JUNE 7, 2026
How IAB forum listings are structured, what they reveal, how they are priced, and what they mean for your CTI program.
Somewhere on a dark web forum right now, there is a thread titled something like “[AD Access] [US] Financial Sector, Rev $800M, 1,200 Hosts, Domain Admin, $35,000.” The seller is not a hacker in the cinematic sense. They are a specialist who identified a vulnerable VPN appliance, exploited it, confirmed domain-level access, took notes, and created a sales listing. The listing will be up for 48 to 72 hours. A ransomware affiliate will purchase it. Twenty-two seconds later, on average, deployment will begin.
Initial Access Brokers (IABs) are one of the most important and least understood actors in the modern cybercrime economy. They do not run ransomware attacks. They do not exfiltrate data. They specialize in one thing: obtaining confirmed, working access to corporate networks and selling that access to whoever will pay the most. They are the wholesale layer of the ransomware supply chain.
Understanding how IAB listings are structured is not an academic exercise. Every field in an IAB listing, sector, revenue, access type, privilege level, antivirus product, host count, is a data point that CTI programs can use. When your organization’s profile matches the parameters of an active IAB listing, you are a target. When those parameters shift toward your industry or technology stack, your risk level has changed. The listing is the signal.
This blog covers what IABs are and where they operate; the anatomy of a real IAB listing, field by field; how pricing is determined and what each price tier buys; the IAB-to-ransomware handoff and why it happens so fast; and how CTI programs extract actionable intelligence from IAB activity.
| $2,700 average price paid for corporate network access on IAB markets in 2025 (Rapid7) | 100%+ growth in IAB listing volume in early 2025 compared to the same period two years prior | 22 sec average time from IAB access sale to ransomware affiliate deployment (Mandiant M-Trends 2026) | 71.4% of all IAB sales in 2025 included privileged access, not just basic user credentials |

An Initial Access Broker is a cybercriminal who specializes exclusively in the first phase of a corporate breach: gaining a foothold inside a target organization’s network. They do not conduct the attack from start to finish. They stop at the point where they have confirmed, working access, document that access in structured detail, and sell it.
The IAB model emerged as a natural division of labor in the cybercrime economy. Ransomware groups discovered that deploying ransomware at scale required more initial-access operations than they could run themselves. Skilled exploit operators discovered that they could generate consistent revenue selling access rather than running the riskier, more visible end-game operations. The market cleared: IABs focus on access acquisition, ransomware operators focus on monetization, and the handoff between them happens through forum transactions.
IABs are rational economic actors. They invest time and resources in obtaining access, and they price that access to recover their investment plus margin. A VPN exploit that takes two hours to run against a small company with 50 endpoints generates a different price point than a multi-week compromise campaign that yields domain admin access to a Fortune 500 with 10,000 endpoints. The listing reflects that investment.
IAB activity is concentrated on a small number of Russian-language dark web forums. Exploit.in and XSS.is are the two most active venues, together accounting for the majority of observed access listings. RAMP (Ransom Anon Market Place) and several Telegram-based channels serve as secondary markets. Each forum has its own reputation system: sellers with high post counts and verified transaction histories command premium prices and attract more serious buyers.
Forums require registration and, for active sellers, payment of deposit fees that serve as both commitment signals and fraud deterrents. The most established IABs operate with verifiable transaction histories spanning years. The marketplace has its own trust infrastructure: escrow services, guarantors (third-party forum members who vouch for sellers), and reputation scores that function similarly to eBay seller ratings.
| 💡 The Forum Economy IAB forums are not anonymous chaos. They are structured commercial marketplaces with established norms, reputation systems, dispute resolution mechanisms, and escrow services for high-value transactions. A seller who fails to deliver valid access as described loses their reputation rating and their ability to operate on that forum. The commercial incentives create a paradoxical quality control mechanism: IABs are motivated to deliver exactly what they advertise, because their business model depends on repeat buyers. |
A mature IAB listing is a structured document. It contains specific fields that buyers use to evaluate purchase decisions, just as a real estate listing contains square footage, location, and price. Each field serves a purpose, and each field is a data point for CTI analysts who monitor these markets.
The first and most important field describes how the IAB has access to the target network. This determines what the buyer can do with the access and, therefore, how much it is worth. The most common access types, in rough order of value:
| Access Type | What It Gives the Buyer |
| VPN / SSL VPN | Authenticated entry to the internal network through the organization’s own remote access infrastructure. The buyer appears as a legitimate remote user. Most common listing type; lowest average price. |
| RDP (Remote Desktop Protocol) | Direct interactive access to a specific internal endpoint. Useful for lateral movement staging but limited to the privileges of the compromised RDP account. |
| Web Shell | Persistent command execution on an internet-facing web server. Limited privilege but highly persistent; survives credential resets. Often used as a staging point. |
| AD / Domain Admin | Full administrative control over Active Directory; ability to create accounts, modify permissions, access any system, and push GPOs. Highest-value single access type after full domain control. |
| C2 / Backdoor | Active command-and-control session via installed malware. The IAB maintains a persistent backdoor on one or more systems. Often sold alongside domain access as a bundle. |
| Cloud Console (AWS/Azure/GCP) | Authenticated access to cloud management infrastructure. IAM admin access provides control over all cloud resources; limited-scope access prices depend on which services are accessible. |
| SSO / Okta Admin | Identity provider admin access; can modify permissions for all connected applications, create new admin accounts, disable MFA for specific users. Second highest-value type. |

