Cyberthreats/Incidents

Cybercrime as a service: trends shaping the service-based cybercrime model

Anna Vyatkina

Anna Vyatkina

Analyst, Research Group of PT Cyber Analytics

About the report

This study analyzes over 4,300 cybercrime service listings from 2024 to 2025 across 38 major dark web forums, marketplaces, and Telegram channels, covering multiple languages and topics. We examined service types, pricing, and supply-and-demand dynamics to identify key trends and assess how the cybercrime landscape may evolve. The focus of our research is "cybercrime as a service" (CaaS) and its impact on today's cybercriminal economy.

However, the listings we analyzed were not limited to subscription models. We also examined other forms of interaction on the dark web, including one-off sales, the hiring of contractors, free tool giveaways, and hybrid collaboration models.

Because many threat actors negotiate prices privately, our pricing estimates and median calculations rely exclusively on listings with explicitly stated prices.

Executive summary

  • The CaaS model remains highly lucrative and is likely to keep expanding. The financial incentive driving the underground market is clear: the profits from successful attacks can far exceed the cost of purchasing the necessary services. As long as the cost of attack tools continues to fall while the damage from incidents continues to grow, the financial incentive to develop the underground market will remain. 
  • he barrier to entry continues to fall. Off-the-shelf tools enable low-skilled actors to launch attacks, while market specialization allows criminals to monetize highly specific skill sets.
  • Low-cost services fuel mass attacks. Infrastructure rentals (median: $8), DDoS attacks ($20), and stealer logs ($20) are the most affordable offerings, making large-scale, low-sophistication attacks accessible to almost anyone.
  • Exploits are the most expensive services, with a median price of $27,500 and 35% of listings exceeding $100,000. However, subscription-based exploit kits starting around $500 per month are lowering the barrier to entry even in this high-end segment.
  • The market is shifting toward unified ecosystems that consolidate multiple attack stages into a single, comprehensive service.
  • Individual services are consolidating into unified offerings. For instance, infostealer logs are now sold alongside credential validation, and ransomware operations are merging with initial access sales.
  • Threat actors are already using AI to personalize phishing campaigns, generate code, and manage communications with ransomware victims. Soon, autonomous AI agents will likely orchestrate complete, end-to-end attacks by integrating the results of various services. 
  • The market segments will evolve differently. Mature segments like infrastructure rental, ransomware, phishing, and off-the-shelf malware will continue functioning as full-fledged businesses.
  • Services for bypassing security controls, code signing, and crypting are in high demand. Median prices reflect this trend: EDR killers cost $2,250, code signing certificates cost $2,150, and crypting costs $150 per file (or $1,000–$5,000 for subscriptions).
  • Advances in AI and automation will likely lead to the emergence of services that autonomously gather open-source intelligence, aggregate data, and generate reports, turning reconnaissance into a separate market segment.
     

Introduction

Cybercrime as a service (CaaS) mirrors legitimate service-oriented business models. Threat actors now sell the tools, infrastructure, and expertise needed for cyberattacks as separate services. This frees attackers from building their own tools from scratch; instead, they can purchase off-the-shelf components and piece their attacks together. Consequently, cybercrime has become highly structured, specialized, and accessible to a larger pool of attackers.

The evolution of the CaaS model is driven by several key factors. First, cybercrime is heavily commercialized. Threat actors operate like profit-driven businesses, using the service model to secure higher, steadier income. Second, growing specialization within the underground ecosystem has led different groups to focus exclusively on specific stages of an attack, offering their skills as a service to others. Third, CaaS lowers the barrier to entry by providing turnkey tools to users with limited technical skills. Finally, global forums, marketplaces, anonymization technologies, and cryptocurrencies facilitate communication and payments among threat actors.

The rapid growth of CaaS is transforming the threat landscape. With turnkey tools so readily available, both the number of potential attackers and the variety of attacks they can launch have increased. This is creating a highly collaborative criminal ecosystem where attackers share knowledge, speeding up the evolution of new attack techniques. In addition, the global, decentralized nature of these markets complicates cross-border law enforcement efforts.

Today's CaaS market is moving in two directions: consolidating around major platforms and established providers, while simultaneously branching out into highly specialized niche services. This creates a complex but agile ecosystem reliant on outsourced tools and services. Despite law enforcement takedowns, the market remains resilient, and new platforms are rapidly replacing closed ones.

Initial access listings dominate our dataset (61%), highlighting a mature market with steady demand. This high volume is largely because access is typically sold on a one-off basis, requiring a new listing for every transaction. Malware ranks second (18%), reflecting its critical role in modern attacks. The remaining categories account for much smaller shares, pointing to either narrower specialization or lower market supply.

Figure 1. Listing subjects

Cyberattacks are multi-stage operations, and threat actors can now outsource almost every step. The shift from one-off sales to subscription models is a clear sign of a maturing market. It points to consistent demand, standardized processes, and long-term relationships between vendors and buyers. Unlike one-off purchases, subscriptions provide regular tool updates, technical support, and new features—all of which require robust infrastructure and dedicated resources.

Figure 2. Use of services at different attack stages
Figure 2. Use of services at different attack stages

Dark web services are shifting to subscription models at varying rates. We classify subscription adoption into three stages: established, developing, and nascent. In established segments, subscriptions are widely adopted and represent the industry standard. In developing segments, subscription offerings are growing, marking a gradual shift away from one-off sales. In nascent segments, one-off transactions still dominate, and subscription models are only beginning to appear.

