FortiRecon Dark Web Field Guide: What's Actually Out There
The 2026 "dark web" is not a single hidden place. It is an economy — a fluid network of infostealer log drops, ransomware leak sites, criminal Telegram channels and the smoking remains of BreachForums / Genesis / XSS / RAMP. This is a field guide to what is actually out there, what FortiRecon sees across its Adversary-Centric Intelligence module, and what it means for an Indian enterprise in 2026.
Every load-bearing claim below is sourced from a CISA #StopRansomware advisory, a DOJ / NCA / Europol press release, a named vendor threat-research paper, or a CERT-In advisory. URLs are inline. No marketing claims, no invented percentages, no "industry estimates."
🧠 Credential records
100 billion+
On darknet (Fortinet 2025 GTLR)
📈 Infostealer surge
500% / 42%
YoY log activity / credential surge
💸 Akira proceeds
$244.17M
CISA AA24-109A, late Sep 2025
📡 Telegram scale
43.5M channels
Blocked by Telegram in 2025
🇮🇳 India context
16B credentials
CERT-In CIAD-2025-0018
Disclosure: Ogma Consulting is an authorised Fortinet partner and operates FortiRecon as a managed service for Indian enterprises. This is a technical field guide built on public law-enforcement and vendor research. Where an industry claim cannot be traced to a primary source, we flag it in-line.
Part 1 — The Infostealer Log Economy
The single largest source of new credentials on the dark web in 2026 is not a breached database. It is the daily output of infostealer malware running on compromised consumer PCs — crypto wallets, corporate SSO cookies, VPN credentials, session tokens. Every day, tens of thousands of fresh "logs" hit markets, Telegram channels and private brokers.
Windows PCs infected by Lumma Stealer in just 60 days — between 16 March and 16 May 2025, per Microsoft Threat Intelligence. Microsoft's Digital Crimes Unit filed a civil legal action on 13 May 2025; law enforcement seized or transferred 1,300+ domains of Lumma's infrastructure, with another 300 actioned by Europol.
Source: Microsoft — "Disrupting Lumma Stealer" (21 May 2025)Lumma is a malware-as-a-service. Its primary developer operates under the handle "Shamel", based in Russia. Pricing tiers are public: Experienced $250, Professional $500, Corporate $1,000, Source $20,000. In a November 2023 interview Shamel claimed about 400 active clients. Microsoft's action did not shut Lumma down — Check Point Research showed on 29 May 2025 that log-sale activity on Russian Market had climbed from 95 post-takedown to 406 within days.
Lumma / LummaC2
Infostealer MaaS Disrupted, not deadRedLine + META
Infostealer MaaS Seized Oct 2024Vidar 2.0
Infostealer Active 2025Raccoon / Mark Sokolovsky
Infostealer ProsecutedStealC (and SHAMOS on macOS)
Infostealer Cross-platform shiftIncrease in infostealer credential-log activity in 2024, per Fortinet's 2025 Global Threat Landscape Report. FortiGuard Labs tracked a 42% surge in stolen credentials offered on darknet forums — over 100 billion unique records (email, password, session tokens, MFA bypass data) traded and sold.
Source: Fortinet 2025 GTLR (28 Apr 2025)Where the logs end up
Russian Market is the dominant stealer-log marketplace in 2026. Rapid7 Labs' October 2025 investigation found more than 180,000 infostealer logs offered for sale in H1 2025, with ~30,000 new "bots" listed every month at a standard price of ~$10 each. Geographic distribution: United States 26%, Argentina 23%, Brazil third. Top three vendors (Nu####ez, bl####ow, Mo####yf) account for over 80% of listings.
Parallel distribution runs through Telegram channels Group-IB formally tracks as "Underground Clouds of Logs" (UCL) — closed subscriber-only channels where operators drop fresh stealer-log archives daily. Russian-language criminal slang for these channels: облака логов ("clouds of logs") or стачи стилер логов.
Part 2 — The Ransomware Leak-Site Wall
Every major ransomware operation in 2026 runs a Tor-hosted leak site where unpaid victims' data is dumped. FortiRecon's ACI module monitors these sites continuously — the product page has a named "Ransomware Intelligence" feature that tracks threat-actor activities, past and potential targets, and supply-chain vendor exposure.
