agentsclimarketplace

Carding financial fraud

Skill Liberty91LTD/cti-skills/skills/carding-financial-fraud

Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.

Install
npx -y skills add Liberty91LTD/cti-skills --skill carding-financial-fraud

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when the user asks about carding, BIN attacks, payment-card breach markets, fullz/CVV2 trade, autoshops (BidenCash, Brian's Club, Russianmarket, B1ack's Stash), or financial-fraud TTPs. Self-updating knowledge cell.

SKILL.md

12.6 KB, as published. Nobody here has run it

Carding & Financial Fraud

Executive Summary

Carding and financial fraud represent one of the oldest and most mature cybercriminal ecosystems, encompassing the theft, trade, and monetization of payment card data and financial credentials. The ecosystem spans from initial data theft (via digital skimming, POS malware, phishing, and database breaches) through underground marketplace trading to ultimate monetization via card-not-present (CNP) fraud, money mule networks, and reshipping schemes. The shift toward EMV chip cards largely eliminated traditional card cloning for in-person fraud in developed markets, pushing the ecosystem heavily toward CNP fraud in e-commerce, which now represents the vast majority of card fraud losses globally — estimated at over $30 billion annually.

The digital skimming landscape, dominated by the umbrella term "Magecart," continues to evolve with threat actors injecting malicious JavaScript into e-commerce payment pages through compromised third-party scripts, CMS vulnerabilities, and supply chain attacks. Card shops and carding forums provide the marketplace infrastructure, with BidenCash emerging as a prominent card shop known for large-scale free dumps to attract customers. The Genesis Market takedown in Operation Cookie Monster (April 2023) disrupted a major marketplace for stolen credentials and browser fingerprints, though alternatives rapidly filled the gap.

The fraud ecosystem increasingly overlaps with other cybercriminal domains. Infostealer malware feeds card data and banking credentials directly into fraud pipelines. Business Email Compromise (BEC) operators share techniques and money mule networks with carding groups. SIM swapping enables account takeover for financial fraud and cryptocurrency theft. The emergence of Fraud-as-a-Service (FaaS) platforms has lowered barriers to entry, offering turnkey fraud toolkits, tutorials, and operational support to less sophisticated actors.

Key Actors

Actor/EntityTypeNotable CharacteristicsStatus
BidenCashCard ShopMajor marketplace; known for marketing via large free card dumps (millions of records); Tor-basedActive
Joker's StashCard ShopFormerly dominant card shop; voluntarily retired February 2021Defunct
BriansClubCard ShopMajor card shop; was itself breached in 2019 exposing 26M card recordsStatus unclear
Genesis MarketCredential/Bot MarketSold browser fingerprints and credentials; seized in Operation Cookie Monster April 2023Seized
Russian MarketLog/Credential ShopMajor marketplace for infostealer logs, RDP access, and card dataActive
Magecart GroupsDigital Skimming CollectiveUmbrella term for multiple groups conducting web-based card skimmingActive (various)
FIN7Cybercrime GroupSophisticated group with ties to POS malware (Carbanak/FIN7 campaigns); members arrested but operations continuedPartially disrupted
Scattered SpiderCybercrime CollectiveSIM swapping, social engineering, financial fraud; young Western actorsActive
Various BEC NetworksFraud OperationsWest African (Yahoo Boys) and Eastern European networks conducting BEC and romance fraudActive
SIM Swapping CrewsAccount TakeoverLoosely organized groups bribing telecom employees or exploiting SS7Active

Current Activity

BidenCash Market Dominance and Free Dump Marketing

BidenCash has established itself as a leading card shop through an aggressive marketing strategy of periodically releasing large batches of stolen card data for free — sometimes millions of records at once — to drive traffic and build reputation. These dumps typically contain a mix of fresh and older data across multiple countries. The marketplace operates on Tor and the clear web, selling cards categorized by bank, country, card type, and freshness with a checker service for validity verification.

Magecart/Digital Skimming Evolution

Digital skimming attacks have grown more sophisticated, with actors increasingly targeting server-side injection to avoid client-side detection tools. Attacks against major e-commerce platforms (Magento, WooCommerce, Shopify third-party apps) continue. The PCI DSS 4.0 requirement 6.4.3 (mandating client-side script integrity monitoring) that took effect in March 2025 represents the industry's response, though compliance and enforcement remain works in progress.

SIM Swapping and Account Takeover Escalation

SIM swapping attacks have expanded beyond cryptocurrency theft to target traditional financial accounts, corporate accounts, and even government officials. Techniques include bribing or socially engineering telecom employees, exploiting eSIM provisioning vulnerabilities, and using SS7 protocol weaknesses. Several high-profile arrests of SIM swapping groups have occurred, but the technique remains prevalent due to the fundamental weakness of SMS-based authentication.

Historical Events

DateEventImpact
2018British Airways Magecart breach380,000 card details stolen via injected checkout script; ICO fined BA £20M
2019BriansClub breach26M stolen card records from the card shop itself were leaked; data shared with banks
Feb 2021Joker's Stash retirementLargest card shop voluntarily closed; created market fragmentation
Apr 2023Operation Cookie Monster (Genesis Market)FBI-led takedown seized Genesis Market; 119 arrests globally; disrupted bot/fingerprint market
2023-2024BidenCash free dumpsMultiple large-scale free releases of stolen card data as marketing; 2M+ cards in single dumps
2024PCI DSS 4.0 transitionNew requirements for client-side script monitoring; full enforcement March 2025
2024-2025FIN7 members sentencedMultiple FIN7 members received significant prison sentences in US courts
2024-2025Scattered Spider arrestsSeveral members of the SIM-swapping and social engineering collective arrested by FBI

TTP Evolution

Data Theft Methods: The ecosystem has evolved from physical skimming devices and POS RAM scraping malware (2010s) to predominantly web-based digital skimming (Magecart-style JavaScript injection) and mass data theft via infostealer malware. Server-side skimmers that intercept payment data at the application layer are increasingly common, as they evade client-side Content Security Policy (CSP) and script monitoring solutions.

