Data Heist: How Stolen Information Becomes a Hot Commodity
RSA Conference 2024 · Track Session
Overview
This talk, titled "Data Heist: How Stolen Information Becomes a Hot Commodity," delivered by David at RSAC 2024, delves into the intricate underworld of stolen data, exploring its intrinsic value, the prevalent methods of theft, and its eventual journey through clandestine criminal marketplaces. The presentation meticulously dissects how malicious actors perceive and monetize various types of personal and corporate information, moving beyond the abstract concept of "data value" to a tangible, market-driven reality. It underscores the critical importance of understanding this ecosystem for both individual users and organizational defenders.

Key moments
- 0:00 Introduction: The intrinsic value of data
- 2:00 Facebook vs. Classmates.com: Your data is payment
- 2:50 Criminals' methods: Focus on Infostealer malware
- 3:25 Infostealers in action: stealing credentials and crypto
- 4:00 Categorizing stolen data: The five actionability tiers
- 4:30 Tier A & B: Cryptocurrency and valuable web credentials
- 6:00 Tier C, D, E: Less liquid data and monetization challenges
Data Heist: How Stolen Information Becomes a Hot Commodity
Speakers: David (Full name, title, and company not provided in the talk bundle)
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=SmuLWMw4faY
Overview
This talk, titled "Data Heist: How Stolen Information Becomes a Hot Commodity," delivered by David at RSAC 2024, delves into the intricate underworld of stolen data, exploring its intrinsic value, the prevalent methods of theft, and its eventual journey through clandestine criminal marketplaces. The presentation meticulously dissects how malicious actors perceive and monetize various types of personal and corporate information, moving beyond the abstract concept of "data value" to a tangible, market-driven reality. It underscores the critical importance of understanding this ecosystem for both individual users and organizational defenders.
The speaker highlights that while the general public, corporations, and governments instinctively recognize data's worth, criminals have also keenly identified it as a primary target. The session focuses heavily on infostealer malware as a dominant threat vector, outlining its capabilities in exfiltrating sensitive information from compromised systems. A core contribution of the talk is its framework for categorizing stolen data based on its "actionability" or liquidity, providing a clear lens through which to assess the immediate financial risk posed by different types of data breaches.
Ultimately, this article aims to provide a comprehensive analysis of the talk, illuminating the mechanisms of data theft, the economics of underground data markets, and the practical defensive strategies necessary to mitigate these evolving threats. By detailing the findings on specific infostealers, their targets, and the global distribution of victim data, the article offers actionable insights for anyone concerned with digital security in an era where information is truly a hot commodity.
Background
▶ Watch: Introduction: The intrinsic value of data (0:00)
The premise of the talk is rooted in the universal, yet often unquantified, value of personal data. The speaker, David, illustrates this with a personal anecdote dating back to 2001, recalling his experience with classmates.com, a website that charged a subscription fee for interaction with old school friends. This contrasted sharply with the rise of Facebook in 2005, which offered similar social networking services for free. David's realization was profound: if Facebook wasn't charging users, its operational costs must be covered by something else – the users' data. This personal history effectively sets the stage, demonstrating how the monetization of personal information, initially a legitimate business model, parallels the illicit market that criminals exploit today.
The problem, as articulated, is that while governments and corporations have long understood the value of data for insights, marketing, and operations, criminals have also come to this realization, making data a primary target for illicit gain. The methods by which criminals steal data are varied, but the presentation zeroes in on four primary vectors: Remote Access Trojans (RATs), database leaks, and most prevalently, infostealer malware. While RATs and database leaks are significant, the talk emphasizes infostealers as the most popular and insidious method in contemporary cybercrime.
Infostealer malware is described as a sophisticated type of malicious software designed to aggressively collect a wide array of sensitive data from an infected PC. These programs excel at locating and exfiltrating information stored in web browsers, such as memorized credentials for e-commerce sites like Amazon, as well as accessing cryptocurrency wallets (e.g., Bitcoin, Coinbase accounts). The existence of these specialized malware families highlights a persistent vulnerability: users often store sensitive information in easily accessible locations on their devices, making them prime targets for automated data exfiltration. The overarching problem addressed by the talk is not just that data is stolen, but understanding what data is targeted, how valuable it is to criminals, and where it ultimately ends up in the underground economy.
Key Findings
▶ Watch: Criminals' methods: Focus on Infostealer malware (2:50)
The talk presents several crucial findings derived from an extensive analysis of infostealer malware capabilities and the associated criminal marketplaces:
- Data Actionability Tiers: A novel classification system was developed, categorizing stolen data into five tiers (A through E) based on its liquidity or actionability – how easily and directly it can be converted into money.
