Initial Access Brokers: The Middlemen of Ransomware
Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.
Behind a large share of ransomware incidents is a division of labour most people never see. The crew that encrypted the network often did not break in. They bought the way in from someone else, a specialist who does nothing but compromise organisations and resell the access. That specialist is an initial access broker.
The rise of the broker is one of the quiet structural changes in cybercrime. It turned "getting inside a company" from the hardest part of an attack into a commodity you can purchase, which lowered the bar for everyone downstream.
What a broker actually sells
An initial access broker sells a foothold: a working way into a specific organisation's network or cloud, ready for the buyer to escalate. The broker does the break-in, confirms the access is live, and hands it over. What they do not do is the attack that follows. That is the buyer's job.
The typical products:
| Access type | What the buyer receives | Why it is valuable |
|---|---|---|
| Compromised VPN | Valid VPN credentials or a live session | A trusted route straight into the internal network |
| Compromised RDP | Working remote desktop access | A hands-on interactive foothold |
| Valid accounts | Domain, email, or cloud credentials | Blends in as a legitimate user |
| Webshell | A backdoor on an internet-facing server | Persistent command execution on the perimeter |
| Admin or domain access | Elevated or domain-admin control | Premium, near-total control of the environment |
Price tracks how useful and how deep the access is. A single user's credentials at a small company is cheap. Domain-administrator access at a large, high-revenue organisation commands far more, because it saves the buyer the hardest and riskiest work.
How brokers get in
Brokers are opportunists who industrialise a handful of reliable entry methods. They rarely need novel exploits.
Infostealer logs. This is now a primary source. Infostealers harvest saved passwords and live session cookies from infected machines and bundle them into logs sold in bulk. Brokers mine those logs for corporate credentials, especially VPN and single-sign-on logins, then test which ones still work. A single stealer infection on one employee's device can become a corporate foothold weeks later in someone else's hands. Our infostealer guide covers that supply chain in detail.
Exposed remote services. Internet-facing RDP and VPN endpoints are scanned constantly. Weak passwords, reused credentials, and missing multi-factor authentication turn an exposed service into an open door. MITRE ATT&CK tracks this as External Remote Services (T1133), and the reuse of legitimate logins as Valid Accounts (T1078).
Phishing. Credential-harvesting pages and malicious attachments remain a dependable way to collect working logins at scale.
Unpatched edge devices. VPN gateways, firewalls, and other internet-facing appliances are high-value targets. When a serious vulnerability in one is disclosed, brokers race to exploit exposed instances before defenders patch, because a single flaw can yield footholds across many organisations at once.
Almost none of these methods require an advanced exploit. They require someone exposed: a reused password, an internet-facing box without MFA, a stealer infection on a laptop, an appliance patched a week too late. Brokers scale by finding the many organisations that left one of these open, not by out-engineering anyone.
The marketplace
Access is bought and sold on criminal forums, invite-only communities, and private channels. The economics look surprisingly like a legitimate market.
Listings are usually anonymised to protect the asset. Rather than naming the victim, a broker advertises the generic attributes a buyer needs to judge value: the country, the industry, the approximate revenue, the type of access, and the privilege level, for example "manufacturing, Europe, VPN access, local admin". The specific identity is revealed only once a buyer commits, which keeps the access from being burned by attention before it sells.
Reputation matters in these markets. Established brokers build standing over many sales, sometimes offer replacements if access dies before use, and get access to closed forums that screen newcomers. Trust is the currency that lets the market function despite everyone in it being a criminal. To see the forums and marketplaces where this trade happens, our dark web markets guide maps how these venues operate.
How brokers feed ransomware
The reason initial access brokers matter so much is where their product goes. They are the supply layer beneath the ransomware economy.
A ransomware operation needs to get inside a target before it can encrypt anything, and that first step is the slowest, riskiest, and most skill-dependent part of the whole attack. Buying it from a broker removes that friction. The affiliate starts from a working foothold and moves straight to the profitable stages: escalate privileges, move laterally, steal data for extortion, and deploy the encryptor.