ServiceMain monetization models currently usedSubscription model maturity
Infrastructure as a serviceSubscription, one-off saleEstablished
Vulnerability discovery as a serviceContractor hiring, one-off saleNascent
Malware development as a serviceContractor hiringNascent
Intelligence as a serviceContractor hiringNascent
Stealer logs as a serviceSubscription, one-off saleEstablished
Phishing as a serviceOne-off sale, subscriptionEstablished
Exploit as a serviceOne-off saleNascent
Access as a serviceOne-off saleNascent
Credential validation as a serviceSubscription, one-off saleEstablished
Code signing as a serviceOne-off saleNascent
Defense evasion as a serviceOne-off sale, subscriptionDeveloping
Crypting as a serviceSubscription, one-off saleDeveloping
Malware as a serviceSubscription, one-off saleEstablished
Ransomware as a servicePartnership, one-off saleEstablished
DDoS attack as a serviceSubscriptionEstablished
Hacker as a serviceContractor hiringNascent

Dark web market participants

The CaaS market consists of two main groups: providers and consumers. Providers are advanced threat actors or specialized groups with deep expertise in areas like malware development, exploit creation, or infrastructure management. Consumers range from novices to seasoned professionals who use third-party services to streamline their operations.

 While the service model has democratized cybercrime, allowing low-skilled novices to launch attacks using off-the-shelf tools, the barrier to entry is not zero. Many listings, particularly partnerships or joint ventures, still demand practical skills, experience, or resources. While novices can easily rent botnets or use turnkey phishing tools, orchestrating complex, high-impact attacks still requires expertise comparable to that of legitimate cybersecurity professionals.

Cybercriminals gradually build their experience. Novices master basic tools, execute minor operations, and eventually integrate into established groups or affiliate networks. The dark web operates as a highly interconnected ecosystem with clearly defined roles, rather than a community of isolated actors.

The CaaS model allows experienced threat actors to outsource parts of their operations. Buying specific attack components saves time and boosts scalability, while turnkey solutions let them easily replicate successful tactics and launch large-scale campaigns. Meanwhile, less experienced actors who discover a vulnerability or gain initial access can sell their findings to more advanced criminals.

Preparation and development

Infrastructure as a service

IaaS is the technical layer of the CaaS ecosystem. These services provide the computing resources, network infrastructure, and tools needed to organize and scale attacks—sparing attackers from having to deploy or maintain the hardware themselves.

Most IaaS listings offer resources (75%), followed by buyer requests (17%). The remainder consists of free tool giveaways (6%) and partnership offers for shared infrastructure (2%).

IaaS is a highly scalable market with a large number of providers and steady demand. Because infrastructure is a prerequisite for almost all subsequent attack stages, it accounts for the vast majority of dark web listings. Buyer listings are less common and typically seek highly specialized solutions tailored to specific tasks.

Figure 3. Infrastructure-related listing types, share of listings

Offers to sell or rent infrastructure range from $0.35 per day for a VPS server to $25,000 for highly specialized services. The median price is $8, indicating that low-cost, widely available offers dominate the market. This pricing structure is driven by fierce competition among providers and the highly scalable nature of the business.

Figure 4. Distribution of infrastructure services by price, share of listings

On underground markets, infrastructure services include the rental or sale of server infrastructure, proxy services, botnets, and bulk messaging.

Figure 5. Infrastructure type, share of listings

The most common infrastructure service is the provision of server resources (66% of listings). This includes virtual private servers (VPS), remote desktops (RDP), hosting services, and cloud platform accounts. Threat actors use this infrastructure to support their operations, including phishing websites, malware C2 servers, botnet control panels, malware distribution servers, and repositories for stolen data.

The minimum cost of renting infrastructure is $0.35 per day for a dedicated VPS server. The cheapest monthly offer is a virtual machine priced at $0.99 with the following basic configuration: 1 core, 256 MB RAM, 5 GB NVMe, 100 Mbps. Providers offer a range of configurations at various price points. Additional options include international server hosting, DDoS protection, WAF and Tor support, no user verification, enhanced anonymity, and disregard for DMCA requests from copyright holders.

Figure 6. Listing offering VPS resources
Figure 6. Listing offering VPS resources

Dark web forums offer not only legitimate server rentals, but also compromised servers and hacked cloud provider accounts. These resources allow threat actors to quickly deploy infrastructure and distribute attack components across multiple jurisdictions, making it much harder to trace the source of the malicious activity.

Prices for these services start at $10 for AWS accounts with 8 vCPUs. For $400, buyers can obtain access to a verified Google Cloud account with trial credits, created using a real bank card.

Figure 7. Listing offering cloud provider accounts
Figure 7. Listing offering cloud provider accounts

Proxy services on underground markets allow attackers to route network traffic through intermediary hosts, hiding the true source of the connection. According to an analysis of PT Network Attack Discovery pilot projects conducted in 2024–2025, traces of malicious residential proxy network activity were found in the network traffic of 46% of companies. These services may include proxies based on infected user devices, compromised servers, or dedicated proxy networks. Proxy nodes allow attackers to bypass geographic restrictions, mask their activity, and make it significantly harder for law enforcement and security teams to trace their operations.

Prices start at $0.10 per residential proxy node per day, with discounts and better rates available for bulk purchases. Some sellers offer additional options such as country selection, targeting by state or city, rotating proxies, and static subnets.

Figure 8. Listing offering proxy services
Figure 8. Listing offering proxy services

Bulk messaging services allow threat actors to send large volumes of messages via email, messengers, or social networks. These services include access to specialized software, target mailing lists, delivery infrastructure, and tools to bypass anti-spam filters. Their main purpose is to distribute phishing messages, malicious attachments, or links to infected resources. Prices start at $3.50 for one day of mailing, or $1 for sending messages to a database of 10,000 email addresses.

Figure 9. Listing offering bulk email sending
Figure 9. Listing offering bulk email sending

The most expensive listing in this category offered a complete infrastructure package for generating and monetizing malicious traffic through browser extensions, priced at $25,000. The seller offered a ready-made kit that included a modified browser extension, a system for generating and accumulating traffic, and mechanisms for redirecting that traffic to third-party resources or software products. The extension was positioned as cross-platform, supporting Windows, macOS, and Linux, and was advertised as capable of operating for a long time without detection by bypassing browser security mechanisms, including Chrome security checks. The cost of acquiring one infected traffic node ranged from USD 0.50 to USD 2. At scale, this becomes highly profitable.

