logo svg
logo

August 24, 2026

Updated: August 24, 2026

What Is STYX Market? The Financial-Fraud Marketplace Explained

Inside the dark web platform that sells financial crime as a product, from the stolen credential to the laundered cash.

Abdalla Mohamed

Featured Image

STYX Market is a dark web marketplace built for one purpose: financial crime. Documented by the threat-intelligence firm Resecurity in 2023, it specializes in money laundering, identity theft, and fraud, selling stolen bank logins, card data, cash-out services, fake IDs, banking malware, and the tools criminals use to bypass two-factor authentication. It is not a general contraband bazaar; it is a purpose-built "fraud-as-a-service" platform. This guide explains what STYX Market is, everything it sells, how its operating model works, where it sits in the wider fraud economy, and, most importantly, how banks, businesses, and individuals can defend against it.

Updated: August 2026. A defensive, threat-intelligence and law-enforcement overview for security teams, financial institutions, and consumers. It contains no marketplace addresses, login pages, or access instructions, and does not endorse or assist any illegal activity.

The quick answer

Here is the whole picture in one table; the rest of this guide expands each row.

QuestionShort answer
What is it?A dark web marketplace specializing in financial fraud, laundering, and identity theft
Who found it?Resecurity, which published the defining report in April 2023
When did it launch?January 19, 2023, after mentions surfaced in 2022
What does it sell?Bank logins, card data, cash-out, fake IDs, SIM cards, DDoS, 2FA-bypass tools, banking malware
What is its model?Fraud-as-a-service, with escrow, vetted "Trusted Sellers," and Telegram bots
Is using it legal?No. Buying or using stolen data for fraud, unauthorized access, or laundering is illegal; exact offenses vary by jurisdiction
Is it a scam?It is a real marketplace, but engaging with it risks crime charges, phishing, and being scammed

The one line to remember: STYX Market packages financial crime as a product, from the stolen credential to the laundered cash.

What is STYX Market?

STYX Market is a specialized dark web marketplace focused on the money side of cybercrime. Where a market like BriansClub sold raw card data and Russian Market sells infostealer logs, STYX bundles the full financial-fraud toolkit: the stolen accounts, the malware and bots to abuse them, the fake documents to defeat identity checks, and the cash-out and laundering services to turn the proceeds into clean money. It was uncovered and named by Resecurity, whose April 2023 report remains the authoritative account.

It belongs to the ecosystem we map in our top dark web marketplaces roundup, and like other hidden services it operates over anonymity networks, explained in dark web vs darknet vs Tor. What sets STYX apart is its focus: it is a one-stop shop for financial fraud, organized like a real e-commerce platform.

Is STYX the same as River Styx Market? A quick disambiguation

Because searches for "Styx Market" collide with a real business, it is worth stating plainly: the two are unrelated.

NameWhat it is
STYX Market (this article)A dark web financial-fraud marketplace
River Styx MarketA legitimate grocery store in River Styx, Ohio

If your search was about photos, reviews, or opening hours, you want the Ohio grocery store, not this. Everything below concerns the criminal marketplace only.

A short history of STYX Market

STYX did not appear overnight. Resecurity's analysts traced its development through the underground before it opened its doors.

DateEvent
Early 2022Earliest dark web mentions of the project in development
~January 2023STYX Market goes operational
April 2023Resecurity publishes its report; wide press coverage follows
2023 to 2024Continues to be tracked as a specialized financial-fraud marketplace
2025 to 2026No confirmed public takedown was found in credible reporting reviewed for this update; live status should still be treated cautiously

The timing was favorable to STYX's positioning. It launched as older fraud and credential markets were being disrupted or retired, giving it room to market itself as a specialized platform for financial crime.

What STYX Market sells: the full catalog

STYX's inventory reads like a menu for every stage of a fraud operation. Here is the master list, grouped by function.

CategoryExamples on offer
Stolen financial dataCard data and dumps, compromised online banking credentials
Stolen accountsCryptocurrency exchange and e-commerce accounts
Fraud toolsOTP bots and 2FA/SMS bypass, banking malware and trojans
Attack servicesDDoS-for-hire
Identity productsFake and stolen ID documents
TelecomSIM cards
Cash-out"Clean" funds via PayPal and Apple Pay business accounts with merchant terminals
Money launderingIndividual and business laundering services

No single category is unique to STYX; what is notable is the completeness. A buyer can source a stolen login, a bot to break its 2FA, a fake ID to pass a verification check, and a laundering service to move the proceeds, all in one place. The next sections break down the clusters that matter most for defenders.

