Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Exploit.in: inside a Russian hacker forum, 2005 to 2008

Dancho DanchevBy Dancho DanchevSeptember 17, 2026Updated:September 17, 2026No Comments17 Mins Read30 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Exploit.in forum database 2005 to 2008, 9,647 members, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Exploit.in is a Russian-language hacker forum that opened in February 2005 and is still running in 2026, and it is one of the boards where ransomware crews go to hire. I have a copy of its database covering the forum from its first day, 18 February 2005, to the end of May 2008: 9,647 registered members, 13,925 threads and 80,891 posts across 35 sections. This is what the forum was before ransomware existed as a business, and how many of the people from that time are still around.

I was reading Russian-speaking forums in those years, and I have kept reading them since, so I had a fair idea of what the board would look like. The sections and the thread titles were about what I remembered. What I had not expected was how many of the members I would find again on the boards of the ransomware era, twenty years on.

What was on the front page of Exploit.in in 2005?

Start with the section list, because it tells you most of what you need. There is Вирусология, which the forum describes as “everything connected with the study, description and analysis of malicious code (bots/trojans/viruses), reversing, malware analysis in general.” There is Спам, рассылки, Киберсквоттинг, Криптография и приватность, Wardriving & Bluejacking, and a section offering vulnerability testing as a service.

Next to those, and I mean next to them in the same list, are АвтоМир for car and motorbike tuning and street racing, Юмор и Приколы for jokes, Игры, Музыка и Кино, a general flame section, a hardware section and a web design section.

The threads follow the sections. From the marketplace and hacking areas: “Покупаем загрузки” (we buy installs), “Создание и Аренда бот сетей” (creating and renting botnets), “Клонирование SIM-карт”, “Как угнать ICQ номер?” (how to steal an ICQ number), “Обнал через биллинги” (cashing out through billing systems), “продам шелл”, “Скрипт для спама на php”, and one titled simply “Дарю кредитки”, giving away credit cards, which sits near a competition thread offering the same thing as a prize. From the rest of the board: “Тюнинг Мазда”, “Мнения насчет Nokia 7370”, “Лучший производитель авто”, a thread on the computers used in Formula 1, one on internet radio, one asking for help with a damaged hard drive.

One section is called Сетевые пейджеры, network pagers, which in 2005 meant ICQ. A thread in it asks whether you need a five-digit number. Short ICQ numbers were a status item on these boards and they were also stock: the marketplace section’s own description lists “icq numbers, passwords, accesses, shells and a mass of other things” as what gets traded there.

Most writing about Russian cybercrime forums calls them marketplaces, and they were. What the writing tends to leave out is that they were also where a lot of teenagers went to talk about cars and phones. Both things happened in the same place with the same accounts, and nobody on the board seems to have found that strange.

The post counts bear that out. The moderators kept a recycle bin, and about 7,000 posts ended up in it. Of the 74,000 or so that did not, the eight sections the forum filed under hacking and security hold 20,314, which is 27%. The marketplace and its two reputation lists hold 11,168, and the three closed sections 7,220. The entertainment sections, meaning flame, games, humour, cars and the creative corner, hold 14,867 between them, and the software, hardware and mobile sections another 9,937, so a third of what got written on Exploit.in in those years was people talking about their kit and about each other. The biggest single section was the marketplace, at 10,377 posts, with security and hacking second at 7,224 and the flame board third at 6,772, ahead of anything behind a password.

Where the 80,891 posts went: the twelve busiest sections Buy, sell, trade, work Покупка/Продажа/Обмен/Работа 10,377 Security and hacking Безопасность и взлом 7,224 Flame Флейм, the general chat section 6,772 1st Access Level closed section, password on the door 5,536 Network pagers (ICQ) Сетевые пейджеры 4,012 Money Деньги 3,355 Games, music and film Игры, Музыка и Кино 3,282 Software Программы 3,089 Mobile devices Мобильные устройства 2,870 Humour and jokes Юмор и Приколы 2,680 Hardware Железо 1,887 Spam and mailings Спам, рассылки 1,851 Opening posts and replies per section, Feb 2005 to May 2008. Recycle bin (6,992 posts) left out. Source: topic table.

