The modern cybercrime ecosystem operates as a sophisticated, multi-stage supply chain, a significant departure from the outdated image of a lone attacker. This intricate structure involves distinct specialized roles, each with its own pricing model, allowing for a division of labor that enhances efficiency and profitability for criminal enterprises.
The initial stage of this supply chain is handled by "harvesters," who specialize in deploying information-stealing malware. Their primary objective is to collect sensitive data, particularly credentials and session cookies. These stolen credential logs are then sold on illicit markets, typically fetching between $5 and $50. The acquisition of session cookies is particularly valuable as it enables attackers to bypass multi-factor authentication (MFA) mechanisms, streamlining subsequent access attempts.
Following the harvesting stage, "brokers" enter the picture. These individuals or groups are responsible for verifying the legitimacy of the stolen access and then reselling it to other cybercriminals. Listings for verified access are commonly priced under $1,000, reflecting the value added by confirming the usability of the compromised accounts or systems.
The third stage involves "ransomware-as-a-service" (RaaS) operators. These entities develop and maintain the sophisticated toolkits and infrastructure required to execute ransomware attacks. They provide the technical framework, including the ransomware payload, command-and-control servers, and payment portals, to other criminals who lack the technical expertise to build such systems themselves.
"Affiliates" constitute the fourth stage of the supply chain. These are the individuals or groups who lease or purchase the RaaS toolkits and then actively conduct the intrusions into target networks. They are responsible for deploying the ransomware, negotiating with victims, and ensuring the successful encryption and potential decryption of data.
The final stage of the cybercrime supply chain is managed by "launderers." Their role is critical for converting illicit gains, typically cryptocurrency obtained from ransomware payments, into spendable assets while obscuring the origin of the funds. This process involves various techniques to move and clean the proceeds, making them difficult to trace by law enforcement.
This five-stage model demonstrates a highly organized and commercialized approach to cybercrime, where specialized groups focus on specific tasks, from initial data theft to financial obfuscation, each contributing to and profiting from the overall operation.






