August 24, 2026
Updated: August 24, 2026
Inside the dark web platform that sells financial crime as a product, from the stolen credential to the laundered cash.
Abdalla Mohamed

STYX Market is a dark web marketplace built for one purpose: financial crime. Documented by the threat-intelligence firm Resecurity in 2023, it specializes in money laundering, identity theft, and fraud, selling stolen bank logins, card data, cash-out services, fake IDs, banking malware, and the tools criminals use to bypass two-factor authentication. It is not a general contraband bazaar; it is a purpose-built "fraud-as-a-service" platform. This guide explains what STYX Market is, everything it sells, how its operating model works, where it sits in the wider fraud economy, and, most importantly, how banks, businesses, and individuals can defend against it.
Updated: August 2026. A defensive, threat-intelligence and law-enforcement overview for security teams, financial institutions, and consumers. It contains no marketplace addresses, login pages, or access instructions, and does not endorse or assist any illegal activity.
Here is the whole picture in one table; the rest of this guide expands each row.
| Question | Short answer |
|---|---|
| What is it? | A dark web marketplace specializing in financial fraud, laundering, and identity theft |
| Who found it? | Resecurity, which published the defining report in April 2023 |
| When did it launch? | January 19, 2023, after mentions surfaced in 2022 |
| What does it sell? | Bank logins, card data, cash-out, fake IDs, SIM cards, DDoS, 2FA-bypass tools, banking malware |
| What is its model? | Fraud-as-a-service, with escrow, vetted "Trusted Sellers," and Telegram bots |
| Is using it legal? | No. Buying or using stolen data for fraud, unauthorized access, or laundering is illegal; exact offenses vary by jurisdiction |
| Is it a scam? | It is a real marketplace, but engaging with it risks crime charges, phishing, and being scammed |
The one line to remember: STYX Market packages financial crime as a product, from the stolen credential to the laundered cash.
STYX Market is a specialized dark web marketplace focused on the money side of cybercrime. Where a market like BriansClub sold raw card data and Russian Market sells infostealer logs, STYX bundles the full financial-fraud toolkit: the stolen accounts, the malware and bots to abuse them, the fake documents to defeat identity checks, and the cash-out and laundering services to turn the proceeds into clean money. It was uncovered and named by Resecurity, whose April 2023 report remains the authoritative account.
It belongs to the ecosystem we map in our top dark web marketplaces roundup, and like other hidden services it operates over anonymity networks, explained in dark web vs darknet vs Tor. What sets STYX apart is its focus: it is a one-stop shop for financial fraud, organized like a real e-commerce platform.
Because searches for "Styx Market" collide with a real business, it is worth stating plainly: the two are unrelated.
| Name | What it is |
|---|---|
| STYX Market (this article) | A dark web financial-fraud marketplace |
| River Styx Market | A legitimate grocery store in River Styx, Ohio |
If your search was about photos, reviews, or opening hours, you want the Ohio grocery store, not this. Everything below concerns the criminal marketplace only.
STYX did not appear overnight. Resecurity's analysts traced its development through the underground before it opened its doors.
| Date | Event |
|---|---|
| Early 2022 | Earliest dark web mentions of the project in development |
| ~January 2023 | STYX Market goes operational |
| April 2023 | Resecurity publishes its report; wide press coverage follows |
| 2023 to 2024 | Continues to be tracked as a specialized financial-fraud marketplace |
| 2025 to 2026 | No confirmed public takedown was found in credible reporting reviewed for this update; live status should still be treated cautiously |
The timing was favorable to STYX's positioning. It launched as older fraud and credential markets were being disrupted or retired, giving it room to market itself as a specialized platform for financial crime.
