Executive Summary
In early 2024, cybersecurity researchers observed a surge in Crime-as-a-Service (CaaS) operations leveraging a subscription-based model. Attackers now rent access to advanced phishing kits, infostealer logs, Remote Access Trojans (RATs), and one-time password bots on popular chat platforms like Telegram, dramatically lowering the barrier to entry for cybercrime. These CaaS platforms enable even low-skilled actors to execute sophisticated intrusion campaigns targeting organizations across industries, often resulting in credential theft, ransomware outbreaks, and large-scale data breaches. This operational shift has enabled attackers to strike at scale and adapt quickly to new defenses, amplifying business risks and potential regulatory violations.
The rise of CaaS signifies a pivotal threat evolution: democratized, on-demand cybercrime. Organizations must now address not just known threat actors, but a growing pool of opportunists leveraging plug-and-play hacking tools. This trend is accelerating, leading to urgent pressures for improved identity controls, network segmentation, and rapid anomaly detection.
Why This Matters Now
Crime-as-a-Service is fueling a dramatic increase in highly capable, low-skill attackers. The urgent threat is the accessibility of advanced exploit tools, making coordinated cyberattacks more frequent and harder to trace. Without proactive controls, organizations face greater risks of breach, financial loss, and regulatory penalties.
Attack Path Analysis
The attacker gained initial access by leveraging commodity phishing kits and infostealer logs obtained via Crime-as-a-Service platforms to compromise user credentials. They escalated privileges through misuse of valid access and leveraging remote access tools rented on a SaaS-like basis. With elevated access, lateral movement occurred across internal workloads and between cloud resources using techniques such as remote desktop tools or API calls. The attacker established command and control using covert channels, possibly via shadow IT SaaS or unauthorized VPNs. Sensitive data and credentials were exfiltrated using encrypted outbound channels or direct API exports. Finally, the adversary impacted the business by deploying ransomware, deleting backups, or causing operational disruption, all enabled by the as-a-service cybercrime ecosystem.
Kill Chain Progression
Initial Compromise
Description
Attackers acquired and used credential dumps and phishing kits to obtain access to cloud accounts via infostealer logs and SaaS-based tools.
Related CVEs
CVE-2020-5902
CVSS 9.8A remote code execution vulnerability in F5 BIG-IP Traffic Management User Interface (TMUI) allows unauthenticated attackers to execute arbitrary system commands.
Affected Products:
F5 Networks BIG-IP – 15.1.0.4 and earlier, 14.1.2.6 and earlier, 13.1.3.4 and earlier, 12.1.5.2 and earlier, 11.6.5.2 and earlier
Exploit Status:
exploited in the wildCVE-2019-19781
CVSS 9.8A directory traversal vulnerability in Citrix Application Delivery Controller (ADC) and Gateway allows unauthenticated remote attackers to execute arbitrary code.
Affected Products:
Citrix ADC and Gateway – 13.0 before 13.0-58.32, 12.1 before 12.1-55.18, 12.0 before 12.0-63.13, 11.1 before 11.1-65.15, 10.5 before 10.5-70.18
Exploit Status:
exploited in the wildCVE-2018-13379
CVSS 9.8A path traversal vulnerability in Fortinet FortiOS SSL VPN web portal allows unauthenticated attackers to download system files via specially crafted HTTP resource requests.
Affected Products:
Fortinet FortiOS – 6.0.0 to 6.0.4, 5.6.3 to 5.6.7, 5.4.6 to 5.4.12
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Credentials from Password Stores
Obfuscated Files or Information
Command and Scripting Interpreter
Application Layer Protocol
User Execution
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Managed Identities and Least Privilege
Control ID: Identity Pillar PR.AC-1
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21(2) (d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Crime-as-a-Service models directly target banking credentials and payment systems, exploiting encryption gaps and requiring enhanced east-west traffic security for compliance.
Health Care / Life Sciences
HIPAA-regulated entities face elevated ransomware risks from accessible phishing kits and RAT rentals, necessitating zero trust segmentation and encrypted traffic controls.
Information Technology/IT
SaaS subscription crime models exploit cloud infrastructure vulnerabilities, demanding multicloud visibility controls and Kubernetes security for service-to-service communications protection.
Government Administration
Low-skill attackers accessing advanced capabilities through crime-as-a-service threaten critical infrastructure, requiring comprehensive threat detection and anomaly response systems.
Sources
- Cybercrime Goes SaaS: Renting Tools, Access, and Infrastructurehttps://www.bleepingcomputer.com/news/security/cybercrime-goes-saas-renting-tools-access-and-infrastructure/Verified
- Top Routinely Exploited Vulnerabilitieshttps://www.cisa.gov/sites/default/files/publications/AA21-209A_Joint_CSA%20Top%20Routinely%20Exploited%20Vulnerabilities.pdfVerified
- F5 BIG-IP TMUI RCE Vulnerability CVE-2020-5902https://support.f5.com/csp/article/K52145254Verified
- Citrix ADC Security Bulletin for CVE-2019-19781https://support.citrix.com/article/CTX267027Verified
- Fortinet FortiOS Path Traversal Vulnerability CVE-2018-13379https://fortiguard.com/psirt/FG-IR-18-384Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, workload isolation, east-west security, and strict egress controls would have limited attacker movement and data exfiltration at every kill chain stage. CNSF capabilities enable centralized, identity-driven policy, real-time threat detection, and enforce least privilege across multi-cloud environments to break the chain of Crime-as-a-Service-enabled attacks.
Control: Multicloud Visibility & Control
Mitigation: Unusual login patterns and unauthorized access attempts would trigger rapid detection and alerting.
Control: Zero Trust Segmentation
Mitigation: Access to critical cloud services is limited by strict, identity-based segmentation policies.
Control: East-West Traffic Security
Mitigation: Lateral traversal between workloads and internal resources is blocked without explicit policy.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound connections to unauthorized C2 infrastructure are prevented or flagged in real-time.
Control: Cloud Firewall (ACF)
Mitigation: Unauthorized data transfer or bulk outbound traffic is detected and blocked.
Destructive or ransomware actions are rapidly detected and contained.
Impact at a Glance
Affected Business Functions
- Network Operations
- Data Management
- Customer Services
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential exposure of sensitive customer data, including personal identifiable information (PII) and financial records, due to unauthorized access facilitated by exploited vulnerabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation across all cloud workloads, users, and network flows to limit unauthorized access and movement.
- • Implement advanced egress policy controls and cloud firewalls to prevent covert C2, shadow SaaS, and unauthorized exfiltration.
- • Increase threat detection and response capabilities focused on baselining, anomaly, and behavioral analytics for early-stage discovery of commodity toolkit abuse.
- • Improve east-west traffic security and microsegmentation to contain lateral movement across regions, clusters, and hybrid environments.
- • Centralize multi-cloud visibility, incident response, and policy automation using Cloud Network Security Fabric capabilities.