Figure 10. Listing offering comprehensive infrastructure for generating and monetizing malicious traffic through browser extensions
Figure 10. Listing offering comprehensive infrastructure for generating and monetizing malicious traffic through browser extensions

Vulnerability discovery as a service

This category includes services for detecting vulnerabilities in software, web applications, and corporate network infrastructure. They may include automated scanning, penetration testing, system configuration analysis, and the preparation of vulnerability reports.

Compared to other categories, vulnerability discovery as a service remains a relatively niche and underdeveloped segment of the CaaS market. The abundance of free vulnerability scanning tools reduces the incentive to sell them.

There are two main approaches in this segment. The first involves distributing automated tools that scan infrastructure to identify vulnerable services. Prices for these solutions start at $90 for tools with advanced functionality. While basic versions of these tools are free, advanced features, regular updates, and additional modules are offered for a fee.

Figure 11. Listing offering a free vulnerability scanner with a premium mode
Figure 11. Listing offering a free vulnerability scanner with a premium mode

The second approach is outsourced vulnerability scanning, where threat actors hire specialists to analyze targeted infrastructure. This often involves manual work, such as searching for complex or non-standard vulnerabilities that automated tools miss. These listings are less common and rarely specify a fixed price; costs depend on the target's characteristics, task complexity, and the required expertise. This model resembles an illicit version of a bug bounty program or penetration test.

Figure 12. Listing seeking vulnerability discovery services
Figure 12. Listing seeking vulnerability discovery services

Vulnerability discovery listings are less popular because the results are not ready-to-use products that cybercriminals can immediately act on. Unlike services that provide ready-made access or tools for immediate exploitation, vulnerability discovery requires additional time and technical resources. Consequently, demand shifts toward ready-to-use solutions, making discovery services less attractive.

As a result, vulnerability discovery supports other stages of an attack and is rarely viewed as a standalone product. Nevertheless, the availability of these solutions lowers the barrier to entry, allowing even low-skilled actors to conduct basic reconnaissance and prepare for attacks.

Malware development as a service

Malware development as a service is a high-demand CaaS segment. It has balanced supply and demand: 42% of listings offer these services, while another 42% seek to buy them. This indicates an established market where some actors specialize in development while others act as customers.

Figure 13. Types of cooperation in malware development listings, share of listings

A large share of listings are posted by developers offering to create malware from scratch or modify existing tools. This often involves completing specific tasks rather than building a complete product, such as adding new functionality, modifying operational logic, or adapting a tool for a specific target.

Figure 14. Listing offering tool development
Figure 14. Listing offering tool development

Buyer listings reveal highly specific demands, with threat actors seeking specialists for distinct tasks and detailing exact requirements for functionality, programming languages, and infrastructure. This reflects a growing division of labor, where malware development has become a separate function distinct from the execution of attacks.

Figure 15. Listing seeking services to modify a miner
Figure 15. Listing seeking services to modify a miner

Ransomware development makes up the largest share of service listings (23%), mirroring the leading role of this malware in today's cyberattacks. Ransomware was used in half of all malware attacks against organizations in 2025.

Figure 16. Listing offering ransomware development
Figure 16. Listing offering ransomware development

Another popular service is the development of checkers and brute force tools, which account for 19%. These tools are used to automate credential validation and large-scale access attempts. They are in high demand because attackers constantly need them customized for specific platforms—a demand developers can easily meet, since adapting the core functionality is a relatively simple and scalable task.

Figure 17. Development requests by tool type, share of listings

Remote administration tools (16%) and infostealers (14%), used for system persistence and data extraction, also make up a significant share of listings. Botnets (9%) and requests to integrate machine learning features (9%) stand out; these are typically not standalone products but enhancements for existing tools.

Figure 18. Searching for an AI specialist for pentesting tasks
Figure 18. Searching for an AI specialist for pentesting tasks

Pricing in this segment is opaque; most listings lack a fixed price because they involve project-based work with custom requirements. Nevertheless, some examples indicate the price range: basic services or simple components start at a few dozen dollars, while complex custom tools or full-fledged malware systems cost hundreds or thousands of dollars. This price variation depends directly on task complexity, required functionality, and the need to bypass security mechanisms.

For instance, developing a botnet with a control panel and API is offered for just $20. The buyer receives a fully configured attack infrastructure with customizable interfaces, commands, methods, and parameters. Hosting is available as an additional service for $4 per month.

Figure 19. Listing offering botnet development
Figure 19. Listing offering botnet development

Meanwhile, the market also features highly complex projects that require custom development and significantly larger budgets. For example, developing a complex software tool for automated cryptocurrency transactions starts at $3,000.

Figure 20. Listing seeking a tool for cryptocurrency transactions
Figure 20. Listing seeking a tool for cryptocurrency transactions

Malware development as a service is a key element in the CaaS ecosystem. Abundant supply, active demand, and flexible interaction models allow threat actors to acquire the tools they need without any development expertise. This lowers the barrier to entry and drives the proliferation of complex attack tools, including those that previously required advanced skills to build.

Intelligence as a service

The intelligence as a service segment is in its infancy and remains poorly represented on the underground market. There is niche, highly specialized demand that has not yet evolved into a scalable service model. This limited adoption may be because intelligence results are difficult to standardize and scale.

Figure 21. Listing seeking the services of an OSINT specialist
Figure 21. Listing seeking the services of an OSINT specialist

Nevertheless, this segment has growth potential. Advances in AI and automation will likely lead to the emergence of services that autonomously gather open-source intelligence, aggregate data, and generate reports, turning reconnaissance into a separate market segment. As cybercrime as a service evolves, intelligence could emerge as a standalone service.

The role of large language models (LLMs) deserves special attention, as they can potentially be used across all preparation and development stages—from information gathering and target analysis to code generation and task automation. The proliferation of these technologies could further lower entry barriers and accelerate specific attack stages.

Researchers highlight an emerging service category: jailbreak as a service. This involves specialized methods to bypass the restrictions of commercial LLM platforms, allowing attackers to use them for malicious purposes. Notably, the trend is toward bypassing the restrictions of legitimate models rather than creating custom uncensored ones. This is because matching the quality of commercial platforms requires immense time and computational resources. It is faster and more cost-effective for threat actors to bypass existing protections than to train their own models.

