Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (2024)

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (1)

Home

Resources

Blog

Jan 19, 2023

10 Mins Read

By SOCRadar Research

Russian-speaking Hydra Market was the biggest amongdarknet markets, with a$1B turnoverin 2020. It was also the largest narcotic market among the countries of the former USSR.

With the operation started by German and US law enforcement in 2021, Hydra’s Germany-based servers were taken down in April 2022. In this operation,$25M worth of Bitcoinwas also seized. More than a drug bust, this takedown dealt a massive blow to the malicious Russian-speaking dark web ecosystem.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (2)
  • Until its shutdown, Hydra hosted 80% of dark web activity.

After the Hydra servers were shut down, most Hydra users organized in theRuTor forum. But they soon suspected law enforcement might launch a hunt with Hydra clones. The initial fear of users came with the capture of Hydra’s co-founder,Dmitry Pavlov. They suspected that internal correspondence and transactions might also have leaked. Still, they thought western authorities would keep this information private from Russian officials due to the currentRussia-Ukraine war.

  • Hydra market had 19,000 seller accounts and more than 17 million customers.

Again, although there may be developments on this subject in the coming days, no major event has yet to emerge. However, what has been seen so far is the rapid emergence of new Dark Web Markets and the new big 5 dividing the dark market.

Dark Web Marketplaces

Dark Web Markets (DWMs)are the markets on the dark web that are used to access illegal products and services. Users can access illicit products, such as drugs, unregistered firearms, fake ID cards, credentials, and data sets in DWMs. These illegal shopping platforms, which gained popularity in the dark web in 2011 withSilkroad, which we call the first modern DWM, have increased their activity until today. After the Silkroad closed with the FBI operation in 2013, big names such asRAMP,one of the longest-lived dark web markets, and Hydra emerged and were later taken down. The closure of these illegal markets resulted from the operations carried out a significant blow to the dark web activities. Still, it caused the emergence of other underground markets as well.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (3)

Cyber Criminals on DWMs

Although up to the majority of the products in DWMs are drugs. One should remember cyber threat actors also take place in these markets. So, data, a tool, or a service can occur in theseblack markets. EvenStealer as a service (SaaS), one of the most recent cyber attack vectors, has taken its place in black markets. However, the most striking ones regarding cybercrime in terms of numbers areDDoS for hire services, RDP accesses, and credentials. In terms of value, data such as VIP credentials and databases stand out.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (4)

Besides, DWMs may not only appear as drug markets but can also be interpreted as nesting spots for cyber threats.

As of the beginning of 2023, the main markets that pose a cyber threat are as follows:

  • Russian Market
  • Genesis Market
  • 2easy

Various credentials, stolen data, and credit cards are the main items in these markets.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (5)

Cryptocurrencies and Crypto Laundry

Another topic in modern DWMs is the transactions made withcryptocurrencyand the concept of crypto laundry. DWMs, where most of these transactions are made withBitcoin, are said to be one of the mechanisms that keep the crypto market alive, according to some researchers. Hydra Market alone reached a$5B trading volumefrom 2015 to 2022. Just in 2021, the total black market transactions added $2.1B to the crypto market volume.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (6)

Althoughblockchainprovides anonymity for the wallet owner, the fact that crypto wallets are traceable assets can damage thisanonymity. Many cryptocurrencies are built on blockchain technology, and this providesdecentralization. Therefore, cryptocurrencies are considered anonymous and untraceable. However, these transfers are held by distributed ledgers and are publicly available. For this reason, it also makes it traceable with tools such as Bitcoin explorer. For this,crypto money laundryis done with various methods. These methods are:

  • Nested services,
  • Gambling platforms,
  • Mixers,
  • Non-compliant exchanges,
  • Services headquartered in high-risk jurisdictions.

Vacuum Left by Hydra

It took almost no time for the void left by Hydra to be filled, and dozens of new illicit markets emerged. These DWMs, mostly Russian-speaking, have repopulated80% of the entire illegal ecosystem. According to TRM Labs’s research, these markets reached 24% more volume than the previous year of Hydra within the first five months of Hydra’s shutdown.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (7)

Although more than 70 DWMs were observed at the end of last year, the four big Russian markets divide80%of the total volume among them, while the western bitcoin-based marketASAPcomes in 5th place with 7%. All the remaining DWMs have only 13% of the total market volume.

Infinity: A Black Market under a Hacker Forum

In addition to dark web markets, hacker forums are one of the dark web platforms where sales are made. The recent Ukraine-Russia war was reflected in the cyber world, and nationalist Russian threat actors came together in some forums.

TheInfinity Forumlaunched in January 2023 as a forum founded by Killmilk, the former leader of theKillNetthreat group, and comprised of members of Russian hacktivists and threat actors. Infinity, which researchers traced back to November of the previous year, was aTelegram group. The forum brings together many Russian hacker groups and the cyber underground world. Although it has similarities with other Russian-speaking forums and markets, Infinity members are discussing and making operational decisions in line with their political views.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (8)

The part that highlights the Infinity forum as a dark web market and creates a cyber threat is theHack Shopsection. In addition to sharing and selling many tools and exploits, it is among the products sold in DDoS, frequently used by Russian hacktivist groups.