IAB listings almost always identify the target’s industry sector. This serves two functions: it helps buyers identify whether the target fits their operational profile (a ransomware group that specializes in healthcare will specifically seek healthcare targets), and it signals the potential data value of the access. A hospital’s patient records, a law firm’s case files, and a financial institution’s transaction data each carry different monetization value to different buyers.
Sector information in listings is typically derived from public business databases. IABs check the target company’s revenue against Dun and Bradstreet, Crunchbase, or similar sources before listing, because revenue is a primary price signal. A $50M revenue manufacturing company and a $5B revenue financial services firm with the same access type will be priced very differently, and the sector label tells the buyer what downstream damage potential they are purchasing.
Revenue is the IAB’s primary proxy for breach impact potential. A company with $1B in revenue likely has more valuable data, more resources to pay a ransom, and more reputation risk from a public breach than a company with $10M in revenue. The listing price scales accordingly. IABs typically source revenue data from public filings, LinkedIn company pages, or commercial business databases. The figure is approximate and sometimes wrong, but it is present in nearly every listing.
The number of hosts (endpoints, servers, and network devices) on the target network tells the buyer how much infrastructure they have to work with. A network with 50 hosts limits lateral movement options. A network with 5,000 hosts provides extensive staging and propagation surface for ransomware deployment. Larger networks command higher prices, both because they take longer to compromise initially and because they produce larger ransom demands.
Perhaps the most operationally critical field for the buyer: what permissions does the compromised account actually have? The difference between ‘local user on one endpoint’ and ‘domain admin’ is the difference between a starting point and a finished operation. Listings are explicit about this because privilege level is the primary determinant of how much additional work the buyer needs to do after purchasing. A domain admin listing sells itself. A basic user listing requires the buyer to invest in their own privilege escalation.
Many IAB listings include the security products deployed in the target environment. This is directly useful to ransomware operators who need to know which EDR or AV product they will need to disable or evade before deploying their payload. A target running a well-known EDR with strong behavioral detection requires different pre-deployment preparation than a target running a legacy signature-based antivirus. Some listings advertise that the security product has already been identified and tested against; others leave it as a known variable for the buyer to handle.


