Module 05: Initial Access Brokers (IABs)
Validated foothold brokers reselling access to ransomware affiliates at major markup. Node 04 in the EDP Dependency Map, assessed HIGH tier with MEDIUM replace difficulty.
HIGH TierNode 04 / M05Phase BDownload PDF
Position in Ecosystem: Node 04, Initial Access Brokers Open the full ecosystem map ↗
Validated footholds are sold and brokered through forum reputation systems, escrow, and section-level trust controls.Underground ForumsUpstream dependencyHuman-layer access generation can be converted into saleable footholds for IAB resale.Callers & SpammersUpstream dependencyLoader infections create raw footholds that can be validated, packaged, and sold into the IAB market.Loaders & BotnetsUpstream dependencyCredential logs and session data are a major supply source for initial access brokers.Stealers & Log MarketsUpstream dependencyExploit-driven intrusions can be converted into validated access sold by IABs.Exploit BrokersUpstream dependencySome IAB infrastructure uses bulletproof hosting for listings, broker comms, or staging, though the dependency is less direct.Bulletproof HostingUpstream (partial)IABs sit in MVD Department K’s enforcement lane when they lack confirmed FSB protection; laundering and fraud framing works better than cyber framing.MVD Dept KState protection / toleranceIABs are the main commercial transfer point moving validated footholds to ransomware operators.RaaS OperatorPrimary dependencyAffiliates buy pre-positioned access from brokers to shorten time from intrusion to encryption.RaaS AffiliatesPrimary dependencyValidated foothold brokers reselling access to ransomware affiliates at major markup.INITIAL ACCESS BROKERSNode 04 / M05HIGH TIER / REPLACE: MEDIUM
Primary dependency Partial dependency State protection / dual use First-degree connections as assessed in the current ecosystem map (v3.0). Hover any node for the dependency note. Left side: what this node draws on or is protected by. Right side: what depends on it.
Module Number05
Module NameInitial Access Brokers (IABs)
EDP Node ReferenceNode 04 — Initial Access Broker (IAB) Markets (Phase B)
Ecosystem LayerInitial Access / Supply
Upstream ConnectionsNode 10 (Stealer Logs / Module 01), Node 05 (Loaders / Module 02), Node 07 (Underground Forums / Module 10), Node 03 (BPH / Module 09)
Downstream ConnectionsModule 07 (RaaS Groups — primary buyers), Nation-state APT buyers (secondary), BEC/fraud operators
Research DateApril 2026
Primary ResearcherReno
Source Tools UsedPerplexity AI; Rapid7 Access Brokers Reports (2025, 2026); Cyberint IAB Report 2025; WatchGuard IAB Analysis 2023; KELA; Picus Security; Zscaler / HP Threat Research
ClassificationINTERAGENCY

Section 1: What It Is

Definition

Initial Access Brokers (IABs) are cybercriminal specialists who compromise corporate networks and sell that unauthorized access to other threat actors — primarily ransomware affiliates, nation-state proxies, and fraud operators. They function as the dedicated supply layer of the ransomware-as-a-service (RaaS) economy, converting technical exploitation capability into a tradeable commodity and enabling division of labor across the criminal ecosystem. CONFIRMED

How It Functions: Step-by-Step

Role in the Ransomware Ecosystem

IABs bridge the capability gap between intrusion specialists and ransomware operators, enabling RaaS affiliates to focus on deployment, lateral movement, and extortion rather than initial compromise. This division of labor increases operational velocity for ransomware groups and insulates individual actors from full-chain exposure. The IAB market is the upstream supply node that directly gates ransomware deployment tempo. CONFIRMED

The structural position of IABs — between credential and loader infrastructure upstream and RaaS deployment downstream — makes Node 04 a high-leverage interdiction point whose disruption compounds across the entire supply chain. ANALYST INFERENCE

