Initial-Access Brokers & the Access Economy
An initial-access broker (IAB) is a specialist who breaks into a network, verifies and packages the access (admin rights, VPN credentials, RDP, a foothold on a domain controller), and lists it for sale on a criminal forum — supplying the front door a ransomware affiliate uses before encrypting anything. The IAB is the wholesale tier of the attack supply chain, and in H2 2025 it professionalized and moved up-market: Rapid7's threat research found the average alleged revenue of victim organizations whose access was being sold had climbed to $3.24B, while the average advertised base price for an access listing jumped to ~$113,000 — roughly a 40× increase over 2024. The access economy is where the #1 intrusion vector — stolen credentials — is manufactured, priced, and distributed, which is a central reason identity security is among the most acquisitive segments in the market.
The two layers of the access economy
The access economy is a two-tier funnel that converts raw stolen data into a turnkey intrusion:
The bulk layer is the infostealer / stealer-log market — high-volume, low-price, commodity. Infostealer malware (Lumma, RedLine, Vidar, Raccoon, StealC) harvests everything a browser stores: saved passwords, session cookies, autofill, crypto wallets. The output ("logs") sells for $5–$50 per log (~$10 average per infected machine) in automated dark-web shops, while the malware itself is rented as a service for $100–$200/month (StealC, for example, ~$200/month or ~$800 for six months). This is the raw material — billions of stolen credentials, with industry trackers citing on the order of 15B+ exposed credentials circulating.
The wholesale layer is the IAB — low-volume, high-price, curated. The broker takes raw access (often sourced from the bulk layer, or from exploiting an edge device), validates it, establishes how valuable the victim is, and resells a verified, ready-to-use foothold. This is the value-add step: a buyer pays a premium for access that is confirmed to work, to a named target, at a known privilege level. The H2-2025 data shows brokers concentrating on government (~14% of listings), retail, and IT, and clustering on newer forums — RAMP and DarkForums together carried ~81% of observed access threads after older marketplaces were disrupted.
Why the access economy matters more than any single attack
The IAB layer is the structural reason ransomware survives takedowns and a central reason identity is among the most active M&A categories. Three implications:
- It decouples intrusion skill from monetization. A ransomware affiliate no longer needs to know how to break in — only how to buy access and deploy a payload. This is the same labor-specialization that made RaaS resilient: the access supply is a distinct, liquid market that persists regardless of which extortion brand is up or down.
- It makes credentials the product. When the wholesale price of "a working login to a $3B-revenue company" is six figures, the defensive value of preventing credential theft and abuse is enormous — and quantifiable. That is the demand curve under IAM, PAM, MFA, ITDR, and machine-identity.
- It moves up-market. The H2-2025 shift to higher-revenue victims and premium pricing means brokers are doing more reconnaissance and selectivity — the criminal market maturing toward "enterprise sales." Premium access implies premium targets, which implies the defensive spend follows the same up-market curve.
The landscape: markets, malware, and the disruption pattern
| Layer | Representative names (2025–26) | Note |
|---|---|---|
| Infostealer families | Lumma, RedLine, Vidar, Raccoon, StealC, Atomic (macOS) | Sold as MaaS; periodic LE takedowns (e.g., the 2025 disruptions) reshuffle market share |
| Log marketplaces | Automated dark-web shops + Telegram channels | Commoditized; volume-driven; cheap entry |
| Access forums | RAMP, DarkForums (≈81% of H2-25 threads), Exploit, XSS | Migrated here after older forums seized; access "auctions" |
| Historical takedowns | Genesis Market (seized Apr 2023), various RaaS infra | Each seizure displaces — but does not destroy — the supply |
The disruption pattern matters for the bear case: law enforcement has repeatedly seized marketplaces (Genesis Market in April 2023 being the landmark) and disrupted infostealer infrastructure — and each time the supply migrates to new forums rather than disappearing. The access economy is a hydra, which is precisely why the durable defensive answer is to make the stolen credential worthless (phishing-resistant MFA, session-binding, identity threat detection) rather than to rely on suppressing supply.
Falsifiable bear case
The "access economy guarantees an identity-security supercycle" thesis has real counter-arguments. (1) Phishing-resistant auth could collapse the value of stolen credentials. If passkeys/FIDO2 and continuous session validation reach scale, a stolen password becomes far less useful — compressing both the criminal market and the legacy MFA/credential-monitoring vendors built around the password problem. The winners would be a narrower set (passwordless, ITDR) than the broad identity complex. (2) Platform bundling absorbs the category. Microsoft Entra, Okta, and the platform vendors increasingly ship identity-threat detection and credential monitoring as features, capping standalone pure-plays. (3) The data is noisy. "Average victim revenue $3.24B" and "$113k base price" come from advertised listings, which are self-reported and gameable; the true clearing prices may differ. None of these kills the thesis — credentials will be stolen and sold for years — but each reshapes which identity vendors capture the value.
/ angle
→ The access economy is the proof behind the identity-M&A wave. When the wholesale market prices "a working corporate login" in the six figures, the strategic logic of Palo Alto–CyberArk and the broader identity consolidation (Identity) is no longer abstract — it is the defensive answer to a priced criminal product. That makes ITDR, machine-identity (20b), and credential-/dark-web-intelligence vendors a coherent buy-side targeting cluster.
→ Infostealer + browser theft → browser-security thesis. Logs are harvested from the browser, which is why enterprise browser and browser-extension security (the CrowdStrike–SGNL/Seraphic, Palo Alto–Talon, Zscaler–SquareX lineage on 11) sits directly downstream of this market.
Sources: Rapid7 — IABs shift to high-value targets & premium pricing (H2 2025) · DeepStrike — Dark Web Data Pricing 2025 · DeepStrike — Stealer Log Statistics 2025 · Flare — Infostealer Malware · DeepStrike — Dark Web Statistics 2025
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.