Picture a representative access-broker listing assembled from patterns documented across underground markets: domain admin access to a US manufacturing company, 4,000 hosts, annual revenue north of $200 million. No exploit code, no malware, no encryption — just a login. The seller may never deploy ransomware or negotiate with the victim; a buyer handles the next stage, and the company’s name may later appear on a leak site.

The seller didn’t do the breaking-and-entering and the burglary. They just sold the key.

TL;DR

  • Initial Access Brokers (IABs) are threat actors who specialize only in breaching networks — via stolen credentials, exploited edge devices, or phishing — then sell that access to ransomware operators, espionage actors, and other buyers.
  • Access is sold on forums like Exploit, XSS, RAMP, and DarkForums, and increasingly through private Telegram channels. Rapid7 measured the average listing price jumping from $2,726 to $113,275 year-over-year in H2 2025, after a major forum collapse consolidated the market into fewer, higher-value listings.
  • Mandiant’s M-Trends 2026 report found the median time between an IAB establishing access and handing it to a ransomware crew has dropped from over 8 hours (2022) to 22 seconds (2025) — evidence of automated, pre-arranged pipelines rather than one-off forum sales.
  • Named clusters like GOLD MELODY (aka UNC961, PROPHET SPIDER) and EXOTIC LILY (tied to Conti and Diavol) show this specialization has existed for years and is well-documented by Mandiant, Secureworks, and Google’s Threat Analysis Group.
  • Edge devices — VPNs, firewalls, RMM (Remote Monitoring and Management) tools — remain IABs’ favorite door in, which is exactly where patching speed and log hygiene pay off most.

Why This Matters to You

If you think about ransomware as a single actor breaking in and encrypting your files, you’re modeling the wrong threat. Modern ransomware operations are supply chains, and the company that breaches your VPN gateway is very often not the company that later demands payment.

That distinction changes what you should watch for. A scan against your edge devices this week, a suspicious RDP (Remote Desktop Protocol — a Windows feature for remote system access) login from an unfamiliar IP next week, and a ransomware note a month later can all be the same incident, executed by three separate criminal businesses that never spoke to each other outside a forum listing. Understanding the IAB market tells you where the earliest, quietest signals of an incoming attack actually show up.


Table of Contents


What Is an Initial Access Broker?

An Initial Access Broker (IAB) is a threat actor whose entire business is getting into networks — and nothing else. No ransomware deployment, no data theft for extortion, no espionage. They breach an organization, establish a reliable foothold, and then sell that foothold to someone else who does the actual damage.

Think of it as a real-world burglary analogy taken literally: one specialist figures out how to duplicate the key to a warehouse, then sells that key to whoever wants to rob it. The locksmith never enters the building. The buyer never has to pick a lock.

This specialization exists because breaking in and monetizing a breach require different skills, different risk tolerance, and different time horizons. An IAB wants speed, volume, and a clean exit before anyone notices. A ransomware affiliate wants to stay inside long enough to map the network, disable backups, and deploy encryption everywhere at once. Combining both skill sets in one operator is possible, but specializing is more profitable — which is exactly why the market split into distinct roles.


The Division of Labor in Modern Cybercrime

Ransomware-as-a-Service, or RaaS, is the model most IAB customers operate under: a ransomware “developer” builds and maintains the encryption software, negotiation portal, and leak site, then licenses it to independent “affiliates” who handle the actual intrusion and deployment in exchange for a cut of the ransom. IABs sit one layer earlier in that chain, feeding affiliates a foothold they don’t have to find themselves.

RoleWhat they doWhat they never touchHow they get paid
Initial Access BrokerBreaches networks via stolen creds, exploited edge devices, or phishing; sells the footholdRansomware payloads, extortion negotiations, victim dataFlat fee per sale, or a small percentage of the eventual ransom
RaaS OperatorBuilds and maintains the ransomware, leak site, and negotiation infrastructureThe initial breach itselfLicensing fee plus a percentage cut of every affiliate’s ransom
RaaS AffiliateBuys or finds access, moves laterally, exfiltrates data, deploys the ransomwareMalware developmentThe majority share of the ransom, after the operator’s cut
Ransom Negotiator / Money LaundererHandles victim communication and converts cryptocurrency into usable fundsAny technical intrusion stepPercentage fee on successful payment

No single person in this chain needs to be a generalist. That’s the point — and it’s why arresting one IAB rarely stops the ransomware groups who bought from them; there’s usually another seller with similar access up within days.


Where and How Access Gets Sold

The forums

Access sales happen primarily on Russian-language cybercrime forums. Exploit and XSS have historically been the two most established venues, alongside newer entrants RAMP and DarkForums — the latter two grew fast after BreachForums was seized and XSS’s administrator was arrested in 2025, scattering sellers across smaller, harder-to-monitor platforms. Rapid7’s threat intelligence team, tracking listings through the second half of 2025, found DarkForums had become the single most active venue with 221 access-sale threads, ahead of RAMP’s 208, while activity on Exploit and XSS both declined sharply — XSS dropped from nearly 200 threads in 2024 to just 18. Beyond the forums, private, invite-only Telegram channels have become a parallel, less visible sales channel for higher-trust, repeat-buyer relationships sellers don’t want indexed by researchers.

