Skip to content

Topic

Malware-as-a-Service

A cybercrime business model in which developers rent malware like stealers, droppers, and RATs to affiliates via subscription, with dashboards and support.

Current stories

securityConfirmed3 publishers

Fake Cloudflare checks on more than 100 hacked sites trick Ukrainians into installing Lunex Stealer

CERT-UA says attackers planted fake Cloudflare checks on more than 100 legitimate websites to get visitors to install Lunex Stealer themselves. Ontinue says its browser components can keep file access after the stealer is deleted, so cleanup has to reach the browsers.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 62%
Investor
Investor 8%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives25
Confidence70
securityConfirmed4 publishers

Meta ads steer Android users to fake Google Play pages carrying the RemControl banking trojan

Group-IB says the RemControl Android banking trojan reaches bank customers in six countries and the Middle East via Meta ads and fake Google Play pages. Its server address sits in a Telegram dead-drop, so the operator can move infrastructure without a new build.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence65
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence65
securityConfirmed3 publishers

WeedHack lost its C2 and kept its funnel: ten fake Minecraft sites still convert victims

McAfee says the WeedHack stealer's control server is dead and its renter dashboard gone, but ten impersonation sites and the search rankings behind them are still delivering victims.

Perspective Coverage

3 publishers
Builder
Builder 18%
Operator
Operator 77%
Investor
Investor 5%

Reality

Evidence55
Adoption40
Hype gap+15
Incentives55
Confidence60