The pipeline looks like this:
- A broker compromises an organisation and verifies the access works.
- The broker lists it on a marketplace with anonymised attributes and a price.
- A ransomware affiliate buys it, often selecting by sector, revenue, and geography to match a payout target.
- The affiliate runs the attack from the foothold: escalation, lateral movement, data theft, encryption.
- The ransom is negotiated and split among the affiliate, the ransomware operator, and the broker's earlier cut.
This specialisation is a big part of why ransomware scaled the way it did. It let ransomware-as-a-service crews focus on tooling and extortion while outsourcing the break-in to specialists. Our ransomware-as-a-service guide covers the affiliate side that sits directly downstream of the broker.
Everything a broker sells is something a defender can hunt for: an unexpected VPN login from a new location, RDP exposed to the internet, a domain credential in a public stealer-log dump, a webshell on an edge device. If you can find it before they list it, or invalidate it before a buyer uses it, you break the pipeline at the cheapest possible point.
How to defend against access brokers
Because brokers rely on a small set of sources, defence is about closing those sources and detecting the access itself.
- Kill the stealer supply. Application control, download hygiene, and phishing-resistant authentication cut off the logs brokers mine. Treat any stealer infection on a device with corporate access as a credential compromise, not just a malware cleanup.
- Lock down remote access. Put every VPN and RDP endpoint behind multi-factor authentication, never expose RDP directly to the internet, and enforce strong unique passwords. This removes the most common broker entry point.
- Patch edge devices fast. Internet-facing gateways and appliances need the shortest patch window you can manage, because brokers weaponise their vulnerabilities within days of disclosure.
- Monitor for exposed credentials. Watch for your domains appearing in stealer-log and credential dumps so you can rotate before a broker sells the access.
- Hunt for the foothold. Alert on anomalous remote logins, new or unusual valid-account activity, and webshells on perimeter servers. This catches access a broker has already established.
- Assume the first step was bought. In incident response, do not assume the intruder broke in themselves. Trace the origin of the access, because it may point to a stealer log or exposed service you need to close for good.
To see the ransomware crews and affiliates that buy from brokers, along with the sectors they focus on, our Threat Groups directory tracks the actors sitting downstream of the access trade, so you can understand who is likely to arrive after a broker sells the way in.
How a broker verifies and packages access
Selling a foothold is only worth doing if the buyer believes it works, so brokers put real effort into verification and packaging. This step is why the access that reaches a ransomware affiliate is usually live and usable rather than a stale credential dump.
After a broker obtains a credential or a session, they confirm it functions. For a VPN or RDP login this means logging in and checking that the account is active, has not been locked, and reaches an internal network worth attacking. For a webshell it means confirming the shell still executes commands. Brokers often note the privilege level, whether the account is a standard user or an administrator, and whether it can reach a domain controller, because those details set the price.
They also profile the target enough to write a listing. A buyer wants to judge payout potential before committing, so the broker records the sector, the country, the approximate revenue, the number of endpoints or the size of the environment, and the security tooling present. None of this names the victim. It describes the asset the way a real-estate listing describes a property without giving the address, so the access is not burned by attention before it sells.
The final package a buyer receives is compact: a working credential or session, notes on privilege and reach, and enough context to plan the next steps. The broker has done the slow, risky part, gaining entry and proving it holds, and hands over a foothold the buyer can act on immediately.
A leaked password from an old breach may or may not still work. What a broker sells is verified, current access, tested shortly before listing and sometimes backed by a replacement guarantee. This is why the broker layer accelerates attacks so much: the buyer starts from a foothold that has already been confirmed to function, skipping the trial and error of guessing at stale credentials.
A worked example: from stealer log to ransomware
Tracing one path from the original infection to the eventual ransom shows how the layers connect.
- The infection. An employee installs a cracked application on a personal laptop that also holds saved corporate logins. Bundled with it is an infostealer, which harvests the browser's saved passwords and active session cookies and sends them to its operator.