Business Model Variants

Section 2: Key Actors and Examples

Named Actors and Archetypes

Actor / ArchetypeTypeKey TTPsConfidence
High-volume Bulk IABs (multiple handles; RU-language forums)Volume access resellers (low-mid price; many victims)Scan/exploit exposed RDP and VPN; leverage stealer logs for credentials; minimal enrichment; sell as-is via public forum threads; high listing velocityCONFIRMED
High-end Boutique IABs (long-lived Exploit/XSS brokers; Rapid7, Cyberint, WatchGuard reporting)Premium access sellers (fewer, larger victims)Target large-revenue enterprises and government/critical infrastructure; privilege escalation to domain admin; provide detailed victim profiles (revenue, headcount, sector, AV/EDR stack); price $2,700–$10,000+CONFIRMED
Raspberry Robin (malware-based IAB platform)Platform-scale IAB (automated access factory)USB worm + multi-vector loader (WSF, Discord CDN, 0-day exploitation); fast-flux C2 network on compromised NAS/IoT; >200 C2 domains across 20+ TLDs; feeds high-quality access to ransomware and espionage crewsCONFIRMED
Forum-Embedded IAB Collectives (RAMP / DarkForums broker groups)Broker collectives tied to specific marketsCurated corporate access sections only; buyer vetting; move high-value deals to Telegram/TOX; sometimes bundle operational playbooks with access packagesCREDIBLE
IAB-RaaS Hybrid Crews (ransomware affiliates selling overflow access)Mixed IAB + RaaS affiliateRun stealer/loader campaigns; use subset of access for ransomware; sell remaining or stale access on forums; maintain direct RaaS program relationshipsCREDIBLE

Geographic Concentration

Russia and the broader CIS region dominate the IAB market. RU-language forums — Exploit, XSS, RAMP, and DarkForums — are the primary transaction venues. Eastern European operators (historically including Ukrainian actors pre-2022) remain active, though post-invasion dynamics have consolidated Russian-language forum dominance. English-language activity on BreachForums declined following successive seizures in 2023–2024. CONFIRMED

H2 2025 saw a confirmed migration of activity from Exploit and XSS toward RAMP and DarkForums, accompanied by increasing asking prices and a shift toward larger-revenue victims. Government, Retail, and IT sectors saw increased targeting frequency. CONFIRMED Source: Rapid7 2026.

Scale and Volume

MetricValueSourceYear
Average sale price~$2,700Rapid72025
Most common price range$500–$1,000 (approx. 40% of listings)Rapid72025
Premium listing threshold>$10,000 (large enterprises / critical infra)Rapid7, Cyberint2025
Privileged access share71.4% of observed transactionsRapid72025
Market concentration5 entities = approx. 25% of all IAB offersWatchGuard2023
Corporate networks sold (top 5 entities)>2,300 corporate network accessesWatchGuard2023
Average price (WatchGuard dataset)~$2,800 per accessWatchGuard2023
VPN share of listings23.5% (Rapid7) / ~33% (Cyberint)Rapid7 / Cyberint2025
RDP share of listings16.7% (Rapid7) / ~55% (Cyberint)Rapid7 / Cyberint2025
Domain User share of listings19.9%Rapid72025

Note: RDP/VPN share discrepancy between Rapid7 and Cyberint likely reflects methodology or dataset composition differences (forum coverage scope). Both sets cited; reconciliation requires a third-party comparison dataset.

State Adjacency

No confirmed direct state ownership or control of IAB operations is documented in public reporting. CONFIRMED FSB has historically leveraged access obtained through cybercriminal proxies for intelligence purposes, and IAB-generated access to government and critical infrastructure organizations likely generates passive FSB interest. CREDIBLE

Dark Covenant 3.0 (Recorded Future) screening is required before any public attribution of Russia-based IAB operators, particularly boutique brokers who may have established protection relationships. Financial designation and infrastructure disruption actions carry LOW backfire risk. Individual attribution without prior screening carries MEDIUM to HIGH backfire risk. ANALYST INFERENCE

