| Flare Darkroom, Part 2 | At a Glance |
|---|---|
| Environment | Darkroom by Flare (simulated dark-web training environment) |
| Subject | NovaCrest (fictional victim organisation) |
| Simulated Sources | RAMP · Cracked |
| Analytical Focus | Ransomware ecosystem roles, actor pivoting, credential lifecycle |
| Method | Manual investigation and analysis |
| Analyst | Joshua Berkoh · Part 2 of a three-part series |
Part 1 ended with two observations pointing at the same fictional company. On Exploit, an Initial Access Broker was selling corporate VPN access to NovaCrest. On BreachForums, NovaCrest credentials were circulating in data from a breach at a vendor, Vectrix Solutions.
Two artifacts, one organisation, and no established relationship between them.
The next two stages moved away from the question of how the access was obtained and toward what happens to access and credentials once they are in circulation.
RAMP → Cracked
One stage covered the ransomware ecosystem. The other showed where compromised credentials end up after the market for them stops being exclusive.
1. RAMP and the Ransomware Ecosystem
The third stage took place inside a simulated archive of RAMP, a forum historically associated with the ransomware ecosystem: Ransomware-as-a-Service recruitment, affiliate arrangements, and access trading.
Darkroom’s simulation centres on a fictional ransomware operation called BlackVortex. The objective was to identify the actor behind a recruitment post, then pivot from the post into that actor’s profile, which exposed a further communication identifier tied to the operator.
- Ransomware recruitment postPublic, written to attract affiliates
- Forum handleThe operational identity attached to the post
- User profileRegistration details, activity, self-description
- Contact identifierA channel the actor uses off-forum
Mechanically that is four clicks. What makes it worth writing about is what each step actually buys you, because the value is uneven. The post tells you what the operation is advertising for. The profile tells you how long the identity has existed and what else it has done. The contact identifier is the most durable of the three, because handles are cheap to abandon but a channel an actor has built correspondents around is not.
2. Attribution Is an Accumulation of Relationships
Attribution rarely looks like a single decisive finding. It looks like a slowly growing set of relationships around an identity, none of which is conclusive on its own.
Forum handle
- authors → recruitment post
- advertises → ransomware programme
- uses → contact identifier
- appears in → other sources
Each edge adds context. None of them adds certainty, and the distinction matters more than it might sound.
A forum identity is an operational persona. It can be shared between people, sold, retired, or rebuilt. Establishing that a persona ran a recruitment campaign and used a particular contact channel is a claim about the persona, not about whoever is behind it. The Darkroom exercise never asks you to name a human being, and that restraint is the right instinct: operational identity is what the evidence can actually support, and it is also the thing defenders can act on.
Worth stating plainly, because these get collapsed together often: what I observed were forum artifacts. What I inferred was a consistent operational identity behind them. Those are different confidence levels and should be reported as such.
3. Different Actors, Different Roles
Exploit introduced a broker. RAMP introduced a ransomware operation. Treating them as the same kind of participant would flatten the thing the exercise is actually teaching.
A simplified view of the division of labour:
- Initial Access BrokerObtains a foothold and sells it
- Ransomware affiliateBuys or is assigned access, executes against the victim
- RaaS operatorSupplies the ransomware, infrastructure, and negotiation apparatus; takes a cut
Real arrangements vary, since affiliates sometimes source their own access and operators sometimes run intrusions directly, but the principle holds. Different participants perform different functions inside the same incident.
Which is why role matters as much as identity. Once you have found an actor, the more productive question is what they do:
- Are they selling access, or buying it?
- Operating infrastructure, or renting someone else’s?
- Recruiting affiliates?
- Developing or deploying malware?
- Reselling credentials?
- Handling victim negotiation?
Finding an actor is a result. Knowing their function is what lets you predict what comes next.
4. Cracked and the Credential Economy
The fourth stage moved to a simulated version of Cracked, and the change in register was immediate. Compared with Exploit and RAMP, this was a lower tier of the same economy: compromised NovaCrest accounts selling for a few dollars each, and a separate actor trading a combolist assembled specifically around NovaCrest users.
Combolists, credential stuffing, cheap account resale, wordlists: this is the volume end of the market, and it operates on entirely different economics from a $3,500 access listing.
Seeing it directly after the BreachForums stage reframed the earlier credential exposure. The vendor breach was not the end of that incident. It was the first step in a lifecycle.
- BreachThe original compromise, here at a third-party vendor
- LeakData published or traded
- RedistributionCopied, mirrored, merged with other datasets
- CombolistRepackaged and targeted at a specific organisation or service
- Credential stuffingAutomated testing against live services
- Account compromiseValidated credentials become working access
- ResaleConfirmed accounts sold on cheaply
- Further abuse
The same credential can generate risk repeatedly, at different times, through different actors, long after the organisation has stopped thinking about the breach that produced it. A leaked password is not an event with an end date; it is an input to a pipeline.
5. A Three-Dollar Account Can Still Be a Real Problem
The resale price on Cracked was the detail I kept turning over. A few dollars per compromised account is close to worthless individually.
Low price does not mean low impact. It reflects supply. When validated credentials are abundant and the tooling to test them is commodity, the unit price collapses. The thing that makes them cheap is the same thing that makes them dangerous, which is that there are a great many of them and testing them costs almost nothing.
The organisational risk from a cheap account is rarely the account itself. It is what the account is reused for, what it can see, and whether it grants a path to something that matters.
| High-value access | Low-cost accounts | |
|---|---|---|
| Product | Corporate VPN access, elevated privilege | Individual compromised user accounts |
| Price | Thousands of dollars | A few dollars |
| Buyer | Ransomware affiliates, intrusion operators | Fraud, resale, opportunistic abuse |
| Volume | Scarce, individually negotiated | Abundant, sold in bulk |
| Risk to the organisation | Direct path to enterprise compromise | Reuse, escalation, and a foothold in adjacent services |
Different products, different buyers, different price points, one ecosystem. That was the most useful thing this stage did. It refused to present “the dark web” as a single undifferentiated place, and instead showed tiers with distinct functions and distinct economics.
6. The Attack Chain Starts to Resolve
By the end of the fourth stage, enough of the NovaCrest story was visible for the separate exercises to stop looking separate.
Credential track
- Third-party vendor breach
- Credential exposure
- Redistribution and combolists
- Stuffing, account resale
Access track
- Corporate access obtained
- Initial Access Broker listing
- Ransomware ecosystem demand
- Potential post-compromise activity
Two tracks, running at different speeds, both originating from the same organisation’s exposure.
What changes at this point is not the amount of evidence. It is the shape of it. The same artifacts that read as a list in Part 1 now read as a sequence, and a sequence supports questions a list cannot: about ordering, about causation, about what should have been detectable and when.
7. What Part 2 Reinforced
Cybercrime is specialised, and roles are analytically load-bearing. Brokers, operators, affiliates, credential traders, and account resellers occupy different positions in the same supply chain. Working out which one you are looking at does more for an assessment than another indicator does.
Credentials have a lifecycle, and it outlasts the breach. Exposed credentials keep moving: copied, merged, validated, stuffed, resold. Treating a leak as a closed event underestimates it by a wide margin.
One thread was still loose. Reviewing the access listing again, the broker from the very first stage turned up somewhere I had not been looking: a second forum, carrying the same NovaCrest access, and not quite the same details.
That cross-post is what makes the final stage possible.
Next: Part 3: Cross-Forum Intelligence and Simulated Threat-Actor Engagement