Tuesday, February 25, 2025
HomeBackdoorCybercrime as a Service - Hackers Selling Ransomware, RDP logins and Credit...

Cybercrime as a Service – Hackers Selling Ransomware, RDP logins and Credit Card Details on the Underground Markets

Published on

SIEM as a Service

Follow Us on Google News

The underground markets flooded with a number of hacking tools that can be used to perform various malicious activities in the form of Cybercrime as a Service.

All these tools and services are offered at various pricing range, there are here are a number of dark web markets available such as Berlusconi Market, Empire Market, Wall Street Market, DreamPoint.

An analysis by Eset estimates the cost of products on the dark web markets and their prices.

RaaS

A ransomware-as-as-service is a service allows attackers to host their service in dark web which allows anyone to buy and use the services with their own modifications.

Eset spotted a wide range of ransomware packages for sale on the dark web, the criminals offering Updates, technical support, access to C&C servers.

Also Read: Hackers Offering DDoS-for-Hire Service Powered by Bushido Botnet in Dark Web Markets

RDP Logins

RDP logins sold on the dark web markets giving access to various RDP servers around the globe and the price varies between US$8-15 per server based on country and operating system.

“After buying such access, a cybercriminal might then use it to run ransomware or perhaps to install more discreet malware, such as banking Trojans or spyware.”

Servers for DDoS attacks

Cybercriminals put botnets on sale for launching DDoS attacks or for sending spam emails. the price varies depends on the service and how long you are to use the botnet.

The price ranging from 1 to 24 hours, an example indicates for three hours it costs US$60.

PayPal and credit card accounts

Credit card and Paypal details are for sale in various dark web stores and the charges about 10% of the total credit available in the stolen account.

Some cybercriminals also show what are the tools that they have used in conducting the phishing activity.

So, we can see that cybercriminals, hidden by tools that give them a certain degree of anonymity, have put together a profitable criminal industry, which includes everything from advertising and marketing to customer service, updates, and user manuals.  ESET Said.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read: Cybercrime-as-a-Service – DDoS Attack Services Available in Dark Web Markets for $10 per Hour

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

GitVenom Campaign Abuses Thousands of GitHub Repositories to Infect Users

The GitVenom campaign, a sophisticated cyber threat, has been exploiting GitHub repositories to spread...

UAC-0212: Hackers Unleash Devastating Cyber Attack on Critical Infrastructure

In a recent escalation of cyber threats, hackers have launched a targeted campaign, identified...

Widespread Chrome Malware: 16 Extensions Infect Over 3.2 Million Users

A recent cybersecurity investigation has uncovered a cluster of 16 malicious Chrome extensions that...

Sliver C2 Server Vulnerability Enables TCP Hijacking for Traffic Interception

A significant vulnerability has been discovered in the Sliver C2 server, a popular open-source...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

GitVenom Campaign Abuses Thousands of GitHub Repositories to Infect Users

The GitVenom campaign, a sophisticated cyber threat, has been exploiting GitHub repositories to spread...

UAC-0212: Hackers Unleash Devastating Cyber Attack on Critical Infrastructure

In a recent escalation of cyber threats, hackers have launched a targeted campaign, identified...

Widespread Chrome Malware: 16 Extensions Infect Over 3.2 Million Users

A recent cybersecurity investigation has uncovered a cluster of 16 malicious Chrome extensions that...