Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces
Dark Web Identity-Theft Ecosystem (TL-2026-0919), also tracked as Inside the dark web: stolen identities for 95¢, is a high-severity data breach, first published 2026-06-23. It has no confirmed attribution, affects Google Chrome / Chromium browsers, maps to 24 MITRE ATT&CK techniques (T1005, T1041, T1059.001), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-0919
- Threat ID
- TL-2026-0919
- Also known as
- Inside the dark web: stolen identities for 95¢
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-06-23
- Last reviewed
- 2026-06-23
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumers, financial, retail, media, transportation, technology, government
- Target regions
- North America, Europe, South America, Asia
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Dark Web Identity-Theft Ecosystem
Malware and tooling: STORM Infostealer, Operator-controlled VPS connected to STORM central servers
A Malwarebytes Labs investigation documents a maturing dark web criminal economy where complete US identity packages ('fullz' with name, SSN, DOB, and address) sell for as little as $0.95 on 9-Digits Market, the subscription-rented STORM infostealer harvests browser credentials, session cookies, and crypto wallets via server-side decryption, and forums such as DarkForums, BreachForums, Exploit, and XSS broker turnkey scam and social-engineering kits. Researchers counted 7,500+ compromised datasets totalling 8.4 billion+ records listed since the start of 2026.
How Dark Web Identity-Theft Ecosystem works
Malwarebytes Labs conducted a 48-hour investigation into the dark web identity-theft and fraud-as-a-service ecosystem and found a low-friction, commoditized criminal supply chain. At the data layer, dedicated identity markets such as 9-Digits Market liquidate complete US 'fullz' identity sets — full name, Social Security Number (SSN), date of birth (DOB), and address — for as little as $0.95 per set, low enough that fraud is profitable at scale. Aggregator forums concentrate the supply: DarkForums hosts more than 115,000 members and over 1,200 small-and-medium breach listings (approximately 63 pages at 20 listings per page), while BreachForums has accumulated 700+ compromised database listings (about 37 pages at 20 entries per page) since the start of 2026. Russian-language professional forums Exploit and XSS, the WWH community, and the Link-Base directory round out the marketplace tier. In aggregate, Malwarebytes researchers identified 7,500+ compromised datasets containing 8.4 billion+ records listed since early 2026, with breach listings naming organizations including SoundCloud, ADT, Hallmark, Amtrak, Vimeo, and Instagram.
At the tooling layer, the ecosystem is powered by malware-as-a-service. The STORM infostealer (documented separately by Varonis Threat Labs) is rented on a tiered subscription — $300 for a 7-day demo, $900/month standard, and $1,800/month for a team license bundling 100 operator seats and 200 builds. STORM steals saved usernames and passwords, autofill data, session cookies, Google account tokens, stored payment/credit-card details, browsing history, and cryptocurrency wallets from both browser extensions and desktop apps. It targets Chromium and Gecko-based browsers (Chrome, Edge, Firefox, Waterfox, Pale Moon), pulls session data from Telegram, Signal, and Discord, steals documents from user directories, and captures screenshots across multiple monitors. Its defining innovation is server-side decryption: rather than decrypting Chrome-protected data on the victim endpoint (which generates antivirus-detectable behavior), STORM ships the encrypted browser files to operator-controlled infrastructure for remote decryption, evading endpoint telemetry. Operators connect their own VPS to STORM's central servers, and stolen Google Refresh Tokens paired with a geographically matched SOCKS5 proxy let attackers restore victim sessions and bypass multi-factor authentication. Builds keep harvesting even after a subscription lapses. One observed STORM intrusion against a US-based computer exfiltrated 87 username-and-password combinations.
The downstream impact is large-scale identity theft and fraud. The US Federal Trade Commission (FTC) received more than 1.15 million identity-theft reports in the first three quarters of 2025. With fullz priced below a dollar, a compromised SSN enables fraudsters to open credit lines, file fraudulent tax returns, obtain medical services, and impersonate victims across government and legal systems for years. This record documents the ecosystem for defenders: the marketplaces and forums to monitor, the STORM infostealer TTPs to detect, and the credential-and-identity exposure that downstream fraud depends on.