The threads themselves were short. Nearly half of them, 6,214 of the 13,870 with a post in them, got no reply at all. The median thread ran to two posts and the median post to 191 characters, two or three lines. The most viewed thread on the whole board sat in the marketplace and was called Смерть Барыгам, death to the profiteers, with 63,876 views and 334 replies. Behind it came a six-post thread listing where to find source code and exploits, viewed 43,373 times, a thread in the software section titled simply 1C, after the Russian accounting package, with 381 replies, and Заявки на взлом!, hacking requests, with 744. The most replied-to thread on the forum, at 1,077 replies, was an ICQ number giveaway.

What was behind the closed sections?

Two sections were gated, and the forum said on the door what was inside them. These are its own descriptions, translated:

1st Access Level: “[how do you get in?] First level of closed access. Posted in this section is private material, from proxy lists, credit cards, six-digit numbers and domains through to bank accounts and the rest.”

2nd Access Level: “[how do you get in?] Second access level. A private section, access to which the chosen have. Valuable and closed material is posted. Discussions that cannot be brought into public, or into the 1st.”

I have watched modern ransomware operations vet affiliates before they hand over a panel, and the process is not very different from this. The tiering was in place in 2005, on a stock installation of Invision Power Board, and the reward for climbing was advertised openly.

How did Exploit.in members decide who to trust?

There were no escrow services on the board in 2005. What there was instead were two sections:

Black List: “Here you can add all the dishonest people, rippers, and people who have deceived you.”

White List: “Here are placed honest people who can be trusted, and with whom you can calmly conduct financial business.”

That worked while the forum was small enough that a name meant something to everyone reading it. It stopped working once it was not. In the private message archives I hold from the modern Russian-language forums, the job has gone to paid intermediaries: on RAMP, the ransomware forum, 11.8% of conversations mention a guarantor or escrow, and on XSS it is 8.8%. I am not aware of anyone having measured that before, so treat the figure as a first estimate rather than a settled one.

Who was actually on the forum?

Here is the number I would put on a slide if I had one. Of 9,647 registered members, 5,843 never posted once. That is 60.6% of the whole forum. Another 15% posted exactly one time. Only 82 accounts ever got past 200 posts, and the top 1% of members wrote 52.6% of everything on the board.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

How much the 9,647 members actually posted Never posted 60.6% of members 5,843 Posted once 15.0% 1,450 2 to 9 posts 15.7% 1,514 10 to 49 posts 6.0% 574 50 to 199 posts 1.9% 184 200 or more 0.9% 82 The top 1% of members wrote 52.6% of all 72,290 counted posts. Source: member post counters.

I mention the 60% because it explains something people ask me about takedowns. A forum with ten thousand members sounds like a large thing to disrupt. In practice the forum was about ninety people who posted and several thousand who read, and ninety people can register somewhere else in an afternoon. I saw that happen after the Verified takedowns and I expect to see it again.

Registrations came in at 1,534 in 2005, 2,597 in 2006, 2,958 in 2007 and 2,558 in the first five months of 2008, and the posting grew faster than the membership did: 10,939 posts in 2005, 20,956 in 2006 and 33,036 in 2007, with the busiest month of the board’s life in March 2007, at 4,949. The owner is member number 1, registered on the first day, and he is also the most prolific poster on the forum at 2,065 posts. Four moderators sit below him with between 1,100 and 1,451 posts each. 219 accounts, 2.3%, ended up in the banned group.

Posts per month, February 2005 to May 2008 2005 2,066 0 2006 2007 4,949 212 2008 3,703 80,891 posts by month (UTC). Two silences: 69 days from 11 Dec 2005, 44 days from 13 Aug 2007. Source: post table.

The board went dark twice. Nothing was posted for 69 days from 11 December 2005, and again for 44 days from 13 August 2007, and registrations stopped at the same time in both cases, one new account in the first gap and none in the second, against several a day either side. So these were outages rather than holes in the copy. The database does not record why.

The clock on the posts says something about who these people were. Posting starts to climb at about nine in the morning Moscow time, holds through the afternoon and peaks at ten at night: 5,517 posts were written in the 22:00 hour over the life of the board, against 852 in the 05:00 hour. Weekends run about 8% quieter than weekdays. That is the rhythm of people with school or a job in the daytime and the forum in the evening, which fits the section list.

When the forum was awake: posts by hour, Moscow time 00 03 852 06 09 12 15 18 21 5,517 80,891 posts, February 2005 to May 2008, by hour written, shifted to UTC+3. Busiest hour 22:00 (5,517 posts), quietest 05:00 (852).

