Malware-as-a-Service (MaaS)
Malware-as-a-service is the criminal business model of renting ready-made malware, infrastructure and support to attackers on a subscription basis.
Malware-as-a-service (MaaS) is the criminal mirror of the software industry's subscription model: a developer builds and maintains malware, then rents it — with hosting, control panels, update cycles, and customer support — to attackers who could never write it themselves. The customer picks a tier, pays in cryptocurrency, and receives a working attack capability the same day. MaaS is the main reason the volume of sophisticated attacks has decoupled from the number of sophisticated attackers.
How it works
The economics were laid bare when Microsoft and international law enforcement dismantled Lumma Stealer in May 2025: court filings described subscription tiers from $250 to $20,000, roughly 400 active criminal customers, and over 394,000 devices infected in a two-month window — a full breakdown is in our infostealer guide. The pattern generalizes. Infostealer operators rent the stealer and sell the harvested "logs"; ransomware-as-a-service groups franchise their lockers to affiliates for a revenue share; phishing kits and phishing-as-a-service panels handle the credential-harvesting front end; initial access brokers sell the footholds that the malware produces. Each layer specializes, which means the person who phishes your employee, the person who wrote the malware, and the person who ultimately ransoms your network are usually three different actors who never meet.
How to defend against it
You cannot arrest your way past a business model, so plan for cheap, polished, high-volume attacks as the permanent baseline. Concretely: assume commodity malware quality is professional grade even when the attacker is not, so lean on layered controls — endpoint detection, egress filtering, phishing-resistant MFA — rather than expecting clumsy tradecraft. And because MaaS tooling still almost always enters through a person (a phishing email, a fake update, a cracked download), keep the human layer measured and trained: security awareness training and simulation directly raise the cost of the one step the subscription can't automate — persuading your employee.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo