Cybercrime as a service (CaaS) mirrors legitimate service-oriented business models. Threat actors now sell the tools, infrastructure, and expertise needed for cyberattacks as separate services. This frees attackers from building their own tools from scratch; instead, they can purchase off-the-shelf components and piece their attacks together. Consequently, cybercrime has become highly structured, specialized, and accessible to a larger pool of attackers.
The evolution of the CaaS model is driven by several key factors. First, cybercrime is heavily commercialized. Threat actors operate like profit-driven businesses, using the service model to secure higher, steadier income. Second, growing specialization within the underground ecosystem has led different groups to focus exclusively on specific stages of an attack, offering their skills as a service to others. Third, CaaS lowers the barrier to entry by providing turnkey tools to users with limited technical skills. Finally, global forums, marketplaces, anonymization technologies, and cryptocurrencies facilitate communication and payments among threat actors.
The rapid growth of CaaS is transforming the threat landscape. With turnkey tools so readily available, both the number of potential attackers and the variety of attacks they can launch have increased. This is creating a highly collaborative criminal ecosystem where attackers share knowledge, speeding up the evolution of new attack techniques. In addition, the global, decentralized nature of these markets complicates cross-border law enforcement efforts.
Today's CaaS market is moving in two directions: consolidating around major platforms and established providers, while simultaneously branching out into highly specialized niche services. This creates a complex but agile ecosystem reliant on outsourced tools and services. Despite law enforcement takedowns, the market remains resilient, and new platforms are rapidly replacing closed ones.
Initial access listings dominate our dataset (61%), highlighting a mature market with steady demand. This high volume is largely because access is typically sold on a one-off basis, requiring a new listing for every transaction. Malware ranks second (18%), reflecting its critical role in modern attacks. The remaining categories account for much smaller shares, pointing to either narrower specialization or lower market supply.