Cybersecurity might as well have its own language. There are so many acronyms, terms, and sayings that unless you are deeply knowledgeable, have experience in the security field, or have a keen interest, one may not know what they mean. Understanding these terms is the first step to developing a thorough understanding of cybersecurity and, in turn, better protecting yourself, clients, and employees.
In this blog series, we aim to explain and simplify some of the most commonly used terms. Previously, we have covered bullet proof hosting, CVEs, APIs, brute force attacks, zero-day exploits, doxing, data harvesting, IoCs, credential stuffing, ransomware as a service, push bombing, web application attacks, man-in-the-middle attacks, ransomware leak sites, the CIA Triad, and encryption. In this edition, we dive into malware as a service..
Malware is one of the most persistent threats facing organizations worldwide. From stealing sensitive information to disrupting business operations, malicious software can cause significant financial and reputational damage. Traditionally, developing and deploying sophisticated malware required technical expertise, time, and resources. Today, cybercriminals can bypass much of that work by purchasing access to malware through a model known as Malware as a Service (MaaS).
Malware as a Service is a cybercrime business model in which malware developers sell or lease malicious software, infrastructure, and related services to other threat actors. Rather than building their own tools, buyers can purchase ready-made malware, often through subscription plans or one-time payments. Depending on the offering, these packages may include software updates, technical support, hosting infrastructure, and dashboards for managing campaigns. The result is a more accessible criminal ecosystem. Individuals with limited programming knowledge can use tools developed by more experienced threat actors to launch attacks against organizations and individuals.
MaaS operates similarly to legitimate Software as a Service (SaaS) platforms, where customers pay to access software maintained by a provider. The difference is that MaaS products are designed to facilitate cybercrime. Developers may earn recurring revenue from subscriptions, while customers use the tools to steal credentials, collect sensitive information, establish unauthorized access, or distribute additional malware.
This business model also creates specialization within the cybercrime economy. Developers can focus on building and maintaining malware, while affiliates and customers concentrate on distributing it and exploiting the information or access they obtain. Like Ransomware as a Service (RaaS), MaaS lowers the barrier to entry for cybercriminals and allows malicious campaigns to scale beyond the capabilities of a single operator.
Not all malware is designed to accomplish the same objective. MaaS offerings can support a range of malicious activities, depending on the software, infrastructure, and services included in a package. Below are some of the most common.
Information stealers, also known as infostealers, are types of malware designed to collect sensitive information from infected devices. Depending on the malware, this information may include saved browser credentials, authentication tokens, cryptocurrency wallet data, and other sensitive files.
Cybercriminals can use this information to access corporate accounts, impersonate legitimate users, commit financial fraud, or sell the stolen data to other threat actors.
Infostealer operators frequently monetize their activity through subscriptions and the sale of stolen information. Some services also provide access to stealer logs, which are collections of data extracted from infected devices. These logs can become valuable commodities on darknet marketplaces and underground forums, particularly when they contain credentials associated with corporate systems.
Remote Access Trojans (RATs) are malicious programs that allow an attacker to gain unauthorized remote control over an infected device. Depending on their capabilities, RATs may enable an operator to monitor activity, access files, execute commands, or collect sensitive information.
Through MaaS arrangements, threat actors can obtain access to remote-control malware without developing it themselves. Once deployed, these tools may provide a foothold that enables further malicious activity, including surveillance, credential theft, or attempts to move deeper into an organization’s network.
Nimbus Manticore, the Iranian hacking group, has been connected to two (NodeRabbit and PollCat) previously undocumented malwares targeting Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Nimbus Manticore, also known as Iranian Dream Job, has been targeting job candidates with fake recruitment coding challenges designed to infect their computers. In one case, attackers distributed a project-management application called Taskflow and asked candidates to find bugs in the frontend within three hours. The challenge appeared legitimate, but malicious code was hidden in the supposedly “bug-free” server.js file. It loaded a trojanized Node.js package that secretly launched NodeRabbit, a backdoor capable of communicating with attacker-controlled servers. Once installed, NodeRabbit can collect system information, run commands, access and modify files, manage directories, and gather network details. It can also execute temporary scripts and delete them afterward to hide evidence of its activity. Read more here.
A botnet is a network of compromised devices that can be controlled by an operator. These devices may include computers, servers, and Internet of Things (IoT) devices.
Some MaaS offerings provide malware that recruits infected devices into a botnet, while other services sell access to existing botnet infrastructure. Threat actors may use these networks to conduct Distributed Denial-of-Service (DDoS) attacks, distribute spam, or support other malicious campaigns.
The scale of a botnet can make it particularly disruptive. By coordinating activity across many compromised devices, attackers can overwhelm online services or use distributed infrastructure to support additional operations.
Ransomware is malware that encrypts files or otherwise prevents victims from accessing their systems or data, typically to extort payment. Some ransomware operations use a service-based model in which developers supply the malware and supporting infrastructure to affiliates.
Although Ransomware as a Service is often treated as its own category, it shares many of the same characteristics as MaaS. Both models allow threat actors to access malicious tools without independently developing the underlying software.
The distinction is that ransomware is specifically designed to support extortion, while MaaS is a broader category that can include many different types of malicious software and objectives.
MaaS is not simply a transaction in which someone purchases a malicious program. It is an ecosystem of developers, vendors, infrastructure providers, and customers who work together to distribute malware and monetize its impact.