Figure 22. Listing offering a ready-made jailbreak
Figure 22. Listing offering a ready-made jailbreak

Initial access and monetization

Some threat actors purchase ready-made access or tools for obtaining it; others generate profit by monetizing successful breaches.

Exploit as a service

One in fifteen listings involves threat actors buying or selling services related to exploiting software vulnerabilities. Zero-day vulnerabilities are traded in 40% of these listings.

These are mostly one-off transactions involving the sale, purchase, or distribution of specific exploits for particular vulnerabilities. Every major vulnerability is unique and has a limited lifecycle: once it is publicly disclosed and vendors release patches, the exploit's effectiveness drops rapidly. The constant need to discover new vulnerabilities and create new tools makes it difficult to scale and standardize this service under a subscription model. Consequently, the exploit market is less suited for subscriptions than other CaaS segments, where a single tool can be used long-term.

Figure 23. Types of exploit-related listings, share of listings

Exploits are the most expensive cybercriminal services, which creates a high barrier to entry. The median price for an exploit is $27,500. However, the most valuable ones can be much more expensive, with 35% of them costing over $100,000. Such prices make exploits inaccessible to novice cybercriminals and limit the pool of potential buyers to more experienced threat actors or groups.

Figure 24. Exploit price distribution

Adopting a service-based model could help exploit developers expand their customer base and maximize profits. Instead of selling a single copy to one buyer, developers could rent access to the tool to multiple clients.

This demand is visible in listings where threat actors who regularly perform attacks are looking to partner with developers of exploits for popular software and network services. They typically offer high payouts and seek long-term partnerships, indicating a shift toward more stable relationships in this segment.

Figure 25. Listing seeking exploits
Figure 25. Listing seeking exploits

Currently, exploit kits are the closest thing to a full-fledged service model. These software packages automate the exploitation of vulnerabilities in websites and web applications. Unlike standalone exploits, these solutions bundle multiple ready-to-use tools and receive regular module updates. Access to such kits is often subscription-based, costing around $500 per month. This is much cheaper than buying individual exploits, making these tools accessible to a broader range of threat actors.

Figure 26. Listing offering subscription-based exploits
Figure 26. Listing offering subscription-based exploits

Phishing as a service

This category includes online platforms and tools that allow users to launch phishing campaigns without deep technical expertise. Typically, these services include either ready-made templates or the development of custom phishing emails, web pages, and campaign management panels.

The phishing market offers everything from single pages—sold individually or given away for free—to entire platforms equipped with ready-made panels and phishing toolkits. Instead of just selling templates, threat actors now offer complete, ready-to-use solutions.

Figure 27. Listing offering website cloning services for phishing attacks
Figure 27. Listing offering website cloning services for phishing attacks

Today's phishing tools are highly sophisticated, built specifically to evade detection and maximize success rates. Listings frequently offer anti-bot protection, anti-analysis mechanisms, and management interfaces for real-time campaigns. To build victim trust, some solutions even adapt pages for specific countries or perfectly mimic local banks and services.

Figure 28. Listing offering a phishing panel
Figure 28. Listing offering a phishing panel

Attackers also run mass campaigns without setting up their own infrastructure. These tools often include automated messaging, credit card validation, traffic filtering, and device-specific targeting (such as focusing only on mobile phones).

Figure 29. Listing offering a phishing kit
Figure 29. Listing offering a phishing kit

Complex phishing ecosystems are also emerging. A single service might offer victim databases, custom control panels, landing pages, message interception, and fake documents for bank verification. Some even offer add-ons like cryptocurrency theft and custom software development.

Figure 30. Listing offering phishing services
Figure 30. Listing offering phishing services

Voice phishing (vishing) is also becoming a major threat. These services use specialized systems to handle calls, capture one-time passwords (OTPs), and interact with victims in real time. Backed by professional call centers or automated systems, these tools allow threat actors to launch large-scale campaigns.

Figure 31. Subscription-based vishing services
Figure 31. Subscription-based vishing services

Phishing service costs vary widely based on infrastructure complexity, automation, and campaign scale. Most fall into the low-to-mid price range: 45% cost under $100, and 42% cost between $101 and $1,000.

Figure 32. Price distribution for phishing services

AI is transforming the phishing market more than most other factors. Generative models can create highly personalized emails, websites, and audio/video recordings. This makes fraudulent messages highly convincing, and mass campaigns increasingly use unique scenarios that adapt to specific victims, rather than generic templates.

Deepfake as a service is emerging as a distinct offering, closely related to phishing. It is growing rapidly because tools that once required substantial resources and expertise are now cheap and accessible. Subscriptions cost up to $50 per month, putting them in the hands of ordinary attackers. Offerings include photo face-swapping, video and image generation, and voice synthesis for calls, all of which increase victim trust. In Q2 2025 alone, deepfake-related damages reached $347 million, highlighting just how quickly this technique is scaling.

Stealer logs as a service and credential validation as a service

Processing and exploiting stolen credentials is one of the most scalable and profitable CaaS segments. Unlike operations aimed at obtaining initial access, which require advanced technical skills, handling credentials is easy to standardize and automate. This segment merges two categories: the sale of logs harvested by info-stealers (stealer logs as a service) and automated credential validation (credential validation as a service). Together, they form a unified process that provides attackers with ready-made entry points into corporate systems.

Sellers of stealer logs provide massive datasets of user credentials, cookies, authorization tokens, and device fingerprints harvested from infected systems. Attackers use this data for direct access, follow-on attacks, or fraud. Because they collect data continuously and in bulk, sellers use a subscription model, delivering fresh data in small, regular batches.Processing and exploiting stolen credentials is one of the most scalable and profitable CaaS segments. Unlike operations aimed at obtaining initial access, which require advanced technical skills, handling credentials is easy to standardize and automate. This segment merges two categories: the sale of logs harvested by info-stealers (stealer logs as a service) and automated credential validation (credential validation as a service). Together, they form a unified process that provides attackers with ready-made entry points into corporate systems.

Sellers of stealer logs provide massive datasets of user credentials, cookies, authorization tokens, and device fingerprints harvested from infected systems. Attackers use this data for direct access, follow-on attacks, or fraud. Because they collect data continuously and in bulk, sellers use a subscription model, delivering fresh data in small, regular batches.

Figure 33. Listing offering processed stealer logs
Figure 33. Listing offering processed stealer logs

The median cost for log services is $20, though individual records can cost just a few cents. Buyers often subscribe to specialized services or Telegram bots for database access. These subscriptions range from $20 to $100 per month, depending on data volume, update frequency, and quality. In this highly competitive market, sellers differentiate themselves through data freshness, uniqueness, lack of duplicates, specialization by region or service, and convenient search and export features.

Figure 34. Stealer log marketplace
Figure 34. Stealer log marketplace

Private logs are in particularly high demand. Because they are not publicly distributed, they are more valuable, more unique, and less likely to involve accounts that have already been blocked. Attackers often use this data in targeted operations where reliable access is critical.

Figure 35. Purchase of private stealer logs
Figure 35. Purchase of private stealer logs

Stolen data is usually processed further using specialized validation tools. Credential validation as a service relies on checkers and brute force tools to automatically verify usernames and passwords, identify accessible accounts, and extract additional account details.

These tools, including specialized scanners and brute-checkers designed for corporate services, can cost tens of thousands of dollars.

Figure 36. Sale of a brute-checker
Figure 36. Sale of a brute-checker

The subscription model, however, is far more common. Prices typically range from $100 to $1,000 per month. Regular updates help keep the tools effective. For example, a checker with 39 modules and continuous updates is offered at $125 for one month, $200 for two months, or $275 for three months.

Figure 37. Sale of a checker
Figure 37. Sale of a checker

By combining stealer logs with credential validation tools, threat actors can automate the process of obtaining access, with each step offered separately as a service. The process begins with large-scale data collection, followed by filtering and validation. Valid credentials are then used for further exploitation or resold. This automation allows attackers to speed up attacks and minimize human involvement.

At the same time, the widespread use of automated tools has made manual data processing more valuable. Automated systems can generate network noise and increase the risk of detection, while careful manual verification of accounts can reduce the risk of lockouts and help attackers maintain compromised access for longer. As a result, manual account verification and exploitation now command higher prices and are in greater demand, especially for targeted attacks.

Figure 38. Purchase of private logs with manual verification
Figure 38. Purchase of private logs with manual verification

These services are often offered through partnership models, where the provider receives a share of the profits generated from the use of the compromised access.

Figure 39. Partnership offer from a log provider
Figure 39. Partnership offer from a log provider

AI is also starting to play a role in this segment, particularly in data processing. New services claim to use AI to analyze stealer logs, identify relevant accounts, and improve the quality of the data they provide. Because these solutions cost roughly the same as traditional tools, they are spreading quickly.

Figure 40. Stealer log marketplace
Figure 40. Stealer log marketplace

Looking ahead, these services are likely to become even more automated. The market will probably move toward all-in-one platforms that combine data supply and validation in a single product. This would allow threat actors to sell verified credentials that are ready for use or monetization, further lowering the barrier to entry and enabling attacks to be carried out faster.

Access as a service

The sale of access to already compromised corporate systems and networks is the most common service on underground markets, accounting for the largest share of listings at 61%. This segment is a core part of the cybercrime economy because access to an organization's infrastructure is often the easiest starting point for an attack.

Selling access to corporate networks has become a stable and profitable business. It has also created a dedicated role: initial access brokers, or IABs. These actors focus solely on obtaining access and reselling it, without taking part in the attacks that follow. This specialization lowers the barrier to entry for less experienced criminals. Even if an attacker lacks the skills to complete an intrusion, they can still monetize the access they have obtained by selling it to more capable operators.

Most activity in this segment involves the sale of access, which accounts for 70% of access-related listings. Another quarter of listings involve buyers looking for access to purchase. Despite how widespread the service is, access is usually sold as a one-off item, often to a single buyer. Subscription models are almost absent from this market because every access offering is different. Its value depends on factors such as privilege level, the victim organization's industry and location, and the security posture of the infrastructure. This makes the service difficult to standardize or turn into a recurring subscription. As a result, one-off sales and partnership agreements remain the main business models.

Figure 41. Access-related listing types

The median price of access is $600, although actual prices vary widely. The most common range is $100 to $1,000, making these offerings affordable to a broad range of threat actors. Higher-priced listings typically involve high-value access, large organizations, or administrative privileges. Cheaper options usually come with limited permissions or access to less valuable infrastructure.

Figure 42. Access price distribution

The most common types of access are VPN access at 19% and RDP access at 16%, followed by shell access at 12% and access to various remote administration tools at 8%.

Figure 43. Access types

Privilege level is one of the main factors shaping both the price and appeal of an access listing. A significant share of offerings, 30%, include administrative rights.

Figure 44. Privileges in access listings

The organizations most often mentioned in listings are in the retail sector at 17%, manufacturing at 16%, and services at 13%. This likely reflects their broad market presence and potential financial value. Access to financial institutions, at 9%, and government organizations, at 6%, can be significantly more expensive because of the sensitivity of the data involved and the potential impact of a compromise.

Figure 45. Access listings by industry

In addition to one-off access sales, partnership models are also common. In these arrangements, the access provider receives a percentage of the profits generated from the later exploitation of the compromised system. This model can be more attractive than a fixed fee because the quality of access can vary significantly, and its real value often becomes clear only after it has been tested, used, and monetized. Partnerships also reduce risk for the buyer, since payment is tied to a successful financial outcome.

Figure 46. Purchase of access provision services
Figure 46. Purchase of access provision services

Looking ahead, this segment is likely to retain its current business model. Unlike other CaaS segments where automation and standardization make services easier to scale, the access market depends on the unique value of each individual access and the specific conditions of the compromise. For this reason, one-off sales and partnership agreements are likely to remain dominant, while full subscription-based access offerings will probably remain the exception rather than the norm.

