Exploit.in is a Russian-language hacker forum that opened in February 2005 and is still running in 2026, and it is one of the boards where ransomware crews go to hire. I have a copy of its database covering the forum from its first day, 18 February 2005, to the end of May 2008: 9,647 registered members, 13,925 threads and 80,891 posts across 35 sections. This is what the forum was before ransomware existed as a business, and how many of the people from that time are still around.
I was reading Russian-speaking forums in those years, and I have kept reading them since, so I had a fair idea of what the board would look like. The sections and the thread titles were about what I remembered. What I had not expected was how many of the members I would find again on the boards of the ransomware era, twenty years on.
What was on the front page of Exploit.in in 2005?
Start with the section list, because it tells you most of what you need. There is Вирусология, which the forum describes as “everything connected with the study, description and analysis of malicious code (bots/trojans/viruses), reversing, malware analysis in general.” There is Спам, рассылки, Киберсквоттинг, Криптография и приватность, Wardriving & Bluejacking, and a section offering vulnerability testing as a service.
Next to those, and I mean next to them in the same list, are АвтоМир for car and motorbike tuning and street racing, Юмор и Приколы for jokes, Игры, Музыка и Кино, a general flame section, a hardware section and a web design section.
The threads follow the sections. From the marketplace and hacking areas: “Покупаем загрузки” (we buy installs), “Создание и Аренда бот сетей” (creating and renting botnets), “Клонирование SIM-карт”, “Как угнать ICQ номер?” (how to steal an ICQ number), “Обнал через биллинги” (cashing out through billing systems), “продам шелл”, “Скрипт для спама на php”, and one titled simply “Дарю кредитки”, giving away credit cards, which sits near a competition thread offering the same thing as a prize. From the rest of the board: “Тюнинг Мазда”, “Мнения насчет Nokia 7370”, “Лучший производитель авто”, a thread on the computers used in Formula 1, one on internet radio, one asking for help with a damaged hard drive.
One section is called Сетевые пейджеры, network pagers, which in 2005 meant ICQ. A thread in it asks whether you need a five-digit number. Short ICQ numbers were a status item on these boards and they were also stock: the marketplace section’s own description lists “icq numbers, passwords, accesses, shells and a mass of other things” as what gets traded there.
Most writing about Russian cybercrime forums calls them marketplaces, and they were. What the writing tends to leave out is that they were also where a lot of teenagers went to talk about cars and phones. Both things happened in the same place with the same accounts, and nobody on the board seems to have found that strange.
The post counts bear that out. The moderators kept a recycle bin, and about 7,000 posts ended up in it. Of the 74,000 or so that did not, the eight sections the forum filed under hacking and security hold 20,314, which is 27%. The marketplace and its two reputation lists hold 11,168, and the three closed sections 7,220. The entertainment sections, meaning flame, games, humour, cars and the creative corner, hold 14,867 between them, and the software, hardware and mobile sections another 9,937, so a third of what got written on Exploit.in in those years was people talking about their kit and about each other. The biggest single section was the marketplace, at 10,377 posts, with security and hacking second at 7,224 and the flame board third at 6,772, ahead of anything behind a password.
The threads themselves were short. Nearly half of them, 6,214 of the 13,870 with a post in them, got no reply at all. The median thread ran to two posts and the median post to 191 characters, two or three lines. The most viewed thread on the whole board sat in the marketplace and was called Смерть Барыгам, death to the profiteers, with 63,876 views and 334 replies. Behind it came a six-post thread listing where to find source code and exploits, viewed 43,373 times, a thread in the software section titled simply 1C, after the Russian accounting package, with 381 replies, and Заявки на взлом!, hacking requests, with 744. The most replied-to thread on the forum, at 1,077 replies, was an ICQ number giveaway.
What was behind the closed sections?
Two sections were gated, and the forum said on the door what was inside them. These are its own descriptions, translated:
1st Access Level: “[how do you get in?] First level of closed access. Posted in this section is private material, from proxy lists, credit cards, six-digit numbers and domains through to bank accounts and the rest.”
2nd Access Level: “[how do you get in?] Second access level. A private section, access to which the chosen have. Valuable and closed material is posted. Discussions that cannot be brought into public, or into the 1st.”
I have watched modern ransomware operations vet affiliates before they hand over a panel, and the process is not very different from this. The tiering was in place in 2005, on a stock installation of Invision Power Board, and the reward for climbing was advertised openly.
How did Exploit.in members decide who to trust?
There were no escrow services on the board in 2005. What there was instead were two sections:
Black List: “Here you can add all the dishonest people, rippers, and people who have deceived you.”
White List: “Here are placed honest people who can be trusted, and with whom you can calmly conduct financial business.”