IAB pricing is not arbitrary. It follows a consistent market logic based on four variables: the access type and privilege level, the target’s revenue and sector, the current buyer demand for that sector, and the IAB’s reputation and track record. Understanding the pricing structure is useful for CTI programs because price signals reflect attacker demand for specific target profiles.
| Access Type | Price Range | Primary Price Drivers |
| Basic credentials / stealer log | $20-$50 | Volume product; no network access confirmed; used for credential stuffing |
| VPN / RDP (basic user) | $500-$2,000 | Revenue size; sector; host count; whether credentials are fresh vs. from log |
| VPN + domain user | $1,000-$5,000 | Domain visibility; lateral movement potential; AV product known |
| Local admin access | $3,000-$10,000 | Privilege level; sector (healthcare, finance pay premium); IAB reputation |
| Domain admin access | $8,000-$50,000 | Full AD control; sector; revenue; whether ransomware groups are actively bidding |
| Cloud console / SSO admin | $5,000-$30,000 | IAM scope; data volume accessible; cloud resource inventory value |
| Bundle (VPN + domain + C2 backdoor) | $15,000-$100,000+ | Multi-vector redundancy; fastest time-to-ransomware; Fortune 500 premium |
Sources: Rapid7 2025 Access Brokers Report; DeepStrike Dark Web Pricing Analysis; Saptang Labs IAB Economy 2025; Brandefense CTI monitoring
Most IAB listings on auction-format forums include two prices: a starting bid (the minimum acceptable offer) and a ‘blitz’ or ‘buy it now’ price. The blitz price is typically 2 to 5 times the starting bid and is specifically designed to allow a motivated buyer to close the transaction immediately, without waiting for the auction to run. Ransomware operators with active deployment capacity will frequently pay the blitz price to prevent competitors from acquiring the same access.
The blitz price structure reveals something important about buyer psychology: for serious ransomware operators, the cost of waiting is higher than the premium for immediate acquisition. If a competing ransomware group buys the access first, the opportunity is lost. The blitz price is the seller’s capture mechanism for this urgency, and it succeeds because it matches how ransomware affiliate operations actually work.

Mandiant’s M-Trends 2026 documented a figure that reframes how defenders should think about the IAB threat model: the average time from IAB access sale to ransomware affiliate deployment of that access is 22 seconds. Not 22 minutes. Not 22 hours. Twenty-two seconds.
This number reflects the operational reality of modern ransomware affiliate programs. The largest ransomware groups maintain on-demand deployment infrastructure: pre-built payloads, pre-configured lateral movement tools, pre-authorized C2 infrastructure, and affiliate operators standing by specifically to act on freshly purchased access. When an IAB listing is purchased, the buyer is not starting a new operation from scratch. They are activating the final stage of an operation that was already prepared and waiting.
| T | Stage | What Happens |
| 0s | Transaction completed | Forum escrow releases payment to IAB; credentials and access details transmitted to buyer via encrypted channel |
| 0-5s | Credential validation | Automated tooling validates that the purchased credentials still work against the target authentication endpoint |
| 5-10s | Environment fingerprinting | Automated scripts run against the access to confirm host count, domain structure, and AV product; matches IAB’s advertised parameters |
| 10-20s | Payload staging | Pre-built ransomware payload configured for the target environment; C2 callbacks confirmed; lateral movement tools staged |
| 22s | Deployment begins | Ransomware operator begins lateral movement from the purchased access point; clock starts on the actual breach |
The 22-second figure makes one point unavoidably clear: the defensive response window that exists after a ransomware operator acquires access from an IAB is measured in seconds, not hours. Detection at the lateral movement stage, the point at which most SOC playbooks begin the incident response process, is too late to prevent deployment. The only defensive layer that operates within the actual response window is the one that detects the IAB listing itself, before the transaction completes.
| 🔴 The Response Window Problem Most incident response programs are designed around detection-to-containment timelines measured in hours: detect the breach, investigate, scope the damage, contain the affected systems. Against a 22-second IAB-to-deployment handoff, this entire timeline collapses. By the time an alert fires in a SOC, the ransomware payload is already staging. The only response window that matters is the one that exists before the IAB listing is purchased, and that window is visible only through continuous dark web monitoring. |