Defense evasion

Defense evasion as a service

Services that provide tools and techniques for bypassing security controls and hiding malicious activity within corporate environments are still an emerging market, but they are growing quickly. Demand is driven by the wide deployment of modern cybersecurity products. These services allow threat actors to disable or bypass antivirus software, EDR and XDR platforms, and other detection tools, while also helping them conceal activity inside a compromised network.

The most common tools in this segment are so-called EDR killers: specialized utilities designed to neutralize endpoint protection mechanisms. Their popularity is driven by the widespread adoption of detection and response technologies, which have made traditional attack techniques harder to execute. These tools are widely used by ransomware operators, which explains their high demand. According to ESET, more than 90 EDR killers are being actively used in ransomware attacks.

These tools are technically more complex than many other offerings. Building them requires a deep understanding of how security products work, how threats are detected, and how operating systems behave internally. As a result, prices remain relatively high. Basic tools start at around $500, while more advanced offerings can reach $9,000, with a median price of $2,250. Pricing depends on various factors, including supported operating systems, compatibility with specific security products, and the evasion techniques used. Tools also differ in how they interfere with security controls and how broadly they can be applied. The more platforms and security products a tool supports, the more valuable and in-demand it becomes.

These tools are distributed both as ready-made products through one-off sales and by subscription. Under a subscription model, developers provide updates, support, and sometimes custom modifications, such as adding bypasses for specific security products. Subscriptions are especially attractive because security tools are constantly updated, and evasion tools also need regular changes to remain effective and avoid detection.

Figure 47. Listing offering a tool for bypassing antivirus and EDR products
Figure 47. Listing offering a tool for bypassing antivirus and EDR products

Crypting as a service

Crypting as a service refers to the modification and obfuscation of malware to help it evade detection. Crypters and packers alter the structure and signatures of malicious code, reducing the likelihood of detection by antivirus products and security monitoring systems.

The median price for these services is $150. The cheapest offering is single-file crypting, which costs no more than $500. Automated tools are offered at lower prices, while private crypting with a guaranteed bypass can be significantly more expensive.

Figure 48. Price distribution in listings for crypter services

Subscription-based tools are usually much more expensive, ranging from $1,000 to $5,000. The subscriptions include updates to obfuscation algorithms, technical support, and regular signature changes, allowing the tool to remain effective as security products continue to evolve.

Figure 49. Subscription-based crypter service
Figure 49. Subscription-based crypter service

Private crypters are especially valuable on the dark web. Because they are used by a limited number of customers, they are less likely to appear in security vendors' signature databases. Sellers face a trade-off between revenue and detection risk: the more customers use the same tool, the higher the chance that security products will identify it. For this reason, developers often prefer to sell access to a small number of customers at a higher price rather than distribute their tools widely.

Figure 50. Listing offering crypter services
Figure 50. Listing offering crypter services

Manual work remains highly valued. Custom crypting services may go beyond basic obfuscation and include more advanced techniques for bypassing different types of detection, including signature-based, heuristic, and behavioral analysis. In some cases, customers pay only after they have tested the result.

Figure 51. Offer for private crypting services
Figure 51. Offer for private crypting services

Listings for ready-made file-crypting platforms also point to the high profitability of this segment. Sellers offer a software platform as a one-time purchase, allowing the buyer to build their own crypting business, including under a subscription model.

Figure 52. Sale of a platform for monetizing file crypting
Figure 52. Sale of a platform for monetizing file crypting

Overall, the crypting market appears mature and competitive. Automated tools compete by improving quality and ease of use, offering regular updates and additional features. Individual operators focus on customization and guaranteed results. Over time, some of the manual work is likely to be automated, leading to the emergence of more advanced tools designed to bypass newer security mechanisms and make malware more resistant to detection.

Code signing as a service

Services offering digital certificates, including code signing and EV certificates, are becoming more popular on underground markets. These certificates allow threat actors to sign software, making it appear more trustworthy to operating systems and security tools. They can reduce the likelihood of user-facing warnings, including alerts from built-in operating system protections, and increase the chances that malware will run successfully in the target environment.

Certificates are typically sold individually. The median price of a certificate is $2,150, making these offerings accessible mainly to mature threat actors or groups conducting targeted attacks.

Figure 53. Offer for issuing EV certificates
Figure 53. Offer for issuing EV certificates

From a technical standpoint, little prevents this segment from shifting toward a service-based model. A subscription model could appeal to threat actors who need to regularly generate and sign new malware builds, particularly in large-scale campaigns or operations involving rapidly evolving malware strains.

For now, the high cost of individual certificates limits their use in mass attacks. However, if automated services for issuing and managing certificates become more widely available, prices may fall and these offerings could be used at scale.

The limited validity period of digital certificates is another factor that could lead to the adoption of a subscription-based model. Once a certificate expires, it can no longer be used and must be replaced. Under a subscription model, the provider could automatically supply new certificates as older ones expire, freeing customers from having to search for and purchase new certificates each time.

Early signs of this trend are already visible. Some listings now offer certificate packages instead of individual certificates, suggesting a shift toward a more systematic approach.

Figure 54. Listing offering EV certificates
Figure 54. Listing offering EV certificates

Attack execution

Ransomware as a service

Ransomware as a service (RaaS) is a cybercrime business model in which ransomware developers build and maintain the infrastructure, while affiliates use it to carry out attacks. Under this model, affiliates do not need deep technical expertise. They can rely on ready-made tools and infrastructure provided by the operators.

Affiliates can work with operators under several commercial models, including monthly subscriptions, partnership programs, one-time licensing fees, or revenue-sharing agreements. The most common monetization models are:

  • A fixed monthly fee for access to the infrastructure and malware
  • A percentage of the ransom payment
  •  A one-time fee for using a specific ransomware strain
  • Joint operations between operators and affiliates, with profits shared across different stages of the attack

The RaaS model is closely related to other segments of the cybercrime ecosystem. For example, initial access brokers provide access to corporate networks, which affiliates then use to deploy ransomware. In some cases, the flow works in reverse: ransomware operators sell access they have obtained, creating an additional revenue stream.