Infinity Forum will target NATO and Western countries with its ideological aims throughout the Russian-Ukrainian war. So it may remain one of the threats to watch out for throughout 2023, especially with the sale of services such as DDoS, which is both a gathering place for cybercriminals and a high damage capacity even in the hands of threat actors that have not yet been well-seasoned.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (9)

At the end of February 2023, there was a change in the management of the Infinity Forum.KillMilkput the Infinity Forum up for sale for unknown reasons, which may be good news that the forum may be disbanded, but KillNet has since relaunched its Telegram forum. KillNet’s Telegram forum is a different form created by managing multiple chat groups from the same hand; this forum also includes a market that offers the same services.

This outcome may be due to the threat actors being unable to profit from the Infinity Forum or achieve as much growth as they would like. At the same time, KillNet’s return to the Telegram forum system seems to support the new dark web system based on Telegram for Russian-speaking threat actors. As a result, the forum is still active, but its future may seem uncertain. These seasoned threat actors will continue their activities under a different name.

Top Dark Web Marketplaces

  • BlackSprut Market
  • Mega Darknet Market
  • OMG! OMG! Market
  • Solaris Market
  • ASAP Market

    Other dark web marketplaces:

Tor2door Market

Nova Market

Abacus Market

Vice City Market

Archetyp Market

Bohemia Market

Incognito Market

Psycellium

Flugsvamp 4.0

Mega Darknet Market

Cypher Market

Revolution Market

WeTheNorth Market

Kerberos Market

Royal Market

Cocorico Market

MGM Grand

Nemesis Market

Cannabia

TorZon Market

Kingdom Market

Black Pyramid Market

Tor Market

Ares Market

Exolix Exchange

Majestic Bank

FixedFloat

Elude Exchange

Kraken Market

Russian Market

What The Future Holds

Researchers, on the other hand, follow a specific threat. We could see a new DWM called Kraken Market, which several DWMs will prepare as the real successor of Hydra in the next year.

WayAWay, an old dark web forum, has been re-observed on the dark web. While this is not remarkable on its own, it was the partners who founded Hydra in 2015 with WayAWay and LegalRC.

With the shutdown of Hydra, cybercriminals gathered in the RuTor forum, but the presence of many competitors led RuTor to partner with the OMGOMG marketplace. However, this partnership faced opposition from WayAWay and led them to associate itself as Kraken. At the same time, researchers claim that the RuTor/OMGOMG and WayAWay/Kraken competitions also mirror the Russian-Ukrainian war. The researcher also said that RuTor’s pro-Ukraine and Kraken’s pro-Russia stance showed us once again that geopolitical issues are also taking place in cyberspace.

Effect of the Russia-Ukraine War on the Dark Web

Since the war began, geopolitical dynamics have changed, and its reflection can be seen on the dark web. Especially the fact that Russian-speaking countries make up a massive part of the dark web population made this even more visible.

In the dark web, Russian-speaking criminals tended not to take actions that would harm or target former Soviet Union countries. However, this situation changed with the start of the war, especially Conti’s declaration of total loyalty to Russia set an excellent example for this situation.

DWMs have also become one of the battlegrounds. Ukraine-born cyber intelligence expert Alex Holden claimed to have hacked the Solaris DWM and siphoned the 1.6 Bitcoin transaction, and donated it to a Kyiv Charity.

Threats to Watch Out For

Considering the recent growth, Dark Web Markets will likely reach larger transaction volumes. In addition to illegal products such as drugs, these black markets, which are marketed in data sets, data leaks, malware, and exploits, pose a significant danger to every institution.

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (10)

Like hacker forums, critical data such as VIP credentials, employee data, and espionage information are sold in dark web markets as well.

Moreover, threat actors offer ransomware and stealers “as a service” in these markets.

Using SOCRadar Extended Threat Intelligence, when you have leaked or stolen data about your organization on the dark web and black markets, it can be detected automatically and take proactive measures.

Top Articles

The Top 10 Dark Web Telegram Chat Groups and Channels

Apr 14, 2022

SMS Bomber: How Dangerous Can a Text Be?

Aug 15, 2023

Top 10 Deep Web and Dark Web Forums

Feb 23, 2024

Top 5 Dark Web Search Engines

Aug 15, 2023

Top 5 Underground Hacker Forums That are Accessible via Your Web Browsers such as Google Chrome, Firefox, and Internet Explorer

Apr 19, 2021

Subscribe to our newsletter and stay updated on the latest insights!

PROTECTION OF PERSONAL DATA COOKIE POLICY FOR THE INTERNET SITE

Protecting your personal data is one of the core principles of our organization, SOCRadar, which operates the internet site (www.socradar.com). This Cookie Usage Policy (“Policy”) explains the types of cookies used and the conditions under which they are used to all website visitors and users.

