Cybercrime-as-a-Service Explained: The Criminal Gig Economy
How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.
There is a common picture of a cybercriminal: a lone expert writing custom code in a dark room. That picture is decades out of date. Modern cybercrime looks like a supply chain. One group writes the malware, another sells the way into your network, a third rents the servers, and a fourth actually runs the attack, having built almost none of it. Each is a business with customers, pricing, and support.
This is cybercrime-as-a-service, and it is the single biggest reason attacks have scaled the way they have. When every part of an attack can be rented, the skill and effort needed to launch one collapse.
What "as-a-service" means here
The legitimate software world moved to services long ago. You do not build your own email server, you subscribe to one. Criminals copied the model exactly. Instead of every attacker mastering every skill, specialists build one capability well and rent it to others.
The effect is a marketplace where an attack is assembled from parts:
- Someone provides the way in (stolen access).
- Someone provides the weapon (ransomware, a stealer, a botnet).
- Someone provides the delivery (phishing kits and lures).
- Someone provides the infrastructure (criminal hosting and traffic services).
- A buyer combines these into an operation.
None of the participants needs to be good at all of it. That division of labour is what makes the ecosystem productive and resilient, and it is why the barrier to entry keeps falling.
The main services on offer
The criminal market has specialised into recognisable service categories.
| Service | What it provides | Who buys it |
|---|---|---|
| Ransomware-as-a-service | Ready-made encryptor, leak site, negotiation support | Affiliates who run the attacks |
| Phishing-as-a-service | Fake login pages, kits, delivery | Low-skill credential thieves |
| Malware-as-a-service | Infostealers, loaders, botnets on subscription | A broad range of criminals |
| Access-as-a-service | Working footholds into named organisations | Ransomware crews and others |
| Bulletproof hosting | Servers and infrastructure that ignore takedowns | Almost everyone in the ecosystem |
Ransomware-as-a-service
Ransomware-as-a-service (RaaS) is the model that made ransomware an industry. Operators build and maintain the malware, the payment and negotiation systems, and the leak site used for extortion. Affiliates rent the kit and carry out the intrusions, and the two sides split the ransom. It lets people with intrusion skills but no malware development skills run professional-grade attacks. Our ransomware-as-a-service guide breaks the model down in full.
Phishing kits and phishing-as-a-service
A phishing kit is a packaged fake: convincing clone login pages, the code to capture and relay credentials, and often templates for well-known brands. Phishing-as-a-service goes further and rents the whole operation, including hosting and delivery, sometimes with tooling to relay multi-factor prompts in real time. MITRE ATT&CK tracks the underlying technique as Phishing (T1566). The result is that running a credible phishing campaign no longer requires building anything.
Malware-as-a-service
Infostealers, loaders, and botnets are rented on subscription, frequently with the trappings of a real product: a control dashboard, regular updates, and customer support. Infostealer operations are a prime example, harvesting credentials and session cookies and selling both the malware and the stolen logs. Our infostealer guide covers how that particular service works end to end.
Access-as-a-service
Initial access brokers sell footholds into specific organisations: valid VPN or RDP credentials, working accounts, or webshells. This service removes the hardest step of an attack, the break-in, and hands it to a buyer as a product. Our initial access brokers guide explains the supply layer that feeds ransomware directly.
Bulletproof hosting
Underneath all of it sits the infrastructure. Bulletproof hosting providers rent servers and network services while deliberately ignoring abuse complaints and takedown requests, often operating from jurisdictions where enforcement is weak. They are the criminal equivalent of a cloud provider, and their resilience is what keeps phishing pages, malware servers, and leak sites online.
A modern ransomware incident might combine a foothold bought from a broker, that foothold sourced from a stealer log bought from a malware operator, an encryptor rented from a RaaS crew, all running on bulletproof hosting. Four services, four suppliers, one attack, and the person running it built none of the pieces.
Why this lowered the skill barrier
Two decades ago, launching a serious attack meant real technical depth: writing or heavily modifying malware, finding your own way in, and running your own infrastructure. The as-a-service economy removed each of those requirements one at a time.
