Genesis Market Takedown and Infostealer Ecosystem
Law enforcement dismantled Genesis, but the stolen credential market simply moved elsewhere.

Genesis Market didn't just sell stolen logins. It sold the ability to become someone else, right down to the browser fingerprint, for as little as a few bucks a bot. When the FBI and Dutch police finally took it offline in April 2023, they got a full anatomy chart of how the infostealer economy actually works, from the malware that steals your cookies to the guy three keyboard clicks away buying your identity like it's a used car with low mileage. That anatomy chart matters more than the takedown itself because the ecosystem it exposed didn't die. It multiplied instead of shrinking.
How the infostealer supply chain flows, from infection to identity sale
Genesis, running on both the clearnet and the dark web, worked on an invitation-only model. Getting in as a buyer was easy. Getting approved as a seller was not, which kept quality control tight on the supply side while demand kept climbing on the other.
What buyers actually got were "bots": bundles of stolen fingerprints, cookies, saved logins, and autofill data, all harvested off one infected device by infostealer malware. To use one, a buyer installed a Chromium-based Genesis browser extension, imported the bot, and watched their browser quietly reset itself into someone else's digital identity. To any website checking, the buyer looked exactly like the real victim logging in from their usual device. No red flags, no second factor tripped, nothing.
What made Genesis genuinely nasty wasn't the initial sale. It was that the bot kept working after purchase. If the same infected device got a new user, say a shared family laptop or a work machine, that fresh data streamed to the original buyer at no extra charge. Buy once, keep collecting. It's less a purchase and more a subscription nobody canceled.
None of this ran on Genesis's own malware. Genesis was the middleman, the commoditization layer sitting between three distinct groups: the malware-as-a-service developers building the stealers, the affiliates and sellers who actually infected devices and packaged the loot into bots, and the buyers running fraud, account takeover, or ransomware intrusions. Buyers needed zero technical skill. That's the business model working as designed.
By February 2023, Genesis was openly recruiting new sellers, a sign that buyer demand had outpaced the supply of fresh bots. The market's own numbers back this up: a 2021 Netacea survey counted roughly 350,000 bots for sale. By March 2023, that number had climbed to 450,000. A year's growth, right before the lights went out.
What Operation Cookie Monster achieved, and where it fell short
On April 4, 2023, the FBI and Dutch National Police led Operation Cookie Monster, with 17 countries joining in, coordinated through Europol's EC3 and its J-CAT unit. The FBI's Milwaukee Field Office ran point, backed by 44 other FBI field offices, a striking show of scale for one takedown. That's a lot of badges for one marketplace.
The enforcement haul: more than 100 arrests and over 200 searches of Genesis customers across 13 countries, all people who'd bought stolen credentials off the platform. Canada alone brought 28 different police forces into the operation, coordinated by a national cybercrime coordination body run by its federal police, resulting in 79 separate law enforcement actions concentrated heavily in Quebec.
Private security firms did quiet, unglamorous work before any of this became public. Trellix and Computest were brought in by law enforcement ahead of the takedown to analyze the malicious binaries tied to Genesis Market, including DanaBot and other malware families circulating through the same pipeline. The Dutch police worked alongside them, and the infection signatures they identified got shared with VirusTotal and Microsoft so antivirus tools could catch the same malware going forward.
Nobody arrested Genesis's operators, and the same gap shows up in almost every operation like this. They're believed to be based in a country that won't extradite them, comfortably out of reach. A marketplace can be seized. Its people cannot, if they're sitting in a jurisdiction that doesn't extradite them for this kind of thing.
The infostealer ecosystem's scale after Genesis was removed
Genesis coming down should have shrunk the infostealer economy. Genesis coming down should have shrunk the infostealer economy, but it didn't. KELA's "State of Cybercrime 2024" report found more than 4.3 million machines infected with infostealer malware, adding up to over 330 million compromised credentials floating around. That's a full year after Genesis went dark, and the numbers went the wrong direction.
Three strains, Lumma, StealC, and Redline, made up more than 75% of everything detected on infected machines in 2024. Huntress found infostealers drove 24% of all cyber incidents that year, nearly one in four. CheckPoint's 2025 Cyber Security Report tracked a 58% jump in infostealer attacks during 2024 alone.
The year after Genesis died was the ecosystem's best year, not its worst. Taking out the store didn't reduce demand for what the store was selling. It just meant customers went shopping somewhere else.
