April 6, 2023, 8:43 p.m. | Dancho Danchev

Security Boulevard securityboulevard.com


Dear blog readers,


I've decided to take a deeper look inside the Internet connected infrastructure of the recently seized Genesis Market cybercrime-friendly marketplace with the idea to provide actionable intelligence and to assist vendors organizations and researchers including U.S Law Enforcement on its way to properly track down and monitor the cybercriminals behind these campaigns.


Related Genesis Market domains:


hxxp://sync[.]genesis-update[.]net


hxxp://sync[.]genesis-security[.]net


hxxp://g3n3sis[.]pro


hxxp://xmpp[.]genesis[.]market


hxxp://genesis[.]marjet


hxxp://g3n3sis[.]org


hxxp://sync[.]gsconnects[.]com


hxxp://g3n3sis[.]org


hxxp://g3n3sis[.]pro


hxxp://g3n3sis[.]me


Sample IPs known to have been involved in the campaign include: …

actionable actionable intelligence blog campaign campaigns cybercrime cybercriminals domains down enforcement genesis genesis market infrastructure intelligence internet ips law law enforcement market marketplace monitor .net org organizations pro profiling researchers security seized sync update vendors xmpp

Sr Cyber Threat Hunt Researcher

@ Peraton | Beltsville, MD, United States

Lead Consultant, Hydrogeologist

@ WSP | Chattanooga, TN, United States

Senior Security Engineer - Netskope/Proofpoint

@ Sainsbury's | London, London, United Kingdom

Senior Technical Analyst-Network Security

@ Computacenter | Bengaluru Bengaluru (Bengaluru, IN, 560025

Senior DevSecOps Engineer - Clearance Required

@ Logistics Management Institute | Remote, United States

Software Test Automation Manager - Cloud Security

@ Tenable | Israel - Office - CS