MITRE ATT&CK techniques used in TL-2026-0919
Collection
T1005 Data from Local System; T1113 Screen Capture; T1213 Data from Information Repositories
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
Command and Control
T1071.001 Web Protocols; T1090.002 External Proxy; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1566 Phishing
Discovery
T1082 System Information Discovery
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
defense-impairment
T1553 Subvert Trust Controls; T1556 Modify Authentication Process
Resource Development
T1583 Acquire Infrastructure; T1583.003 Virtual Private Server; T1587.001 Malware; T1588.001 Malware; T1650 Acquire Access
Impact
Affected products and versions in Dark Web Identity-Theft Ecosystem
- Google — Chrome / Chromium browsers
Vulnerable versions: credential and cookie stores targeted by STORM - Mozilla / Community — Gecko browsers (Firefox, Waterfox, Pale Moon)
Vulnerable versions: credential and cookie stores targeted by STORM - Various — Consumer/enterprise identity data (US fullz: name, SSN, DOB, address)
Vulnerable versions: 8.4 billion+ records listed since early 2026
Remediation for Dark Web Identity-Theft Ecosystem
Immediate actions
- Enable dark web / credential exposure monitoring for organizational domains and named breached brands (SoundCloud, ADT, Hallmark, Amtrak, Vimeo, Instagram)
- Force password resets and revoke active sessions/refresh tokens for any user whose credentials appear in breach dumps
- Hunt for STORM infostealer indicators: bulk reads of browser credential stores and exfiltration of encrypted browser files to external infrastructure
Workarounds
- Bind sessions to device posture and revoke Google/Entra refresh tokens on anomalous geo or proxy (SOCKS5) usage
- Restrict browser password-manager use in favor of hardened enterprise secret stores
Longer-term hardening
- Deploy EDR with behavioral detection for browser credential-store access and session-cookie theft
- Adopt phishing-resistant MFA (FIDO2/passkeys) and short-lived tokens with continuous access evaluation to blunt session-cookie / refresh-token replay
- Roll out identity-theft protection and SSN/credit monitoring for affected individuals; implement credit freezes where appropriate
Weaknesses (CWE) in Dark Web Identity-Theft Ecosystem
CWE-522, CWE-256, CWE-384, CWE-200
Timeline of Dark Web Identity-Theft Ecosystem
- STORM infostealer vendor account (handle 'StormStealer', forum ID 221756) registered on an underground forum, per Varonis Threat Labs.
- Start of the period over which Malwarebytes counted 7,500+ compromised datasets and 8.4 billion+ records listed across dark web markets.
- STORM infostealer observed advertised on underground cybercrime networks as a tiered subscription service in early 2026.
- Malwarebytes reports US tax forms selling for ~$20 on the dark web, illustrating the same identity-data economy.
- Varonis Threat Labs publicly details STORM's server-side decryption, session hijacking, and MFA-bypass capabilities (version v0.0.2.0 'Gunnar').
- BleepingComputer, Hackread, Infosecurity Magazine, and SC Media report on STORM-as-a-service targeting browsers, wallets, and accounts.
- Breach listings observed naming SoundCloud, ADT, Hallmark, Amtrak, Vimeo, and Instagram among compromised organizations.
- Malwarebytes Labs publishes its 48-hour dark web investigation documenting $0.95 fullz on 9-Digits Market, STORM rental, and scam-as-a-service kits.
Sources cited for Dark Web Identity-Theft Ecosystem
- Inside the dark web: stolen identities for 95¢, malware, and scams-for-hire
- The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
- The silent “Storm”: New infostealer hijacks sessions, decrypts server-side (BleepingComputer)
- Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts
- New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
- Storm infostealer bypasses Chrome encryption, targets crypto wallets (SC Media)
- Your tax forms sell for $20 on the dark web (Malwarebytes)
Threats related to Dark Web Identity-Theft Ecosystem
Detection coverage for TL-2026-0919
As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0919 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.