LockBit / LockBit 3.0 / LockBit 5.0
RaaS Disrupted Feb 2024ALPHV / BlackCat
RaaS (Rust) Exit scam Mar 2024T1598). Brute Ratel C4 and Cobalt Strike beacons. Evilginx2 for MFA/session-cookie theft. Files renamed RECOVER-(seven-digit).txt.Cl0p / CLOP / TA505
RaaS → Data theft Mass exploitAkira
RaaS (Conti lineage) Active 2026CVE-2024-40766 (heavily leveraged), Cisco ASA/FTD CVE-2020-3259 and CVE-2023-20269, VMware ESXi CVE-2024-37085, Veeam CVE-2024-40711. June 2025: first Akira incident encrypting Nutanix AHV VM disk files — new TTP tracked in the Nov 2025 advisory update.Play / PlayCrypt
Closed RaaS Active 2026CVE-2018-13379 and CVE-2020-12812, Microsoft Exchange ProxyNotShell. January 2025 onwards: RMM tool SimpleHelp CVE-2024-57727. Unique TTP: Play ransomware binary is recompiled for every attack, producing unique hashes — AV/EDR signatures are useless.Interlock
RaaS (2024+) Education focusmove.dll targeting Chrome/Firefox/Edge/Brave/Opera, exfiltrates via AZcopy (>250 GB). Zero-day CVE-2025-61155 — "Hotta Killer" gaming anti-cheat driver used to kill security tools (FortiGuard Labs, Jan 2026).LockBit's internal books, seized by UK NCA in Operation Cronos, revealed 194 active affiliates and 7,000+ attacks between June 2022 and February 2024. 148 affiliates built attacks; 119 engaged in negotiations; 75 of those never negotiated a successful payment. Post-disruption active affiliate count: 69.
Source: NCA — LockBit leader unmasked and sanctioned (May 2024)Part 3 — The Telegram Criminal Channel Ecosystem
Post-2022, criminal activity migrated from dark-web forums to Telegram at an extraordinary rate. KELA's 2023 research documented Telegram channels carrying combolists, Clouds of Logs, stealer-log distribution, card shops, initial-access-broker offerings and ransomware leak dumps.
The Durov arrest and its aftermath
Pavel Durov, Telegram's founder, was arrested on 24 August 2024 at Le Bourget Airport, Paris. The Paris Public Prosecutor's Office (Section J3 – JUNALCO, Fight against Cybercrime) indicted him four days later on 12 charges including complicity in distribution of child exploitation material, drug trafficking, running an online platform permitting illicit transactions, money laundering, providing cryptographic services to criminals, and refusal to communicate information to authorities. Prosecutor Laure Beccuau cited Telegram's "almost total failure to respond to judicial requests." Durov was released on €5 million bail, barred from leaving France.
On 23–24 September 2024 Telegram amended its Terms of Service and privacy policy to share user IP addresses and phone numbers with law enforcement in response to valid legal requests — previously reserved only for terrorism cases. Telegram's 2024 transparency report disclosed user data on 2,253 US users (a dramatic jump from near-zero in prior years).
Cybercriminals still use Telegram 362 times more than Signal + Discord combined, four months after Durov's arrest. KELA counted 246,903 cybercriminal links shared on Telegram per month vs. roughly 682 combined across Signal and Discord. Announced migrations (Bl00dy Ransomware Gang, Team ARXU, Al Ahad) largely returned within weeks.
Source: KELA — "Three Months After the Storm" (18 Dec 2024)Telegram channels and groups blocked in 2025 — an 8–10× increase in daily takedown velocity post-Durov. Daily takedowns climbed from 10,000–30,000/day to 80,000–140,000/day with peaks over 500,000 in a single day. Check Point Research estimates ~20% of blocked channels were tied to criminal activity affecting businesses.
Source: Check Point Research — Telegram Crackdown 2026 (18 Mar 2026)Evasion tactics observed by Check Point's Exposure Management team: "Request to Join" gating to block moderation bots, pre-positioned backup channels for instant reconstitution, bio disclaimers claiming compliance. Over a three-month monitoring window, Check Point counted approximately 3 million Telegram invite links shared across underground environments. Discord accounted for less than 6% of the same volume.