Section 3: Infrastructure Dependencies

Upstream Dependencies

Downstream Outputs

Critical Chokepoints

ChokepointWhy CriticalWho Owns Disruption
Forum trust and vetting infrastructureIABs require forum reputation to sell; buyers require vetting to trust access quality. Without trust mechanisms, both volume and price collapse.FVEY LE + private sector forum monitoring (Intel 471, Flashpoint)
Stealer log credential pipeline (Node 10)Most bulk IAB credential sourcing runs through log markets. Degrading log supply raises sourcing cost and forces more resource-intensive direct exploitation.FVEY LE — Node 10 disruption compounds directly to Node 04
Cryptocurrency settlement rails (USDT/TRON)IABs require pseudonymous, liquid payment rails. Tracing and designation of financial flows enables attribution and OFAC action against high-revenue operators.OFAC + blockchain forensics (Chainalysis, TRM Labs, Elliptic)
Raspberry Robin C2 infrastructurePlatform-scale IAB depends on >200 C2 domains and compromised NAS/IoT fleet. Sinkholing degrades access handoff and forces infrastructure reconstitution (estimated 6–18 months).FVEY IC + LE (infrastructure takedown, upstream provider notification)

Cross-Module Linkages

ModuleNodeRelationshipDirection
01 — StealersNode 10Credential sourcing: stealer logs are the primary input for bulk IAB access listing pipelinesUpstream to IABs
02 — LoadersNode 05Malware-based IABs (Raspberry Robin) blur the loader/IAB boundary; loaders also deliver stealers that generate IAB credential inputUpstream to IABs
07 — RaaS GroupsNo dedicated nodePrimary buyer relationship; IAB access directly enables ransomware deployment velocityIABs to Downstream
09 — BPHNode 03C2 infrastructure hosting for platform-based IABs; also used for scanning and reconnaissance infrastructureUpstream to IABs
10 — Underground ForumsNode 07Sales venue, trust and vetting infrastructure, escrow — IAB market health directly tied to forum ecosystem healthUpstream to IABs

Technical Infrastructure

IABs maintain variable technical infrastructure depending on model type. Bulk IABs rely on commodity scanning tools (Shodan, Masscan), stealer log databases, and forum accounts. Boutique IABs maintain post-exploitation tooling (Cobalt Strike, Metasploit, custom scripts), victim profiling workflows, and encrypted communication channels for buyer negotiation.

Platform-based IABs (Raspberry Robin) represent the most complex technical infrastructure in the IAB space: a multi-vector malware delivery system, fast-flux C2 network with >200 unique domains, compromised NAS and IoT device fleet, and custom tooling evolved across multiple years of operation. This infrastructure investment creates significantly higher replace difficulty than traditional IAB models. CONFIRMED

Section 4: Disruption Leverage Points

EDP Node Reference

Node 04 — Initial Access Broker (IAB) Markets | Tier: HIGH | Replace Difficulty: MEDIUM | Backfire: LOW | Phase B

Phase B encompasses Nodes 04 (IAB Markets), 07 (Underground Forums), and 08 (Mixing/Obfuscation). Phase B actions are most effective when Phase A financial and infrastructure pressure (Nodes 01, 02, 03) is already applied. Isolated Phase B action without Phase A support risks rapid recovery through price adjustment and forum migration.