Figure 55. Access marketplace on a ransomware group's site
Figure 55. Access marketplace on a ransomware group's site

Over time, these operations have become increasingly specialized. Some actors focus on malware development, others on obtaining initial access, and others on carrying out attacks and negotiating with victims.

Another feature of ransomware operations is the use of double and triple extortion. Double extortion combines data encryption with data theft, followed by threats to publish the stolen information. Triple extortion adds further pressure, such as threats of follow-on attacks, informing victim's customers or partners, or extortion attempts targeting affected individuals. There have also been cases of quadruple extortion. However, double extortion remains the dominant model: organizations are increasingly refusing to pay ransoms, but some victims are still willing to negotiate.

Ransomware was used in half of all malware attacks against organizations in 2025. Its share increased by 8 percentage points compared to 2024, a trend directly linked to the growth of RaaS. Ransomware is used not only by financially motivated cybercriminal groups, but also by hacktivist gangs.

According to ransomware.live, more than 300 distinct ransomware groups are active worldwide, and more than 2,000 organizations were victimized by ransomware attacks in 2026. Qilin, The Gentlemen, Akira, and Clop are among the most active groups by number of attacks. These groups continue to evolve and release new ransomware versions to maximize their impact.

Threat actors use the RaaS model for several key reasons: 

  • Specialization allows more attacks to be launched in parallel.
  • Ready-made tools lower the barrier to entry for less experienced actors.
  • Some organizations still pay ransoms, especially when business downtime is at stake.
  • Stolen data can be monetized even if the victim refuses to pay.
  • Distributed operations make these ecosystems more resilient to law enforcement efforts.

Prices for RaaS tools vary widely. For example, the source code for basic ransomware can sell for as little as $100.

Figure 56. Listing offering ransomware
Figure 56. Listing offering ransomware

The median price for these tools is $1,000, while the most advanced and feature-rich ransomware offerings can reach $125,000.

Figure 57. Listing offering ransomware
Figure 57. Listing offering ransomware

As in other CaaS segments, artificial intelligence is beginning to play a visible role in the development of RaaS. Large language models can help automate parts of the attack cycle and reduce the workload for threat actors.

There have already been cases of generative models being used to develop ransomware components. For example, Acronis analysts reported in September 2025 that Anthropic's Claude Code had been used to create a RaaS offering.

The trend is not limited to malware development. Attack management is also becoming more automated. Some modern RaaS control panels already include features that support the full attack cycle, from creating a target profile and generating a malicious file to communicating with the victim. Some platforms offer multiple victim communication tools, including automated bots and AI assistants capable of negotiating using predefined scripts or trained models. Overall, RaaS platforms are becoming more automated and less dependent on direct human involvement.

Figure 58. Description of a ransomware control panel
Figure 58. Description of a ransomware control panel

DDoS as a service

DDoS as a service (DDoSaaS) allows customers to launch distributed denial-of-service attacks. These services provide access to botnets and control panels that allow users to select the target, attack duration, intensity, and other parameters.

DDoSaaS is one of the simplest and most accessible cybercrime services. Prices in this segment are relatively low, ranging from $10 to $600 per month, with a median monthly price of $20.

Pricing plans usually differ by:

  • Maximum attack duration
  • Volume of generated traffic
  • Number of concurrent attacks
  • Waiting time between attacks
  • Access to additional management features

Sellers tend to offer flexible pricing, with a wide range of plans tailored to different budgets and use cases.

Figure 59. Offer for DDoS attack services
Figure 59. Offer for DDoS attack services

Some services use marketing tactics commonly associated with legitimate online platforms. For example, providers may offer money-back guarantees if an attack fails, as well as free test runs in the form of short DDoS attacks designed to demonstrate the service's capabilities. These practices point to strong competition in the segment and show that operators are trying to build trust with potential customers.

Figure 60. Listing offering DDoS attack services
Figure 60. Listing offering DDoS attack services

Overall, DDoS as a service is one of the most mature and standardized service segments in the cybercrime market. Its ease of use, low cost, and high level of automation have made it a mass-market tool.

Malware as a service

Malware as a service (MaaS) provides ready-made malware together with management infrastructure, updates, and technical support. This allows threat actors to conduct attacks without developing their own tools.

Malware remains one of the main tools used in attacks against organizations across different industries. Threat actors used malware in 71% of successful attacks on organizations in 2025. Malware is effective, versatile, and plays the central role in modern cyberattacks.

The MaaS market offers both one-off sales of malware source code and subscription-based services. However, subscription-based services are becoming the preferred model, as they give buyers access to regular updates and support.

The malware market is highly active, with strong participation from both sellers and buyers. Purchase listings account for 39% of activity, indicating steady demand for ready-made tools and highlighting the appeal of the service-based model. Free distribution listings, which account for 12%, reflect the common practice of promoting malware through free versions.

Figure 61. Types of malware-related listings

The distribution of malware types in listings reflects attacker priorities. The strongest demand is for tools that provide long-term access to victim infrastructure, enable data theft, or help bypass security controls. The variety of categories also shows how specialized the market has become, with tools available for different stages of the attack chain.

Figure 62. Types of malware in malware-related listings

The most common malware type in listings is remote access tools, or RATs. Remote access Trojans were the second most commonly used malware type in successful attacks on organizations in the first quarter of 2026, appearing in 28% of cases. Prices for RATs vary widely, from a few dollars to hundreds of thousands of dollars, depending on functionality, support, and stealth capabilities. Most listings, 46%, fall into the mid-range price segment of $100 to $1,000, while the median price is $1,000. This points to a mass market for affordable RAT offerings.

Figure 63. Price distribution for remote access trojans (RATs)

Modern remote access tools are evolving into all-purpose attack platforms that combine the capabilities of several malware classes. This allows threat actors to support multiple attack scenarios through a single tool. Unlike ransomware, these platforms allow attackers to maintain long-term access to the victim's infrastructure.

For example, the multimodule malware VioletRat gives attackers extensive control over infected systems, including remote control, keylogging, credential and cryptocurrency theft, screenshot capture, audio recording, DDoS functionality, and file encryption. It also includes mechanisms for bypassing security tools, including Windows Defender, evading analysis, spreading via USB drives, and integrating infected hosts into botnets for coordinated attacks.

