Malware-as-a-Service (MaaS) is now responsible for more than half (57%) of all cyber-threats to organisations, having risen by almost a fifth over the latter part of 2024, figures which mark the dramatic growth of Cybercrime-as-a-Service models over the past year, according to new research from Darktrace.
The cybersecurity firm’s latest Annual Threat Report found that the persistence of CaaS models, particularly Ransomware-as-a-Service (RaaS) and MaaS are growing rapidly as less experienced threat actors gain access to sophisticated new tools to carry out their disruptive attacks.
According to the report, these incidents now follow noticeable trends in technique, such as the use of phishing emails as an attack vector, the exploitation of legitimate tools to mask C2 communication, and the exfiltration of data to cloud storage services.
Among these tactics, the researchers found that phishing remains attackers’ preferred method of entry, with over 30.4 million phishing emails detected across Darktrace’s customer fleet, containing over 940,000 malicious QR codes.
Of those emails, 38% were spear-phishing attempts tailored to attack high-value individuals, 32% used novel social engineering techniques including AI generated text, and a worrying 55% passed through all existing security layers before detection.
Attackers are also increasingly targeting third-party services, including QuickBooks, Zoom Docs, Adobe, and Microsoft SharePoint as phishing lures, in the hope of leveraging these trusted platforms to bypass traditional security measures.
Over the past year, Darktrace observed substantial use of legitimately authenticated senders and established domains, with 96% of phishing emails detected using existing domains rather than registering new ones.
“Email is at the forefront of the evolving threats we’re seeing across the threat landscape,” said Nathaniel Jones, VP of threat research at Darktrace.
“Ransomware-as-a-Service tools, combined with the growing use of AI, are allowing even low-skilled attackers to engineer convincing, targeted email attacks at scale, and making it harder than ever for traditional security measures to keep up.”
The study also found a growing use of Remote Access Trojans (RATs) over H2 2024, rising to 46% from just 12% in the first half of the year.
Darktrace said that the growing use of RATs, which allow attackers to remotely control infected devices to conduct further malicious activity like data exfiltration, credential theft, and surveillance, underscores the rising complexity of the threat landscape, and growing risk of day-to-day threats.
This technique is being used in unison with an ongoing campaign to attack vulnerabilities in edge and perimeter network technologies, with Darktrace finding 40% of malicious activity in the first half of the year involved the exploitation of internet-facing devices.
Recommended reading
- ‘Big Game’ Ransomware Tactics Drives Spike in Attacks
- Is Automation Fuelling a New Era of Cyber-crime?
- Phishing Attacks Spiked in 2024 As Other Cyber-threats Declined
In addition to these vulnerabilities, Darktrace also observed a rise in threat actors using stolen credentials to log into remote network access solutions like VPNs, allowing them to gain initial access to networks before using legitimate tools and processes already present on infected systems to achieve their goals while remaining undetected.
“The combination of Cybercrime-as-a-Service, automation and AI are increasing the sophistication and diversity of attack techniques faster than ever – from AI-enhanced phishing campaigns to evolving ransomware strains,” said Jones.
“Detecting and responding to threats in progress is no longer sufficient. Organisations must prioritise cyber-resilience by proactively addressing weaknesses across systems, people, and data before attackers can exploit them.”