Primary Disruption Levers

Who Owns Disruption

LeverBest MethodPrimary OwnerBackfire Risk
Forum disruption (RAMP, DarkForums, Exploit, XSS)Forum section infiltration + coordinated takedown of IAB-specific market areasFVEY LE + Intel 471, Flashpoint (intelligence support)LOW
Financial designation (high-volume / boutique operators)Blockchain tracing (USDT/TRON) to attribution pipeline; OFAC SDN designationOFAC + Chainalysis, TRM Labs, EllipticLOW
C2 infrastructure takedown (Raspberry Robin)Sinkholing, upstream provider notification, BPH engagement; coordinate with Node 03 actionFVEY IC + LELOW–MEDIUM
Stealer log market disruption (compounding — Node 10)Forum section takedown + purchase disruption; coordinate with Module 01 actionFVEY LE + private sectorLOW
Individual attribution (Russia-based boutique IABs)Dark Covenant 3.0 screening required before any public attribution; protection mapping firstFVEY LE + Recorded FutureMEDIUM–HIGH if screening skipped

Compounding Actions

Section 5: Resilience and Replace Difficulty

Replace Difficulty Assessment: MEDIUM (Node 04)

The overall MEDIUM rating reflects the heterogeneous nature of the IAB market. Bulk IABs have LOW replace difficulty — commodity tools and techniques, minimal operational security requirements, and low entry barriers mean disrupted bulk operators are replaced within days to weeks. Boutique IABs and platform-based IABs have significantly higher replace difficulty, pulling the aggregate toward MEDIUM.

Replace Difficulty by Level

Redundancy and Distributed Structure

The IAB market is distributed across multiple forums and private channels; no single forum controls the entire market. This structural redundancy is a primary resilience factor. H2 2025 migration from legacy forums (Exploit/XSS/BreachForums) to RAMP and DarkForums demonstrates consistent adaptive migration capacity following forum disruption events. CONFIRMED

High-value IAB transactions are increasingly conducted off-forum via Telegram and TOX, reducing law enforcement and private sector visibility into the highest-value market segment. This off-forum migration increases resilience by reducing the disruption surface for the most valuable access categories. CREDIBLE

Historical Reconstitution

Disruption EventOutcomeReconstitution Time
BreachForums seizure (2023)IAB activity migrated to Exploit, XSS, and RAMP within weeks; minimal sustained disruption to listing volume2–4 weeks
BreachForums v2 seizure (2024)Accelerated migration to RAMP and DarkForums; activity continued with minimal interruption; confirmed by Rapid7 2026 reporting1–3 weeks
Genesis Market takedown (2023) — credential market disruptionIABs shifted stealer log sourcing to alternative markets; temporary increase in direct exploitation activity observed4–8 weeks (sourcing adaptation)

Durability Assessment

FactorAssessmentConfidence
Technical barrier to entry (bulk)LOW — commodity tools, well-documented techniques, widely available credential inputsCONFIRMED
Technical barrier to entry (boutique)MEDIUM-HIGH — skill, reputation, and buyer relationships are non-transferableCONFIRMED
Forum ecosystem dependencyHIGH — IAB market health directly tied to forum trust infrastructure healthCONFIRMED
Geographic concentration (Russia/CIS)Provides partial protection from Western LE action; CIS non-extradition norm persistsCREDIBLE
Platform-based resilience (Raspberry Robin)HIGH infrastructure investment; HIGH reconstitution cost; not a rapid-rebuild scenarioCONFIRMED
Off-forum migration trendIncreasing Telegram/TOX usage for high-value deals reduces collection visibility and disruption surfaceCREDIBLE

Ecosystem Adaptation

IABs have demonstrated a consistent and rapid pattern of migrating to new forums following takedowns, with reconstitution times declining across successive disruption events — weeks in 2023, days in 2024. This acceleration suggests IAB operators have developed institutional resilience practices and pre-established fallback venues.

Price increases in H2 2025 indicate the market is internalizing disruption costs and risk premiums rather than collapsing under law enforcement pressure. Higher average prices per access reflect a market absorbing friction costs, not a market in distress. CREDIBLE

