Initial Access Brokers (IABs) are threat actors who specialize in breaching corporate information systems and selling access to them. They do not leverage this access themselves, nor do they carry out full-scale attacks against compromised organizations.
To infiltrate corporate systems, IABs employ a diverse range of tools and techniques. These include exploiting software vulnerabilities, cracking passwords via simple brute force or credential stuffing, as well as phishing and other forms of social engineering.
Having gained stable access to a system, IABs transfer it to other threat actors via private channels, or list it for sale on the dark web.
Types of access and privilege levels
IABs sell initial access defined by two key parameters: the connection method and the level of privileges within the compromised system. These factors combined determine the capabilities available to the threat actor that buys the access. In terms of connection method, IABs tend to offer the following types of access:
- RDP (Remote Desktop Protocol) — remote access to an organization’s workstations or servers
- VPN — accounts for connecting to a corporate network via an encrypted communication channel
- RDWeb (Remote Desktop Web Access) — remote access to an organization’s systems via a web interface
- Web shell — a malicious script uploaded to a compromised web server allowing remote execution of commands on that server
The second key parameter — the privilege level — determines what actions an attacker can perform on the compromised system:
- Domain Admin — full administrative access to all workstations and servers in the domain, as well as to the domain controller
- Local Admin — administrative privileges on a dedicated workstation or server without domain management rights
- Domain User — access to a standard user account within the domain with a limited set of rights
Access-for-sale listings often include details about the target organization (its revenue, country of registration, etc.).
Collaboration between IABs and RaaS groups
Ransomware actors and operators of ransomware-as-a-service (RaaS) affiliate programs often turn to IABs, preferring to outsource the time-consuming task of gaining access. Long-term partnerships may develop between ransomware groups and specific IABs as a result.