Cybercrime Underground Intelligence

Intermediate

Dark web and cybercrime intelligence for defenders: read stealer logs, access broker listings and ransomware leak sites, and turn them into early warning. Following the criminal supply chain from one infected laptop to a leak site post, you grade what each listing, log and post actually proves and write alerts and briefs that stay inside the law and keep your sources safe. You never visit a criminal site: every listing, log and leak site post comes to you as evidence. Four sections, 50 lessons and five hands-on missions built on a single case, with a verifiable certificate at the end.

By CTI Academy Team55 steps4 sections~12 hoursCertificate

Curriculum

55 steps across 4 sections. Sections unlock in order as you complete them.

8 more steps behind a free account

Free account

Ready to start Cybercrime Underground Intelligence?

Create a free account to open the remaining 8 steps, track every one you finish and earn your certificate.

  • Free to start
  • Progress saved on every step
  • Certificate on completion
Sign up with email

About this path

Most organisations meet the cybercrime underground twice. The first time is a stealer log or an access listing that nobody reads, and the second is a ransomware leak site post with a countdown next to their name. The time between those two moments, sometimes years and sometimes hours, is the whole reason a defender watches criminal markets, and this path is about using them.

It follows the supply chain in the order the criminals work it. An infostealer empties a browser, a shop sells the log for the price of lunch, an initial access broker turns a working login into an auction, and a ransomware affiliate turns the access into data theft and a deadline. At each step you learn what the venue is, what its trust signals are worth, what the artifact in front of you proves, and what it does not.

The first section covers how the cybercrime economy became a supply chain of specialised sellers, the difference between forums, automated shops and Telegram channels, and the trust mechanics that hold them together: reputation, escrow, deposits and guarantors. It also covers what happens when a venue is seized, and what a defender may and may not do in these venues, including why even a private message to a seller makes you a participant. The Operational Security for Researchers module is part of the section, so your own exposure is dealt with before you look at anyone else's.

The second section is the access economy. You open an infostealer log, date the infection from its system data, work out which cookies and sessions could still authenticate, and find every account your organisation has in it, including shared team accounts on a client's platform. You learn to tell a fresh stealer log from a recycled combolist or breach dump, triage exposures in the right order and hand over a fix. Then you read an initial access broker's listing, weigh its price and its seller, narrow the likely victim to a stated probability, and follow what happens between the listing and the intrusion.

The third section covers ransomware operations: how ransomware-as-a-service divides the work between operators, affiliates, brokers and negotiators, what a programme's rules and break-ups reveal, and which tools run around the locker. You read a leak site post as evidence, date it against the intrusion, test whether a proof pack holds anything non-public, spot inflated, recycled and fake claims, and count victims without fooling yourself. It also covers extortion that needs no encryption at all, from mass data theft to pressure on patients, staff and SaaS providers, and how to keep a crew's record straight through rebrands, splits and vendor naming.

The fourth section turns all of this into a programme and its products. You set requirements before keywords, state what your sources can and cannot see, judge freshness by the age of the underlying event rather than the day of the post, and handle third-party data lawfully. Then you write the early warning alert, brief leadership during a live extortion, share with peers and law enforcement, and protect the sources and methods that made the finding possible.

Dark web monitoring services and threat intelligence feeds will hand you these hits. What they cannot decide for you is which hits are real, how old the underlying event is and who has to act. That judgement is what this path teaches, and it works the same whichever service or feed you use.

The missions run on one case from start to finish. You catch a client's domain in a shop log, match an anonymous access listing to that client against a base rate, test a leak site's proof pack, warn leadership while the countdown runs, and write the closing brief once the data is out. Nothing asks you to visit a criminal site or buy anything. The skill here is reading what the underground shows you, fast and honestly, and saying who needs to act.

What you will learn

  • Read a venue for what it can prove. Tell a forum claim from a shop's inventory row and from a leak site post, and know what each one can and cannot establish.
  • Weigh a seller before the listing. Use reputation, deposits and escrow to judge whether an offer is real or a scam among criminals.
  • Date an infostealer infection. Read a stealer log's system data to find when the machine was infected and how fresh the log is.
  • Scope an exposure to every account. Find every credential and session a log puts at risk, including the shared and vendor accounts nobody remembers.
  • Tell a stealer log from a combolist. Work out where exposed credentials came from, because provenance decides the response.
  • Match an access listing to a victim. Narrow an anonymised listing with its victim fingerprint and a base rate, and state the match with calibrated confidence.
  • Map a ransomware programme. Know who builds, who breaks in and who negotiates, and what a breakup or exit scam means for victims.
  • Test a leak site claim. Date a post against the intrusion, check the proof pack and avoid counting recycled or fake victims.
  • Keep a crew's record straight. Maintain a crew card through rebrands and vendor naming without letting a copied template rewrite history.
  • Write early warning people act on. Produce alerts and extortion briefs with a clear bottom line, the right marking, and no exposure of your sources.