Section 6: Indicators and KPIs

Health Indicators

IndicatorNormal StateUnder Pressure
Monthly listing volume (major forums)Stable or increasing trend; consistent thread frequency on Exploit/XSS/RAMP/DarkForums20%+ decline in monthly listings sustained over 30 days
Average asking price~$2,700; trending upward with target quality increase (H2 2025 trend)Sudden price spike (scarcity signal) or price collapse (quality/volume degradation)
Access type mix (VPN/RDP/Domain User share)VPN ~23–33%, RDP ~17–55%, Domain User ~20% across observed datasetsShift toward lower-quality access types; decline in domain admin share
Privileged access share~71% of transactions offer privileged access (Rapid7 2025)Decline below 60% — indicates sourcing capability degradation
Forum activity level (Exploit/XSS/RAMP/DarkForums)Regular broker threads, active buyer engagement, escrow useReduced thread frequency, fewer buyer responses, increased escrow disputes
Off-forum migration signalsLow; most deals originate on-forum with some high-value private negotiationMajority of high-value listings directing to Telegram/TOX-only channels
Raspberry Robin C2 domain count>200 active domains across 20+ TLDsDecline below 100 active domains; sinkholed domains; reduced beacon traffic

Disruption KPIs

KPIBaselineTargetCollection Method
Forum listing volume (monthly)Establish from Exploit/XSS/RAMP/DarkForums monitoring30% reduction sustained over 60 daysIntel 471, Flashpoint, Recorded Future forum monitoring
Average sale price~$2,700 (Rapid7 2025)Price spike >$6,000 (scarcity) or volume collapse >40%Underground market price tracking; private sector reports
Privileged access share71.4% (Rapid7 2025)Below 55% of observed transactionsForum listing analysis; private sector access broker reporting
Raspberry Robin active C2 domains>200 active domainsBelow 50 sustained active domainsPicus Security, Zscaler, HP Threat Research telemetry
Top 5 IAB entity market share~25% of all observed offers (WatchGuard 2023)Confirmed disruption of 2+ entities from top 5FVEY LE attribution + Intel 471, Flashpoint
Time from compromise to saleDays–weeks (bulk); 1–4 weeks (boutique)Increase to 30+ days average across listing typesVictim notification correlation with forum listing dates

Collection Methods

Baseline Data

MetricValueSourceDate
Average sale price~$2,700Rapid72025
Price range (most common)$500–$1,000 (approx. 40% of listings)Rapid72025
Premium listing threshold>$10,000Rapid7, Cyberint2025
Privileged access share71.4% of observed transactionsRapid72025
Top 5 entities market share~25% of all observed IAB offersWatchGuard2023
Corporate networks sold (top 5)>2,300 network accessesWatchGuard2023
Average price (WatchGuard dataset)~$2,800WatchGuard2023
VPN share23.5% (Rapid7) / ~33% (Cyberint)Rapid7 / Cyberint2025
RDP share16.7% (Rapid7) / ~55% (Cyberint)Rapid7 / Cyberint2025
Domain User share19.9%Rapid72025
Raspberry Robin active C2 domains>200 unique across 20+ TLDsPicus Security2025

Alert Thresholds

IndicatorAlert ThresholdPriority
Monthly listing volume decline>20% sustained over 30 days (may indicate disruption or migration)HIGH
Average price spike>$6,000 average (100%+ increase — scarcity signal, not market health)MEDIUM
Major forum disruptionTakedown or access loss for Exploit, XSS, RAMP, or DarkForumsHIGH — collection retasking required
Raspberry Robin C2 domain countBelow 100 active domainsHIGH — infrastructure pressure signal
Forum migration eventNew primary venue identified (successor to RAMP or DarkForums)HIGH — collection retasking required
Off-forum migration (Telegram/TOX)Majority of high-value deals confirmed to originate exclusively off-forumHIGH — significant collection visibility loss

