In our 2025 State of the Underground report, we found that 384 unique varieties of malware were sold across the top three criminal forums in 2024, a 10% increase from 349 in 2023, signifying an expansion in the underground malware marketplace. These figures reflect malware explicitly offered for sale (not shared freely), and each distinct version or naming variation is counted independently.
The malware market is diverse and evolving, with some stand-out players. For the past three years, stealers have consistently ranked as the most prevalent malware type sold, followed closely by Remote Access Trojans (RATs). The popularity of stealers is unsurprising given their ability to quickly monetize information from the targeted computer. According to Bitsight Threat Intelligence, the vast majority of these malicious tools target Windows systems, while a smaller segment focuses on Android. Other specialized malware variants have emerged targeting major tech platforms, underscoring how cybercriminals innovate to exploit new opportunity gaps.
In this blog post we’ll give an introduction to the Malware-as-a-Service economy, highlight some notable examples, and provide advice on how to protect your organization.
What is Malware-as-a-Service?
Malware‑as‑a‑Service (MaaS) replicates legitimate Software-as-a-Service (SaaS) in structure but serves the underground; developers offer pre-built malware (e.g. ransomware, spyware, trojans, adware) for rent or purchase. This allows threat actors, even those with minimal technical skills (derogatorily called “script kiddies”), to conduct complex cyberattacks without ever developing code. This model is particularly attractive to individuals with limited technical expertise, as it empowers them to launch effective cyberattacks, often with the ultimate goal of extorting victims through ransomware, without needing to develop or understand the underlying malware code.
Key features
Malware-as-a-Service (MaaS) platforms offer a broad range of malicious software tailored to different attack objectives. These include ransomware for extortion-based campaigns, trojans that enable remote access and system compromise, spyware for surveillance and data theft, and adware used to generate fraudulent ad revenue. Buyers can select specific malware types depending on their goals, such as stealing credentials, constructing botnets, or disrupting operations.
Much like legitimate Software-as-a-Service (SaaS) offerings, MaaS platforms typically operate on a subscription-based model with tiered pricing. Higher-tier subscriptions often include advanced features such as obfuscation modules to bypass detection, geofencing capabilities to target victims in specific regions, custom payload creation tools, and even 24/7 technical support and usage analytics.
These services are designed to be highly accessible. Many include user-friendly dashboards, admin consoles, and control panels that make it easy to launch and manage malware campaigns, no deep technical expertise required. This “plug-and-play” approach has effectively commercialized cybercrime and broadened the pool of potential threat actors.
Impact on organizations
By lowering technical barriers, MaaS has increased the scale and sophistication of cyber threats. As a result, less experienced attackers can mount high-impact campaigns rapidly. The resulting consequences for organizations include financial loss, operational disruption, reputational damage, and broader erosion of trust in digital systems.