The successive takedown pattern: Operation Magnus, LummaC2, and what followed
Operation Magnus landed on October 28, 2024. Dutch police, Europol, Eurojust, Belgian police, the Australian Federal Police, Portuguese police, and other law enforcement partners worked together to dismantle RedLine and META, two of the era's biggest infostealer families. The seizure list reads like a full IT department got confiscated: source code, REST-API services, license servers, stealer binaries, Telegram bots, plus IP addresses, credentials, and registration data on the users themselves.
The DOJ unsealed charges against Maxim Rudometov, named as a RedLine developer, covering access device fraud, conspiracy, and money laundering. He's facing up to 35 years if convicted, assuming he's ever actually in a courtroom to hear the verdict.
ESET Research had worked with law enforcement in the lead-up to Magnus, and days after the takedown went public, ESET released its own breakdown of RedLine's previously undocumented backend systems. That's about as clean an example as exists of private research directly feeding a law enforcement operation, not just commenting on it after the fact.
Then came LummaC2, disrupted on May 21, 2025. Between March 16 and May 16 of that year, Microsoft identified over 394,000 Windows machines worldwide infected by Lumma. Acting on a court order from a federal court. District Court for the Northern District of Georgia, a Microsoft security enforcement team seized and helped take down, suspend, or block roughly 2,300 malicious domains. The DOJ hit Lumma's command structure at the same moment, while Europol's EC3 and international partners handled suspending infrastructure based in their regions. Three coordinated strikes, one shared target.
Why the ecosystem keeps regenerating: the structural incentives no single takedown can reach
The malware-as-a-service model separates developers, affiliates, and buyers into different rooms, and nobody has solved this. Arrest a pile of buyers, and the developer never even notices. Seize a developer's servers, and a competitor absorbs the orphaned customer base within weeks, sometimes days.
Lumma's own pricing tells the story better than any report could. Subscriptions ran $250 to $1,000 a month, structured like any legitimate SaaS product. That recurring revenue means developers don't need to touch the risky part of the operation. Affiliates handle the infections, buyers handle the fraud, and the person who wrote the code just collects a monthly fee like a landlord who never has to fix the plumbing.
Uncertainty over which jurisdiction can prosecute shows up in every single one of these cases without exception. Genesis's operators were never caught, believed to be outside the reach of the jurisdictions involved in the takedown. The infrastructure gets seized, the money gets traced, and the person who built it stays comfortably out of reach across Cookie Monster, Magnus, and Lumma alike.
A stranger wrinkle inside Genesis was the reseller subeconomy, buyers who purchased cheap bots purely to hold and resell at a markup later, the same way someone flips sneakers or concert tickets. These people had no malware skills whatsoever. What they had was a financial incentive to keep the marketplace liquid, which means the ecosystem doesn't even need technical talent at every level to keep growing. It just needs enough people willing to speculate on stolen identities like they're a commodity future.
What the Genesis anatomy tells defenders about where to intervene
The persistent-update mechanic in Genesis bots proves something uncomfortable: rotating passwords isn't enough on its own. If the infostealer is still sitting on the device, it grabs the new password the moment it's typed. Endpoint detection and actual malware removal need to happen before or alongside any credential reset, not after.
Session cookie theft breaks another assumption people lean on too heavily, which is that multi-factor authentication solves everything. It doesn't stop this attack type, because a stolen session cookie walks right past MFA. The real controls here are token binding, shorter session lifespans, and systems that flag a session behaving oddly, logging in from a new location with the same cookie an hour after the legitimate user logged off.
Defenders keep underestimating timing. Roughly 36.4% of stolen credentials get indexed and available for sale within 24 hours of theft, not on some weekly breach-scanning cycle security teams might assume. Identity threat monitoring has to run continuously and close to real time, or it's chasing a problem that already resolved itself in the attacker's favor.
Genesis also functioned as an initial access broker for ransomware crews, and the data backs up how directly: 54% of ransomware victims had domains already sitting in infostealer credential dumps before the ransomware ever hit. The credential theft comes first, sometimes weeks ahead of the actual intrusion. Anyone treating an infostealer infection as a low-priority alert is looking at the opening scene of a much longer movie and calling it the whole show.

Sources
- Cybercrime marketplace Genesis Market shut by FBI, international law enforcement
- How 'Operation Cookie Monster' took down a major dark web market | World Economic Forum
- Operation Cookie Monster: Genesis Market seized, 120 suspects arrested | Cybernews
- Operation Cookie Monster: Taking Down Genesis Market
- Genesis Market No Longer Feeds The Evil Cookie Monster


