Skip to content

Security1 publisher2 min readPublished

Researcher matches 205 early Exploit.in handles to later criminal forums

Researcher Dancho Danchev matched 205 handles from a 2005-2008 Exploit.in dump to private messages on five later forums, 26 of them from active early members. A matching handle does not prove a matching person, so 205 is a ceiling, but the forum's core was only about 90 accounts, few enough to follow from board to board.

The Watch · Security desk

Illustration accompanying Researcher matches 205 early Exploit.in handles to later criminal forums

What happened

  • Ransomnews researcher Dancho Danchev obtained an Exploit.in database dump covering February 2005 to May 2008, with 9,647 members, 13,925 threads and 80,891 posts.
  • A small group did most of the posting: the top 1% of members wrote 52.6% of all posts, while 5,843 accounts, 60.6% of the forum, never posted once.
  • Checking the member list against private-message archives from five later forums, including XSS, RAMP and BreachForums, turned up 205 distinctive handles present in both periods.
  • In archives from later forums, 11.8% of RAMP conversations and 8.8% of XSS conversations mention a paid guarantor or escrow service.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Pressure on this scene depends on following a few dozen core accounts across boards over years, since seizing any single forum leaves its main writers free to regroup elsewhere.
  • constraint Handle overlap can open an attribution lead but cannot close one: 205 is an upper bound, and each match needs other evidence before it names a person.
  • exposure Anyone holding the dump has email addresses, IP addresses and password hashes for 9,647 people, most of them, per the researcher, kids never accused of anything.

Against the whole membership, the overlap is small. The 205 matched handles are about 2.1% of the 9,647 accounts registered between February 2005 and May 2008 [1]. Only 26 of them belonged to accounts with 20 or more posts on Exploit.in, which is 12.7% of the matches. Thirteen had passed 100 posts [7][2]. The report does not say what those handles do on the later forums. The overlap connects names across two decades. It does not place any of them in a ransomware crew [6].

Handle matching is the weakest step. Generic handles that two unrelated people might pick were stripped out before matching. The researcher still treats 205 as a ceiling because a shared handle is not proof of a shared person, and is withholding the handles themselves [6][8].

The stronger finding is how small the group was. Exploit.in ran on around 90 active users and several thousand people who mostly read [5]. According to the researcher, those 90 could move to another forum and register new accounts within a few hours [5]. A group that size can be followed by name from one board to the next, and the 26 active matches suggest some of them were still on criminal forums two decades later [7].

Much of today's structure was already running in 2005 on a standard forum installation. Two password-protected sections held stolen credit cards, bank accounts and conversations members did not want in public [9]. The researcher ties that tiering to the way ransomware groups now vet affiliates before giving them panel access [9]. Trust ran on two public lists. One named people who had ripped others off, and the other named people reliable enough to do business with [10]. Those lists stop working once a forum is too big for anyone to vouch for a handle personally. On RAMP and XSS, paid guarantors and escrow services do that job [10].

The early board was also a hangout. About a third of everything written there was talk about phones and each other. The marketplace was the largest section at 10,377 posts, or 12.8% of the total [11][4]. Posting rose from 9 a.m. Moscow time and peaked at 10 p.m., with weekends about 8% quieter than weekdays [12]. The researcher takes that as the timetable of people with school or a job during the day [12]. The Ransomnews report says: "Most writing about Russian cybercrime forums calls them marketplaces, and they were. What the writing tends to leave out is that they were also where a lot of teenagers went to talk about cars and phones." [13]

What to watch

  • Any published link between one of the 26 active matched handles and a named ransomware operation or affiliate panel.
  • Wider circulation of the 2005-2008 dump itself, with its email addresses, IP addresses and password hashes.
  • Law-enforcement use of pre-2008 forum records to identify people operating on XSS or RAMP today.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories