Genesis Store is a likely Russian cybercrime marketplace and threat actor that has operated since 2018 using a pay-per-bot model to monetize access to data stolen from infected machines. Rather than functioning solely as a self-contained intrusion operator, it appears to occupy a broker role in the cybercrime supply chain, acquiring large volumes of compromised-machine data and reselling victim access and harvested information through a structured market. Evidence indicates Genesis Store has relied heavily on commodity infostealer malware, especially AZORult, and likely worked with one or more malware-as-a-service providers or affiliated suppliers to source infections at scale. The actor’s operations center on compromised endpoints whose stolen browser data, credentials, and related victim metadata are packaged as market listings. Analysis of listing structure and bot identifiers indicates Genesis Store experimented with multiple malware-derived infection classes over time, but from late 2018 onward the overwhelming majority of its inventory was associated with AZORult-derived infections. This suggests a mature procurement and resale pipeline rather than opportunistic one-off campaigns. Historical activity also indicates the operators actively sought partnerships capable of delivering large numbers of infected hosts. Genesis Store’s victim base has included small and medium-sized businesses, enterprises, private-sector organizations, and government officials. The marketplace therefore enabled downstream criminal activity against both commercial and public-sector targets by selling access to already-compromised systems and stolen authentication material. Its core capabilities are consistent with credential theft, session hijacking through stolen browser artifacts, exfiltration of victim data from infected hosts, and post-exploitation monetization via resale of compromised-machine access. The actor is best understood as a persistent cybercriminal access-and-data broker embedded in the broader infostealer and malware-as-a-service ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a pay-per-bot criminal marketplace selling data from infected machines, likely sourcing large volumes of infostealer infections through cooperation with Malware-as-a-Service providers rather than acting fully independently.
Operates a pay-per-bot criminal marketplace selling data from infected machines, apparently sourcing large volumes of infostealer infections and working with Malware-as-a-Service providers rather than acting fully independently.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.