- You no longer need to write malware, you rent it with a dashboard.
- You no longer need to break in, you buy the access.
- You no longer need to run infrastructure, you rent bulletproof hosting.
- You no longer need to build phishing pages, you subscribe to a kit.
What remains for the buyer is closer to operating a business than engineering an exploit: pick suppliers, combine services, and run the operation. This is why the population of capable attackers grew so fast. Specialisation let a small number of skilled builders equip a large number of less-skilled operators, and the total volume of attacks rose accordingly.
It also professionalised the ecosystem. Services compete on quality, reputation, and support. Sellers build standing on criminal forums, offer guarantees, and screen buyers, because trust is what lets an illegal market keep functioning. Our dark web markets guide covers the venues where that trade takes place.
The division of labour that scaled cybercrime also created shared choke points. Many different attacks depend on the same few services: phishing delivery, stolen access, criminal hosting. Disrupting a widely used service, or defending against it well, hurts every downstream attacker that relied on it, across the whole market rather than a single crew.
How the model evolved
The service economy did not appear fully formed. It grew out of a few slow shifts that each removed a bottleneck.
The first was the move from custom code to reusable kits. Early banking trojans and exploit packs were sold or leaked, and once a working codebase existed in the wild, other people extended it and rented it out. A tool built once could serve hundreds of operators, which is the same logic that drives legitimate software.
The second shift was the arrival of cryptocurrency as a settlement layer. Anonymous, irreversible payment made it practical to charge subscriptions, take deposits, and split proceeds between parties who never meet and do not trust each other. A criminal service that cannot get paid reliably cannot become a business. Payment rails turned one-off scams into recurring revenue.
The third shift was specialisation itself. As the money grew, it became worth someone's time to be excellent at one narrow thing: writing a stealer, running a phishing panel, brokering access, keeping servers online. Each specialist could sell to every operator in the market rather than run attacks alone. That is the division of labour that defines the ecosystem today, and it keeps deepening as niches split into sub-niches.
The result is a market that looks less like a hacker scene and more like an industry with tiers of suppliers, resellers, and end users. The people who run the visible attacks are frequently the least technical participants in the chain.
Walking one attack through the supply chain
It helps to trace a single realistic intrusion through the services it rents, because the assembly is where the model becomes concrete. The steps below describe the general pattern, with no specific victim or event attached.
- The access is sourced. An initial access broker has valid credentials for a company's remote-access portal, harvested weeks earlier from an infostealer log. The broker lists the access with a rough description of the target's size and sector, and an affiliate buys it.
- The weapon is rented. The affiliate already has a subscription to a ransomware kit. The operator behind that kit supplies the encryptor, a leak site to host stolen data, and a negotiation panel, in exchange for a share of any payment.
- The ground is prepared. The affiliate logs in with the bought credentials, looks around, and uses widely available tooling to find privileged accounts and reach more systems. Much of this stage uses legitimate administrative features rather than custom malware.
- The data is taken and the payload runs. The affiliate copies valuable data out to storage they control, then deploys the encryptor across the reachable machines. The leak site and negotiation panel come from the kit operator.
- The infrastructure holds it together. The credential harvesting, the staging servers, and the leak site all sit on bulletproof hosting that ignores abuse complaints, so takedown requests go nowhere.
The affiliate at the centre of this wrote none of the malware, discovered none of the access, and built none of the infrastructure. They coordinated four suppliers and ran the operation. That is the shape of a modern intrusion, and it is why counting skilled malware authors badly underestimates the number of people capable of causing serious harm.
How the market keeps itself honest
An illegal market has a trust problem that a legal one solves with courts and contracts. Criminal services solve it with reputation and intermediaries, and understanding those mechanics explains why the ecosystem is stable enough to function.
Sellers build standing over time. A vendor with a long history of delivering working products and honouring refunds can charge more and attract better buyers, so reputation becomes an asset worth protecting. New sellers start cheap and unproven, and they climb by delivering.