Part 4 — The Forum Graveyard
Law-enforcement pressure on dark-web forums intensified between 2022 and 2026. The list of takedowns reads like a who's-who of criminal-marketplace history.
Hydra Market
5 Apr 2022Russia-based darknet market. $5.2 billion in cryptocurrency received since 2015. 17M customers, 19,000+ seller accounts. German BKA seized servers and ~$25M in Bitcoin. US Treasury OFAC sanctions + DOJ indictment of admin Dmitry Pavlov (press release JY0701). 80% of 2021 darknet market crypto volume at takedown.
RaidForums
Feb 2022Operation Tourniquet (NCA-led). Sold access to 10+ billion consumer records from 2016. Alleged admin Diogo Santos Coelho arrested in UK 31 Jan 2022 at US request. BreachForums became de-facto successor within weeks.
Genesis Market
5 Apr 2023Operation Cookie Monster (Eurojust + FBI + 13 countries). 100+ arrests, 200+ property searches. At takedown, Genesis advertised credentials from ~460,000 devices. Per Recorded Future, Russian Market listings paused for one week then resumed — 15% above pre-takedown level by mid-May.
BreachForums (1st)
Mar 2023Admin Conor Fitzpatrick ("pompompurin") arrested EDVA. Forum had 340,000+ members. Initial 20-year supervised release overturned; resentenced to 3 years prison on access-device-fraud + CP possession charges.
BreachForums (2nd)
15 May 2024FBI seizure of clearnet + onion sites + Telegram channel. Relaunched June 2023 by ShinyHunters + Baphomet. DOJ described: "clear-net marketplace for cybercriminals to buy, sell, and trade… stolen access devices, means of identification, hacking tools, breached databases."
BreachForums (3rd — IntelBroker)
Feb 2025Kai West (25, British national) unmasked as "IntelBroker"; arrested in France Feb 2025; identity published 25 Jun 2025. Charged SDNY with conspiracy to commit computer intrusions, wire fraud — potential 25-year sentence. $25M+ alleged damages. Breaches linked: Europol, DC Health Link, Cisco, GE, AMD, HPE, Nokia. Four French nationals also arrested under handles ShinyHunters, Hollow, Noct, Depressed.
XSS.is / DaMaGeLaB
22 Jul 2025Admin "Toha" arrested in Kyiv by Ukrainian SBU Cyber Department (French Police + Paris Prosecutor + Europol). 50,853 members, 110,000+ threads, €7M estimated profits (Europol). Clearweb seized; onion survived. Former moderators launched DamageLib on 3 Aug 2025 (KELA: 33,487 users in first month, but only 248 threads).
RAMP (ransomware forum)
Jan 2026FBI + SDFL US Attorney + DOJ CCIPS seizure. Ransomware affiliate recruitment forum founded July 2021. Used by LockBit, ALPHV, Conti, DragonForce, Qilin, Nova, Radiant, RansomHub for affiliate coordination.
The pattern: disruptions don't eliminate criminal activity. They redistribute it. After XSS, Exploit.in traffic rose ~24% (Intel 471). After BreachForums, ShinyHunters relaunched. After Genesis, Russian Market absorbed the demand. The Fortinet 2025 GTLR's 100-billion-record credential number is an aggregate across this fragmented, constantly-rebuilding ecosystem.
