Exploit
Active Since
February 2005
Dark web or clear web
Dark web and clear web
Predominant Lanuage
Russian
Known Admins
Admin, Support, Garant, Adv, BigBear, L.Luciano, Mr.Burns, Pixe1, JohnRipper, Oxygen, Quake3, Weaver
Exploit is an extremely long-running Russian cybercrime forum that has been active since at least 2005.
Exploit and other Russian forums tend to view themselves as more professional than other dark web communities, often shunning non-Russian speakers and those perceived as unskilled or inexperienced.
As such, the site acts as something of a network for career cybercriminals to connect with potential collaborators on illegal business ventures, be it hacking, scamming, or working on Ransomware-as-a-Service (RaaS) schemes. At times the ransomware aspect has been tempered – for example, during the unwanted attention Exploit received in the wake of the 2021 Colonial Pipeline attack.
In this vein, we regularly witness threat actors auctioning initial access to organizations, usually through VPN or other remote access software. The posts typically have a “start” price to kick off the auction, a “step” price that indicates the increments of bidding, and a “blitz” price if a bidder wants to buy the access outright.