Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

The demand for hacking tools and malware is greater than the current supply

Add as a preferred source on Google

A 34-page report published by Positive Technologies reveals a high demand for malware creation on the dark web: Three times greater than the current supply. The report is based on 25 Russian and English-based dark web sites with around 3 million registered individuals to reveal the most-popular malware in use today, the cost of attack services, and more.

“Such utilities are becoming increasingly available as a result of partner programs, malware leasing, and as-a-service distribution models,” the firm states. “This trend is not only causing a rise in the number of cyber-incidents, but seriously hindering investigative efforts to properly attribute attacks.”

Recommended Videos

What is the dark web? Of all the internet pages available on the web, only four percent are indexed in search engines. The remaining “hidden” pages fall into the “deep web” consisting of private forums, databases and other resources both legal and illegal. It’s this illegal portion that falls under the dark web banner: A place you should never, ever visit without full protection.

On the dark web you’ll find the “shadow market,” a place where illegal products and services are sold. Most of what you’ll find on this market can be split into four categories: Malware (ransomware, miners), Exploits (known, zero-day), Data (credit cards, banking), and Access (user credentials).

Image used with permission by copyright holder

Currently, the most widely used malware is the cryptominer, which seizes PCs and mines digital coins for hackers. In second place are hacking utilities followed by botnet malware, Remote Access Trojans, and ransomware. The remaining 55 percent deals with creation and distribution.

On the pricing front, the most expensive “service” can cost more than $4,500 for attacking an organization, depending on the difficulty. Malware designed for attacking ATM machines has a starting cost of $1,500 while compromising a website to gain full control can cost a mere $150. But that’s just a sample: Any type of attack is possible if you have the funds, such as a DDoS attack for around $50 per day.

The average cost of malware in dollars. Image used with permission by copyright holder

According to the report, the most requested hack-for-hire request is finding vulnerabilities followed by accessing email accounts. Social network account and email hacks are at the top of the commonly offered services list, as these attacks are supposedly the easiest to perform.

The report also notes the prison time you’ll receive for hacks and attacks. For instance, hacking the accounts of U.S. government officials will land you a five-year prison sentence while conducting a DDoS attack requires a minimum of one year in prison. If you want a long-term stay, managing a shadow service will place you behind bars for 35 years.

Positive Technologies ultimately points out that the fight against cybercriminals is only getting harder. Just in the first quarter of 2018 alone, the number of hacker-related incidents was up 32 percent versus the same quarter in 2017. The fact that the demand for new hacking tools is greater than the current supply is alarming enough.

A good way to protect yourself is to routinely change passwords, use two-factor authentication, biometrics, and/or use physical USB-based security keys.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AI browsers like Perplexity Comet can be tricked into spilling your password through BioShocking exploit
Six AI browsers were found leaking saved passwords and many of them haven't fixed it yet.
MacBook Air in hand, Comet browser loaded—let’s see what Perplexity’s AI can really do

Security researchers just found a strange way to trick AI browsers into handing over your passwords. They managed to trick AI browser agents into exposing sensitive data like saved passwords, session cookies, and private tokens by disguising the theft as part of a harmless "game."

The technique is called BioShocking, named after the popular video game BioShock, where a brainwashed character is manipulated into believing a false reality. Once an AI browser falls for the same trick, it stops following its own safety rules entirely.

Read more
Google Play’s latest speed boost goes way beyond the phone
Play Store v52.1 targets app install performance across Android devices, including cars, TVs, watches, tablets, and phones.
Google Play Store Photo

Google is rolling out Play Store v52.1 with changes built around a practical Android problem, getting apps installed more smoothly on very different kinds of hardware.

The update focuses on Play Store infrastructure, with Google pointing to stability, performance, and better memory use while a device adds an app. That install path now has to work on phones, tablets, Wear OS watches, Google TV, Android TV, Android Auto, and cars running Android Automotive.

Read more
Peacock Premium Plus joins YouTube as the streaming bundle battle gets messier
The $16.99 subscription brings Peacock’s sports-heavy catalog into YouTube, with account details still unclear.
Adult, Female, Person

Peacock Premium Plus is now available through YouTube Primetime Channels, giving viewers a new way to add a major streaming service inside YouTube.

The $16.99-per-month subscription brings Peacock’s live sports, NBC and Bravo shows, originals, Universal movies, Telemundo programming, and Spanish-language FIFA World Cup 2026 coverage into YouTube’s channel marketplace.

Read more