Huntress researchers John Hammond and Dave Kleinatland take a guided tour through the dark web, covering popular underground forums like BreachForums, XSS, and Exploit. The post explains how these forums operate — from pay-to-play cryptocurrency access and infostealer log markets to creative threat actor marketing tactics like credit card giveaways. It also covers ransomware groups' name-and-shame data leak sites, including Play's countdown timers and FAQ pages for victims. A notable highlight is the ongoing BreachForums drama, where administrator ShinyHunters warned the site had been compromised by law enforcement, and a bounty was posted for an individual called 'Yukari.' The post concludes with a surprising find: threat actors on the dark web were actively testing Huntress' own EDR platform against malware samples.

8m read timeFrom huntress.com
Post cover image
Table of contents
What is the dark web?Dark web forums and marketplaces: XSS, Exploit, and moreBreachForums: The latest in its tumultuous historyRansomware groups pressure victims with ‘name and shame’ sitesChats, sales, and…a Huntress Easter egg?