Researchers reported that the Genesis Store cybercrime marketplace was selling complete victim profiles that combined stolen credentials, browser cookies, and device fingerprinting data, allowing buyers to impersonate more than 60,000 users in online services. The market, advertised on carding forums and active since 2018, also offered a Chrome extension that imported a purchased identity so an attacker’s browser would mimic the victim’s environment, helping fraudsters evade anti-fraud checks during account takeover, identity theft, and money mule operations.
Further analysis of more than 335,000 Genesis listings found the marketplace was fed largely by infected machines and operated on a pay-per-bot model tied to a broader criminal supply chain. Researchers linked over 300,000 infections to Genesis or its suppliers and concluded that more than 90% of observed bot identifiers matched the AZORult infostealer, indicating Genesis relied heavily on malware-as-a-service partners rather than sourcing all stolen data independently.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
KELA found that a 32-character GUID class appeared on Genesis in late 2019 before the marketplace reverted to the 8-8-8-8-8 class as its leading product. This reflected experimentation with multiple malware-linked bot sources over time.
According to KELA's historical analysis, Genesis switched in late 2018 to an 8-8-8-8-8 GUID class later linked to the AZORult infostealer, and the number of infected machines it obtained increased. The report says this class went on to represent over 90% of Genesis infections.
Genesis Store launched in fall 2018 as a cybercrime marketplace selling stolen digital identities and account data from infected users. It was advertised on carding forums and offered profiles containing credentials, cookies, and device fingerprinting data.
KELA analyzed more than 335,000 Genesis listings and matched GUIDs and metadata with AZORult logs from a Malware-as-a-Service provider, confirming the dominant 8-8-8-8-8 class was based on AZORult. The researchers linked over 300,000 AZORult infections to Genesis or its suppliers and concluded Genesis likely worked with MaaS partners.
Kaspersky researchers disclosed the Genesis marketplace at the Kaspersky Security Analyst Summit in Singapore, describing a service selling full digital fingerprints for more than 60,000 users. They said some cybercriminal gangs were already using Genesis 'digital doppelgangers' to bypass anti-fraud systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
kelacyber.com
Open sourcekaspersky.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.