STYX's inventory reads like a menu for every stage of a fraud operation. Here is the master list, grouped by function.
| Category | Examples on offer |
|---|---|
| Stolen financial data | Card data and dumps, compromised online banking credentials |
| Stolen accounts | Cryptocurrency exchange and e-commerce accounts |
| Fraud tools | OTP bots and 2FA/SMS bypass, banking malware and trojans |
| Attack services | DDoS-for-hire |
| Identity products | Fake and stolen ID documents |
| Telecom | SIM cards |
| Cash-out | "Clean" funds via PayPal and Apple Pay business accounts with merchant terminals |
| Money laundering | Individual and business laundering services |
No single category is unique to STYX; what is notable is the completeness. A buyer can source a stolen login, a bot to break its 2FA, a fake ID to pass a verification check, and a laundering service to move the proceeds, all in one place. The next sections break down the clusters that matter most for defenders.
The raw material of the market is compromised financial access.
| Product | What it enables |
|---|---|
| Card data / dumps | Card fraud, both online and counterfeit-card |
| Online banking credentials | Direct account takeover and transfers |
| Cryptocurrency accounts | Draining exchange balances and wallets |
| E-commerce accounts | Fraudulent purchases, stored-card abuse, reputation laundering |
This kind of data can originate upstream in infostealer infections, phishing, payment-card theft, and breaches, which is why STYX is best understood as a monetization layer sitting on top of the wider infostealer economy. Logs sold on credential markets such as Russian Market can feed the same downstream fraud ecosystem, although public reporting does not establish that every STYX listing originates there. For how this stolen data is priced across the underground, see our dark web data pricing breakdown.
Beyond data, STYX sells the instruments that make the data usable.
The presence of these tools is what elevates STYX from a data shop to a fraud platform. It does not just sell you a stolen identity; it sells you the means to weaponize it.
Of everything STYX sells, OTP-bypass tooling is especially important for defenders to understand because it targets a major control organizations rely on: two-factor authentication.

The mechanism, documented by researchers including Kaspersky and others, is social engineering wrapped in automation. It works like this:
A parallel technique, adversary-in-the-middle (AiTM) phishing, uses a proxy page to capture both the password and the live session token in real time. Either way, the SMS or voice one-time passcode, once considered strong, becomes a speed bump. These bots are sold like legitimate software, with pricing tiers, support channels, and refund policies for failed attempts. The defensive answer is not a better OTP; it is phishing-resistant authentication, covered in the defense sections below.
The final stage of any fraud is turning stolen value into spendable money, and laundering is one of STYX's specialities.
| Service | How it works |
|---|---|
| Cash-out shops | Move stolen funds through PayPal and Apple Pay business accounts with merchant terminals to produce "clean" money |
| Individual laundering | Offered from around $15,000 per engagement |
| Business laundering | Higher-tier services for larger volumes |
| Mule networks | Recruited individuals move funds between accounts to break the trail |
Money mules are the human infrastructure of this stage. Criminals recruit people, often through fake job offers or romance scams, to receive and forward illicit funds, obscuring the path back to the fraud. Law-enforcement and financial-crime agencies routinely warn about mule recruitment through fake jobs, romance scams, and other social-engineering schemes, while instant payment rails can make stolen funds harder to stop once they begin moving. Understanding this stage matters because it is where fraud becomes traceable, and therefore where a lot of detection and law enforcement focuses.
STYX is notable less for what it sells than for how professionally it sells it. Resecurity documented an operating model that mirrors legitimate e-commerce.
This is the real story of STYX: the platformization of fraud. It applies the conveniences of modern commerce, escrow, reviews, support, curation, to crime, lowering the skill barrier so that buyers without technical ability can still commit sophisticated fraud.

The "as-a-service" shift is the reason markets like STYX are dangerous out of proportion to their size. In the old model, a fraudster needed technical skill to steal data, write malware, and launder money. STYX unbundles those steps and sells each as a service, so the buyer only needs money and intent.
| Old fraud model | Fraud-as-a-service (STYX-style) |
|---|---|
| One actor with broad technical skill | Many buyers renting specialist services |
| Steal your own data | Buy stolen data on demand |
| Build your own tools | Rent OTP bots and malware |
| Launder your own proceeds | Hire a cash-out service |
| High skill barrier | Low skill barrier, high volume |
The consequence for defenders is scale: the pool of people capable of attacking your customers expands from skilled criminals to anyone with a crypto balance. This is the same dynamic driving ransomware-as-a-service, applied to financial fraud.
