The image of a single adversary conducting an intrusion from start to finish is increasingly outdated. Cybercrime has specialised, and one of its most consequential specialisms is the initial access broker — an actor whose entire business is obtaining footholds in organisations and selling them to others who monetise them.
How the market works
A broker obtains access at scale through repeatable methods, verifies it, and lists it for sale. Buyers — frequently ransomware operators — purchase access matching their preferred target profile.
Listings are typically described by sector, geography, revenue band and the level of access obtained, without naming the victim. That structure lets a buyer choose targets by expected payout, which is why revenue is a stronger predictor of being attacked than any assumption about being "too small to matter".
Where the access comes from
- Credentials from information-stealing malware — harvested in bulk from infected machines, including saved browser credentials and active session cookies, which can bypass authentication entirely.
- Exposed remote access — remote desktop and management interfaces reachable from the internet with weak or reused credentials.
- Unpatched edge devices — VPN concentrators, firewalls and file transfer appliances, which are attractive because they sit at the perimeter and are often exempted from normal patch cycles.
- Credential reuse — passwords exposed elsewhere and replayed against corporate services.
- Phishing at scale — including real-time proxy kits that capture session tokens rather than just passwords.
- Third-party and supplier access — a smaller partner compromised as a route into a larger organisation.
What specialisation changes
Specialisation raises overall capability. A broker who does nothing but obtain access becomes very efficient at it, and a ransomware operator who never has to break in can focus entirely on escalation, exfiltration and extortion.
It also changes timing in a way defenders can use. Access is often obtained well before it is used, because it must be listed, sold and acted upon. That interval — sometimes days, sometimes considerably longer — is a window in which the intrusion is present but the damage has not yet occurred. Detecting the quiet foothold is far cheaper than responding to what follows.
Defending against the supply side
- Eliminate exposed remote access. Anything reachable from the internet for administration should require phishing-resistant MFA, and ideally sit behind a controlled access layer.
- Patch edge devices urgently and specifically. They are disproportionately targeted and frequently fall outside normal maintenance windows.
- Deploy phishing-resistant MFA broadly, which devalues both stolen passwords and many phishing kits.
- Treat session tokens as credentials: shorten lifetimes, bind sessions where the platform supports it, and revoke on suspicious signals rather than only at logout.
- Monitor for your own credentials appearing in stealer logs and breach corpora, and force resets on exposure.
- Watch for the quiet foothold — new remote access tooling, unusual VPN logins, and authentication from unexpected locations or devices.
- Extend the same expectations to suppliers with access to your environment.
Using threat intelligence proportionately
Understanding this market is useful, but it is easy to over-invest in intelligence that never changes a decision. The practical value is narrow and concrete: knowing which edge products are being actively exploited, whether your credentials are circulating, and which access methods are currently favoured against your sector.
That is enough to drive patch prioritisation, credential resets and detection focus. Detailed adversary attribution is interesting, but rarely alters what a defender should do next.
Related from TechBiz Security
Sources & further reading
- CISA — Cybersecurity Advisories
- CISA — Known Exploited Vulnerabilities Catalog
- MITRE ATT&CK — Initial Access
- CISA — StopRansomware
0 comments
Leave a comment