That worked while the forum was small enough that a name meant something to everyone reading it. It stopped working once it was not. In the private message archives I hold from the modern Russian-language forums, the job has gone to paid intermediaries: on RAMP, the ransomware forum, 11.8% of conversations mention a guarantor or escrow, and on XSS it is 8.8%. I am not aware of anyone having measured that before, so treat the figure as a first estimate rather than a settled one.
Who was actually on the forum?
Here is the number I would put on a slide if I had one. Of 9,647 registered members, 5,843 never posted once. That is 60.6% of the whole forum. Another 15% posted exactly one time. Only 82 accounts ever got past 200 posts, and the top 1% of members wrote 52.6% of everything on the board.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
I mention the 60% because it explains something people ask me about takedowns. A forum with ten thousand members sounds like a large thing to disrupt. In practice the forum was about ninety people who posted and several thousand who read, and ninety people can register somewhere else in an afternoon. I saw that happen after the Verified takedowns and I expect to see it again.
Registrations came in at 1,534 in 2005, 2,597 in 2006, 2,958 in 2007 and 2,558 in the first five months of 2008, and the posting grew faster than the membership did: 10,939 posts in 2005, 20,956 in 2006 and 33,036 in 2007, with the busiest month of the board’s life in March 2007, at 4,949. The owner is member number 1, registered on the first day, and he is also the most prolific poster on the forum at 2,065 posts. Four moderators sit below him with between 1,100 and 1,451 posts each. 219 accounts, 2.3%, ended up in the banned group.
The board went dark twice. Nothing was posted for 69 days from 11 December 2005, and again for 44 days from 13 August 2007, and registrations stopped at the same time in both cases, one new account in the first gap and none in the second, against several a day either side. So these were outages rather than holes in the copy. The database does not record why.
The clock on the posts says something about who these people were. Posting starts to climb at about nine in the morning Moscow time, holds through the afternoon and peaks at ten at night: 5,517 posts were written in the 22:00 hour over the life of the board, against 852 in the 05:00 hour. Weekends run about 8% quieter than weekdays. That is the rhythm of people with school or a job in the daytime and the forum in the evening, which fits the section list.
Whose name is in the smallest member group?
The member groups are what you would expect on an IPB board: administrators, ordinary users, pending, banned. One group has eight members in it out of 9,647. Among the eight is an account registered on 20 March 2007 under the handle AbdAllah, with 77 posts to its name.
“AbdAllah” is a documented alias of Mykhaylo Sergiyovich Rytikov, the Odessa bulletproof hosting provider on the United States Secret Service’s most wanted list, which gives the handle alongside “Abdulla,” “Boss” and “Rasul.” Prosecutors describe him as having supplied server infrastructure to the ring behind one of the largest payment card breaches ever charged in the US, and as having hosted the servers used to check whether stolen cards were still live.
I need to say clearly what that is. It is a handle match in a leaked database, in the most restricted group on the forum, with a registration date that fits what is publicly known about his activity. It is not proof that the account belongs to him, and I have no way of getting that proof. Rytikov has never been extradited and has not stood trial on the charges. There is a second account in the same dataset, registered a month earlier and with eight posts, under a handle later used by the person who ran the Lampeduza carding forum. Same caveat applies.
Are the 2005 members still active on hacker forums today?
Looking for the well-known names gets you nowhere. None of the handles I associate with Trickbot, Conti or REvil are in the member list, and there is no reason they would be, since this copy of the forum stops in 2008 and those operations came years later. So I ran the test the other way round.
I have been pulling offline copies of forum communities for three years, and I hold private message archives from five later boards, including XSS, RAMP and BreachForums, covering roughly 34,600 correspondents between them. I took the full 2005 to 2008 Exploit membership and checked each handle against those archives.
1,164 of the 9,647 turn up in at least one of the later archives. 310 turn up on XSS, RAMP or BreachForums specifically, which are the boards of the ransomware and data-extortion period.
Handles repeat across forums for boring reasons, so I stripped the generic ones, anything like system or mafia or smith that two unrelated people would plausibly both choose. That leaves 205 distinctive handles present in both periods. Of those, 26 had twenty or more posts on Exploit, so they were active members rather than dormant registrations, and 13 had over a hundred. The most active of them was forum staff in 2005 with 1,451 posts, and the same handle appears in two of the modern archives.
I am not publishing those handles. They belong to people who have not been charged with anything, and printing a line from a 2005 account to a 2026 forum presence would mostly serve whoever is trying to identify them. The number is what I can stand behind, and even the number is a ceiling, because a shared handle is not the same as a shared person.
What does this say about the ransomware ecosystem?
