Kaspersky finds 58% of malware sold as a service are ransomware

Issue 4 2023 News & Events

The Kaspersky Digital Footprint Intelligence team presented a new study that reveals ransomware as the most widespread Malware-as-a-Service (MaaS) over the past seven years. The study is based on research conducted on 97 malware families that have been distributed on the darknet and other resources. Additionally, the researchers found that cybercriminals often lease infostealers, botnets, loaders, and backdoors to carry out their attacks.

MaaS is an illicit model of business involving the leasing of software to carry out cyberattacks. Typically, clients of such services are offered a personal account through which they can control the attack, as well as technical support. It lowers the initial threshold of expertise needed by would-be cybercriminals.

Ransomware the most popular MaaS

Kaspersky examined various malware families’ sale volumes, as well as mentions, discussions, posts, and search ads on the darknet and other resources regarding MaaS to identify the most popular types. The leader turned out to be ransomware, or malicious software that encrypts data and demands payment for decryption (IoT botnets are not included since they are not distributed under the MaaS model, but DDoS-as-a-Service model). It accounted for 58% of all families distributed under the MaaS model between 2015 and 2022. The popularity of ransomware can be attributed to its ability to generate higher profits in a shorter space of time than other types of malware.

Cybercriminals can ‘subscribe’ to Ransomware-as-a-service (RaaS) for free. Once they become partners in the programme, they pay for the service after the attack happens. The payment amount is determined by a percentage of the ransom paid by the victim, typically ranging from 10% to 40% of each transaction. However, entering the programme is no simple task, as it entails meeting rigorous requirements.

Infostealers accounted for 24% of malware families distributed as a service over the analysed period. These are malicious programs designed to steal data such as credentials, passwords, banking cards and accounts, browser history, crypto wallets data, and more.

Infostealer services are paid through a subscription model. They are priced between $100 and $300 per month. For example, Raccoon Stealer, which was discontinued in early February 2023, could be acquired for $275 per month or $150 per week. Its competitor, RedLine, has a monthly price of $150, and there is also an option to purchase a lifetime license for $900, according to the information posted on the darknet by its operators. Attackers also make use of additional services for extra pay.

Furthermore, 18% of malware families being sold as a service proved to be botnets, loaders, and backdoors. These threats are combined into one group since they often have a common goal; to upload and run other malware on the victim’s device.

“For instance, the price of loader Matanbuchus tends to vary over time. The price in June of the current year starts from $4900 per month. This type of malware is more expensive than infostealers, for example, as the malicious code itself is more complex and the operator provides all the infrastructure in this case – meaning the partners don't have to pay extra for bulletproof hosting services. It is also worth noting that the number of subscribers to Matanbuchus is very limited, allowing attackers to remain undetected for a longer time,” said Alexander Zabrovsky, Digital Footprint Analyst at Kaspersky.

Components of MaaS and malefactor hierarchy

The cybercriminals who operate MaaS platforms are commonly referred to as operators, whereas those who purchase these services are known as affiliates. After closing a deal with operators, affiliates receive access to all necessary components of MaaS, such as command-and-control (C2) panels, builders (programs for quick creation of unique malware samples), malware and interface upgrades, support, instructions, and hosting. The panels are an essential component allowing attackers to control and coordinate the activities of the infected machines. For example, cybercriminals are able to exfiltrate data, negotiate with a victim, contact support, create unique malware samples, and much more.

Some types of MaaS, such as infostealers, allow affiliates to create their own kind of team. Members of such a team are called traffers – cybercriminals who distribute malware to increase profits and generate interest, bonuses, and other payments from affiliates. Traffers do not have access to C2 panel or other tools. Their only purpose is to scale up the spread of the malware. Most often, they achieve this by disguising samples as cracks and instructions for hacking legitimate programs on YouTube and other websites.

“Cybercriminals actively trade illicit goods and services, including malware and stolen data, over the shadow segments of the Internet. By understanding how this market is structured, companies can gain insights into the methods and motivations of potential attackers. Armed with this information, we are able to better help businesses develop more effective strategies that prevent cyberattacks by identifying and monitoring cybercriminal activities, tracking the flow of information, and staying up to date on emerging threats and trends,” added Zabrovsky.

Find out more at www.kaspersky.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire Ops SA Partners with Matrix
News & Events Fire & Safety Residential Estate (Industry)
Fire Ops SA, a South African private fire and rescue service, has announced its partnership with Matrix Vehicle Tracking to launch FireStop, providing Matrix and Beame clients with direct access to a dedicated professional private fire service.

Read more...
SABRIC Annual Crime Statistics 2024
News & Events Security Services & Risk Management Residential Estate (Industry)
SABRIC has released its Annual Crime Statistics for 2024, reflecting a significant decline in financial crime losses, but also warning of the growing threat posed by artificial intelligence (AI) in fraud schemes.

Read more...
Adding AI analytics to security monitoring
SEON South Africa News & Events Perimeter Security, Alarms & Intruder Detection Residential Estate (Industry) AI & Data Analytics
SEON has announced its latest integration with Refraime, an AI-powered video analytics platform designed to elevate CCTV surveillance through real-time object detection and intelligent alerting.

Read more...
Blue Security ranked best reaction team in KZN
News & Events Commercial (Industry)
Blue Security has been ranked the Best Reaction Team in KwaZulu-Natal following its outstanding performance at the SAIDSA Reaction Man Competition 2025, which took place on 25 September at the Ballito Defensive Sport Shooting Club.

Read more...
Sophos launches advisory services to deliver proactive cybersecurity resilience
Information Security News & Events
Sophos has launched a suite of penetration testing and application security services, designed to identify gaps in organisations’ security programs, which is informed by Sophos X-Ops Threat Intelligence and delivered by world-class experts.

Read more...
Why Securex matters more than ever
Securex South Africa News & Events Fire & Safety Facilities & Building Management
Visitors will observe the application of integrated security solutions, including AI-enhanced surveillance, cloud-based access control, cybersecurity tools, and perimeter protection within residential, commercial, logistics, and industrial environments

Read more...
SA’s private security industry receives multi-million USD investment
News & Events Security Services & Risk Management
South Africa's private security sector has attracted significant international attention, with the world’s largest tactical flashlight manufacturer, Nextorch, announcing a major investment in its local operations, Nextorch Africa.

Read more...
Kaspersky highlights biometric and signature risks
Information Security News & Events
AI has elevated phishing into a highly personalised threat. Large language models enable attackers to craft convincing emails, messages and websites that mimic legitimate sources, eliminating grammatical errors that once exposed scams.

Read more...
Keenfinity launches Radionix as new intrusion brand
Perimeter Security, Alarms & Intruder Detection News & Events
Keenfinity Group’s Intrusion & Access Business Unit has launched Radionix as its new brand for intrusion alarm systems, unlocking new potential and growth opportunities.

Read more...
From the editor's desk: Can it be October already?
Technews Publishing News & Events
Welcome to the final SMART Handbook of the year. In this issue, we focus on residential estate security, from the fence to the gate and beyond. We also review our Durban SMART Estate Security Conference, ...

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.