Whose name is in the smallest member group?

The member groups are what you would expect on an IPB board: administrators, ordinary users, pending, banned. One group has eight members in it out of 9,647. Among the eight is an account registered on 20 March 2007 under the handle AbdAllah, with 77 posts to its name.

“AbdAllah” is a documented alias of Mykhaylo Sergiyovich Rytikov, the Odessa bulletproof hosting provider on the United States Secret Service’s most wanted list, which gives the handle alongside “Abdulla,” “Boss” and “Rasul.” Prosecutors describe him as having supplied server infrastructure to the ring behind one of the largest payment card breaches ever charged in the US, and as having hosted the servers used to check whether stolen cards were still live.

I need to say clearly what that is. It is a handle match in a leaked database, in the most restricted group on the forum, with a registration date that fits what is publicly known about his activity. It is not proof that the account belongs to him, and I have no way of getting that proof. Rytikov has never been extradited and has not stood trial on the charges. There is a second account in the same dataset, registered a month earlier and with eight posts, under a handle later used by the person who ran the Lampeduza carding forum. Same caveat applies.

Are the 2005 members still active on hacker forums today?

Looking for the well-known names gets you nowhere. None of the handles I associate with Trickbot, Conti or REvil are in the member list, and there is no reason they would be, since this copy of the forum stops in 2008 and those operations came years later. So I ran the test the other way round.

I have been pulling offline copies of forum communities for three years, and I hold private message archives from five later boards, including XSS, RAMP and BreachForums, covering roughly 34,600 correspondents between them. I took the full 2005 to 2008 Exploit membership and checked each handle against those archives.

1,164 of the 9,647 turn up in at least one of the later archives. 310 turn up on XSS, RAMP or BreachForums specifically, which are the boards of the ransomware and data-extortion period.

Handles repeat across forums for boring reasons, so I stripped the generic ones, anything like system or mafia or smith that two unrelated people would plausibly both choose. That leaves 205 distinctive handles present in both periods. Of those, 26 had twenty or more posts on Exploit, so they were active members rather than dormant registrations, and 13 had over a hundred. The most active of them was forum staff in 2005 with 1,451 posts, and the same handle appears in two of the modern archives.

Exploit.in members of 2005 to 2008 still present on later forums All members, 2005 to 2008 the starting population 9,647 Handle seen in any later archive Verified, Carder Pro, XSS, RAMP, BreachForums 1,164 Seen on XSS, RAMP or BreachForums the ransomware and data-extortion era boards 310 Distinctive handle only generic handles removed 205 and 20+ posts on Exploit active members, not dormant registrations 26 and 100+ posts on Exploit the core of the 2005 forum 13 Handle matches only. Each figure is a ceiling: a shared handle is not proof of a shared person.

I am not publishing those handles. They belong to people who have not been charged with anything, and printing a line from a 2005 account to a 2026 forum presence would mostly serve whoever is trying to identify them. The number is what I can stand behind, and even the number is a ceiling, because a shared handle is not the same as a shared person.

What does this say about the ransomware ecosystem?

The usual story about Russian cybercrime is that it churns. Crews form, get indicted, rebrand and vanish, and a younger set replaces them. The enforcement record makes it look that way because the names that reach the public are the names that got caught.

What this database suggests is that there is a layer underneath the churn that does not move much. A couple of hundred people who were on a Russian hacking board in 2005, when the trade was stolen ICQ numbers and pay-per-install, are still on the boards in the ransomware era. They were not the famous ones then and they are not the famous ones now, and I suspect that is the reason they are still here. Twenty years of arrests took the people at the top and mostly left the rest.

The forum’s own machinery survived along with them. The reputation lists turned into escrow services, the access tiers turned into affiliate vetting, and the section that sold shells and accesses turned into what we now call the initial access market. I do not think the ransomware-as-a-service model would look unfamiliar to anyone who was on Exploit in 2006. The scale is different. The design is not.