Part 5 — What FortiRecon ACI Actually Monitors
FortiRecon is Fortinet's "AI and Human gathered intelligence-powered Continuous Threat Exposure Management service" (datasheet, verbatim). It was named Overall Leader, Market Leader and Innovation Leader in the 2025 KuppingerCole Leadership Compass for Attack Surface Management. Four modules, of which three intersect with the dark-web economy above:
Module · ACI
Adversary-Centric Intelligence
- Ransomware intelligence — monitors LockBit, ALPHV, Cl0p, Akira, Play and successors; reports past and potential targets and TTPs relevant to your profile and vendors
- Stealer infections — detects Lumma, RedLine, Vidar, StealC and others harvesting your employees
- Data leakage intel — credential leaks, stealer-log drops, data-for-sale listings
- Card-fraud monitoring — credit/debit cards on darknet markets (Financial Services add-on)
- MITRE ATT&CK view — TTP mapping against your sector
- Supply-chain / vendor risk — 25 vendors monitored by default (expandable)
Module · Brand Protection
Brand & Executive Protection
- Typosquatting + lookalike domain detection
- Rogue mobile-app monitoring (iOS/Android app stores)
- Brand + executive impersonation (LinkedIn, X, Telegram, Facebook)
- Data leak in code repositories
- Open cloud-bucket detection
- FortiGuard Labs takedown service — 2 default per account, add-ons via
FRN-TKD-*SKUs
Module · EASM
Attack Surface Management
- Continuous external asset discovery (domains, sub-domains, ASNs, IPs)
- Alerts on exploitable vulnerabilities, mis-configurations, SSL cert issues, exposed DB services
- Internal Attack Surface Management via lightweight scanner container
- Web-application security assessment (SQLi, XSS, RCE; auto-discovers exposed APIs)
- Supply-chain and subsidiary monitoring
Module · Orchestration
Security Orchestration
- Pre-built playbooks: Vulnerability Intelligence, Ransomware Intelligence, Malware Intelligence, APT, CERT Advisories
- Visual drag-and-drop playbook builder + low-code mode
- 100 playbook executions/month default; stackable add-ons
- Integrates with FortiGate, FortiSOAR, FortiSIEM, FortiDAST; AWS / Azure / GCP; Teams, Slack, email
A concrete example of ACI in action: when Fortinet's own July 2023 Cl0p roundup states "As of July 15th, 2023, Fortinet's FortiRecon service listed 419 victim organisations on the Cl0p ransomware data leak site" — that 419 is a FortiRecon ACI count. The product doesn't scrape leak sites manually; it ingests the feed continuously, maps to MITRE ATT&CK, and alerts when a customer or their supply-chain vendor appears.
Part 6 — India-Specific Reality Check
Login credentials exposed globally and flagged by CERT-In in advisory CIAD-2025-0018 on 23 June 2025. Consolidated from 30 distinct sources, "predominantly acquired through info stealer malware attacks" per CERT-In's own wording. Any Indian enterprise's users are almost certainly represented in this dataset somewhere.
Source: CERT-In Advisory CIAD-2025-0018Manufacturing 30.14%
Manufacturing absorbed 30.14% of reported Indian ransomware incidents in 2024. LockBit alone responsible for 61.8% of tracked attacks against Indian targets.
44,000+ Lumma infections
Indian Windows systems compromised by Lumma Stealer in March–May 2025. RisePro, Vidar and RedLine also active. Indian organisations averaging 2,000+ cyberattacks per week in 2025 — well above global average.
India 2nd globally
Across the full infostealer dataset (Aug 2023 – Feb 2024), "Brazil overwhelmingly dominated the counts for the highest number of infostealer logs, followed by India." (Caught in the Net, 2 Jul 2024.)
12,632 ChatGPT creds
India accounted for 12,632 stolen ChatGPT credentials on illicit markets between June 2022 and May 2023 — the highest count in Asia-Pacific. The credential file typically came from a Lumma or RedLine stealer log.
Digital Lutera UPI fraud
Toolkit distributed across 20+ Telegram groups, each with 100+ members. One monitored group: ₹25–30 lakh fraudulent transactions in two days. APK masquerades as traffic-fine / wedding invitation, forwards SMS/OTP to attacker Telegram channel, registers victim's UPI on attacker device.
750M subscriber records
1.8TB dataset of ~750 million Indian mobile subscribers (name, number, address, Aadhaar) listed for $3,000 on dark web by actors "CyboDevil" and "UNIT8200".
The AIIMS Delhi attack — still the reference Indian incident
23 November 2022: All India Institute of Medical Sciences (AIIMS) Delhi ransomware attack. More than 100 servers encrypted; approximately 40 million patient records impacted. Ransom demand reported at roughly ₹200 crore (~$24.5M) in cryptocurrency. CERT-In's investigation identified payloads including Wammacry variant, Mimikatz and a trojan. ProtonMail addresses used by attackers ("dog2398" and "mouse63209") were generated in Hong Kong the first week of November 2022. CERT-In's initial analysis flagged possible foreign state-actor involvement. Systems were restored on 12 December 2022. The incident remains the anchor case for Indian health-sector cybersecurity planning.