- The log for sale. The stealer operator bundles this victim's data with thousands of others into a log and sells access to the collection on a marketplace.
- The broker mines it. An initial access broker buys the log collection and searches it for corporate value, filtering for VPN portals, single-sign-on domains, and admin panels. They find the employer's VPN credentials.
- Verification. The broker tests the credentials against the VPN portal. They work, and because the organisation did not enforce multi-factor authentication on that portal, the broker is now inside the internal network. They confirm reach and note the privilege level.
- Listing. The broker lists the access with anonymised attributes: the sector, the country, an approximate revenue, and VPN access with the observed privilege. A price is set to match the apparent value.
- The sale. A ransomware affiliate shopping for a target in that revenue range buys the access.
- The attack. Starting from the VPN foothold, the affiliate escalates privileges, moves laterally to reach file servers and backups, steals data for extortion leverage, and deploys the encryptor. The organisation learns of the whole chain only when the ransom note appears.
The single stealer infection on one personal device became a corporate ransomware event, passing through two separate criminal specialists on the way. Each layer added value and distance, which is exactly what makes the model efficient and hard to trace back.
How brokers compare to related actors
The broker sits in a crowded ecosystem, and it is easy to blur them with adjacent roles. Distinguishing them clarifies where each fits.
| Actor | What they do | What they sell or keep | Relationship to the broker |
|---|---|---|---|
| Infostealer operator | Runs malware that harvests credentials in bulk | Sells logs in bulk | Upstream supplier the broker mines |
| Initial access broker | Breaks in and verifies a foothold at a named target | Sells the specific access | The layer in focus |
| Ransomware affiliate | Runs the intrusion and deploys the encryptor | Keeps most of the ransom | Downstream buyer of the access |
| Ransomware operator | Builds the encryptor and runs the brand and infrastructure | Takes a cut from affiliates | Sits alongside the affiliate |
| Exploit broker | Trades vulnerabilities and exploit code | Sells the capability to break in | Supplies methods, not footholds |
The clean division of labour is the story of modern cybercrime. Each specialist does one thing well and sells the output to the next, which lowers the skill any single participant needs and raises the overall throughput of the whole economy.
Common misconceptions
Brokers are elite hackers. Most are not. Their advantage is scale and diligence, not novel exploitation. They industrialise a handful of reliable methods and profit by finding the many organisations that left one of those methods open.
Only large companies are targeted. Brokers sell access to organisations of every size, because there is a buyer for every payout tier. A small company with weak remote access is an easy, cheap listing, and plenty of ransomware affiliates prefer soft targets over hardened large ones.
A stolen password is only a risk to the person who lost it. The stealer-log pipeline turns one employee's personal-device infection into a corporate foothold. Saved corporate credentials on any device a stealer touches can become access a broker sells weeks later.
Multi-factor authentication makes us immune. Strong multi-factor authentication removes the most common broker entry point, which is enormously valuable, but it is not absolute. Session-cookie theft, authentication that falls back to weaker methods, and gaps where multi-factor is not enforced all remain. It raises the cost sharply without reducing it to zero.
If we were not ransomed, the access was not sold. Brokered access can sit unused, be resold, or be used for goals other than ransomware, including data theft and espionage. The absence of a ransom note does not mean a foothold was never established or sold.
Detection signals: finding brokered access
Everything a broker sells leaves traces you can hunt for, and finding them early breaks the pipeline at its cheapest point.
- Your domains in stealer-log and credential dumps. Monitoring for corporate credentials appearing in the dumps brokers mine lets you rotate before a foothold is verified and sold.
- Anomalous remote logins. A VPN or RDP session from an unusual location, at an unusual hour, or from an unfamiliar device is the signature of freshly used brokered access. Baseline normal access and alert on deviation.
- Impossible travel and concurrent sessions. The same account authenticating from two distant locations in a short window suggests the credential is in more than one party's hands.
