PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Malware-as-a-Service Lowers the Technology Bar for Threat Actors, Study Finds

By Wesley Grant
February 19, 2025
in Analysts Coverage, Cybersecurity, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
malware-as-a-service

Closeup of a keyboard in ultraviolet light

Malware-as-a-Service (MaaS) now accounts for over half of cyber threats targeting organizations. These threats have become more prevalent as cybercriminals increasingly outsource their operations.

According to a research from Darktrace, the use of MaaS tools picked up steam in the latter half of 2024, making up 57% of identified fraud activities. One of the most commonly used malware tools is Remote Access Trojan (RAT) software, which allows cybercriminals to take control an infected device remotely. Once inside, they can steal data, harvest credentials, or monitor a user’s activities.

MaaS is a subset of the broader Cybercrime-as-a-Service (CaaS) model, where criminals offer illicit software services to individuals or groups for financial gain. These services—sold through CaaS platforms—can include ransomware attacks, data breaches, and Distributed Denial of Service attacks that can cripple an organization’s website for days or even weeks.

Phishing for Entry

The most common entry method for CaaS attacks remains phishing.  Darktrace’s survey uncovered over 30 million phishing emails in the past year alone. Of these attempts, 38% were highly customized spear phishing attacks targeting high net-worth individuals.

However, spear phishing can also be directed at specific customer bases, as seen in the attacks on CrowdStrike’s customers following the global outage caused by the company’s software update last year.

Impersonating Services

As with the attacks targeting CrowdStrike’s customers, Darktrace observed that many phishing communications impersonated third-party services that organizations frequently rely on. The report identified phishing emails that appeared to be from Microsoft SharePoint, Adobe, and QuickBooks, among others.

Cybercriminals have also increasingly impersonated major merchants to scam consumers. Separate data from the Federal Trade Commission revealed that Best Buy, Amazon, and PayPal were among the most frequently impersonated retailers.

The advent of new technologies like artificial intelligence has made these scams more effective. According to Darktrace, 32% of phishing attempts now employ novel social engineering techniques designed to manipulate recipients. Many of these messages feature AI-generated text that is both complex and compelling.

As CaaS platforms provide advanced tools to even tech-challenged threat actors, organizations face growing risks in an evolving fraud landscape filled with emerging threats.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: CybercrimeCybercrime-as-a-ServiceMalwareMalware-as-a-ServiceRansomware

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    payment cards as customer experience

    From Hygiene Factor to Hero Product: Why the Card Deserves a Second Look

    May 5, 2026
    cobrand credit card

    Co-Branded Credit Cards Still Hold Promise for Smaller Issuers

    May 4, 2026
    Dual-rail recurring billing for agentic commerce

    Fueling Agentic Commerce with Dual-Rail Recurring Billing

    May 1, 2026
    credit union p2p

    How Should Legacy Banks Compete with Chime?

    April 30, 2026
    Prepaid cards for payroll and tipping

    Tips on a Prepaid Card: A Practical Solution with Broad Industry Impacts

    April 29, 2026
    credit-push fraud

    Inside the Battle Against Credit-Push Fraud: What’s Changing

    April 28, 2026
    real-time payments fraud

    Stopping Fraud in Real-Time Payments Before It Starts

    April 27, 2026
    Navigating Global Fintech Regulations Through Strategic Regulatory Arbitrage

    PACE Act Could Open Fed Payment Rails Beyond Banks

    April 24, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result