Other 2024–2025 named Indian victims (via public reporting): Polycab India, Motilal Oswal, SPARSH Hospital, ASRAM Medical College, Lupin Limited, NewGen. Roughly two dozen ransomware brands attacked Indian targets in January–November 2025 (Check Point India 2025).
💡 Why this changes the DPDPA conversation
Under the Digital Personal Data Protection Act 2023, "personal data breach" triggers notification obligations. If an employee's Lumma-infected home PC has leaked their SSO cookies into a Russian Market listing, and those cookies reach corporate SSO and touch Indian data-principal records — the breach detection clock starts from the time you knew, not from the time the credential was sold. Dark-web monitoring is the mechanism that lets you know.
Part 7 — If You Find Yourself on the Dark Web: A Playbook
FortiRecon ACI detects exposure. The value of the detection depends entirely on what your team does next. This is the playbook Ogma runs.
Verify the source
Analyst confirms the leak is genuine — not a recycled breach from 2019, not a typosquat detection, not a false positive. Timestamp and original paste-site or channel captured as evidence.
Scope the exposure
Which users, which services, which data. Check if the same stealer log contains cookies for SSO, VPN, GitHub, Okta, admin consoles. Cookies are worse than passwords because they bypass MFA.
Contain
Force password reset, kill active sessions (revoke SSO tokens), invalidate OAuth refresh tokens. If admin credentials are in play, quarantine the endpoint and do an IR sweep for persistence. Cycle API keys and SSH keys that might be in the log.
Takedown where applicable
FortiGuard Labs takedown for fake domains, phishing pages, rogue mobile apps, social-media impersonation. Two takedowns per account included by default; more via add-on. Typical resolution time: days, not weeks.
Notify — DPDPA, CERT-In, regulators
If personal data of Indian data principals is involved, prepare Data Protection Board notification. CERT-In has a 6-hour incident reporting requirement for certain categories. Maintain the evidence package for the auditor.
Root-cause the infection
Most stealer-log leaks trace back to a personal device. Was the compromised user using corporate SSO on a home laptop? Was the browser profile synced? Policy updates and endpoint hardening prevent recurrence.
✅ Key Takeaways
- The dark web in 2026 is an economy — infostealer log drops, ransomware leak sites, Telegram criminal channels — not a single hidden corner.
- Infostealers are the credential pipeline. Microsoft hit 394,000 Lumma infections in 60 days in 2025. Russian Market offered 180,000+ logs in H1 2025. India ranks second globally by volume.
- Ransomware hasn't stopped — it's reorganised. Operation Cronos identified 194 LockBit affiliates and 7,000+ attacks in 20 months. Akira alone claimed $244M by late 2025.
- Telegram, even under pressure, remains the centre of gravity. KELA measured 362× more criminal activity on Telegram than on all alternatives combined after the Durov arrest.
- Indian exposure is not theoretical: CERT-In flagged 16 billion exposed credentials; Check Point counted 44,000+ Indian Lumma infections in one quarter; 20+ Telegram groups run active UPI-fraud operations.
- FortiRecon ACI is the industry's top-ranked platform for exactly this category of threat — Overall + Market + Innovation Leader in the 2025 KuppingerCole Leadership Compass for ASM.
Find out what's already out there about your organisation
Ogma will run a free one-shot FortiRecon scan against your primary domain and email range and deliver a written exposure report within 48 hours. If anything's leaked, you'll know. If it's clean, you'll have a baseline. Either way, you'll know more than you do right now.
📡 Request a free exposure scan See the FortiRecon service →🔥 Authorised Fortinet Partner
Talk to the threat team
Ogma Consulting runs FortiRecon as a managed service for Indian BFSI, manufacturing and government estates. NSE7-certified engineers, 24×7 analyst-verified alerts, India-context Hindi/regional-language coverage, FortiGuard Labs takedown support, DPDPA breach-notification readiness.
Stay ahead of cyber threats
One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.