Forums and markets add escrow, where a neutral party holds payment until the buyer confirms the goods work. That removes the incentive for a one-off scam, because the seller only gets paid on delivery. Disputes go to moderators who can freeze funds and ban accounts. The dark web markets guide covers these venues and their rules in detail.
Vetting runs in both directions. Access brokers screen buyers to avoid selling to researchers or law enforcement, and ransomware operators interview affiliates before granting them a kit. The friction is deliberate, because a careless partner draws attention that hurts everyone in the chain.
The same trust systems that make the market work also make it observable. Vendors advertise, build reviews, and defend their names, which means their tooling, pricing, and target preferences leak into public view. Tracking a service and its reputation over time tells defenders which delivery methods and access types are in fashion before the finished attacks arrive.
Detection signals: spotting a rented attack
Because an attack is assembled from standard parts, it tends to carry the fingerprints of those parts. Defenders who know the catalogue can recognise the pieces.
- Credentials appearing in stealer-log dumps. Your users' logins surfacing in infostealer collections is an early sign that access to your environment is being packaged for sale. This is upstream of any intrusion.
- Remote-access logins from unusual locations or hosts. Bought footholds are used from the buyer's infrastructure, so a valid account authenticating from a new country or a hosting provider is a strong lead.
- Off-the-shelf tooling in the environment. Widely rented loaders, common post-exploitation frameworks, and known persistence patterns indicate a buyer running standard playbooks rather than bespoke work.
- Known phishing-kit artifacts. Reused kit templates, credential-relay endpoints, and recognisable landing-page code point to phishing-as-a-service rather than a hand-built lure. MITRE tracks the technique as Phishing (T1566).
- Leak-site and negotiation infrastructure. Naming and formatting conventions that match a specific ransomware kit tie an incident to a known operator and its affiliate pool.
None of these is proof on its own. Their value is in narrowing the field: recognising which services an incident rented tells you which supplier's playbook you are facing and what usually comes next.
The old model against the service model
Setting the two side by side shows why the shift changed the threat landscape so completely.
| Dimension | Lone-operator model | Service model |
|---|---|---|
| Skills required | Deep, across malware, intrusion, and infrastructure | Narrow, mostly operational and coordination |
| Time to launch | Weeks or months of building | Days, by assembling bought parts |
| Cost structure | High upfront effort, low cash | Low effort, recurring cash for subscriptions and access |
| Resilience | Fails if the one operator is caught | Survives loss of any single participant |
| Population of attackers | Small, limited by skill | Large, limited mostly by willingness to pay |
| Attribution | One actor, one toolset | Many suppliers, shared tooling, blurred lines |
The right-hand column is the world defenders now operate in. The barrier that used to be technical is now mostly financial, and money is far easier to find than years of skill. That single change is why the volume of attacks rose so sharply and why the same malware families and access patterns turn up across unrelated incidents.
Common misconceptions
"Attackers are lone geniuses." The image of a single expert doing everything is the exception now. Most operations are coordinated purchases from specialists, and the person running the attack is often the least skilled link.
"Cheap tools mean amateur threats." A rented kit can be professionally built and maintained by people who are very good at their niche. Low price for the buyer reflects the economics of selling one tool to many operators, and it says nothing about the tool's quality.
"Stopping one group ends the threat." Because attacks draw on shared services, removing a single crew leaves the suppliers intact. The access brokers, malware operators, and hosting providers keep serving everyone else. Durable disruption targets the shared layer.
"It is all on the dark web." Plenty of this trade happens on ordinary messaging platforms and semi-public forums. The venue varies, and treating it as a single hidden marketplace misreads how distributed the ecosystem is, and how easy much of it is to reach.
How to defend in a service economy
When attacks are assembled from bought parts, the most efficient defence targets the shared services rather than chasing each final payload.
- Harden against delivery. Phishing is the entry point for a huge share of the market. Phishing-resistant authentication (passkeys and hardware keys), strong email filtering, and user awareness cut off the most rented service of all.
- Deny the footholds brokers sell. Multi-factor authentication on all remote access, no RDP exposed to the internet, fast patching of edge devices, and monitoring for your credentials in stealer-log dumps. This starves the access-as-a-service layer.
