Operation Cookie Monster (Genesis Market Takedown)
Key Facts
- Legal Status: ALLEGED in U.S. District Court for the Eastern District of Wisconsin.
- Primary Target Sector: Consumer Accounts, Banking, E-Commerce.
- Documented Financial Loss: $50.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Consumer Accounts, Banking, E-Commerce networks. Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.
Operational & Financial Fallout
Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide. Impacted Consumer Accounts, Banking, E-Commerce infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Consumer Accounts, Banking, E-Commerce networks. Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.
Adversary Kill Chain Flow
2 Documented PhasesPurchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.
Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.
Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide. Impacted Consumer Accounts, Banking, E-Commerce infrastructure and associated victim operations.
Procedural & Incident Timeline
FBI and 17 international partner agencies seize 11 domains hosting the Genesis Market infrastructure.
Over 120 arrests executed globally against Genesis Market high-volume purchasers.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1555 | Credentials from Password Stores Credential Access | "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware." | DOJ Seizure Affidavit ¶ 12 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection." | DOJ Seizure Affidavit ¶ 16 | reviewed |