Skip to content
threat-intelbeginner#genesis-market#infostealers#dark-web#law-enforcement#session-cookies

Genesis Market: The Bot Shop and Operation Cookie Monster

How Genesis Market sold infostealer bots with cookies and fingerprints, how Operation Cookie Monster took it down in 2023, and what replaced it.

Most stolen-credential markets sell a list: an email, a password, maybe a URL. Genesis Market sold something closer to a person's browser. A buyer could load a victim's cookies, saved logins and device fingerprint into a special browser and arrive at the victim's bank or email looking like the same laptop that had logged in yesterday.

That design made Genesis one of the most useful shops for fraud and network intrusion between 2018 and 2023. It also made it a law enforcement priority. This guide covers how the shop worked, how Operation Cookie Monster took it down, and what the market looks like since.

What Genesis Market sold

Genesis listed what its operators called bots. Each bot was one computer infected with information-stealing malware. Europol's description of a purchased bot: access to "all the data harvested by it such as fingerprints, cookies, saved logins and autofill form data."

The US Justice Department described the fingerprints as "unique combinations of device identifiers and browser cookies that circumvent anti-fraud detection systems used by many websites." The malware behind the bots is the same class we cover in What Is an Infostealer.

Three features set Genesis apart from a typical log shop:

  • Live updates. Europol said the data was collected in real time: buyers were notified when the victim changed a password. A bot kept producing value for as long as the infection lasted.
  • Search by target. The DOJ noted buyers could search by location and account type, such as banking, social media or email.
  • Impersonation tooling. Buyers received a custom browser that mimicked the victim's. Netacea's 2021 research named the components a Genesis Security plugin and a Genesium browser, which let buyers "browse the internet as the victim."

Genesis also ran on the open web behind an invite-only registration, which Europol said lowered the barrier for buyers compared with Tor-only markets.

Why cookies and fingerprints mattered

Many websites decide how much to trust a login by comparing it with what they have seen before: the same browser, the same operating system, a familiar location, an existing session cookie. A buyer who replays the victim's cookies through a browser that reports the victim's fingerprint passes those checks. If the session cookie is still valid, there may be no password prompt and no MFA challenge at all. Our session hijacking guide explains why a live session token is worth more than a password.

Scale and price

MeasureFigureSource
Operating sinceMarch 2018US Department of Justice
Compromised computers offeredMore than 1.5 millionUS Department of Justice
Account credentialsMore than 80 millionUS Department of Justice
Packages listed on 1 February 2023About 460,000US Treasury (OFAC)
Bot listings at takedownMore than 1.5 million, over 2 million identitiesEuropol
Price per botUSD 0.70 to several hundred dollarsEuropol
Dutch victimsAbout 50,000Dutch National Police

The most expensive bots carried banking access. The DOJ also called Genesis "one of the most prolific initial access brokers" and said private-sector reports showed its access being used by ransomware actors, the supply chain described in our initial access brokers guide.

The takedown came after a long investigation. Europol's European Cybercrime Centre (EC3) had supported the case since 2019 through the Joint Cybercrime Action Taskforce.

Action day, 4 April 2023. Law enforcement seized 11 Genesis domains under a warrant from the US District Court for the Eastern District of Wisconsin, replacing the site with a seizure banner. At the same time, police in multiple countries moved against the shop's users. Europol reported 119 arrests, 208 property searches and 97 "knock and talk" visits, coordinated from a command post at Europol's headquarters in The Hague. Eurojust ran a command centre to resolve legal issues across parallel operations in 13 countries.

Who led it. The FBI's Milwaukee Field Office and the Dutch National Police led the operation, with 44 other FBI field offices and agencies from the UK, Italy, Denmark, Australia, Canada, Romania, France, Spain, Germany, Sweden, Poland, Finland, Switzerland, Estonia, Iceland and New Zealand, plus Eurojust and Europol. The Dutch police said 17 countries took part and made 17 arrests in the Netherlands.

Targeting the buyers. The operation went after customers as well as the shop. The DOJ said federal investigators worked to identify prolific Genesis users who bought and used stolen credentials, which produced hundreds of leads for FBI field offices and foreign partners. Deputy Attorney General Lisa Monaco said Genesis "falsely promised a new age of anonymity and impunity, but in the end only provided a new way for the Department to identify, locate, and arrest on-line criminals." For buyers, the seizure turned years of purchase records into evidence.

