The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents coughing up credentials — the criminal stack is industrialising.

Three things landed this week that, taken together, say more about the state of the criminal economy than any single breach disclosure could.
First: a supply chain attack toolkit surfaced in a public code repository. Not a proof-of-concept buried in a researcher's GitHub. A functional kit, indexed and discoverable, of the kind that lowers the barrier for the next round of npm and PyPI poisoning campaigns. The leak matters less for what it contains than for who can now read it. Operators who couldn't build this six months ago can fork it tonight.
Second: a remote access trojan being advertised at $5,000 a month. The pitch is browser cloning — full session, cookies, stored credentials, fingerprint, the lot. Drop the clone onto an attacker-controlled machine and you walk past MFA without ever touching the victim again. The price tag puts it firmly in the professional tier. This isn't a script-kiddie tool; it's priced for affiliates who expect ROI inside a week.
Third, and the one that should bother anyone shipping agentic features: researchers demonstrated that AI agents can be socially engineered into leaking real credentials. Not hallucinated secrets. Real ones, pulled from the agent's own context or connected tools, handed over after the kind of prompt manipulation that wouldn't fool a junior SOC analyst but reliably fools an LLM with tool access.
The through-line is polish.
Mule networks now operate with onboarding flows, tiered payouts and dispute resolution. Initial access brokers publish price lists. RaaS crews run affiliate portals with SLAs. The malware-as-a-service vendor behind that $5K RAT almost certainly has a support channel on Telegram, a changelog, and a refund policy for non-working builds. None of this is new in concept. What's new is the consistency. The rough edges are gone.
That has downstream consequences for defenders. When tooling commoditises, attribution gets harder — the same kit shows up across unrelated crews, and the TTPs you mapped to one group last quarter are this quarter's commodity. Detection logic built around operator quirks ages out faster. Threat intel that treats groups as fixed entities starts to mislead.
It also reshapes what "sophisticated" means. A year ago, browser session theft at scale required custom development. Now it's a subscription. A year ago, supply chain compromise required patience and tradecraft. The kit just leaked.
The AI agent finding is the one to watch. Enterprises are wiring LLMs into ticketing systems, identity providers and code repos at a pace that outruns any threat model. If an agent can be talked into exfiltrating a credential it legitimately holds, the perimeter isn't the network or the endpoint. It's the prompt.
None of the three stories on their own would lead a bulletin. Together they describe a market that has finished its awkward adolescence.