Cookies are small text files stored on your computer or mobile device by the websites you visit.

Cookies are commonly used to provide you with a personalized experience while using a website, enhance the services offered, and improve your overall browsing experience, contributing to ease of use while navigating a website. If you prefer not to use cookies, you can delete or block them through your browser settings. However, please be aware that this may affect your usage of our website. Unless you change your cookie settings in your browser, we will assume that you accept the use of cookies on this site.

1. WHAT KIND OF DATA IS PROCESSED IN COOKIES?

Cookies on websites collect data related to your browsing and usage preferences on the device you use to visit the site, depending on their type. This data includes information about the pages you access, the services and products you explore, your preferred language choice, and other preferences.

2. WHAT ARE COOKIES AND WHAT ARE THEIR PURPOSES?

Cookies are small text files stored on your device or web server by the websites you visit through your browsers. These small text files, containing your preferred language and other settings, help us remember your preferences on your next visit and assist us in making improvements to our services to enhance your experience on the site. This way, you can have a better and more personalized user experience on your next visit.

The main purposes of using cookies on our Internet Site are as follows:

  • Improve the functionality and performance of the website to enhance the services provided to you,
  • Enhance and introduce new features to the Internet Site and customize the provided features based on your preferences,
  • Ensure legal and commercial security for the Internet Site, yourself, and the Organization, and prevent fraudulent transactions through the Site,
  • Fulfill legal and contractual obligations, including those arising from Law No. 5651 on the Regulation of Publications on the Internet and the Fight Against Crimes Committed Through These Publications, as well as the Regulation on the Procedures and Principles Regarding the Regulation of Publications on the Internet.

3. TYPES OF COOKIES USED ON OUR INTERNET SITE 3.1. Session Cookies

Session cookies ensure the smooth operation of the internet site during your visit. They are used for purposes such as ensuring the security and continuity of our sites and your visits. Session cookies are temporary cookies and are deleted when you close your browser; they are not permanent.

3.2. Persistent Cookies

These cookies are used to remember your preferences and are stored on your device through browsers. Persistent cookies remain stored on your device even after you close your browser or restart your computer. These cookies are stored in your browser’s subfolders until deleted from your browser’s settings. Some types of persistent cookies can be used to provide personalized recommendations based on your usage purposes.

With persistent cookies, when you revisit our website with the same device, the website checks if a cookie created by our website exists on your device. If so, it is understood that you have visited the site before, and the content to be presented to you is determined accordingly, offering you a better service.

3.3. Mandatory/Technical Cookies

Mandatory cookies are essential for the proper functioning of the visited internet site. The purpose of these cookies is to provide necessary services by ensuring the operation of the site. For example, they allow access to secure sections of the internet site, use of its features, and navigation.

3.4. Analytical Cookies

These cookies gather information about how the website is used, the frequency and number of visits, and show how visitors navigate to the site. The purpose of using these cookies is to improve the operation of the site, increase its performance, and determine general trend directions. They do not contain data that can identify visitors. For example, they show the number of error messages displayed or the most visited pages.

3.5. Functional Cookies

Functional cookies remember the choices made by visitors within the site and recall them during the next visit. The purpose of these cookies is to provide ease of use to visitors. For example, they prevent the need to re-enter the user’s password on each page visited by the site user.

3.6. Targeting/Advertising Cookies

They measure the effectiveness of advertisem*nts shown to visitors and calculate how many times ads are displayed. The purpose of these cookies is to present personalized advertisem*nts to visitors based on their interests.

Similarly, they determine the specific interests of visitors’ navigation and present appropriate content. For example, they prevent the same advertisem*nt from being shown again to the visitor in a short period.

4. HOW TO MANAGE COOKIE PREFERENCES?

To change your preferences regarding the use of cookies, block or delete cookies, you only need to change your browser settings.

Many browsers offer options to accept or reject cookies, only accept certain types of cookies, or receive notifications from the browser when a website requests to store cookies on your device.

Also, it is possible to delete previously saved cookies from your browser.

If you disable or reject cookies, you may need to manually adjust some preferences, and certain features and services on the website may not work properly as we will not be able to recognize and associate with your account. You can change your browser settings by clicking on the relevant link from the table below.

5. EFFECTIVE DATE OF THE INTERNET SITE PRIVACY POLICY

The Internet Site Privacy Policy is dated The effective date of the Policy will be updated if the entire Policy or specific sections are renewed. The Privacy Policy is published on the Organization’s website (www.socradar.com) and made accessible to relevant individuals upon request.

SOCRadar
Address: 651 N Broad St, Suite 205 Middletown, DE 19709 USA
Phone: +1 (571) 249-4598
Email: [emailprotected]
Website: www.socradar.com

Hydra Aftermath and the Future of Dark Web Marketplaces - SOCRadar® Cyber Intelligence Inc. (2024)
Top Articles
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 5821

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.