Sanctions. On 5 April 2023 the US Treasury's Office of Foreign Assets Control designated Genesis Market, describing it as "believed to be located in Russia" with both clearnet and darknet presence.

Illustrated cybersecurity scene for Genesis Market: The Bot Shop and Operation Cookie Monster
Illustration for Genesis Market: The Bot Shop and Operation Cookie Monster.
How victims could check

The FBI shared about 8 million email addresses with Have I Been Pwned. Troy Hunt flagged the breach as sensitive, so results show only after you verify control of the address through the Notify Me service. Passwords from the data were also added to Pwned Passwords. Separately, the Dutch police set up politie.nl/checkyourhack, which emails you only if your address appears in the seized data.

Why changing passwords was step two

The Dutch police were explicit that "just changing passwords is not enough." Because bots reported changes in real time, a new password typed on an infected machine would go straight to the buyer. Europol's advice put the order plainly: run antivirus first, and only then change passwords. Microsoft and antivirus vendors updated detections so Windows Defender and other products could find and remove the malware.

What came after

The takedown removed the main clearnet shop and identified many buyers. The underlying trade continued.

The Tor mirror stayed up. The UK National Crime Agency told The Record that the dark web version remained active because it was "hosted in an inaccessible jurisdiction."

The operators claimed a sale. In July 2023, an account called GenesisStore, previously associated with the administrators, posted on the Russian-language Exploit forum that "a buyer has been found and a deposit has been made." The listing offered the source code, scripts, server infrastructure and database, excluding some customer details. The claim was never independently confirmed in public.

Rival shops absorbed demand. Russian Market, which sells raw infostealer logs rather than packaged bots, reacted at once. Recorded Future's Alexander Leslie told The Record: "we observed an immediate stop to the daily listing of all new infostealer logs, beginning on April 4, 2023." Listings resumed about a week later, and a Flashpoint analyst estimated volume at about 15% above pre-takedown levels.

Russian Market grew into the default. ReliaQuest's June 2025 research described it as "the Amazon of stolen credentials," with more than 5 million logs by 2023 and logs selling for as little as USD 2. ReliaQuest raised over 136,000 customer alerts tied to Russian Market in 2024. Lumma accounted for nearly 92% of those credential log alerts in Q4 2024, and after Microsoft and law enforcement disrupted Lumma's infrastructure in May 2025, ReliaQuest named Acreed as the likely successor stealer.

The pattern matches what our dark web markets guide describes: a takedown removes a shop and burns its users, while the supply of infections moves to whichever venue remains. The pwnsy infostealer tracker follows the major stealer families and their takedown timeline.

ShopWhat it sellsStatus as of 2026
Genesis MarketPackaged bots with cookies, fingerprints and an impersonation browserClearnet seized April 2023; Tor mirror persisted; sale claimed July 2023
Russian MarketRaw infostealer logsActive; documented by ReliaQuest in 2025
2easy ShopInfostealer logsReported as a Genesis alternative in 2023; Flashpoint noted doubts about its administrators

How to defend against bot-shop exposure

For individuals

  1. Check exposure. Use Have I Been Pwned for the Genesis data and later stealer collections. Dark web monitoring services work the same way; see how dark web monitoring works for what an alert does and does not tell you.
  2. Clean the device first. If you were exposed, run a full scan or reinstall before changing passwords.
  3. Revoke sessions. After cleanup, sign out of all sessions on email, banking and social accounts so stolen cookies stop working, then change passwords.
  4. Use phishing-resistant MFA and a password manager. Passkeys and hardware keys reduce what a future infection can be replayed against, and avoiding browser-saved passwords removes one easy harvest.
  5. Avoid cracked software and fake installers, the most common infostealer delivery routes.

For organisations

  1. Monitor for your domain in stealer data. The pwnsy stealer exposure lookup checks a domain against infostealer exposure.
  2. Treat a stealer hit as a session compromise. Revoke tokens and sessions for the affected user and investigate the device, along with the password reset.
  3. Bind sessions to managed devices. Conditional access with compliant devices, short session lifetimes for sensitive apps, and device-bound tokens all reduce the value of a replayed cookie.
  4. Watch for fingerprint-perfect anomalies. A session with the right device characteristics from an unexpected network, or a cookie reused after the user signed out, is worth an alert.
  5. Restrict personal browser sync on work devices. Saved corporate passwords synced to a personal profile end up on personal machines that the company does not protect.

Sources & further reading