STYX does not operate alone; it is one link in a chain that starts with a malware infection and ends with laundered cash.
Seeing the whole chain is what makes defense possible: you can break it at the harvest stage (stop the infostealer), at the exploitation stage (defeat the OTP bot with phishing-resistant MFA), or at the cash-out stage (fraud and mule detection). STYX is strongest in the middle and end of that chain, which is exactly where financial institutions and their customers feel it.
STYX is best understood by contrast with the markets it succeeded and sits beside.
| Market | Specialty | Status |
|---|---|---|
| Genesis Market | Bots with browser fingerprints for impersonation | Seized 2023 |
| BriansClub | Magnetic-stripe card dumps | Contested, magstripe era declining |
| Russian Market | Infostealer logs (credentials, cookies) | Active |
| STYX Market | End-to-end financial fraud, tools, and laundering | Reported active |
We track the takedowns of the older markets in dark web marketplace takedowns. STYX represents the current stage of this evolution: not a single-product shop, but a full-service financial-crime platform.
This is a common search, and the honest answer has two parts.
First, STYX is a real, functioning marketplace, not a fictional bogeyman. Resecurity's research documented a live platform with real vendors, escrow, and services. So "is it real" is, unfortunately, yes.
Second, and more important, that does not make it safe to touch:
So the safe answer to "real or fake" is: real enough to hurt you, and not worth going near.
The harm from a market like STYX lands on several groups at once.
| Who | How they are exposed |
|---|---|
| Consumers | Account takeover, identity theft, drained bank and crypto accounts |
| Banks and fintechs | Fraud losses, OTP-bypass attacks on customers, mule accounts |
| E-commerce and merchants | Stolen-account purchases, chargebacks, cash-out abuse |
| Businesses generally | Business email compromise, invoice fraud, laundering through their rails |
The common thread is that STYX turns a security failure somewhere upstream, a phished employee, an infected customer device, a weak authentication flow, into direct financial loss. That is why defense has to span the whole chain.
You cannot shut down STYX, but you can make its products fail against you.
For financial institutions and any business handling accounts or payments, the goal is to neutralize the tools STYX sells.
| Control | What it defeats |
|---|---|
| Phishing-resistant MFA (FIDO2/passkeys) for staff and high-risk flows | OTP bots, AiTM phishing, MFA fatigue |
| Move away from SMS/voice OTP where possible | SIM-swap and OTP-relay attacks |
| Device binding and step-up authentication | Session hijacking and impossible-travel logins |
| Behavioral and transaction fraud monitoring | Cash-out patterns, mule-account movement |
| Strong KYC/KYB and document verification | Fake and stolen ID documents |
| Stealer-log and dark-web monitoring for your customers and brand | Compromised credentials before they are abused |
| Segmentation and regular penetration testing of auth and payment flows | The technical gaps fraud tools exploit |
Regulators increasingly require stronger authentication in defined contexts. PCI DSS and NYDFS both include MFA requirements for covered access scenarios, although they do not universally mandate FIDO2 or passkeys. Phishing-resistant MFA is the stronger defensive choice where it is practical. When an incident does occur, a tested incident response plan determines how much damage it causes.
Because the tools STYX sells follow predictable patterns, the attacks they power leave recognizable signs. Knowing them helps both individuals and fraud teams catch an attack mid-flight.
For individuals, treat these as immediate red flags:
For fraud and security teams, the telltale patterns are different:
| Signal | What it may indicate |
|---|---|
| Bursts of OTP requests followed by successful logins | OTP-bot or AiTM relay in progress |
| Logins from new devices immediately after a password reset | Credential stuffing from stealer logs |
| New payees or transfers to first-seen accounts | Mule-network cash-out |
| Rapid small transactions testing many cards | Card validation ("carding") |
| Account changes (email, phone) before a large transfer | Takeover hardening before theft |
The point is not to memorize a criminal script but to instrument for its footprints. Detection at any one of these moments can stop the fraud before the cash-out stage, which is the hardest to reverse.