- Tier A (Most Liquid): Cryptocurrency assets (e.g., crypto wallets). These are immediately convertible to cash, akin to physical cash in a stolen wallet.
- Tier B (High Liquidity): Web credentials, particularly email accounts. These require minimal effort to monetize, as email access often facilitates password resets for numerous other online services (Facebook, Twitter, Instagram, YouTube), allowing for account takeover or spamming operations. This is compared to a stolen credit card.
- Tier C (Moderate Effort): Other credentials like gaming accounts. Monetization requires more effort, such as selling virtual assets or exploiting in-game economies, similar to a stolen work badge.
- Tier D (Low Liquidity): Less valuable credentials like FTP passwords or loyalty cards. These require significant creativity and effort to monetize.
- Tier E (Least Liquid): Insignificant data like Wi-Fi passwords or "lint" in a wallet, offering minimal or no direct monetary value to remote attackers.
- Dominant Infostealers: An analysis of the top 16 infostealers revealed significant disparities in their feature sets and popularity.
- Redline emerged as the overwhelmingly most popular infostealer, with over 2 million mentions on VirusTotal, an order of magnitude higher than its closest competitors.
- Lokibot, Mars, and Aurora followed with approximately 200,000 mentions each.
- Niche infostealers like Ducktail (targeting only Facebook web credentials) were found to be far less prevalent and effective.
- Post-Infection Risk Matrix: By combining data actionability (feature set) with popularity (VirusTotal mentions), the research created a post-infection risk matrix. This matrix allows for an assessment of how concerned a victim should be if infected by a specific infostealer. For instance, infection by Redline indicates a very high risk due to its broad data theft capabilities and widespread use, whereas infection by Ducktail poses a much lower, more targeted risk.
- Criminal Marketplaces and Data Pricing: The stolen data is actively traded on dedicated criminal marketplaces, which function much like eBay. These platforms allow buyers to search for specific types of credentials (e.g., amazon.com) and purchase "logs" (stolen data records) for specific prices.
- Prices observed included $10 for a US record containing various web credentials and $2.60 for a Zambian record, potentially including university access.
- The marketplaces are heavily geared towards indexing and selling web credentials, making them highly accessible for buyers.
- Geographical Disparities in Victimization:
- Initial analysis of raw stolen logs showed India, Brazil, and Indonesia as the top countries by volume.
- However, when normalizing for internet user population (logs per million users), a vastly different picture emerged: Portugal stood out as the country with by far the highest percentage of internet users affected, with 56,000 stolen logs from a relatively small internet population of 7.6 million. This was a 100% higher rate than the next highest country, Brazil (50%). The US, by comparison, registered a very low rate, indicating that while it may have high-value targets, the per-user infection rate is significantly lower.
- Data Accessibility on Marketplaces:
- Web credentials are the most easily searchable and indexed data type on these platforms.
- Cryptocurrency records are less indexed but still findable.
- Specific email platforms like Outlook are somewhat searchable.
- Other data, such as screenshots, are much harder to locate and require manual browsing of individual records.
These findings collectively paint a detailed picture of the modern data theft landscape, from the initial compromise to the final sale on underground markets, offering crucial insights for cybersecurity professionals and individuals alike.
Technical Deep Dive
▶ Watch: Infostealers in action: stealing credentials and crypto (3:25)
The technical depth of the talk primarily resides in its methodology for analyzing infostealer malware and its subsequent impact on the criminal marketplaces. The speaker outlined a systematic approach to understanding the value and flow of stolen data.
The core of the analysis began with identifying the capabilities of 16 prominent infostealer malware families. These programs are designed to scour infected systems for specific types of valuable information. For example, they target browser-stored credentials, which are often encrypted but can be decrypted by the malware. This includes usernames and passwords for a vast array of websites (e.g., Amazon, eBay, social media platforms). Beyond browser data, infostealers are adept at locating and exfiltrating cryptocurrency wallet files or associated credentials, which represent direct monetary value. Other targets include FTP client configurations, VPN credentials, and system information, including screenshots.
To quantify the value of the stolen data, the concept of data actionability was introduced, categorizing data into five tiers based on its ease of monetization for criminals:
- Tier A (Cash Equivalent): Cryptocurrency wallets. These are highly liquid; once stolen, the funds are often immediately drained by the initial attacker, representing a direct financial loss.
- Tier B (Credit Card Equivalent): Web credentials, especially email account access. An email account is a gateway to numerous other services via password reset mechanisms. Gaining access to one email can compromise an entire digital identity, making these highly valuable for account takeover, identity theft, or spamming operations.
