{
  "id": "case-genesis-market",
  "slug": "genesis-market-takedown-cookie-monster",
  "title": "Operation Cookie Monster (Genesis Market Takedown)",
  "summary": "Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
  "case_number": "Operation Cookie Monster",
  "court": "U.S. District Court for the Eastern District of Wisconsin",
  "district": "E.D. Wis.",
  "country": "United States",
  "opened_at": "2023-04-04",
  "status": "alleged",
  "victim_sector": "Consumer Accounts, Banking, E-Commerce",
  "victim_country": "United States, United Kingdom, European Union, Australia",
  "loss_amount_usd": 50000000,
  "loss_amount_note": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide.",
  "first_seen_at": "2018-01-01T00:00:00Z",
  "last_updated_at": "2026-09-02T13:00:00Z",
  "actor_slug": "genesis-market",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1555",
      "evidence_excerpt": "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.",
      "evidence_locator": "DOJ Seizure Affidavit \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Press Release 23-388",
      "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
      "technique_name": "Credentials from Password Stores",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.",
      "evidence_locator": "DOJ Seizure Affidavit \u00b6 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Seizure Notice",
      "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "court_order",
      "event_date": "2023-04-04",
      "description": "FBI and 17 international partner agencies seize 11 domains hosting the Genesis Market infrastructure."
    },
    {
      "event_type": "arrest",
      "event_date": "2023-04-05",
      "description": "Over 120 arrests executed globally against Genesis Market high-volume purchasers."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Accounts, Banking, E-Commerce networks. Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
    "blast_radius": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide. Impacted Consumer Accounts, Banking, E-Commerce infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 2: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.",
        "technical_artifacts": [
          "T1555",
          "Credentials from Password Stores"
        ],
        "mitre_technique_id": "T1555"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}