Marketplace Infrastructure: Card shops have moved from forums with manual transactions to automated platforms with APIs, validity checkers (testing cards with small transactions), replacement guarantees (refunds for dead cards), and sophisticated search/filter capabilities. Multi-vendor marketplaces now coexist with single-operator shops. Telegram channels serve as both advertising and direct sales channels.

Monetization: CNP fraud techniques include using residential proxies to match cardholder geolocation, anti-fingerprinting browsers (Multilogin, GoLogin) to evade device fingerprinting, and automated checkout bots for rapid purchases. Gift card purchasing remains a primary cashout method. Cryptocurrency purchasing using stolen cards provides another laundering avenue.

Money Mule Operations: Recruitment of money mules has shifted from in-person "work from home" scams to social media and messaging app recruitment. Professional mule herders manage networks of mules across countries. Mules receive fraudulent funds and forward them, taking a commission. Some operations use cryptocurrency ATMs for rapid conversion.

Identity Fraud (Fullz): Complete identity packages ("fullz") containing name, SSN, DOB, address, email, phone, and sometimes bank credentials trade for $15-$65 depending on credit score and completeness. Synthetic identity fraud — combining real and fabricated data to create new identities — is a growing trend that is harder to detect than traditional identity theft.

Ecosystem & Infrastructure Patterns

Supply Chain: Card data flows from theft (skimming, breaches, infostealers) → aggregation by data brokers → card shop listings → purchase by carders → monetization via CNP fraud or resale. Each stage has specialized actors, and data may pass through multiple intermediaries before final use.

Quality Assurance: Card shops offer "checker" services that validate cards are still active by running small authorization charges. Cards are priced by freshness, bank, type (credit vs. debit), level (Classic, Gold, Platinum, Corporate), and geographic region. Corporate and high-limit cards command premium prices ($20-$100+).

Fraud-as-a-Service: Turnkey fraud packages include phishing kits targeting specific banks, fraud tutorials, pre-configured anti-detect browsers with stolen cookies/fingerprints, residential proxy access, and money mule network access. These services democratize fraud, enabling low-skill operators to conduct sophisticated attacks.

Geographic Patterns: Major carding actor concentrations include Russia/CIS (card shop operators, malware developers), West Africa (BEC, romance fraud, money mules), Southeast Asia (scam compounds, pig butchering operations), and Western countries (SIM swapping, money mule recruitment). Fraud scam compounds in Myanmar, Cambodia, and Laos have drawn international attention for human trafficking elements.

Tooling

ToolCategoryUsage
Magecart skimmersData TheftJavaScript injections into e-commerce checkout pages
Anti-detect browsers (Multilogin, GoLogin)Fraud ToolingSpoof browser fingerprints to evade fraud detection
Residential proxies (911.re successors, various)InfrastructureMatch cardholder geolocation for CNP fraud
SMS interceptors / SS7 toolsAccount TakeoverIntercept 2FA codes for bank account takeover
Card checker servicesValidationVerify card validity before use
Infostealer logsData SupplyRedLine, Raccoon, Lumma output feeding card/credential markets
POS malware (various)Data TheftRAM scraping on point-of-sale terminals (declining)
E-commerce botsMonetizationAutomated checkout for rapid fraudulent purchases
Telegram botsMarketplaceAutomated card shops and checker services via Telegram
Cashout guides/tutorialsKnowledgeStep-by-step fraud methodology documentation

Intelligence Gaps

  • Scam compound scale: The true scale and financial impact of Southeast Asian scam compounds (pig butchering, investment fraud) is poorly quantified, though estimates suggest tens of billions in annual losses.
  • Synthetic identity fraud volume: The prevalence of synthetic identity fraud is difficult to measure because many losses are misclassified as credit losses rather than fraud losses by financial institutions.
  • Cryptocurrency intersection: The overlap between traditional carding/fraud operations and cryptocurrency-focused theft (exchange account takeover, DeFi exploitation) is not well-mapped.
  • Real-time card fraud attribution: Attributing specific card fraud transactions to specific card shop purchases or breach events remains extremely difficult for law enforcement and financial institutions.
  • Fraud-as-a-Service market size: The total revenue of FaaS platforms and their contribution to overall fraud losses is not well-estimated.

Sources & References

  1. Europol - "Internet Organised Crime Threat Assessment (IOCTA) 2024" — https://www.europol.europa.eu/iocta-report
  2. Gemini Advisory (Recorded Future) - "Card Fraud Intelligence Reports" — https://www.recordedfuture.com/
  3. FBI - "Operation Cookie Monster: Genesis Market Takedown" (April 2023) — https://www.fbi.gov/
  4. PCI Security Standards Council - "PCI DSS v4.0" — https://www.pcisecuritystandards.org/
  5. APWG - "Phishing Activity Trends Reports" — https://apwg.org/trendsreports/
  6. Group-IB - "Hi-Tech Crime Trends" reports — https://www.group-ib.com/resources/research/
  7. Flashpoint - "Financial Fraud Intelligence" — https://flashpoint.io/
  8. US Secret Service - Financial Crimes Investigations — https://www.secretservice.gov/investigation/financial-crimes

Change Log

DateChangeSource
2026-04-05Initial creation with baseline intelligence through early 2025Training knowledge

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.