34 Russian Cybercrime Groups Stole Over 50 Million Passwords with Stealer Malware

Share:

As many as 34 Russian-speaking gangs distributing information-stealing malware under the stealer-as-a-service model stole no fewer than 50 million passwords in the first seven months of 2022.

“The underground market value of stolen logs and compromised card details is estimated around $5.8 million,” Singapore-headquartered Group-IB said in a report shared with The Hacker News.

Aside from looting passwords, the stealers also harvested 2.11 billion cookie files, 113,204 crypto wallets, and 103,150 payment cards.

A majority of the victims are located in the U.S., followed by Brazil, India, Germany, Indonesia, the Philippines, France, Turkey, Vietnam, and Italy. In total, 890,000 devices in 111 countries were infected during the time frame.

Group-IB said the members of several scam groups who are propagating the information stealers previously participated in the Classiscam operation.

 

These groups, which are active on Telegram and have around 200 members on average, are hierarchical, consisting of administrators and workers (or traffers), the latter of whom are responsible for driving unsuspecting users to info-stealers like RedLine and Raccoon.

This is achieved by setting up bait websites that impersonate well-known companies and luring victims into downloading malicious files. Links to such websites are, in turn, embedded into YouTube video reviews for popular games and lotteries on social media, or shared directly with NFT artists.

 

“Administrators usually give workers both RedLine and Racoon in exchange for a share of the stolen data or money,” the company said. “Some groups use three stealers at the same time, while others have only one stealer in their arsenal.”

Following a successful compromise, the cyber criminals peddle the stolen information on the dark web for monetary gain.

The development highlights the crucial role played by Telegram in facilitating a range of criminal activities, including functioning as a hub for announcing product updates, offering customer support, and exfiltrating data from compromised devices.

The findings also follow a new report from SEKOIA, which disclosed that seven different traffers teams have added an up-and-coming information stealer known as Aurora to their toolset.

“The popularity of schemes involving stealers can be explained by the low entry barrier,” Group-IB explained. “Beginners do not need to have advanced technical knowledge as the process is fully automated and the worker’s only task is to create a file with a stealer in the Telegram bot and drive traffic to it.”

https://thehackernews.com/2022/11/34-russian-hacker-groups-stole-over-50.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:22 am, Jul 12, 2025
weather icon 20°C
L: 18° | H: 21°
clear sky
Humidity: 73 %
Pressure: 1018 mb
Wind: 5 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:57 am
Sunset: 9:14 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 21°°C 0 mm 0% 10 mph 70 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 28°°C 0.51 mm 51% 6 mph 66 % 1014 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
19° | 26°°C 0.3 mm 30% 15 mph 60 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 21°°C 0 mm 0% 12 mph 68 % 1018 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
17° | 20°°C 1 mm 100% 13 mph 93 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 19°°C 0 mm 0% 3 mph 70 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 69 % 1018 mb 0 mm/h
Today 10:00 am
weather icon
26° | 26°°C 0 mm 0% 5 mph 46 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 7 mph 32 % 1015 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 10 mph 29 % 1014 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 10 mph 37 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 57 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,615.36
1.74%
Ethereum(ETH)
€2,532.66
0.69%
XRP(XRP)
€2.34
8.23%
Tether(USDT)
€0.86
0.02%
Solana(SOL)
€139.73
-0.08%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.172305
4.24%
Shiba Inu(SHIB)
€0.000011
0.20%
Pepe(PEPE)
€0.000010
0.12%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top