Take down a large criminal marketplace and the demand it served does not go with it. Rapid7's threat intelligence team has been watching where that demand went, and the answer is a scattering: smaller specialist storefronts, Telegram channels and peer-to-peer arrangements selling the same goods without the single point of failure a big market represents.
Analyst Gal Givon calls the result a fragmented environment. The fragmentation is the point.
What a beginner can buy off the shelf
The shops Rapid7 monitors, among them Xleet, BlackPass, Infodig and Styx, between them cover the whole path from idea to payout. Manuals first, often from a forum or from Styx, then infrastructure and credentials, then the stolen personal or business data used to cash out, frequently through business email compromise, where a customer is talked into wiring money straight to an account the fraudster controls.
The infrastructure listings are the part defenders will recognize. Xleet, first observed in 2022, advertises stolen credentials at scale alongside mailer and SMTP servers, cPanel access, web shells, SSH and RDP into what it claims are protected networks, and VoIP accounts. Rapid7 notes that Xleet is unusually open about its stock, often posting screenshots or proof emails sent to a compromised account's own address. Access to somebody else's SMTP server is what lets a fraudster reach a large audience while sliding past email filtering, which is precisely the leverage that makes a supply-chain phishing run work.
BlackPass, which began life as Paysell, sells RDP credentials and proxy services for hiding an operator's real location. Rapid7 says estimates put its lifetime sales in the hundreds of millions of accounts, that legal documents indicate Russian control, and that its stock targets Western countries, particularly the United States. Infodig has dealt in phone infrastructure, and foreign or stolen numbers are useful for intercepting one-time passcodes, for impersonating an IT helpdesk by phone, and for self-registering accounts elsewhere.
Styx is the odd one out. It rents promotional space to sellers who trade mainly through their own Telegram channels, and runs a freemium tier that keeps the valuable material behind a significant fee. Rapid7 reads both as signs the administrators know how much competition they now have.
A new framework, and the gap it leaves
MITRE introduced its Fraud Fighting Framework, F3, in early 2026. It borrows the familiar matrix structure but extends into the monetization stage where cybersecurity and financial crime meet, and Rapid7 says the overlap with what it sees in these marketplaces is heavy, mostly account takeover techniques. Its criticism is about organizational shape rather than content: a matrix cannot fix the fact that security, fraud and financial crime teams in most companies do not share what they know, and watching these venues for mentions of your own assets only pays off when somebody inside can act on what comes back.
None of this is new in kind. Group-IB mapped a similar full-stack economy when it traced a billion-dollar fraud network built around the 2026 World Cup, and the resilience on display here is the same resilience that let one phishing kit stand up 700 fresh pages after an FBI takedown. What has changed is the shape of the target. There is no longer one market to seize, which makes a takedown a disruption rather than an ending, and makes monitoring the smaller venues the only way to see what is being sold about you. Rapid7's write-up is published in full on its blog.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.