulnerabilities. Exploit naturally evolved to encompass discussions about other types of cybercrime activity, from social engineering techniques to tutorials on breaking cryptographic algorithms.