NEW

Passguard ranked #2 Cyber Start-up of Europe

Read more

English

Contact

Login

NEW

Passguard ranked #2 Cyber Start-up of Europe

Read more

Malware

What is malware-as-a-service (MaaS)?

What is malware-as-a-service (MaaS)?

·

Written by Anthony Wedding

— co-founder

Short answer

Malware-as-a-Service (MaaS) is a business model in which infostealer developers rent their tools to other criminals through subscription plans, typically priced between 100 and 1,000 dollars per month. Most active infostealers, including Lumma, RedLine, and Raccoon, operate this way, which has made infostealer deployment accessible to anyone regardless of technical skill. This model drives the growing volume of infostealer attacks organizations face.

How MaaS works

MaaS operators develop and maintain the malware, host command-and-control infrastructure, and provide a management panel where customers can configure campaigns, view stolen data, and download logs. Pricing typically ranges from 100 to 1,000 dollars per month, depending on the stealer’s capabilities and the level of support included.

Some MaaS platforms even offer customer support, feature updates, and documentation, directly mirroring legitimate SaaS businesses. For infostealers specifically, this means constant improvement in evasion techniques, new data targets, and faster exfiltration, making them increasingly difficult to detect.

Why MaaS drives the infostealer explosion

  • Lower barrier: anyone with cryptocurrency can deploy a sophisticated infostealer, with no coding required.

  • Rapid innovation: MaaS developers compete on features, better evasion, more data types, and faster exfiltration, which drives constant improvement.

  • Scale: thousands of operators can run campaigns simultaneously using the same malware, multiplying the volume of infections.

  • Specialization: the ecosystem splits into roles, including developers, distributors, access brokers, and end-users of stolen data, with each role optimizing its part.

Impact on organizations

MaaS means the volume of infostealer attacks will continue to grow: more operators, more campaigns, more stolen sessions. Defending against this requires monitoring the output of these campaigns, the stolen logs and active sessions that appear on criminal marketplaces.

Passguard continuously monitors these criminal marketplaces, and alerts your organization the moment stolen sessions linked to your systems are listed for sale.

Detect infostealers before they strike

Trusted by security experts • See results in 1 minute

Detect infostealers before they strike

Trusted by security experts • See results in 1 minute

Detect infostealers before they strike

Trusted by security experts • See results in 1 minute