Stolen financial data and accounts

The raw material of the market is compromised financial access.

ProductWhat it enables
Card data / dumpsCard fraud, both online and counterfeit-card
Online banking credentialsDirect account takeover and transfers
Cryptocurrency accountsDraining exchange balances and wallets
E-commerce accountsFraudulent purchases, stored-card abuse, reputation laundering

This kind of data can originate upstream in infostealer infections, phishing, payment-card theft, and breaches, which is why STYX is best understood as a monetization layer sitting on top of the wider infostealer economy. Logs sold on credential markets such as Russian Market can feed the same downstream fraud ecosystem, although public reporting does not establish that every STYX listing originates there. For how this stolen data is priced across the underground, see our dark web data pricing breakdown.

Fraud tools and services

Beyond data, STYX sells the instruments that make the data usable.

The presence of these tools is what elevates STYX from a data shop to a fraud platform. It does not just sell you a stolen identity; it sells you the means to weaponize it.

How OTP bots defeat two-factor authentication

Of everything STYX sells, OTP-bypass tooling is especially important for defenders to understand because it targets a major control organizations rely on: two-factor authentication.

How an OTP bot bypasses two-factor authentication by relaying a one-time passcode

The mechanism, documented by researchers including Kaspersky and others, is social engineering wrapped in automation. It works like this:

  1. The attacker already has your username and password, typically from an infostealer log or phishing.
  2. They enter your credentials on the real site, which triggers a legitimate one-time passcode to your phone.
  3. A rented bot immediately calls you, posing as your bank's fraud or security desk, and asks you to confirm the code it just sent.
  4. You read the real code aloud; the bot relays it to the attacker in seconds, who completes the login.

A parallel technique, adversary-in-the-middle (AiTM) phishing, uses a proxy page to capture both the password and the live session token in real time. Either way, the SMS or voice one-time passcode, once considered strong, becomes a speed bump. These bots are sold like legitimate software, with pricing tiers, support channels, and refund policies for failed attempts. The defensive answer is not a better OTP; it is phishing-resistant authentication, covered in the defense sections below.

Money laundering and cash-out

The final stage of any fraud is turning stolen value into spendable money, and laundering is one of STYX's specialities.

ServiceHow it works
Cash-out shopsMove stolen funds through PayPal and Apple Pay business accounts with merchant terminals to produce "clean" money
Individual launderingOffered from around $15,000 per engagement
Business launderingHigher-tier services for larger volumes
Mule networksRecruited individuals move funds between accounts to break the trail

Money mules are the human infrastructure of this stage. Criminals recruit people, often through fake job offers or romance scams, to receive and forward illicit funds, obscuring the path back to the fraud. Law-enforcement and financial-crime agencies routinely warn about mule recruitment through fake jobs, romance scams, and other social-engineering schemes, while instant payment rails can make stolen funds harder to stop once they begin moving. Understanding this stage matters because it is where fraud becomes traceable, and therefore where a lot of detection and law enforcement focuses.

How STYX Market operates: the fraud-as-a-service model

STYX is notable less for what it sells than for how professionally it sells it. Resecurity documented an operating model that mirrors legitimate e-commerce.

This is the real story of STYX: the platformization of fraud. It applies the conveniences of modern commerce, escrow, reviews, support, curation, to crime, lowering the skill barrier so that buyers without technical ability can still commit sophisticated fraud.

Fraud-as-a-service: why the model matters

Fraud-as-a-service why the model matters

The "as-a-service" shift is the reason markets like STYX are dangerous out of proportion to their size. In the old model, a fraudster needed technical skill to steal data, write malware, and launder money. STYX unbundles those steps and sells each as a service, so the buyer only needs money and intent.

Old fraud modelFraud-as-a-service (STYX-style)
One actor with broad technical skillMany buyers renting specialist services
Steal your own dataBuy stolen data on demand
Build your own toolsRent OTP bots and malware
Launder your own proceedsHire a cash-out service
High skill barrierLow skill barrier, high volume

The consequence for defenders is scale: the pool of people capable of attacking your customers expands from skilled criminals to anyone with a crypto balance. This is the same dynamic driving ransomware-as-a-service, applied to financial fraud.

Where STYX fits in the fraud supply chain

STYX does not operate alone; it is one link in a chain that starts with a malware infection and ends with laundered cash.