Section 7: Sources and Confidence

Primary Sources

Secondary Sources

Gaps and Uncertainties

Confidence Notes

ClaimConfidenceBasis
Typical sale price ~$2,700CONFIRMEDRapid7 2025 primary dataset; corroborated by WatchGuard 2023 (~$2,800 in independent dataset)
71.4% of transactions offer privileged accessCONFIRMEDRapid7 2025 primary dataset
VPN = 23.5%, Domain User = 19.9%, RDP = 16.7% of listingsCONFIRMEDRapid7 2025 primary dataset
5 entities = ~25% of all IAB offers; >2,300 corporate networksCREDIBLEWatchGuard 2023; dataset composition not fully specified in public reporting
H2 2025 shift toward RAMP/DarkForums; higher prices; government/retail/IT targeting increaseCONFIRMEDRapid7 2026 market shift report
Raspberry Robin functions as elite IAB platform with >200 C2 domainsCONFIRMEDPicus Security 2025; corroborated by Zscaler and HP Threat Research
FSB passive interest in IAB-generated government and critical infrastructure accessANALYST INFERENCEStructural reasoning from observed APT-cybercriminal access overlap; no confirmed direct FSB-IAB relationship in public reporting
Off-forum migration increasing for high-value dealsCREDIBLESingle-source (Rapid7 trend reporting); consistent with operational security logic

Section 8: Analyst Assessment

Generated by Claude (Anthropic) — April 2026 | EDP Module 05 — Initial Access Brokers (IABs)

Key Takeaway

The IAB layer is the most commercially mature segment of the ransomware supply chain. Prices are trending upward, targets are concentrating around higher-revenue victims, and the market is migrating to more-vetted, less-monitored forums. This structural maturation is simultaneously increasing the cost-per-disruption of law enforcement action and degrading passive collection visibility. The leverage window for sustained degradation is Phase B — but only if forum trust infrastructure (Node 07) and financial rails (Nodes 01 and 02) are targeted simultaneously. Isolated IAB takedowns without upstream credential market pressure and downstream forum disruption have historically produced weeks-long disruptions, not sustained ecosystem degradation. CREDIBLE

Priority Recommendation

Two coordinated actions are the recommended primary IAB disruption pathway:

Secondary Recommendation

Maintain sustained Raspberry Robin C2 sinkholing pressure. The platform represents a high-automation, high-volume access pipeline with multi-year infrastructure investment. Sustained sinkholing and upstream provider notification forces infrastructure reconstitution estimated at 6–18 months — compared to days-to-weeks for traditional forum-based IAB recovery. This is the highest-durability disruption option in the IAB node and requires no attribution risk.

Connection to EDP Playbook

Node 04 is Phase B (alongside Nodes 07 — Underground Forums and 08 — Mixing/Obfuscation Services). Phase B actions are most effective when Phase A financial and infrastructure foundation pressure is already applied. Initiating Phase B without Phase A progress risks IABs simply absorbing disruption through price adjustments and forum migration, as the financial off-ramp (Nodes 01 and 02) and hosting infrastructure (Node 03) remain intact. Current market evidence — rising prices, higher-value targets, accelerating forum migration — suggests the ecosystem has not yet experienced sustained Phase A pressure. Sequencing matters: Phase A first, then Phase B in coordination.

Dependency Map Update Recommendations

NodeCurrent StatusRecommended UpdateRationale
Node 04 — IAB MarketsHIGH tier, MEDIUM replace difficulty, Phase B, LOW backfireNo change required; mapping is accurateResearch confirms Node 04 characterization across all assessed dimensions
Node 05 — Loaders/BotnetsHIGH tier, HIGH replace difficulty, Phase CAdd cross-reference to Node 04: Raspberry Robin blurs the Node 04/05 boundary and should be noted in both node descriptionsRaspberry Robin data demonstrates that platform-based IABs operate as hybrid loader/IAB systems — cross-node dependency is not currently reflected in the map
New sub-node considerationNot currently in Dependency MapAssess addition of a Platform-Based IAB sub-node under Node 04 or as a standalone cross-cutting nodeMalware-based IABs have a distinct disruption profile (infrastructure takedown vs. forum disruption) with HIGH replace difficulty vs. MEDIUM for the Node 04 aggregate — the heterogeneity is analytically significant

Follow-On Research