Header image

What underground forums can tell businesses about cyber risk

Underground forums are often associated with the sale of stolen credentials, compromised network access and botnet services. However, they can also provide valuable insight into risks that may eventually lead to software supply chain attacks.

Recently, Flare researchers found early warning signs of supply chain attacks in underground forums and marketplaces before they became public incidents.

The Flare researchers documented “a pause moment,” explains Tracey Hannan-Jones, consulting director in information security, UBDS Digital. “By monitoring underground forums and criminal marketplaces, they identified early indicators of software supply chain attacks but not as explicit announcements, rather as mundane advertisements: A GitHub repository offered for sale, source code from a named vendor, API keys and cloud credentials traded in bulk.”

None of these listings stated, “forthcoming supply chain attack," yet taken together, they were “precisely that,” says Hannan-Jones. 

Taking this into account, how can security leaders take advantage of information posted on underground forums to inform a wider cybersecurity strategy?


Warning Signs

Software supply chain attacks rarely announce themselves, but there are often warning signs for companies that know where to look, according to Assaf Morag, cybersecurity researcher at Flare.

Typically, these attacks begin with small, seemingly unrelated exposures such as a leaked API key, a compromised developer workstation, an employee’s credentials, or a contractor’s leaked key appearing in infostealer logs. “Any one of these signs can be significant on their own. Looking at them together can help organisations understand whether they are part of a broader compromise,” says Morag.

This reframes what threat intelligence means in practice, says Hannan-Jones. “Security posture is oriented inwardly at firewalls, endpoint detection, identity controls and an assumption is that threats announce themselves at the perimeter, whereas underground forums tell a different story. The real signal often surfaces in criminal ecosystems days, weeks, or months before an incident registers in security information and event management (SIEM) or makes the headlines.”

Researchers are increasingly finding evidence of stolen GitHub repositories, exposed source code, API keys, cloud credentials and development environment access being advertised on criminal marketplaces long before a breach becomes public knowledge, says Tom Lovell, principal consultant at Infinity. “While these items may appear innocuous in isolation, they can give attackers the information they need to understand how software is built, identify trust relationships and discover weaknesses that could be exploited at scale."

                                                                                                         

Subtle Signs

 One of the biggest misconceptions is that attackers explicitly advertise “we compromised company X.”  In reality, the signals are much more subtle, says Morag.

Attackers often don’t reveal the victim. Instead, they may only reveal the sector or a ballpark figure of revenue. Connecting those assets to a specific organisation often requires additional investigation, which is typically direct engagement with the threat actor, according to Morag.

The value of monitoring underground forums lies in early detection, according to Lovell. “Many organisations only become aware of a cyber incident once malicious activity has already occurred. Threat intelligence gathered from criminal marketplaces can provide advance warning that credentials, source code or development resources linked to an organisation have been exposed.”

This is particularly important in the context of supply chain attacks, says Lovell. “Monitoring underground activity can help security teams identify indicators of compromise earlier, investigate potential weaknesses and reduce the likelihood of a small exposure escalating into a much larger incident."

Teams can then take action. For example, if an employee or contractor's credentials appear in infostealer logs, organisations can immediately rotate passwords, revoke API keys, invalidate session cookies, and terminate active sessions before attackers use the stolen information, explains Morag.


No Silver Bullet

However, while monitoring forums can be useful, it is not a perfect way to predict or detect attacks.

Dark web monitoring “should not be viewed as a silver bullet,” says Lovell. He points out that criminal forums generate vast amounts of information, much of which is unreliable, duplicated or deliberately misleading. “Separating genuine threats from background noise requires specialist expertise and context.”

Gaining useful intelligence from underground forums is “far from straightforward,” says Boris Cipot, principal security engineer at Black Duck. “Many forums are closed communities that require reputation, invitations, or specialised access. Even when access is available, analysts are confronted with enormous amounts of noise, misinformation, recycled breach data, and outright scams. Finding something relevant to your organisation is often like looking for a needle in a haystack.”

If you’re monitoring forums, there are therefore a few things you should keep in mind, according to Crystal Morin, senior cybersecurity strategist at Sysdig.

First, signal versus noise. “These spaces are full of exaggerated claims, resold data, and outright fraud. An advertised ‘access for sale’ post may be fake, recycled, or long since patched, and telling the difference takes real skill.”

Second, the serious threat actors don’t always advertise, because they have direct access to legitimate buyers, according to Morin. “So what you are seeing is only a slice, and absence of evidence is not evidence of absence.”

 

Wider Strategy

It’s not perfect, but the practice can still be useful as part for wider strategy. Dark web monitoring is most effective when combined with strong cyber hygiene and secure development practices, says Lovell. The indicators often identified on underground forums, such as exposed API keys, hard-coded credentials or access to development resources, are “frequently symptoms of deeper governance and security weaknesses,” he says.

Forum and dark web intelligence achieves its full value when integrated into existing security operations, says Hannan-Jones. For organisations with a SIEM and security orchestration automation and response (SOAR) capability, threat intelligence feeds from monitoring services can be ingested as indicators of compromise including credential pairs, IP addresses, and file hashes that trigger automated alerting when matched against internal telemetry, she says.

In vendor risk management, forum monitoring provides an external signal that complements traditional supplier assessment, says Hannan-Jones. For vulnerability prioritisation, forum discussions about active exploitation of specific CVEs “can accelerate patching decisions in a way that CVSS scores alone cannot,” she says.

The market for dark web monitoring is broad, and the right fit for your organisation depends entirely on your needs, according to Morin. “These services monitor forums, marketplaces, paste sites, messaging channels, and credential dumps for mentions of your organisation, domains, credentials, and executives, and then alert you and sometimes pursue takedowns. They range from largely automated scanners to human-led intelligence teams that curate and add context to what they find.”

What matters is not only how much a service can surface, but how actionable the information is: In other words, “is it timely and accurate?” says Morin. “The service’s job ends at the alert. An alert that a credential has leaked is worth very little if you can’t confirm whether it has been used and act on it quickly. Treat these services as a complement to your internal detection, never as a replacement.”

Kate O'Flaherty
Kate O'Flaherty Cybersecurity and privacy journalist
Kate O'Flaherty
Kate O'Flaherty Cybersecurity and privacy journalist

Upcoming Events

No events found.