Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces — Threadlinqs Intelligence
As of 2026-06-23, Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0919 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
A Malwarebytes Labs investigation documents a maturing dark web criminal economy where complete US identity packages ('fullz' with name, SSN, DOB, and address) sell for as little as $0.95 on 9-Digits
Malwarebytes Labs conducted a 48-hour investigation into the dark web identity-theft and fraud-as-a-service ecosystem and found a low-friction, commoditized criminal supply chain. At the data layer, dedicated identity markets such as 9-Digits Market liquidate complete US 'fullz' identity sets — full name, Social Security Number (SSN), date of birth (DOB), and address — for as little as $0.95 per set, low enough that fraud is profitable at scale. Aggregator forums concentrate the supply: DarkForums hosts more than 115,000 members and over 1,200 small-and-medium breach listings (approximately 63 pages at 20 listings per page), while BreachForums has accumulated 700+ compromised database listings (about 37 pages at 20 entries per page) since the start of 2026. Russian-language professional forums Exploit and XSS, the WWH community, and the Link-Base directory round out the marketplace tier. In aggregate, Malwarebytes researchers identified 7,500+ compromised datasets containing 8.4 billion+ records listed since early 2026, with breach listings naming organizations including SoundCloud, ADT, Hallmark, Amtrak, Vimeo, and Instagram.
At the tooling layer, the ecosystem is powered by malware-as-a-service. The STORM infostealer (documented separately by Varonis Threat Labs) is rented on a tiered subscription — $300 for a 7-day demo, $900/month standard, and $1,800/month for a team license bundling 100 operator seats and 200 builds. STORM steals saved usernames and passwords, autofill data, session cookies, Google account tokens, stored payment/credit-card details, browsing history, and cryptocurrency wallets from both browser extensions and desktop apps. It targets Chromium and Gecko-based browsers (Chrome, Edge, Firefox, Waterfox, Pale Moon), pulls session data from Telegram, Signal, and Discord, steals documents from user directories, and captures screenshots across multiple monitors. Its defining innovation is server-side decryption: rather than decrypting Chrome-protected data on the victim endpoint (which generates antivirus-detectable behavior), STORM ships the encrypted browser files to operator-controlled infrastructure for remote decryption, evading endpoint telemetry. Operators connect their own VPS to STORM's central servers, and stolen Google Refresh Tokens paired with a geographically matched SOCKS5 proxy let attackers restore victim sessions and bypass multi-factor authentication. Builds keep harvesting even after a subscription lapses. One observed STORM intrusion against a US-based computer exfiltrated 87 username-and-password combinations.
The downstream impact is large-scale identity theft and fraud. The US Federal Trade Commission (FTC) received more than 1.15 million identity-theft reports in the first three quarters of 2025. With fullz priced below a dollar, a compromised SSN enables fraudsters to open credit lines, file fraudulent tax returns, obtain medical services, and impersonate victims across government and legal systems for years. This record documents the ecosystem for defenders: the marketplaces and forums to monitor, the STORM infostealer TTPs to detect, and the credential-and-identity exposure that downstream fraud depends on.
Weaknesses (CWE)
CWE-522, CWE-256, CWE-384, CWE-200
Target sectors: consumers, financial, retail, media, transportation, technology, government
Target regions: North America, Europe, South America, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1583, T1583.003, T1588.001, T1587.001, T1650, T1059.001, T1555.003, T1555, T1539, T1552.001