- Tier C (Work Badge Equivalent): Gaming credentials or other specific service logins. These require more specialized knowledge or effort to monetize, such as selling in-game virtual assets.
- Tier D (Gym Membership Equivalent): Less sensitive credentials like FTP passwords. While providing access to an FTP server, monetizing this access (e.g., by finding valuable data to sell) is often complex and labor-intensive.
- Tier E (Lint Equivalent): Data with negligible immediate value, such as Wi-Fi passwords for a home network. For a remote attacker, exploiting such information offers little direct financial return.
The research then combined the technical capabilities (feature set) of the 16 infostealers with their real-world prevalence. Each infostealer was scored based on the highest tier of data it could steal (e.g., 5 points for Tier A, 1 point for Tier E). To assess popularity, the researchers leveraged VirusTotal, counting mentions of each infostealer. This revealed Redline as an outlier with 2 million mentions, significantly more than Lokibot, Mars, and Aurora (around 200,000 each), and vastly overshadowing less common ones like Ducktail.
These two scores (actionability and popularity) were multiplied to create a post-infection risk matrix. This matrix provides a practical measure for assessing the risk posed by a particular infostealer infection, indicating how much valuable data is likely to be compromised and how widespread that threat is. Redline, due to its high actionability and extreme popularity, topped this risk matrix. Other infostealers like Blackguard and Rhadamanthys also scored highly due to their extensive feature sets, indicating they steal a broad range of valuable data, even if not as popular as Redline.
The talk further detailed the operational mechanics of criminal marketplaces. These platforms operate like e-commerce sites, allowing criminals to buy and sell "logs" containing stolen data. Buyers can search for specific domains (e.g., amazon.com, ebay.com) to find compromised accounts. The marketplaces display a breakdown of the stolen assets within each log, including passwords, domains, and whether a crypto wallet was present. Prices vary, often starting around $10 for a comprehensive US record or $2.60 for a record from a developing country, such as Zambia, which might include university credentials. The speaker explicitly noted that the primary attackers often drain cryptocurrency wallets immediately upon theft, selling only the remaining credentials. However, it was acknowledged that some might simply bulk upload records without prior sifting.
The accessibility of data on these marketplaces was also tiered:
- Web credentials are highly indexed and easily searchable.
- Cryptocurrency information is less indexed but still findable.
- Specific email providers like Outlook have dedicated search capabilities on some platforms.
- All other types of data, such as screenshots or less common credentials, require manual browsing of individual records, making them less accessible.
Finally, the geographical analysis highlighted a critical distinction between raw volume of stolen logs and the per-capita impact. While countries with large internet populations like India, Brazil, and Indonesia show high raw numbers, normalizing by logs per million users revealed that smaller nations, notably Portugal, face disproportionately high rates of victimization. This suggests that while attackers may cast a wide net, certain regions are either more susceptible or more frequently targeted relative to their internet user base. The US, despite its economic significance, was found to have a very low per-capita rate of stolen logs appearing on these specific marketplaces.
Demo / Proof of Concept
▶ Watch: Tier A & B: Cryptocurrency and valuable web credentials (4:30)
During the talk, the speaker provided a clear demonstration of the criminal marketplaces where stolen data is bought and sold. While not a live hack or exploit, the presentation included multiple screenshots of these clandestine platforms, effectively serving as a proof of concept for how the stolen information transitions from exfiltration to monetization.
The first screenshot displayed a record from a US victim, showcasing a wealth of stolen credentials. The image clearly showed a list of domains for which passwords were compromised and stored in the victim's browser, including prominent sites like amazon.com and ebay.com. A "buy" button and a price of $10 were visible, alongside a folder breakdown indicating the types of assets included, such as passwords and potentially a screenshot (though noted as "useless" by the speaker). This visually reinforced how buyers could immediately see the potential value of a log and make a purchase. The speaker explained that if a victim had numerous credentials stored, all would be bundled into a single purchase, leaving it to the criminal buyer to assess the overall worth and potential for exploitation. For instance, a buyer might target an eBay account, hoping the victim is a large seller from whom significant illicit profits could be made.
A second screenshot depicted another marketplace, highlighting a stolen record from Zambia. This particular example was chosen because it clearly indicated the victim's affiliation with a university, showing credentials for a "University of Zambia" website and researchgate.net, a platform for academic publications. This log was priced at $2.60. The speaker used this to illustrate how even seemingly lower-value credentials can be monetized. For instance, a university username and password could be sold to access brokers who specialize in providing initial network access as a service, potentially leading to more significant breaches within an academic institution.