What’s for sale, and what it costs

Listings specify the access type, the privilege level, and increasingly the victim’s estimated revenue — the single best predictor of how much a ransomware affiliate can extract. In the listings Rapid7 analyzed, RDP (Remote Desktop Protocol) access was the most common vector (21.2%), followed by VPN credentials (12.8%) and RDWeb, a web-based RDP gateway (11.2%). Just under a third of listings already came with domain administrator rights — control over the entire Windows domain on day one.

Pricing has moved dramatically. Rapid7’s H2 2025 data shows the average base listing price jumped from $2,726 to $113,275 year over year — a market-structure effect, not a uniform 40x value increase: as cheap listings scattered to smaller forums after the BreachForums takedown, the remaining high-visibility listings on established forums skewed toward premium, pre-vetted access to larger organizations. The range at the extremes is still wide, from a few hundred dollars for a small business to over $50,000 for Fortune 500-scale, domain-admin access. RAMP averaged roughly $6,400 per listing against an estimated $440 million in aggregate victim revenue across its threads.

Government (14.2%), retail (13.1%), and IT organizations (10.8%) were the most represented sectors, with US-based organizations accounting for roughly 31% of all listings globally.


How Buyers Verify What They’re Buying

A ransomware affiliate paying five or six figures for access has an obvious problem: how do they know the seller isn’t lying, or reselling access that’s already been burned by a previous buyer?

Public reporting on this side of the market is thinner than on pricing, because verification happens in private chats, not public posts. What is consistently documented is the shape of the transaction: sellers typically provide proof of access — screenshots of an active session, a directory listing, evidence of domain-level privileges — before payment, and established forums run escrow and vendor-reputation systems, much like any other underground marketplace, where a seller’s track record of delivering working access is visible to prospective buyers. Payment is commonly made in cryptocurrency, including Bitcoin — a choice that can itself become an operational security liability, as the IntelBroker case below shows.


From Breach to Handoff in 22 Seconds

The most striking data point in this entire market comes from Mandiant’s M-Trends 2026 report, based on more than 500,000 hours of incident response work. Mandiant measured the time between an initial access broker establishing a foothold and handing that access to a secondary threat group — and found the median has collapsed from over 8 hours in 2022 to just 22 seconds in 2025.

We covered this same finding in more depth in our piece on the collapsing exploitation window, but it’s worth restating in the IAB context specifically: a 22-second median handoff is not a human posting a forum listing and waiting for a buyer to respond. It strongly suggests automated, pre-arranged pipelines — IABs and their downstream ransomware partners running tooling that delivers access (or even deploys second-stage malware directly) the moment a breach succeeds, bypassing the public marketplace entirely for established relationships.

That has a direct defensive implication: by the time your SOC (Security Operations Center) has triaged the alert for the initial compromise, a second, better-resourced threat actor may already be inside. Mandiant also found that exploitation of vulnerabilities remains the single leading initial access vector for the sixth consecutive year, with network edge devices disproportionately represented among the systems attackers hit first.


Notable IAB Groups on the Record

Most access sales never get attributed to a named group — sellers use forum handles, not brand names, and turnover is high. But several IAB clusters have been tracked closely enough by threat intelligence teams to name with confidence.

EXOTIC LILY

Google’s Threat Analysis Group documented EXOTIC LILY operating from at least September 2021 through March 2022, describing it as a financially motivated group functioning as an initial access broker for the Conti and Diavol ransomware operations. At peak activity it sent over 5,000 phishing emails a day to as many as 650 organizations at once, exploiting CVE-2021-40444 (a Microsoft MSHTML vulnerability) before pivoting to ISO files hiding BazarLoader malware, and later a custom loader called BUMBLEBEE. Google noted the group kept a 9-to-5, weekday-only schedule — a professionalized operation, not opportunistic hobbyists.

GOLD MELODY / UNC961 / PROPHET SPIDER

Tracked under three names by three vendors — GOLD MELODY (Secureworks), UNC961 (Mandiant), and PROPHET SPIDER (CrowdStrike) — this group has been active since at least 2017, exploiting unpatched internet-facing servers (Log4Shell, Oracle WebLogic, Apache Struts, Citrix ShareFile, and others) to plant web shells and harvest credentials before selling the resulting access onward. Secureworks’ analysis of five intrusions between mid-2020 and mid-2022 linked the group’s access to later Egregor, MountLocker, and CryptoDefense ransomware deployments. Unit 42 published a 2025 follow-up tracking a related cluster (medium-confidence attributed to the same group) exploiting leaked ASP.NET machine keys to deploy in-memory IIS web server modules, with activity spiking between late January and March 2025 — this broker is still adapting its tradecraft nearly a decade after first being identified.

