Malware-as-a-service (MaaS) is a business model wherein cybercriminals give fellow threat actors access to malicious software and related infrastructure for a fee.
In a sense, MaaS is a malicious variant of the software-as-a-service (SaaS) model. It is also a part of the cybercrime-as-a-service (CaaS) model. So, just like CaaS, marketplaces for MaaS typically reside in the Dark Web.
Read More about Malware-as-a-Service
We’ll tackle the business model in greater detail in the following sections.
How Does the Malware-as-a-Service Business Model Work?
MaaS gained prominence in the cybercriminal underground because attackers no longer have to develop and, sometimes, worry about carrying out malicious campaigns on their own. They can simply employ MaaS providers to develop malware, launch the attack, and direct all the proceeds or send the stolen data to the employer for a fee.
What Kinds of Malware Typically Employ the Business Model?
Over the years, we have seen various malware types distributed via MaaS. We listed some below.
Ransomware
Malware that prevent users from accessing their data by locking them out of their systems or ransomware can be distributed via the ransomware-as-a-service (RaaS) business model. One example would be the Qilin ransomware that made headlines in July 2024.
Data Stealers
Malware that collect data stored on victims’ systems and send it to the attackers or data stealers also often utilize MaaS. An example would be ManticoraLoader, which plagued users in September 2024.
Loaders
Malware that download other malware and unwanted software onto victims’ systems, known as “loaders,” are also offered using the business model. BunnyLoader, which reportedly affected tons of users back in October 2023, would be an example.
Backdoors
Malware that gives attackers remote access to victims’ systems or backdoors can also use MaaS. An example is the Prometheus TDS backdoor, which figured in several attacks back in August 2021.
In many cases, MaaS operators also offer botnets for attackers’ use via the DDoS-as-a-service model.
How Can Organizations Stay Safe from Malware-as-a-Service Attacks?
Thwarting MaaS attacks is no different from protecting your network and systems from any other cyber attack. Here are a few best practices.
- Do not click suspicious links.
- Don’t download unsolicited attachments.
- Use a reputable, robust anti-malware solution.
- Ensure all systems have the latest patches.
- Use strong passwords.
- Never click links in pop-ups.
- Be cautious about phishing emails.
- Implement strong network security measures, such as web application firewalls and intrusion detection solutions.
- Educate employees about MaaS risks and how to avoid them.
- Back up data regularly.
- Despite the best defenses, determined attackers may still breach them, so be sure to have a well-defined and practiced incident response plan.
—
We are bound to see more of MaaS in the future, so knowing how to stay protected against the threat is a must.
Key Takeaways
- MaaS is a business model where cybercriminals give fellow threat actors access to malicious software and related infrastructure for a fee.
- Ransomware, data stealers, loaders, and backdoors are just some of the malware types that employ the business model.
- Refraining from clicking links and opening email attachments from people you don’t know is a good practice against MaaS.
Sources
- https://encyclopedia.kaspersky.com/glossary/malware-as-a-service-maas/
- https://www.europol.europa.eu/media-press/newsroom/news/international-cybercrime-malware-service-targeting-thousands-of-unsuspecting-consumers-dismantled
- https://www.tripwire.com/state-of-security/what-malware-service-maas



