Cointime

Download App
iOS & Android

Fraud Shop Genesis Market Shut Down in International Law Enforcement Operation, Sanctioned by OFAC

Validated Project

On April 4, 2023, authorities shut down popular fraud shop Genesis Market and arrested hundreds of its users around the world in a coordinated international law enforcement effort dubbed Operation Cookie Monster. Additionally, OFAC sanctioned the criminal marketplace the next day on April 5.

Fraud shops like Genesis are an important part of the cybercriminal ecosystem. Typically operating on the dark web, they facilitate the sale of stolen data and personally identifiable information (PII), which in turn can be used for several different forms of cybercrime, including scamming, identity theft, and ransomware. Below, we’ll break down Genesis Market’s role in the cybercriminal ecosystem plus its on-chain activity, and show you how today’s law enforcement action makes the internet a safer place.

What was Genesis Market?

Genesis Market was a fraud shop catering to users around the world. Its marketplace allowed for the sale of several different forms of stolen PII such as credentials for email addresses, social media accounts, bank accounts, and cryptocurrency service accounts, all available to be perused in a searchable database. In many cases, Genesis could provide active session cookies for these accounts that allowed buyers to bypass multi-factor authentication. The screenshot below shows a typical listing on Genesis.

The listing is for a single, compromised victim device, and shows the services that device accessed and for which the seller has user credentials. Those services include three cryptocurrency exchanges (whose names we’ve blurred out) meaning a buyer of this user’s data could potentially steal any funds the victim holds in those accounts. Victims like the one shown above typically have had their machines compromised by information stealing malware, which can access credentials stored in web browsers like Chrome and Firefox. In addition to individual users’ PII, Genesis also offered compromised remote access credentials that could allow cybercriminals like ransomware gangs to break into organizations’ computer networks.

Genesis Market’s on-chain activity

Genesis Market has received tens of millions of dollars’ worth of cryptocurrency during its lifetime, primarily in Bitcoin. Most of its incoming funds since May came from mainstream exchanges, with crypto ATMs also contributing a significant amount.

We also see a few spikes in value received from services we’ve labeled risky, most of which are exchanges with low or no KYC. The Chainalysis Reactor graph below shows a number of actors sending funds to Genesis, including ransomware attackers, underground money laundering services, and other cybercriminals.

Note the relatively low amounts sent from each of these clusters. Credentials purchased on Genesis could cost as little as $1 or less, so while $15 sent from a credit card broker may not seem like a huge deal, it could represent serious financial losses for 15 individuals.

Shutting down Genesis makes all internet users safer

Data sellers like Genesis aren’t necessarily the first thing you think of when it comes to cybercrime, but these sorts of ancillary service providers are crucial to enabling scamming, hacking, and ransomware attacks. For that reason, we commend all of the agencies around the world who contributed to the shutdown of Genesis.

While Genesis’ OFAC designation doesn’t list any of the service’s cryptocurrency addresses, Chainalysis has identified hundreds of thousands of Genesis addresses, with more likely to come as our data improves over time. We’ve already labeled these addresses as belonging to a sanctioned entity in all of our products, and any Chainalysis KYT users with exposure prior to designation would have received alerts for its previous category — fraud shop — per their alert preferences. We will share any other relevant updates on this case as is possible.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.

Read more: https://blog.chainalysis.com/reports/genesis-market-fraud-shop-shutdown-sanction/

Comments

All Comments

Recommended for you

  • Web3 AI platform ChainML completes $6.2 million seed round of financing

    Web3 AI platform ChainML has announced the completion of a $6.2 million seed round of expansion financing, led by Hack VC, with participation from Inception Capital, HTX Ventures, Figment Capital, Hypersphere Ventures, and Alumni Ventures. The platform also announced the launch of its agent-based foundation layer, Theoriq.

  • Metaverse project Baby Shark Universe completes seed round financing

    Baby Shark Universe project, a metaverse project, has completed a seed round of financing with a valuation of $34 million. Participating investors include Animoca Brands, CREDIT SCEND, Sui Foundation, Comma3 Ventures, Creditcoin, GM Ventures, Neuler, Notch Ventures, X+, and Planetarium. The specific amount has not been disclosed, and the new funds will be used for development and global marketing. According to reports, Baby Shark Universe is an open-world role-playing game where players can create their own game content (items, maps), enjoy content created by other players, and expand the game's narrative based on their choices and actions.