These visual demonstrations were crucial in illustrating the real-world operation of these underground economies. They showed how data is indexed, searched, priced, and traded, validating the entire lifecycle of stolen information from initial compromise by infostealer malware to its final sale as a "hot commodity."
Defensive Implications
▶ Watch: Tier C, D, E: Less liquid data and monetization challenges (6:00)
The detailed insights into the data theft economy presented in this talk offer critical defensive implications for both individuals and organizations. Understanding how criminals value, steal, and sell data is the first step toward effective mitigation.
- Prioritize Cryptocurrency Security: Given that cryptocurrency is the most liquid asset (Tier A), individuals and companies dealing with crypto must implement robust security measures. The speaker strongly recommends using hardware wallets to store crypto assets. These devices keep private keys offline, making them impervious to software-based infostealers. Storing crypto keys or seeds in plain text files on a PC, or even on a regular USB drive without encryption, is highly discouraged, as infostealers are specifically designed to locate and exfiltrate such information.
- Avoid Browser Password Storage: The talk unequivocally advises against storing sensitive credentials directly within web browsers. While browsers are improving their security (e.g., Chrome asking for fingerprints or master passwords), they remain a primary target for infostealer malware. Instead, users should leverage dedicated, reputable password managers. These tools store credentials in an encrypted vault, requiring a single master password and often offering additional security features like multi-factor authentication, making them significantly harder for infostealers to compromise.
- Protect Email Accounts Vigorously: Email credentials fall into Tier B, indicating their high value to attackers. Gaining access to a victim's email can serve as a master key to numerous other online accounts through password reset mechanisms. Implementing strong, unique passwords and multi-factor authentication (MFA) on all email accounts is paramount. This includes personal and especially corporate email accounts, as compromised email can lead to broader organizational breaches.
- Be Aware of High-Risk Infostealers: The identification of Redline as a dominant and highly effective infostealer should prompt organizations to ensure their endpoint detection and response (EDR) solutions are robustly configured to detect and block such malware. Regular security awareness training for employees, emphasizing the dangers of phishing and drive-by downloads that lead to infostealer infections, is also crucial.
- Understand the Value of All Credentials: Even seemingly low-value credentials, such as those for a university or internal FTP server (Tier C/D), can be monetized by criminals. For example, university credentials can be sold to access brokers who then use them to gain initial access to an organization's network, which can escalate into a more significant breach. Organizations should treat all credentials, regardless of their apparent sensitivity, as valuable assets requiring strong protection.
- Geographical Risk Awareness: While the US had a low per-capita rate of stolen logs on these specific marketplaces, the data highlights that certain regions (like Portugal) face disproportionately high rates of victimization. Organizations with operations or employees in these higher-risk regions should consider enhanced security protocols and user education tailored to the specific threats prevalent there.
In summary, the talk underscores that effective defense against data theft requires a multi-layered approach: securing the most liquid assets (crypto), adopting best practices for credential management (password managers over browser storage), protecting critical pathways (email), and staying informed about the most prevalent and dangerous threat actors (infostealer malware).
Key Takeaways
- Cryptocurrency is the most liquid asset for criminals: Stolen crypto assets are immediately monetizable, akin to losing cash, and should be protected with hardware wallets rather than being stored on PCs or in browsers.
- Web credentials, especially email, are extremely valuable: Access to an email account can lead to widespread account takeovers across social media, e-commerce, and other services via password resets, making them a Tier B asset for criminals.
- Infostealer malware is a primary threat vector: These programs are highly effective at exfiltrating sensitive data from compromised systems, with Redline being the most popular and dangerous infostealer observed.
- Avoid browser password storage: Storing credentials in web browsers makes them an easy target for infostealers; instead, use a dedicated, secure password manager and enable multi-factor authentication (MFA) wherever possible.
- Criminal marketplaces efficiently monetize stolen data: These platforms operate like e-commerce sites, allowing criminals to buy and sell "logs" of stolen data, demonstrating a clear economic incentive for cybercrime.
- Geographical disparities in victimization exist: While overall volume might be high in populous countries, smaller nations like Portugal show significantly higher per-capita rates of stolen logs appearing on criminal markets.
About the Speaker(s)
The speaker for this session is referred to as David within the transcript. Unfortunately, the provided talk bundle does not include any further details regarding David's full name, title, or company affiliation. Based on the content of the talk, David possesses a deep understanding of cybersecurity, particularly in the realm of malware analysis, criminal underground economies, and data monetization. He shares personal anecdotes from 2001 and 2005, suggesting a long-standing career and experience in the technology and security sectors. His expertise is evident in the detailed analysis of infostealer capabilities, the intricate workings of criminal marketplaces, and the sophisticated methodologies used to quantify data value and risk.