- RDP exposed directly to the internet. Scanning your own perimeter for exposed remote services finds the open doors brokers look for before they do.
- Webshells on internet-facing servers. Unexpected files that execute commands on perimeter hosts are a classic broker persistence method. File-integrity monitoring on edge servers surfaces them.
- Newly disclosed edge-device vulnerabilities left unpatched. When a serious flaw in a VPN gateway or firewall is disclosed, the window before you patch is exactly when brokers weaponise it. Tracking your exposure against fresh advisories is a race worth winning.
How the broker economy grew
The specialist broker is a relatively recent structural feature of cybercrime, and its rise tracks the maturing of the wider criminal economy. In earlier years an attacker who wanted to ransom a company generally had to break in themselves, which capped how many operations any crew could run. The break-in was the bottleneck.
Two developments removed that bottleneck. First, infostealers turned credential harvesting into a bulk, automated business, producing a constant stream of logs from infected machines around the world. That gave brokers a cheap, renewable raw material to mine for corporate access. Second, the ransomware-as-a-service model split ransomware into operators who build and run the platform and affiliates who carry out intrusions, creating a large pool of buyers who wanted footholds without doing the reconnaissance and break-in themselves.
The broker slotted neatly between those two developments, buying from the stealer supply and selling to the affiliate demand. Marketplaces and forums provided the venue, reputation systems provided the trust, and anonymised listings provided the discretion. The result is a mature intermediary market that behaves much like a legitimate one, with pricing tiers, quality signals, and repeat business.
The consequence for defenders is that the number of adversaries able to reach any given organisation multiplied. A crew that could never have broken in on their own can now buy the foothold and focus entirely on extortion. Understanding the broker layer is understanding why attacks scaled, and why the entry points brokers rely on are the highest-leverage places to defend.
Frequently asked questions
What exactly does an initial access broker sell? A working way into a specific organisation: valid credentials, a live VPN or RDP session, or a webshell on an internet-facing server, along with notes on the privilege level and internal reach. The buyer receives a verified foothold and does the rest of the attack themselves.
Where does the access come from? Mostly from a small set of reliable sources: infostealer logs harvested from infected machines, exposed remote services with weak or missing multi-factor authentication, phishing, and unpatched internet-facing appliances. Novel exploits are the exception rather than the rule.
How much does brokered access cost? It varies widely with how deep and how valuable the access is. A single user's credentials at a small company is cheap. Domain-administrator control at a large, high-revenue organisation commands far more, because it saves the buyer the hardest and riskiest work.
Why is the victim not named in listings? To protect the asset. If the target were named publicly, the access could be reported, detected, and closed before it sells. Brokers advertise generic attributes, sector, country, revenue, and access type, and reveal the identity only once a buyer commits.
How does this connect to ransomware? Brokers are the supply layer beneath ransomware. The break-in is the slowest and riskiest part of an attack, so buying it from a broker lets a ransomware affiliate skip straight to escalation, data theft, and encryption. This specialisation is a major reason ransomware scaled the way it did.
What is the single most effective defence? Locking down remote access with enforced multi-factor authentication and never exposing RDP directly to the internet. That removes the most common broker entry point. Close behind is treating any stealer infection on a device with corporate access as a credential compromise rather than a routine malware cleanup.
If we find brokered access, what should we do? Treat it as an active intrusion. Invalidate the credential or session immediately, trace how it was obtained so you can close that source, and hunt for what the access was used to reach. Assume the first step may have been bought rather than earned by the intruder in front of you.
Initial access brokers turned the break-in into a product. That is bad news, because it multiplies the number of criminals who can reach you, and good news, because everything they sell is something you can find, deny, or invalidate first. The break-in they monetise is the one control point where a few basic measures do the most work.
Related guides
Sources & further reading
Related guides
- Cybercrime-as-a-Service Explained: The Criminal Gig Economy
How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.
- Dark Web Markets: How Criminal Marketplaces Work
A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.
- The Bug Bounty Economy: Platforms, Triage & Payouts
How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.