The Malware Economy
Overview
Section titled “Overview”Modern malware operates within a sophisticated criminal economy with a clear division of labour that has dramatically lowered the skill barrier for conducting advanced attacks.
Ecosystem Map
Section titled “Ecosystem Map”┌─────────────────────────────────────────────────────────────┐│ MALWARE ECONOMY │├─────────────────────────────────────────────────────────────┤│ EXPLOIT BROKERS INITIAL ACCESS BROKERS (IABs) ││ ┌─────────────────┐ ┌─────────────────────────────┐ ││ │ Sell 0-days to │ │ Sell network access │ ││ │ nation-states/ │ │ (VPN, RDP, VPN, web shells) │ ││ │ criminals │ │ on dark web markets │ ││ └─────────────────┘ └─────────────────────────────┘ ││ │ │ ││ ▼ ▼ ││ ┌─────────────────────────────────────────────────────┐ ││ │ RANSOMWARE-AS-A-SERVICE (RaaS) │ ││ │ Developers rent tools → Affiliates execute attacks │ ││ │ Revenue share: 20-30% to developer, 70-80% to aff. │ ││ │ Examples: LockBit, BlackCat, Conti, REvil │ ││ └─────────────────────────────────────────────────────┘ ││ │ ││ ▼ ││ ┌─────────────────────────────────────────────────────┐ ││ │ MALWARE-AS-A-SERVICE (MaaS) │ ││ │ Turnkey tools for rent: loaders, stealers, RATs │ ││ │ Lowers skill barrier dramatically │ ││ │ Examples: Emotet, TrickBot, Qakbot, IcedID │ ││ └─────────────────────────────────────────────────────┘ ││ │ ││ ▼ ││ ┌─────────────────────────────────────────────────────┐ ││ │ CRYPTOCURRENCY INFRASTRUCTURE │ ││ │ Anonymous payments, mixing, laundering │ ││ │ Enables the entire economy │ ││ └─────────────────────────────────────────────────────┘ │└─────────────────────────────────────────────────────────────┘Key Players
Section titled “Key Players”| Role | Function | Examples |
|---|---|---|
| Exploit Brokers | Discover/sell 0-days | Zerodium, Exodus, Crowdfense |
| IABs | Sell initial access | Dark web markets (Genesis, Russian Market) |
| RaaS Developers | Build/maintain ransomware | LockBit, BlackCat, Conti, REvil |
| RaaS Affiliates | Execute attacks | Lower-skilled, high volume |
| MaaS Operators | Rent loaders/stealers | Emotet, TrickBot, IcedID, Qakbot |
| Crypto Launderers | Mix, tumble, cash out | Tornado Cash (sanctioned), mixers |
| Bulletproof Hosting | Resilient C2 infrastructure | Abuse-resistant ISPs |
Revenue Model
Section titled “Revenue Model”| Model | Developer Share | Affiliate Share |
|---|---|---|
| RaaS | 20-30% | 70-80% |
| MaaS | Subscription ($100-5000/mo) | N/A |
| IAB | Per-access ($100-$50K+) | N/A |
| Exploit Broker | Per-exploit ($5K-$2M+) | N/A |
Impact on Defence
Section titled “Impact on Defence”| Effect | Implication |
|---|---|
| Lowered Skill Barrier | Script kiddies → advanced attacks |
| Increased Volume | Industrial-scale attacks |
| Specialisation | Each actor optimises their niche |
| Resilience — Decapitation harder | Decentralised, replaceable components |
| Innovation Speed — Market forces | Rapid feature adoption (e.g., double extortion) |
Defence Implications
Section titled “Defence Implications”- ✅ Threat Intel — Track RaaS/MaaS/IAB ecosystems
- ✅ Attribution — Focus on TTPs, not just IOCs
- ✅ Disruption — Target infrastructure (C2, payment, hosting)
- ✅ Financial Investigation — Follow the crypto
- ✅ International Cooperation — Cross-border disruption
Related
Section titled “Related”- Ransomware — RaaS model
- Botnet — Infrastructure
- APT Malware — Nation-state economy
- Cryptominer — Revenue generation