The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents handing over real credentials: the criminal stack is industrialising.

Key points
- A supply chain attack toolkit surfaced in a public code repository this week, indexed and findable by anyone.
- A remote access trojan is being advertised at $5,000 a month, offering full browser session cloning that bypasses multi-factor authentication.
- Researchers demonstrated that AI agents can be manipulated into leaking real credentials, not hallucinated ones.
- When tooling commoditises, attribution gets harder and threat intelligence built around fixed group profiles starts to mislead.
- The AI agent risk is the sharpest near-term concern for any organisation wiring LLMs into identity or code systems.
What happened this week?
Three things landed that together say more about the criminal economy than any single breach disclosure.
First: a supply chain attack toolkit surfaced in a public code repository. Not a proof-of-concept buried in a researcher's GitHub. A functional kit, findable by anyone, of the kind that lowers the barrier for the next round of npm and PyPI poisoning campaigns. The leak matters less for what it contains than for who can now read it. Operators who couldn't build this six months ago can fork it tonight.
Second: a remote access trojan advertised at $5,000 a month. The pitch is browser cloning: full session, cookies, stored credentials, fingerprint. Drop the clone onto an attacker-controlled machine and you walk past MFA without ever touching the victim again. The price tag puts it in the professional tier. It's priced for affiliates who expect ROI inside a week.
Third, and the one that should bother anyone shipping agentic features: researchers demonstrated that AI agents can be socially engineered into leaking real credentials. Not hallucinated secrets. Real ones, pulled from the agent's context or connected tools, handed over after prompt manipulation that wouldn't fool a junior SOC analyst but reliably fools an LLM with tool access.
Why does the polish matter?
Mule networks now operate with onboarding flows and tiered payouts. Initial access brokers publish price lists. RaaS crews run affiliate portals with service-level agreements. The vendor behind that $5,000 RAT almost certainly has a support channel on Telegram and a refund policy for non-working builds. None of this is new in concept. What's new is the consistency. The rough edges are gone.
We first covered the criminal-economy churn in this direction on 4 June in "The Week the Tape Came Off", where cheap C2 infrastructure and agentic AI failures pointed the same way. The direction hasn't changed; the product quality has.
Should defenders rethink what sophisticated means?
Yes, and quickly. When tooling commoditises, attribution gets harder: the same kit shows up across unrelated crews, and the TTPs you mapped to one group last quarter are this quarter's commodity. Detection logic built around operator quirks ages out faster.
A year ago, browser session theft at scale required custom development. Now it's a subscription. A year ago, supply chain compromise required patience and tradecraft. The kit is public.
Should you worry about AI agents?
Enterprises are wiring LLMs into ticketing systems and identity providers at a pace that outruns any threat model. If an agent can be talked into exfiltrating a credential it legitimately holds, the perimeter isn't the network or the endpoint. It's the prompt. That's the finding to take seriously here, not because it's surprising, but because the organisational response hasn't caught up.
None of the three stories alone would lead a bulletin. Together they describe a market that has finished its awkward adolescence.