IAB listings are not just a threat to the organizations being listed. They are a continuous intelligence feed for CTI programs that monitor them. Every listing contains structured data about attacker demand, target selection patterns, pricing signals, and active campaign preparation. CTI teams that monitor IAB markets proactively gain visibility that no other intelligence source provides.
When a specific sector appears disproportionately in IAB listings over a two-to-four-week period, it indicates that ransomware groups are currently running active campaigns in that sector and have created demand for sector-specific access. A healthcare organization that monitors IAB markets and observes a surge in healthcare-sector listings should treat this as an elevated threat signal, even if their specific organization has not appeared in any listing. The sector-level demand pattern precedes individual targeting.
IAB listings specify revenue ranges that correspond to the attacker’s target profile. A ransomware group that consistently purchases access to companies in the $100M to $500M revenue range is not interested in organizations outside that range. If your organization falls within the active revenue parameters of IAB listings in your sector, your risk profile is elevated. If your sector’s listings cluster around revenue ranges well below or above yours, your immediate risk from that specific campaign is lower.
When IAB listings in your sector begin consistently mentioning the same AV product or access technology, it indicates that attackers have developed or acquired tooling specifically to defeat that product in your sector. A sudden increase in Fortinet-specific IAB listings in the financial sector, for example, preceded the CVE-2025-64446 mass exploitation campaign. The listing pattern was the leading indicator of the campaign.
The most direct and actionable signal is an IAB listing that explicitly mentions your organization by name, domain, or sufficiently identifying characteristics. When this appears, the window between listing publication and transaction is typically 48 to 72 hours for high-value targets, and less for listings that attract immediate buyer interest. The 48-to-72-hour window is the response window: accelerated credential rotation, enhanced monitoring, and pre-positioned IR response.

Initial Access Brokers do not operate in isolation. They are one node in a supply chain that begins with credential theft and ends with ransomware deployment, data exfiltration, or both. Understanding where IABs sit in this chain clarifies both their role and the full set of monitoring layers required to address the risk they represent.
| Stage | Who Does It | Detection Opportunity |
| 1 | Credential supply: infostealer malware, phishing, combolist distribution | Dark web credential monitoring: detect stolen credentials before they reach IABs |
| 2 | Vulnerability exploitation: IAB gains network access via CVE or stolen credential | EASM: detect your exposed attack surface before IABs find it; KEV monitoring for active campaigns |
| 3 | Access verification and listing: IAB documents and lists confirmed access on forum | IAB forum monitoring: detect the listing within the 48-72 hour window before transaction completes |
| 4 | Transaction and handoff: ransomware affiliate purchases and deploys within 22 seconds | No viable detection window post-transaction; all prior stages are the defensive opportunity |
| 5 | Ransomware deployment and ransom demand | Behavioral detection, EDR, incident response: the last and most expensive defensive line |
Effective IAB monitoring requires continuous surveillance of a small number of high-activity venues, combined with the analytical capability to match listing parameters against specific organizational profiles. Brandefense’s dark web intelligence platform provides both layers.
| Brandefense Capability | IAB Intelligence Application |
| IAB Forum Surveillance | Continuous monitoring of Exploit.in, XSS.is, RAMP, DarkForums, and Telegram-based access channels for new listings; automated extraction of listing parameters (sector, revenue, access type, price) for profile matching |
| Organization Profile Matching | Automated and analyst-reviewed matching of IAB listing parameters against your organization’s sector, revenue range, technology stack, and geographic profile; alerts when listing characteristics match your risk profile |
| Sector Demand Trend Analysis | Tracking of IAB listing volume by sector over time; identification of sector-specific demand surges that indicate active ransomware campaign targeting your industry before individual organizations are listed |
| Dark Web Credential Monitoring | Continuous scanning of credential markets and stealer log distributions for your organization’s credentials; detects the upstream credential supply that feeds IAB access acquisition before access is confirmed and listed |
| Ransomware Group Activity Correlation | Matching of IAB listing patterns against known ransomware group operational profiles; identifies when a specific group is actively acquiring access in your sector or technology stack |
| 24/7 Analyst-Supported Escalation | All high-priority IAB detections reviewed by analysts; when your organization or a close profile match appears in an active listing, immediate escalation with contextual analysis and recommended response actions |
An IAB listing is not the attack. It is the warning that the attack has been prepared and is about to be sold. The 48-to-72 hour window between listing publication and transaction is the only response window that allows meaningful defensive action before the 22-second deployment clock starts. Organizations with no IAB monitoring learn about the listing when they receive the ransom note. Organizations with continuous monitoring learn about it while there is still time to act.

Take control of your digital security with an exclusive demo of our powerful threat management platform.