AlienVault has uncovered a criminal underground store dedicated to selling access to hacked (rooted) servers. Customers can buy an administrator (root) account in a hacked server, and then perpetrate criminal activities from it, distribute malware, install a botnet command & control infrastructure, upload illegal content, send spam, and so on.
At the time of investigation, the outlet had 13 rooted servers to be sold, with different prices, locations and technical details. Furthermore, the site is gaining a loyal customer base.
"The store seems to be quite profitable," said Alberto Ortega, security researcher at AlienVault, in a blog. "The domain was registered on 07 April 2013 and the store website was probably made available some days after that. At the time of this research, they had around 400 customers, increasing day by day."
At first, the site accepted Liberty Reserve for the payments, but since that hub was shut down, it accepts Perfect Money and WebMoney. It also has a sister store for selling hacked PayPal accounts and credit cards, hosted in the same server.