Figure 64. Listing advertising a multimodule RAT with multiple functions
Figure 64. Listing advertising a multimodule RAT with multiple functions

Like remote access trojans, infostealers are among the most in-demand malware types because they can quickly extract valuable data, including credentials, cookies, financial information, and cryptocurrency keys. Infostealer pricing follows a pattern similar to other malware categories. Most listings, 53%, are priced below $1,000, making these tools accessible to a broad range of threat actors. The median price for infostealers is $1,000.

Figure 65. Price distribution for infostealers

Infostealers have also created a secondary market for "stealer logs as a service." In this model, malware buyers resell stolen data to other threat actors, helping them recoup the cost of the tool and generate additional revenue.

Loaders are used to deliver and install other types of malware, including infostealers, ransomware, and remote access tools. They are an important part of attack infrastructure because they allow threat actors to manage the distribution of malicious components. The median price for a loader is $1,000.

Figure 66. Price distribution for loaders

Tools in this category are often delivered through web-based control panels that automate malware creation and distribution. Users can generate executable files based on selected parameters, manage them through a centralized interface, and track infection statistics, including information about target devices. A notable feature of these platforms is that they can be used not only for the operator's own attacks, but also as a commercial service. Developers often build in subscription-based access, allowing buyers to operate their own MaaS offerings.

Figure 67. Listing offering a web panel for creating and managing infostealers
Figure 67. Listing offering a web panel for creating and managing infostealers

Hacker as a service

Hacker as a service refers to offerings from hired specialists who carry out cyberattacks on demand. These services may include breaching information systems, stealing data, disrupting infrastructure, deploying malware, or performing other actions on behalf of a customer. This is a broad, end-to-end service model that involves hiring an individual specialist or a team capable of carrying out a full attack for a negotiated fee. The median price for these services is $2,750.

Although these offerings are usually tailored to individual requests, the market is gradually moving toward a service-based model. Some listings bundle several services into a single package, allowing customers to obtain a complete solution without coordinating with multiple providers.

Figure 68. Packaged hacking service
Figure 68. Packaged hacking service

Complex, targeted attacks represent a separate segment. For example, some listings advertise the ability to place a person inside an organization to conduct an insider attack. Prices for these services start at $500,000, which means they are generally affordable only to financially motivated groups or APT actors.

Figure 69. Offer for infiltration services inside a company
Figure 69. Offer for infiltration services inside a company

Artificial intelligence is also beginning to appear in this segment. Some listings mention the use of AI for automated infrastructure scanning, vulnerability discovery, and attack scenario development. This reduces the workload for operators and speeds up the reconnaissance and planning stages. This reduces the workload for operators and accelerates the reconnaissance and planning stages.

These offers usually come with guarantees. In some cases, payment is made only after the attack goal has been achieved, such as successful access to a system or a confirmed data breach. This helps build customer trust and reflects the competitive nature of the market.

Figure 70. Listing offering hacking services
Figure 70. Listing offering hacking services

Building an attack from available services and estimating its cost

Many stages of a cyberattack can now be carried out by purchasing separate services. The wide range of specialized offerings, from access acquisition to monetization, makes it possible to assemble an attack from ready-made components. Not every component is available by subscription, but almost all of them can be purchased through one-off payments. The most common approach is a hybrid model, where threat actors combine their own expertise with purchased services.

Figure 71. Median price of services at different stages of an attack
Figure 71. Median price of services at different stages of an attack

Mass campaigns typically rely on low-cost, readily available components, such as rented infrastructure, phishing panels, and stealer logs. Targeted attacks require a more specialized and expensive toolkit, including exploits, EDR killers, and code signing certificates. Between these two extremes is the mid-level threat segment, where malware and access listings are most commonly used in practice.

Figure 72. Median prices for underground market services

To estimate the real cost of an attack, it is important to consider not only the prices of individual components, but also the set of tools required for a specific scenario. The following scenarios illustrate how attacks can be assembled entirely from purchased components: the threat actor does not develop any tools independently, but instead combines ready-made services from the underground market.

Attacker profile: low technical skill, minimal budget. Goal: steal corporate credentials and resell them.

This is the most accessible scenario. It requires only a subscription to a phishing panel with ready-made templates and minimal infrastructure. Phishing panels come with templates for banks, corporate portals, and email services; almost no technical skills are required to launch a campaign.

ComponentCost
Phishing panel, one-month subscriptionapprox. $150
Server or infrastructureapprox. $8
Totalapprox. $158

Potential profit: among access listings for sale, 75% are priced above $150. This means that even a single successfully obtained access can cover the cost of the campaign.

This asymmetry between relatively low attacker investment and potentially severe victim losses is a key driver of the CaaS economy. As long as the cost of attack tools continues to fall while the damage from incidents continues to grow, the financial incentive to develop the underground market will remain.

The evolution of cybercrime as a platform

The modern cybercrime ecosystem is evolving from a fragmented set of services into a modular architecture, in which each stage of an attack is supported by a specialized market segment. This allows threat actors to combine components flexibly and adapt attacks to specific targets and budgets.

Over time, this model may evolve further toward a cybercrime as a platform model: integrated solutions that combine several stages of an attack within a single ecosystem. AI-based systems, particularly autonomous agents, could play an important role in this process by automating the selection, combination, and management of different services. This could further lower the barrier to entry into cybercrime and increase the speed at which attacks are carried out, accelerate the growth of the underground market. At present, however, complex attacks still require practical skills and experience.

Regulatory measures, operations against dark web forums, and restrictions on anonymous cryptocurrencies can disrupt the criminal market, but they do not make it disappear. The underground ecosystem continues to show resilience and can recover quickly after disruptions.

Countering cybercrime as a service requires a comprehensive approach. Priority areas should include stronger monitoring of the dark web and related communication channels, broader information sharing among companies, research organizations, and law enforcement agencies, and coordinated action against the infrastructure that supports these services.