Storm-0324 and the Microsoft Teams pivot

Microsoft tracks Storm-0324 (also known as Sagrid or DEV-0324) as a financially motivated access broker with a long RaaS résumé: the group has fed access to Maze and REvil, and later to the now-defunct BlackMatter and DarkSide operations, after early campaigns delivering Sage and GandCrab ransomware directly. From July 2023, Storm-0324 pivoted to abuse Microsoft Teams, using a publicly available tool called TeamsPhisher to deliver phishing messages straight into employees’ Teams chat, bypassing normal email filtering. Microsoft responded by suspending the tenants and accounts involved and tightening restrictions on external Teams users.

The cost of getting sloppy: IntelBroker

Not every broker stays anonymous. Kai West, a 25-year-old British national who allegedly operated under the handle IntelBroker, was arrested in France in February 2025 and charged by the US Department of Justice with conspiracy to commit computer intrusions and wire fraud. Prosecutors allege West compromised more than 40 organizations — a US telecom firm, a healthcare provider, an internet service provider, and others — and sold stolen data through BreachForums, causing over $25 million in damages. Reporting from The Record says investigators linked the persona to West after he accepted a traceable Bitcoin payment from an undercover officer instead of insisting on Monero, a harder-to-trace cryptocurrency — a reminder that even sophisticated brokers can undo years of operational security with one payment-method mistake.


Favorite Entry Points: Why Edge Devices Keep Winning

IABs consistently favor internet-facing edge infrastructure — VPN gateways, firewalls, remote management software — because these devices are reachable without any prior foothold and often sit outside normal endpoint monitoring. We’ve written before about why enterprise VPN gateways stay perpetually vulnerable, and the IAB market is a direct consumer of that structural weakness.

CISA’s joint advisory AA25-163A is a concrete, government-confirmed example of this pipeline: ransomware actors, including access brokers connected to the Play ransomware operation, exploited CVE-2024-57727 in the SimpleHelp RMM (Remote Monitoring and Management) tool — disclosed January 16, 2025 — to compromise a utility billing software provider and, through it, its downstream customers. By May 2025, the FBI was tracking roughly 900 entities affected by the broader SimpleHelp exploitation wave the advisory describes. RMM tools are attractive to brokers precisely because their traffic looks like legitimate administrative access, not an intrusion.


Follow the Money

The IAB segment is small relative to the ransomware payments it feeds, but the two move together. Chainalysis’s 2026 Crypto Crime Report estimated IABs received at least $14 million in on-chain cryptocurrency payments during 2025 — a fraction of the $820 million in total ransomware payments tracked the same year (itself down roughly 8% even as claimed ransomware attacks rose about 50%). Chainalysis found spikes in payments to IAB wallets tend to precede increases in ransomware payments and victim leak-site postings by roughly 30 days — a potential leading indicator for the ransomware wave that follows.

Sector data reinforces where the pressure lands. Check Point’s research, published December 2025, found IAB activity against healthcare organizations rose nearly 600% between 2023 and 2024, alongside sharp increases against government, education, and transportation targets — sectors Check Point flagged as having “heightened strategic significance,” a description that applies as much to espionage-motivated buyers as to ransomware crews.


What You Can Do Today

Defending against IABs means detecting reconnaissance and early access before it’s sold, not just responding after a ransomware note appears.

Patch edge devices on an emergency timeline, not a quarterly one. VPN gateways, firewalls, and RMM software are IABs’ preferred door. Treat any CVE affecting internet-facing infrastructure that lands on the CISA Known Exploited Vulnerabilities catalog as a 24–48 hour emergency change, not a normal patch cycle item.

Audit and restrict RMM tools. Inventory every remote management tool with legitimate access to your environment, and alert on any RMM software your IT team didn’t deploy — SimpleHelp, AnyDesk, ScreenConnect, and similar tools are routinely abused because their traffic looks like sanctioned administrative access.

Enforce MFA on every remote access path, especially RDP and VPN. Listings frequently advertise credential-based remote access, including RDP, VPN, and RDWeb. MFA does not stop credential theft or every session-based attack, but it can prevent a password alone from remaining immediately usable as working access.

Rotate and monitor for leaked credentials continuously, not just after a known breach. IABs frequently build footholds from credential-stuffing infrastructure and leaked corporate logins circulating long before anyone notices — a credential-monitoring feed covering your domains is cheap relative to the ransomware incident it can prevent.

Hunt for the quiet reconnaissance phase. Before selling access, brokers confirm domain admin rights, enumerate backups, and map the network to raise the resale price. Unusual internal port scanning, unexplained access to backup infrastructure, and new admin accounts created outside change management are worth alerting on regardless of which stage of the supply chain you catch.

Assume your logs are a target too. Ship logs to storage outside the compromised environment immediately — a buyer’s first move after gaining privileged access is often to clear or tamper with local logs before anyone can review them.



Sources