  • Hong Kong Stock Exchange Confirms Crypto ETFs Unavailable to Mainland Chinese Investors

    According to Coindesk, the Hong Kong Stock Exchange has confirmed that cryptocurrency ETFs are not available to mainland Chinese investors. Hong Kong's cryptocurrency ETFs will provide a means to bypass capital controls in mainland China due to their unique physical redemption model.

  • Web3 social infrastructure UXLINK completes $5 million in financing

    Web3 social infrastructure UXLINK announced the completion of a new round of $5 million financing, led by SevenX Ventures, INCE Capital, and HashKey Capital. It is reported that UXLINK's total financing has now exceeded $15 million.

  • Chinese police bust underground bank using cryptocurrency for illegal currency conversion

    Chinese police have arrested six people for running an illegal currency conversion operation that used cryptocurrency to handle around $296 million. The operation was discovered by the Public Security Bureau of Panshi City, Jilin, and involved an "underground bank" that exploited the anonymity and ease of cross-border transfers offered by crypto. The operation used domestic accounts to receive and transfer funds, and exchanged between the yuan and South Korean won. The service was used by Korean purchasing agents, e-commerce firms, and import/export companies, among others.

  • Hong Kong Securities Regulatory Commission warns the public to beware of a suspicious asset investment product called "LENA Network"

    Hong Kong Securities and Futures Commission warned the public to be wary of a suspicious virtual asset investment product called "LENA Network". The product involves pledging and lending arrangements related to virtual assets, and claims to provide high returns to investors. This investment product has not been approved by the Securities and Futures Commission for sale to the Hong Kong public. The Securities and Futures Commission notes that the Hong Kong public can access information about the product and contact the product through the Internet. The Securities and Futures Commission advises against trusting those "too good to be true" investment opportunities and remaining vigilant when making investment decisions.

  • Hong Kong Securities and Futures Commission: The Anti-Money Laundering Ordinance applies to the virtual asset industry

    The "virtual currency to ETF" mechanism in Hong Kong has raised concerns about money laundering. The industry believes that the review difficulty, such as KYT (Know Your Token), is high. Some individuals with mainland backgrounds are trying to conduct small-scale "virtual currency to ETF" transactions, taking the opportunity to "whiten" their own holdings of ether and bitcoin through forms such as personal accounts. They have also deployed some virtual currencies to Hong Kong's virtual currency exchanges and will decide whether to increase capital in the future depending on the situation. When responding to relevant questions, the Hong Kong Securities and Futures Commission emphasized that in the operation of ETF products, every link in the entire virtual asset ecosystem, including fund companies, custodians, asset trading platforms, participating brokers, etc., must be licensed or recognized institutions and strictly comply with requirements such as asset custody, liquidity, valuation, information disclosure, and investor education. The "Anti-Money Laundering Ordinance" of the Securities and Futures Commission also stipulates that financial institutions and designated non-financial enterprises and industry personnel must comply with customer due diligence and record-keeping requirements, and relevant regulations apply to the virtual asset industry.

  • TON community member: Some TON wallets received virtual account NFTs starting with "888", which is a phishing project

    On May 13th, according to a member of the TON official community, a new NFT with a virtual number starting with "888" has been added to the TON wallet. However, the transaction fee for each transfer is as high as 1 TON, which is caused by the fishing project changing the Gas.

  • Swiss Crypto Bank Amina: Listing Ethereum as a Security Could Cause Many Crypto Teams to Exit the Space

    Swiss encrypted bank Amina stated in the latest "Cryptocurrency Market Monitoring" report that classifying Ethereum as a security could not only bring risks to the entire cryptocurrency market, but also lead to many cryptocurrency teams exiting the field. This determination could hinder the development of the cryptocurrency market and potentially reverse progress made over the years. In addition, the US SEC is likely to delay its decision on the status of Ethereum, putting the cryptocurrency asset in a "gray area".

  • Market News: South Africa authorizes 75 companies as cryptocurrency service providers

    According to Jinshi news, South Africa has authorized 75 companies as cryptocurrency service providers.