  1. Harvest. Infostealer malware collects credentials, cookies, and card data from infected devices.
  2. Wholesale. Log markets like Russian Market sell those raw logs in bulk.
  3. Tooling and monetization. STYX supplies the OTP bots, banking malware, fake IDs, and stolen accounts needed to exploit them.
  4. Cash-out. STYX's laundering and cash-out services convert the proceeds into clean money.

Seeing the whole chain is what makes defense possible: you can break it at the harvest stage (stop the infostealer), at the exploitation stage (defeat the OTP bot with phishing-resistant MFA), or at the cash-out stage (fraud and mule detection). STYX is strongest in the middle and end of that chain, which is exactly where financial institutions and their customers feel it.

STYX Market vs other fraud markets

STYX is best understood by contrast with the markets it succeeded and sits beside.

MarketSpecialtyStatus
Genesis MarketBots with browser fingerprints for impersonationSeized 2023
BriansClubMagnetic-stripe card dumpsContested, magstripe era declining
Russian MarketInfostealer logs (credentials, cookies)Active
STYX MarketEnd-to-end financial fraud, tools, and launderingReported active

We track the takedowns of the older markets in dark web marketplace takedowns. STYX represents the current stage of this evolution: not a single-product shop, but a full-service financial-crime platform.

Is STYX Market real or fake?

This is a common search, and the honest answer has two parts.

First, STYX is a real, functioning marketplace, not a fictional bogeyman. Resecurity's research documented a live platform with real vendors, escrow, and services. So "is it real" is, unfortunately, yes.

Second, and more important, that does not make it safe to touch:

So the safe answer to "real or fake" is: real enough to hurt you, and not worth going near.

Who is at risk from STYX Market

The harm from a market like STYX lands on several groups at once.

WhoHow they are exposed
ConsumersAccount takeover, identity theft, drained bank and crypto accounts
Banks and fintechsFraud losses, OTP-bypass attacks on customers, mule accounts
E-commerce and merchantsStolen-account purchases, chargebacks, cash-out abuse
Businesses generallyBusiness email compromise, invoice fraud, laundering through their rails

The common thread is that STYX turns a security failure somewhere upstream, a phished employee, an infected customer device, a weak authentication flow, into direct financial loss. That is why defense has to span the whole chain.

How to defend against STYX-driven fraud: consumers

You cannot shut down STYX, but you can make its products fail against you.

How to defend against STYX-driven fraud: banks and enterprises

For financial institutions and any business handling accounts or payments, the goal is to neutralize the tools STYX sells.

ControlWhat it defeats
Phishing-resistant MFA (FIDO2/passkeys) for staff and high-risk flowsOTP bots, AiTM phishing, MFA fatigue
Move away from SMS/voice OTP where possibleSIM-swap and OTP-relay attacks
Device binding and step-up authenticationSession hijacking and impossible-travel logins
Behavioral and transaction fraud monitoringCash-out patterns, mule-account movement
Strong KYC/KYB and document verificationFake and stolen ID documents
Stealer-log and dark-web monitoring for your customers and brandCompromised credentials before they are abused
Segmentation and regular penetration testing of auth and payment flowsThe technical gaps fraud tools exploit

Regulators increasingly require stronger authentication in defined contexts. PCI DSS and NYDFS both include MFA requirements for covered access scenarios, although they do not universally mandate FIDO2 or passkeys. Phishing-resistant MFA is the stronger defensive choice where it is practical. When an incident does occur, a tested incident response plan determines how much damage it causes.

Warning signs of STYX-style fraud in progress

Because the tools STYX sells follow predictable patterns, the attacks they power leave recognizable signs. Knowing them helps both individuals and fraud teams catch an attack mid-flight.

For individuals, treat these as immediate red flags:

For fraud and security teams, the telltale patterns are different:

SignalWhat it may indicate
Bursts of OTP requests followed by successful loginsOTP-bot or AiTM relay in progress
Logins from new devices immediately after a password resetCredential stuffing from stealer logs
New payees or transfers to first-seen accountsMule-network cash-out
Rapid small transactions testing many cardsCard validation ("carding")
Account changes (email, phone) before a large transferTakeover hardening before theft

The point is not to memorize a criminal script but to instrument for its footprints. Detection at any one of these moments can stop the fraud before the cash-out stage, which is the hardest to reverse.

