Cointime

Download App
iOS & Android

Fraud Shop Genesis Market Shut Down in International Law Enforcement Operation, Sanctioned by OFAC

Validated Project

On April 4, 2023, authorities shut down popular fraud shop Genesis Market and arrested hundreds of its users around the world in a coordinated international law enforcement effort dubbed Operation Cookie Monster. Additionally, OFAC sanctioned the criminal marketplace the next day on April 5.

Fraud shops like Genesis are an important part of the cybercriminal ecosystem. Typically operating on the dark web, they facilitate the sale of stolen data and personally identifiable information (PII), which in turn can be used for several different forms of cybercrime, including scamming, identity theft, and ransomware. Below, we’ll break down Genesis Market’s role in the cybercriminal ecosystem plus its on-chain activity, and show you how today’s law enforcement action makes the internet a safer place.

What was Genesis Market?

Genesis Market was a fraud shop catering to users around the world. Its marketplace allowed for the sale of several different forms of stolen PII such as credentials for email addresses, social media accounts, bank accounts, and cryptocurrency service accounts, all available to be perused in a searchable database. In many cases, Genesis could provide active session cookies for these accounts that allowed buyers to bypass multi-factor authentication. The screenshot below shows a typical listing on Genesis.

The listing is for a single, compromised victim device, and shows the services that device accessed and for which the seller has user credentials. Those services include three cryptocurrency exchanges (whose names we’ve blurred out) meaning a buyer of this user’s data could potentially steal any funds the victim holds in those accounts. Victims like the one shown above typically have had their machines compromised by information stealing malware, which can access credentials stored in web browsers like Chrome and Firefox. In addition to individual users’ PII, Genesis also offered compromised remote access credentials that could allow cybercriminals like ransomware gangs to break into organizations’ computer networks.

Genesis Market’s on-chain activity

Genesis Market has received tens of millions of dollars’ worth of cryptocurrency during its lifetime, primarily in Bitcoin. Most of its incoming funds since May came from mainstream exchanges, with crypto ATMs also contributing a significant amount.

We also see a few spikes in value received from services we’ve labeled risky, most of which are exchanges with low or no KYC. The Chainalysis Reactor graph below shows a number of actors sending funds to Genesis, including ransomware attackers, underground money laundering services, and other cybercriminals.

Note the relatively low amounts sent from each of these clusters. Credentials purchased on Genesis could cost as little as $1 or less, so while $15 sent from a credit card broker may not seem like a huge deal, it could represent serious financial losses for 15 individuals.

Shutting down Genesis makes all internet users safer

Data sellers like Genesis aren’t necessarily the first thing you think of when it comes to cybercrime, but these sorts of ancillary service providers are crucial to enabling scamming, hacking, and ransomware attacks. For that reason, we commend all of the agencies around the world who contributed to the shutdown of Genesis.

While Genesis’ OFAC designation doesn’t list any of the service’s cryptocurrency addresses, Chainalysis has identified hundreds of thousands of Genesis addresses, with more likely to come as our data improves over time. We’ve already labeled these addresses as belonging to a sanctioned entity in all of our products, and any Chainalysis KYT users with exposure prior to designation would have received alerts for its previous category — fraud shop — per their alert preferences. We will share any other relevant updates on this case as is possible.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.

Read more: https://blog.chainalysis.com/reports/genesis-market-fraud-shop-shutdown-sanction/

Comments

All Comments

Recommended for you

  • Ithaca Completes $20 Million New Round of Financing

    Ithaca has completed a new round of funding of $20 million, with participation from Paradigm.

  • BTC breaks through $61,500

    The market shows BTC breaking through $61,500 and now reporting $61,541.65, with a 24-hour increase of 0.77%. The market is volatile, please be prepared for risk control.

  • BTC breaks through $61,000

    The market shows BTC has broken through $61,000 and is now trading at $61,016, with a 24-hour increase of 0.08%. The market is volatile, so please be prepared for risk control.

  • CryptoQuant: More than 63,000 BTC transferred to exchanges from October 7 to 9

    According to CryptoQuant's data, since October 7, 2024, more than 63,000 BTC have been sent to cryptocurrency exchanges, including approximately 28,000 BTC on October 7, 23,500 BTC on October 8, and approximately 12,000 BTC on October 9.

  • Bitcoin hash rate hits new all-time high, reaching 698 EH/s

    According to the latest network data, Bitcoin's computing power reached a historic high of 698 exahashes (EH/s) per second on October 10, 2024. This new record surpasses the previous record of 693 EH/s set on September 8.

  • Hong Kong Treasury Department Deputy Secretary Chan Ho-lim called on investors to participate in virtual currency trading through licensed exchanges

    Chen Haolian, Deputy Director of the Hong Kong Financial and Treasury Bureau, called on investors to participate in virtual currency trading through licensed exchanges. Chen Haolian stated that the Hong Kong government is actively building the entire ecosystem, and the Investment Promotion Bureau is currently promoting relevant companies to expand their business in Hong Kong. The ecosystem of virtual assets includes not only exchanges, but also funds for trading virtual assets and central bank digital currencies (CBDCs). Consultation on stablecoin regulation has been completed, and relevant legislation is currently being prepared for submission to the Legislative Council.

  • US Senators propose stablecoin regulation bill

    US Senator Bill Hagerty, who supports cryptocurrencies, has announced a legislative discussion draft aimed at creating a regulatory framework for stablecoins, which is very similar to the work being done in the House of Representatives. Republican Hagerty said in a statement on Thursday that his bill "provides much-needed regulatory clarity." The bill is very similar to the Clarity for Payment Stablecoins Act drafted by Republican Representative Patrick McHenry and Democrat Maxine Waters in the House.

  • The number of first-time unemployment claims in the United States last week was 258,000

    The number of first-time unemployment claims in the United States last week was 258,000, estimated to be 230,000, and the previous value was 225,000.

  • ZachXBT: Suspected insiders made $3.8 million in profits on RTR

    On August 10th, Chain Detective ZachXBT posted on social media that 4 addresses made a profit of $3.8 million in the RTR sell-off, with the 9G1ELG and GHoW2 addresses belonging to the same person and receiving 500 SOL in new funds within minutes after the TGE. Previously, it was reported that Restore The Republic (RTR) had its TGE on the evening of August 8th, with rumors circulating in the community that it was related to a new project by the Trump family. The RTR token reached a high of $0.156 on August 9th at midnight. Afterwards, Eric Trump, the current Executive Vice President of the Trump Organization and son of Donald Trump, warned on social media to "be careful of false tokens" and that the only official Trump project has yet to be announced and will be announced on Twitter first. After the statement was released, RTR quickly dropped by about 95%, with a trading volume of $164 million within just 15 hours of its creation.

  • The U.S. Internal Revenue Service has released a new draft of the crypto tax form, which no longer requires filling in wallet addresses and transaction IDs

    The US Internal Revenue Service (IRS) released an updated draft version of tax form 1099-DA for cryptocurrency brokers and investors to report certain transaction income. The public has 30 days to provide feedback to the IRS on this version. Starting in 2026, cryptocurrency investors who use brokers (currently mainly Coinbase and Kraken, among others) will receive 1099-DAs from these brokers to report certain cryptocurrency sales and trades as taxable events to the IRS. IRS officials say this form will "bring more convenience and clarity" to users who pay US cryptocurrency taxes.