Method, and what I am not publishing

The source is an Invision Power Board database dump of Exploit.IN. The member table has 9,647 rows, the topic table 13,925 and the post table 80,891, with the first post on 24 February 2005 and the last on 30 May 2008. Posts and new registrations both stop at the end of May 2008, apart from three accounts created that winter, so this is the record of the forum’s first three years and three months rather than its whole history. Exploit.in itself carried on and is running today. The members’ own post counters add up to 72,290 rather than 80,891 because the forum did not count posts in the flame and humour sections, or in the first closed section, towards a member’s total; I use the counters for the member statistics, the post table for timing and the topic table for the section figures. Hours are shifted to UTC+3 throughout. Russia ran on UTC+4 in the summer months in those years, so summer posts sit an hour earlier on the chart than they did on the poster’s clock. A spreadsheet that circulates with the dump, labelled as a March 2010 member list, turned out to be the same 9,647 rows exported again rather than a later snapshot. I checked by comparing every name in both files.

The comparison against later forums uses the private message archives I collect for this work, the same material I use to find interview subjects. Matching is on handle alone. That is why the generic handles are excluded and why I give the result as an upper bound.

What appears in this article is section names, the forum’s own descriptions of them, thread titles, aggregate member figures, and two handles already published by US law enforcement. What does not appear, and will not, is the member table itself. It holds email addresses, IP addresses and password hashes for 9,647 people, most of whom were kids arguing about Nokia handsets, and most of whom were never accused of anything.

Frequently asked questions

What is Exploit.in?

Exploit.in is a Russian-language hacker and cybercrime forum that opened in February 2005 and is still active in 2026. It began as a mixed hobby and hacking board and is now one of the main venues where ransomware operations recruit affiliates and buy network access.

How many members did Exploit.in have in its early years?

The database covering February 2005 to May 2008 contains 9,647 registered members, 13,925 threads and 80,891 posts. Of the members, 60.6% never posted, 15% posted once, and the top 1% wrote 52.6% of all posts on the forum.

What did Exploit.in sell in 2005?

Its marketplace section listed ICQ numbers, passwords, server accesses and web shells, and its gated sections advertised proxy lists, credit cards, six-digit ICQ numbers, domains and bank accounts. Threads also offered malware installs, botnet rental and spam scripts.

Are early Exploit.in members still active on cybercrime forums?

Yes, in measurable numbers. Matching the 2005 to 2008 member list against private message archives from XSS, RAMP and BreachForums finds 205 distinctive handles present in both periods, 26 of them with twenty or more posts on the original forum. The figure is an upper bound because a shared handle does not prove a shared person.

Who is AbdAllah on Exploit.in?

An account registered in March 2007 with 77 posts, in a member group of only eight people. “AbdAllah” is a documented alias of Mykhaylo Rytikov, a Ukrainian bulletproof hosting provider wanted by the US Secret Service. The match is on handle only and is not proof the account was his.

Does the Exploit.in database contain personal information?

Yes. The member table holds email addresses, IP addresses and password hashes for 9,647 people. Ransomnews has published only aggregate figures, section names and thread titles from it, and no individual member data.

Sources and further reading

  • United States Secret Service, Most Wanted: Mykhaylo Sergiyovich Rytikov, listing “AbdAllah” among his aliases.
  • Brian Krebs, “Meet the World’s Biggest ‘Bulletproof’ Hoster,” KrebsOnSecurity, July 2019.
  • Related reading on Ransomnews: inside the Verified.ru forum archive, 2005 to 2010, an RTM Locker representative on the RaaS market, and the threat-group catalogue.
  • Forum section descriptions and thread titles are translated from the Russian originals in the database. Aggregate figures are computed directly from the member, topic and post tables and can be reproduced from the same dump.

This analysis is part of the Ransomnews cybercrime desk’s work on the history of the underground economy. Handle matches are stated as handle matches. No individual member of this forum is identified beyond aliases already published by law enforcement.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous Articlesourcec0de interview: a ransomware operator on why he won’t stop
Dancho Danchev
  • LinkedIn

Dancho Danchev is a Bulgarian threat intelligence researcher who has spent more than two decades tracking cybercrime, malware campaigns, and the infrastructure behind the criminal underground. His research covers botnets, including Koobface, exploit kits, blackhat SEO, scareware, and large-scale domain abuse, with a focus on OSINT work that maps campaigns back to the operators running them. He has published through ZDNet Zero Day, Webroot, GroupSense, and WhoisXML API, and has run his own cybercrime research blog since the early 2000s.

Related Posts

Telegram 120M leak: we counted 63M, most from 2020

September 8, 2026

Condé Nast: 32.8M user records for sale, sample verified

September 7, 2026

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,604 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.