The usual story about Russian cybercrime is that it churns. Crews form, get indicted, rebrand and vanish, and a younger set replaces them. The enforcement record makes it look that way because the names that reach the public are the names that got caught.
What this database suggests is that there is a layer underneath the churn that does not move much. A couple of hundred people who were on a Russian hacking board in 2005, when the trade was stolen ICQ numbers and pay-per-install, are still on the boards in the ransomware era. They were not the famous ones then and they are not the famous ones now, and I suspect that is the reason they are still here. Twenty years of arrests took the people at the top and mostly left the rest.
The forum’s own machinery survived along with them. The reputation lists turned into escrow services, the access tiers turned into affiliate vetting, and the section that sold shells and accesses turned into what we now call the initial access market. I do not think the ransomware-as-a-service model would look unfamiliar to anyone who was on Exploit in 2006. The scale is different. The design is not.
Method, and what I am not publishing
The source is an Invision Power Board database dump of Exploit.IN. The member table has 9,647 rows, the topic table 13,925 and the post table 80,891, with the first post on 24 February 2005 and the last on 30 May 2008. Posts and new registrations both stop at the end of May 2008, apart from three accounts created that winter, so this is the record of the forum’s first three years and three months rather than its whole history. Exploit.in itself carried on and is running today. The members’ own post counters add up to 72,290 rather than 80,891 because the forum did not count posts in the flame and humour sections, or in the first closed section, towards a member’s total; I use the counters for the member statistics, the post table for timing and the topic table for the section figures. Hours are shifted to UTC+3 throughout. Russia ran on UTC+4 in the summer months in those years, so summer posts sit an hour earlier on the chart than they did on the poster’s clock. A spreadsheet that circulates with the dump, labelled as a March 2010 member list, turned out to be the same 9,647 rows exported again rather than a later snapshot. I checked by comparing every name in both files.
The comparison against later forums uses the private message archives I collect for this work, the same material I use to find interview subjects. Matching is on handle alone. That is why the generic handles are excluded and why I give the result as an upper bound.
What appears in this article is section names, the forum’s own descriptions of them, thread titles, aggregate member figures, and two handles already published by US law enforcement. What does not appear, and will not, is the member table itself. It holds email addresses, IP addresses and password hashes for 9,647 people, most of whom were kids arguing about Nokia handsets, and most of whom were never accused of anything.
Frequently asked questions
What is Exploit.in?
Exploit.in is a Russian-language hacker and cybercrime forum that opened in February 2005 and is still active in 2026. It began as a mixed hobby and hacking board and is now one of the main venues where ransomware operations recruit affiliates and buy network access.
How many members did Exploit.in have in its early years?
The database covering February 2005 to May 2008 contains 9,647 registered members, 13,925 threads and 80,891 posts. Of the members, 60.6% never posted, 15% posted once, and the top 1% wrote 52.6% of all posts on the forum.
What did Exploit.in sell in 2005?
Its marketplace section listed ICQ numbers, passwords, server accesses and web shells, and its gated sections advertised proxy lists, credit cards, six-digit ICQ numbers, domains and bank accounts. Threads also offered malware installs, botnet rental and spam scripts.
Are early Exploit.in members still active on cybercrime forums?
Yes, in measurable numbers. Matching the 2005 to 2008 member list against private message archives from XSS, RAMP and BreachForums finds 205 distinctive handles present in both periods, 26 of them with twenty or more posts on the original forum. The figure is an upper bound because a shared handle does not prove a shared person.
Who is AbdAllah on Exploit.in?
An account registered in March 2007 with 77 posts, in a member group of only eight people. “AbdAllah” is a documented alias of Mykhaylo Rytikov, a Ukrainian bulletproof hosting provider wanted by the US Secret Service. The match is on handle only and is not proof the account was his.
Does the Exploit.in database contain personal information?
Yes. The member table holds email addresses, IP addresses and password hashes for 9,647 people. Ransomnews has published only aggregate figures, section names and thread titles from it, and no individual member data.
Sources and further reading
- United States Secret Service, Most Wanted: Mykhaylo Sergiyovich Rytikov, listing “AbdAllah” among his aliases.
- Brian Krebs, “Meet the World’s Biggest ‘Bulletproof’ Hoster,” KrebsOnSecurity, July 2019.
- Related reading on Ransomnews: inside the Verified.ru forum archive, 2005 to 2010, an RTM Locker representative on the RaaS market, and the threat-group catalogue.
- Forum section descriptions and thread titles are translated from the Russian originals in the database. Aggregate figures are computed directly from the member, topic and post tables and can be reproduced from the same dump.
This analysis is part of the Ransomnews cybercrime desk’s work on the history of the underground economy. Handle matches are stated as handle matches. No individual member of this forum is identified beyond aliases already published by law enforcement.
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