The process typically involves several stages:
This division of labor makes the MaaS ecosystem difficult to disrupt. Developers may never interact directly with victims, and the person deploying the malware may not be the person who ultimately profits from the stolen data.
It also means that a single malware infection can have consequences beyond the original compromise. Information stolen from one device may enable additional attacks against an employer, a business partner, or a customer.
MaaS has changed the economics of cybercrime. Threat actors no longer need to possess advanced programming skills or spend months developing malicious software. Instead, they can purchase tools that have already been developed, tested, and maintained by other criminals.
Several factors contribute to the continued growth of this model.
Developing malware from scratch requires technical knowledge, time, and resources. MaaS removes much of that investment by providing ready-made tools that customers can deploy with limited expertise.
Some services even offer user-friendly dashboards, documentation, and technical support. This allows a broader range of threat actors to participate in cybercrime, increasing the number of potential attackers organizations must defend against.
MaaS providers can distribute the same malware to multiple customers, who may use it against different targets simultaneously. Automated features can further increase the speed and scale of malicious campaigns.
For example, a single infostealer sold to multiple subscribers could be used to collect credentials from hundreds or thousands of devices. Those credentials may then be sold, traded, or used to gain unauthorized access to additional systems.
This scalability makes MaaS particularly concerning for organizations that rely on credentials to protect corporate applications, cloud environments, and internal networks.
Cybercriminals increasingly operate through structured marketplaces and service-based business models. MaaS vendors may advertise product features, publish updates, offer customer support, and establish reputations within underground communities.
These practices make malicious services easier to purchase and create recurring revenue streams for developers.
DarkOwl research and analysis provides visibility into these criminal ecosystems by indexing darknet forums, marketplaces, and other underground sources where threat actors advertise malware, discuss attack methods, and exchange compromised information.
MaaS rarely operates in isolation. It can overlap with several other criminal services, creating a chain of activity in which different threat actors specialize in different stages of an attack.
For example, an infostealer may collect corporate credentials from an infected device. Those credentials could be sold through an underground marketplace or passed to an initial access broker (IAB), who specializes in selling unauthorized access to compromised systems. Another threat actor may then use that access to deploy ransomware or steal additional data.
Each participant contributes to the attack without necessarily interacting with the original victim. This interconnected ecosystem makes it more difficult for security teams to understand the full scope of a threat by investigating a single malware sample or security incident.
The darknet plays an important role in the MaaS ecosystem. Underground forums, marketplaces, and encrypted messaging channels give threat actors places to advertise malicious software, recruit customers, exchange information, and sell stolen data.
These environments can also provide valuable intelligence for defenders.
Darknet listings may reveal which malware families are being promoted, what capabilities vendors claim to offer, and which industries or organizations are being discussed by threat actors. Discussions between customers and vendors can provide additional context about the tools being used and the methods associated with particular campaigns.
However, an advertisement does not necessarily mean a product works as claimed or that an attack is imminent. Threat intelligence analysts must evaluate the credibility of the source, corroborate findings, and distinguish between marketing claims, speculation, and evidence of actual malicious activity.
Monitoring underground activity can help security teams identify several types of potential risk:
Connecting these findings can help organizations move beyond reacting to individual security alerts and toward a more proactive understanding of their exposure.
There is no single security control that can prevent every malware infection. Because MaaS supports multiple types of attacks, organizations should combine technical safeguards, employee awareness, incident response, and threat intelligence.
Endpoint detection and response (EDR) solutions help security teams monitor endpoint activity, identify suspicious behavior, and investigate potential compromises.
Rather than relying exclusively on known malware signatures, security teams should also look for behaviors associated with malicious activity, such as unauthorized credential access, suspicious process execution, or unexpected connections to external infrastructure.
Stolen credentials are a common commodity in the cybercrime economy. Organizations should enforce multifactor authentication (MFA), use phishing-resistant authentication where possible, and apply least-privilege access controls.
Security teams should also monitor for exposed credentials and revoke compromised sessions or tokens when necessary. Resetting a password alone may not be sufficient if an attacker has obtained an active authentication token or maintained another form of access.
Unpatched software can provide opportunities for attackers to gain access to systems or execute malicious code. Organizations should maintain an inventory of their assets, prioritize security patches based on risk, and address known vulnerabilities promptly.
Regular updates do not eliminate every attack path, but they help reduce the number of weaknesses available for exploitation.
Phishing emails, malicious attachments, and deceptive downloads remain common ways to distribute malware. Employees should understand how to recognize suspicious messages, verify unexpected requests, and report potential security incidents.
Organizations should also use email security controls, web filtering, and application restrictions to reduce the likelihood that a single mistake results in a successful infection.
Organizations should maintain regular, tested backups of critical data and ensure that recovery copies are protected from unauthorized access or modification.
Incident response plans should address how to isolate infected devices, investigate potential credential theft, determine whether sensitive information was exposed, and restore affected systems.
A malware infection may be only the beginning of a larger incident. Understanding what information was accessed and whether attackers retained access is just as important as removing the initial malware.
Traditional security tools primarily focus on activity within an organization’s devices, networks, and cloud environments. However, information associated with an organization may appear on underground sources after it has already been stolen.
Darknet monitoring provides another layer of visibility by helping security teams identify exposed credentials, leaked data, malware advertisements, and other indicators of potential risk.
When combined with internal security telemetry, this intelligence can help organizations investigate incidents, identify exposure that might otherwise go unnoticed, and prioritize remediation efforts.
Products
Services
Use Cases