For banks, fintechs, and any business that moves money, resilience against a market like STYX comes down to a repeatable set of controls. Use this as a starting checklist.
| Area | Question to answer |
|---|---|
| Authentication | Have we replaced SMS OTP with phishing-resistant MFA for staff and high-risk customer actions? |
| Session security | Do we bind sessions to devices and force step-up auth on risky actions? |
| Identity proofing | Can our KYC/KYB detect the fake and stolen documents sold on these markets? |
| Transaction monitoring | Do our models flag mule-movement and cash-out patterns in real time? |
| Exposure monitoring | Are we watching stealer-log and dark-web sources for our customers' leaked credentials? |
| Customer education | Do customers know we will never ask them to read back a one-time code? |
| Testing | Have we penetration tested the authentication and payment flows on an appropriate risk-based cadence and after material changes? |
Each unanswered question is an opening the fraud-as-a-service economy is built to exploit. The institutions that fare best treat this as continuous validation, not an annual box-check.
STYX Market is a snapshot of where cybercrime is heading: specialized, productized, and low-barrier. The attacker draining your customer's account may have no technical skill at all; they simply assembled a fraud from parts bought on a platform. Defending against that means assuming your credentials are already for sale somewhere and asking whether your controls survive the tools that abuse them. Our dark web statistics roundup shows how much stolen financial data circulates and how quickly.
That reality is why testing has to model a real, well-equipped fraudster, not a hypothetical one. DeepStrike's penetration testing is manual-first and adversary-realistic: our team probes the authentication and payment paths that OTP bots, stolen accounts, and banking malware target, validates whether your MFA and fraud controls actually hold, and delivers the concrete fixes before your customers' data funds someone's cash-out. For US-based organizations, see our US penetration testing services.
STYX Market is a dark web marketplace specializing in financial fraud, money laundering, and identity theft. Discovered by Resecurity in 2023, it sells stolen bank logins and card data, fake IDs, SIM cards, banking malware, DDoS-for-hire, 2FA-bypass tools, and cash-out and laundering services, essentially a full toolkit for financial crime.
No. This article is about the dark web financial-fraud marketplace named STYX. River Styx Market is an unrelated, legitimate grocery store in River Styx, Ohio. If you were searching for the store's hours, photos, or reviews, that is a different business with no connection to cybercrime.
STYX sells stolen financial data (card data, bank logins), compromised crypto and e-commerce accounts, fake and stolen ID documents, SIM cards, banking malware, DDoS-for-hire, OTP bots that bypass two-factor authentication, and money-laundering and cash-out services that convert stolen funds into clean money.
STYX opened on January 19, 2023, after Resecurity analysts had observed mentions of the project during 2022. Resecurity published the defining report on the marketplace in April 2023, which remains the authoritative source for its structure and offerings.
STYX is a real, functioning marketplace, not a myth. But that does not make it safe: everything on it is criminal, dark markets frequently scam their own buyers or exit-scam entirely, and fake mirrors are phishing traps. Legitimate researchers study it through controlled methods, never by casually accessing it.
OTP bots exploit the human step in SMS or voice two-factor authentication. The attacker uses stolen credentials to trigger a real code, then a bot calls the victim posing as their bank and asks them to confirm it. The victim reads the code aloud, and the bot relays it to the attacker instantly.
STYX offers cash-out shops that move stolen funds through PayPal and Apple Pay business accounts with merchant terminals, plus dedicated laundering services from around $15,000. Money mules, people recruited to receive and forward funds, break the trail, and cryptocurrency layering adds further distance from the original fraud.
Use phishing-resistant MFA like passkeys, never read a one-time code to anyone who calls you, and refuse any arrangement that asks you to move money for others. Freeze your credit, enable transaction alerts, and report fraud through your bank and the FTC, not through any underground service.
As of this writing, STYX is reported to remain active as a specialized financial-crime marketplace, with no confirmed law-enforcement takedown in credible reporting. That said, dark web markets are volatile, they change domains, get seized, or exit-scam without warning, so any external claim about its live status should be treated cautiously.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us