Who this path is for

  • CTI analysts asked what the dark web says about their organisation who want a method rather than a feed.
  • SOC and incident response staff who receive stealer log and leak site alerts and must decide what to do within hours.
  • Teams planning to run, buy or evaluate an underground monitoring service.
  • Learners who finished the Cyber Threat Intelligence path and want to specialise in cybercrime.

Guides for this path

  • Infostealer Malware, Explained: How Stolen Logs Get UsedAn infostealer does not break anything, it runs once, copies what the browser already remembered, and leaves. The file it produces, a stealer log, is worth more to the criminal economy than the access it had. How the chain works, why the Lumma takedown didn't hold, and why a password reset is not enough.
  • The Ransomware-as-a-Service Business Model, ExplainedHow the RaaS business model actually works in 2026: the operator/affiliate revenue split, why power has shifted to affiliates, why brand takedowns like LockBit and RansomHub didn't shrink the market, and the rise of encryptionless extortion.
  • Telegram as a Cybercrime MarketplaceTelegram is not the dark web, but its communication, marketplace, automation, and amplification layers have turned it into one of cybercrime's busiest storefronts. See what gets sold, how OTP bots and log-search bots automate the trade, why the 2025 Durov-era crackdown didn't empty the shelves, and how CTI analysts monitor it for early warning.
  • The Initial Access Broker Ecosystem, ExplainedHow the initial access broker economy actually works: the supply chain from infostealer logs to ransomware deployment, what access costs in 2026, where the market lives, and how CTI analysts track it as an early-warning signal.

Frequently asked questions

Dark web intelligence, also called cybercrime underground intelligence, is the work of reading what criminal forums, shops, Telegram channels and ransomware leak sites reveal about threats to your organisation, and turning it into a warning someone can act on. Much of its value is early: a stealer log or an access listing can surface before the intrusion it leads to.

No. The lessons explain how criminal venues work from public research and law enforcement material, and the missions give you every listing, log and leak site post as evidence inside the mission. Nothing asks you to visit a criminal site, create an account there or buy data.

It teaches the analysis behind dark web monitoring rather than one tool. You decide what to watch, judge whether a hit is real and fresh, and turn it into an alert, which applies to any monitoring service or feed. The monitoring programme module also covers the questions to put to a provider before you buy one.

Treat it as a live exposure, not a statistic. Date the infection from the log's system data and list every credential and session cookie in it that reaches your systems, including VPN and single sign-on addresses and shared accounts on client platforms. Treat the machine as infected: isolate or clean it first, then reset the passwords from a trusted device and revoke the sessions. Search your identity provider's logs from the infection date for sign-ins from a new IP address or device, because one of those turns the exposure into an incident. Never test a password on the login page to see whether it works: that is a question for your directory.

Start with the proof pack, not the post. The revenue and headcount in a post are usually copied from business data sites and prove nothing. Check whether the files hold anything non-public and compare them with your own file shares, because a match there settles the claim better than the crew's word. An old file date does not make an old theft, since a 2020 document copied last week is last week's theft. Watch for recycled claims from an earlier incident and outright fabrications, and when there is no proof pack, check your telemetry and suppliers on your own schedule, whatever the countdown says.

Yes. The path is written for defenders and covers the legal boundaries of underground research, including why you never purchase stolen data, why engaging criminals needs an authorised programme and legal sign-off, and how sanctions affect payments.

The Cyber Threat Intelligence path is the natural starting point: this path uses intelligence requirements, estimative language and TLP without re-teaching them. The Operational Security for Researchers module is included here, so you do not need to take it separately.

That path asks who is behind an operation and how much the evidence can carry. This one asks how the criminal economy produces and sells access, how ransomware crews turn it into extortion, and how to warn the right people before harm. The two reference each other where they meet.

About twelve hours: the lessons take roughly nine and the five missions about two to three.

Yes. Completing every step of the path, all twelve modules and the five missions, issues a CTI Academy certificate in your name. Each certificate carries a unique ID, and its QR code opens a public verification page, so an employer can confirm it without contacting us.

The first two modules and the Operational Security for Researchers module are free. The later modules and the missions need a premium subscription.