A fraud-readiness checklist for financial institutions

For banks, fintechs, and any business that moves money, resilience against a market like STYX comes down to a repeatable set of controls. Use this as a starting checklist.

AreaQuestion to answer
AuthenticationHave we replaced SMS OTP with phishing-resistant MFA for staff and high-risk customer actions?
Session securityDo we bind sessions to devices and force step-up auth on risky actions?
Identity proofingCan our KYC/KYB detect the fake and stolen documents sold on these markets?
Transaction monitoringDo our models flag mule-movement and cash-out patterns in real time?
Exposure monitoringAre we watching stealer-log and dark-web sources for our customers' leaked credentials?
Customer educationDo customers know we will never ask them to read back a one-time code?
TestingHave we penetration tested the authentication and payment flows on an appropriate risk-based cadence and after material changes?

Each unanswered question is an opening the fraud-as-a-service economy is built to exploit. The institutions that fare best treat this as continuous validation, not an annual box-check.

Why this matters for security teams

STYX Market is a snapshot of where cybercrime is heading: specialized, productized, and low-barrier. The attacker draining your customer's account may have no technical skill at all; they simply assembled a fraud from parts bought on a platform. Defending against that means assuming your credentials are already for sale somewhere and asking whether your controls survive the tools that abuse them. Our dark web statistics roundup shows how much stolen financial data circulates and how quickly.

That reality is why testing has to model a real, well-equipped fraudster, not a hypothetical one. DeepStrike's penetration testing is manual-first and adversary-realistic: our team probes the authentication and payment paths that OTP bots, stolen accounts, and banking malware target, validates whether your MFA and fraud controls actually hold, and delivers the concrete fixes before your customers' data funds someone's cash-out. For US-based organizations, see our US penetration testing services.

FAQ

What is STYX Market on the dark web?

STYX Market is a dark web marketplace specializing in financial fraud, money laundering, and identity theft. Discovered by Resecurity in 2023, it sells stolen bank logins and card data, fake IDs, SIM cards, banking malware, DDoS-for-hire, 2FA-bypass tools, and cash-out and laundering services, essentially a full toolkit for financial crime.

Is STYX Market the same as River Styx Market?

No. This article is about the dark web financial-fraud marketplace named STYX. River Styx Market is an unrelated, legitimate grocery store in River Styx, Ohio. If you were searching for the store's hours, photos, or reviews, that is a different business with no connection to cybercrime.

What does STYX Market sell?

STYX sells stolen financial data (card data, bank logins), compromised crypto and e-commerce accounts, fake and stolen ID documents, SIM cards, banking malware, DDoS-for-hire, OTP bots that bypass two-factor authentication, and money-laundering and cash-out services that convert stolen funds into clean money.

When did STYX Market launch and who discovered it?

STYX opened on January 19, 2023, after Resecurity analysts had observed mentions of the project during 2022. Resecurity published the defining report on the marketplace in April 2023, which remains the authoritative source for its structure and offerings.

Is STYX Market real or fake?

STYX is a real, functioning marketplace, not a myth. But that does not make it safe: everything on it is criminal, dark markets frequently scam their own buyers or exit-scam entirely, and fake mirrors are phishing traps. Legitimate researchers study it through controlled methods, never by casually accessing it.

How do OTP bots on markets like STYX bypass 2FA?

OTP bots exploit the human step in SMS or voice two-factor authentication. The attacker uses stolen credentials to trigger a real code, then a bot calls the victim posing as their bank and asks them to confirm it. The victim reads the code aloud, and the bot relays it to the attacker instantly.

How do criminals launder money through markets like STYX?

STYX offers cash-out shops that move stolen funds through PayPal and Apple Pay business accounts with merchant terminals, plus dedicated laundering services from around $15,000. Money mules, people recruited to receive and forward funds, break the trail, and cryptocurrency layering adds further distance from the original fraud.

How can I protect myself from the fraud STYX enables?

Use phishing-resistant MFA like passkeys, never read a one-time code to anyone who calls you, and refuse any arrangement that asks you to move money for others. Freeze your credit, enable transaction alerts, and report fraud through your bank and the FTC, not through any underground service.

Is STYX Market still active in 2026?

As of this writing, STYX is reported to remain active as a specialized financial-crime marketplace, with no confirmed law-enforcement takedown in credible reporting. That said, dark web markets are volatile, they change domains, get seized, or exit-scam without warning, so any external claim about its live status should be treated cautiously.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us