- Assume breach and reduce dwell time. Because affiliates often start from bought access, watch for lateral movement and credential abuse inside the network, as well as at the perimeter.
- Use threat intelligence on the services as well as the actors. Knowing which delivery methods, malware families, and access types are being rented tells you where to spend defensive effort.
- Keep resilient backups and a tested response plan. The final payload in this economy is frequently ransomware. Recoverability is what turns a business-ending event into an incident.
To see the operators, affiliates, and brokers that make up this economy, along with the sectors they target, our Threat Groups directory tracks the actors across the supply chain so you can understand who rents from whom and who is likely to arrive at your door.
Cybercrime became an economy of specialists, and that is why it scaled. The same structure is its exposed flank. Attacks are built from a handful of shared services, and defending well against those services (delivery, access, and infrastructure) does more to protect you than trying to counter every finished attack one at a time.
Frequently asked questions
What is the difference between cybercrime-as-a-service and ransomware-as-a-service?
Ransomware-as-a-service is one service category inside the broader cybercrime-as-a-service economy. It covers the rental of encryptors and extortion infrastructure. Cybercrime-as-a-service is the umbrella term for the whole rental market, which also includes phishing kits, malware subscriptions, access brokering, and criminal hosting. A single ransomware incident usually rents from several of these categories at once.
Do buyers need technical skill to use these services?
Far less than they once did. Many services ship with dashboards, documentation, and support precisely so that low-skill buyers can operate them. Some skill still helps with the hands-on-keyboard stages of an intrusion, but the hardest technical work, building malware and finding footholds, has been moved to specialists and sold as a finished product.
Why can't law enforcement simply shut these services down?
The infrastructure often sits in jurisdictions where enforcement is weak, on bulletproof hosting designed to ignore takedown requests. The market is also decentralised, so removing one vendor leaves the suppliers and buyers around it intact. Disruption happens, and it works best when it targets shared services and the money, but the structure is built to survive the loss of any single participant.
How does payment work in this economy?
Cryptocurrency provides settlement that is hard to reverse and hard to attribute, which makes subscriptions, deposits, and revenue splits practical. Markets add escrow so a neutral party holds funds until the buyer confirms delivery, which reduces the incentive for one-off scams and lets the market function despite the lack of legal recourse.
Is cybercrime-as-a-service only found on the dark web?
No. While specialised markets and forums host much of the trade, a large amount happens on mainstream messaging platforms and semi-public forums. The venue varies by service and by the level of vetting the seller wants. Treating it as a single hidden place underestimates how distributed and accessible it has become.
What single defence helps most against this model?
Phishing-resistant authentication has outsized value, because phishing and stolen credentials feed the two most-rented services: delivery and access. Passkeys and hardware security keys break credential theft at its source, which starves both the phishing-as-a-service and access-as-a-service layers that so many finished attacks depend on.
How can a defender tell which service an attacker rented?
By the artifacts the rented parts leave behind: recognisable phishing-kit templates, common post-exploitation tooling, leak-site formatting tied to a specific kit, and logins from hosting infrastructure rather than user devices. Matching those fingerprints to known services tells you which supplier's playbook you face and what usually comes next.
Has the service model changed how fast new techniques spread?
Yes. When a capability is a rentable product, an improvement made by one specialist reaches every buyer through an update, the same way a software release does. A new evasion trick or a fresh phishing template can propagate across the whole customer base quickly, so defenders see the same novel behaviour appear across many unrelated incidents in a short window. Watching the services themselves gives earlier warning than waiting for each finished attack to arrive.
Related guides
Sources & further reading
- MITRE ATT&CK: Enterprise Matrix — MITRE
- CISA: Stop Ransomware — CISA
- MITRE ATT&CK: Phishing (T1566) — MITRE
Related guides
- Dark Web Markets: How Criminal Marketplaces Work
A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.
- Initial Access Brokers: The Middlemen of Ransomware
Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.
- The Bug Bounty Economy: Platforms, Triage & Payouts
How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.