Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - Unpacking IABs: The Middlemen Fueling Ransomware Attacks
Attacks Latest News News & Analysis Ransomware

Unpacking IABs: The Middlemen Fueling Ransomware Attacks

Kirsten DoyleBy Kirsten DoyleApril 14, 2025Updated:April 21, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Unpacking-IABs-The-Middlemen-Fueling-Ransomware-Attacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The U.S. remained the top target for Initial Access Brokers (IABs), with 31% of all access listings aimed at American entities. But in 2024, Brazil (7%) and France (5%) have emerged as fast-rising targets. Analysts believe this shift could be due to expanding digital infrastructure and relatively weaker cybersecurity defenses in these countries.

This was revealed in a new report compiled by Cyberint, a Check Point company.

Initial Access Brokers (IABs) are threat actors who specialize in breaking into networks, systems, or organizations and then selling that access to other malicious actors on underground forums. Rather than carrying out full-scale cyberattacks themselves, IABs focus solely on gaining entry—and then monetizing it.

The Supply Chain Behind Ransomware

The report, which draws on over two years of dark web research across top cybercrime forums like Ramp, Breach, XSS, and Exploit, reveals how IABs are becoming more strategic, more selective, and ultimately more dangerous.

Across the top 10 most-targeted nations, IAB listings surged by 90% in 2024, suggesting that attackers are no longer casting a wide net—they’re honing in on countries with economic potential or high-value data.

SMBs in the Crosshairs

The report also reveals that threat actors are increasingly targeting smaller entities. In 2024, companies with annual revenues between $5 million and $50 million made up 60.5% of all initial access listings. These businesses are seen as easier targets, possibly due to weaker security setups.

As a result, the average revenue of compromised companies dropped from $1.38 billion in 2023 to $1.28 billion in 2024.

Shifting Tactics: From RDP to VPN

IABs are also changing the way they gain access. In 2023, more than 60% of brokers were selling access via exposed Remote Desktop Protocol (RDP) servers. But last year, VPN access surged to 33%, a reflection of how attackers are adapting to remote work environments.

Listings for corporate access typically range from $500 to $3,000, though some high-value listings can exceed $10,000.

“The Venture Capitalists of Ransomware”

“Initial Access Brokers are the venture capitalists of ransomware. They invest effort in breaches and profit by selling access, empowering the entire cybercrime supply chain,” said Adi Bleih, Security Researcher at Check Point External Risk Management.

 “Organizations must shift from reactive to proactive security: patch aggressively, segment networks, and monitor deep and dark web chatter to disrupt access before it’s sold,” Bleih added.

Enabling Ransomware

Initial Access Brokers don’t launch ransomware attacks—they enable them. By auctioning off access to compromised systems, they make it easy for ransomware gangs, nation-state actors, and other cybercriminals to “log in and launch.” It’s low-risk, scalable, and highly profitable.

This business model fuels everything from ransomware-as-a-service (RaaS) to corporate espionage, making IABs a critical part of the global threat ecosystem.

How to Defend Against IABs

Cybering recommends a multi-layered defense strategy, including both technical and business measures:

  • Use multi-factor authentication (MFA) on all remote access points.
  • Limit and monitor services like RDP and VPN.
  • Upgrade endpoint protection—don’t rely on default tools like Windows Defender alone.
  • Regularly audit user permissions and credentials.
  • Monitor underground forums using threat intelligence tools for early warning signs.

The takeaway is clear: organizations must act before their access is sold on the dark web. Being proactive isn’t just smart—it’s necessary.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}