When people hear the word cybercrime, they often picture a technically gifted attacker developing custom malware from scratch. That happens, but it is not how most modern attacks work.
A recent article by cybersecurity writer Maya Levi examines common tools used in cybercrime, including phishing kits, information stealers, ransomware, botnets, network scanners, credential dumping utilities, and artificial intelligence tools. What interested me most was not the list itself. It was the larger picture behind it.
Cybercriminals rarely rely on one program or technique. They combine stolen credentials, rented infrastructure, legitimate administration software, malware, and social engineering into a complete attack chain. In many cases, different people handle different stages of the operation.
This makes modern cybercrime look less like isolated hacking and more like an organized service economy.
The cybercrime service model
A criminal no longer needs to understand every part of an attack. Someone else can collect email addresses, build fake login pages, operate a botnet, or sell access to compromised business networks.
This specialization has produced services such as phishing as a service, malware subscriptions, residential proxy networks, access brokerage, and ransomware affiliate programs. One operator may gain initial access to a company and sell it to another group. That group can steal data, deploy ransomware, and pass the proceeds through additional services designed to obscure the money trail.
The business model matters because it lowers the technical barrier to entry. A person with limited programming knowledge can purchase tools and infrastructure that would previously have required significant expertise.
It also makes attacks easier to scale. If a phishing kit works well, it can be copied, translated, rented, or modified for different organizations. If an information stealer successfully captures browser data, its operators can sell the resulting credentials and session cookies to other criminals.
This creates a supply chain where one victim’s stolen data can support several future attacks.
Identity has become a primary target
The sections about stolen passwords and information stealing malware stood out to me because they show how much cybersecurity now depends on identity.
A password does not need to be stolen directly from the service where it is eventually used. Credentials exposed in an old breach can remain useful for years if the owner reused the same password elsewhere. Criminals test these combinations automatically through credential stuffing.
Password spraying takes a slightly different approach. Instead of testing many passwords against one account, an attacker tries a few common passwords across many accounts. This can help avoid simple lockout rules.
Information stealers make the identity problem even more serious. These programs can collect saved passwords, browser cookies, authentication tokens, cryptocurrency wallet data, and system information. Some browser cookies represent an active authenticated session. If an attacker steals the right cookie, the password itself may no longer be necessary.
That detail has important consequences. Changing a password after an infection may not remove an attacker who already has a valid session. Users may also need to revoke active sessions, remove unknown connected applications, review recovery settings, and check whether multi factor authentication methods were changed.
For organizations, login security should not stop at asking whether the correct password was entered. Device identity, location, login time, session behavior, and actions taken after authentication all provide useful context.
Phishing resistant authentication methods, especially security keys and passkeys, can also provide stronger protection than verification codes sent through SMS.
Many cybercrime tools are legitimate software
One of the strongest points in the source article is that the same tools can appear in both security work and criminal activity.
Network scanners help administrators identify systems, services, and exposed ports. Vulnerability scanners help companies locate outdated software and unsafe configurations. Remote administration tools allow technical support teams to manage devices. PowerShell is a normal and powerful part of Windows administration.
Attackers can use all of them too.
Nmap can map a network during an authorized security assessment, but it can also help an intruder find internal systems. Metasploit can be used in cybersecurity training and penetration testing, but its capabilities can be abused against systems without permission. A legitimate remote support application can provide persistent access if an attacker installs it without the organization’s knowledge.
Credential dumping tools present the same dual use problem. Mimikatz helped researchers demonstrate weaknesses in Windows authentication, but attackers have also used it to extract credentials and expand access inside compromised environments.
This is why blocking software by name is not enough. Security teams need to understand context.
Who launched the tool? Which device ran it? What account was used? Was the activity expected? What happened immediately afterward?
A network scan from an approved security server during a scheduled assessment is very different from the same scan originating from an employee’s laptop late at night.
Behavior based detection is harder than maintaining a blacklist, but it reflects how real attacks operate.
A typical attack is a sequence, not a single event
The article becomes more useful when its categories are viewed as stages of one possible intrusion.
An attacker might begin with a phishing page or credentials purchased from a breach database. After gaining access, the attacker could install a loader that retrieves additional malware. A remote access tool might then provide continuing control over the infected machine.
Network scanners can reveal other devices and services. Credential dumping utilities may expose accounts with greater privileges. Built in administration tools can help the attacker move through the environment while appearing more like a legitimate user.
Before data theft, the attacker may use common archive software to compress sensitive files. The files can then be uploaded to cloud storage or transferred through other channels. Command and control infrastructure allows malware to receive instructions and send information back to its operator.
Ransomware may appear only at the end.
This is worth emphasizing because ransomware is often described as if it suddenly infects an organization and begins encrypting files. In many serious incidents, encryption is the final visible stage of a much longer compromise. The attackers may already have explored the network, stolen credentials, copied data, and damaged backups.
By the time the ransom note appears, the incident may have been developing for days or weeks.
That means ransomware defense cannot depend only on backups or antivirus software. Organizations need to protect identities, limit administrator privileges, monitor unusual remote access, segment important systems, and investigate suspicious behavior before the final payload runs.
Backups still matter, but they must be isolated and tested. A backup that attackers can modify or delete from the same compromised account is not a dependable recovery plan.
Quiet tools can be more dangerous than obvious malware
Some of the tools discussed in the original article are not designed to cause immediate damage. Loaders, web shells, and command and control systems are good examples.
A loader exists mainly to install something else. Its first stage may appear relatively minor, but it gives the operator flexibility to select the final malware later. The same initial infection can lead to an information stealer on one device and ransomware on another.
A web shell is a script placed on a web server to provide continuing access. If an organization patches the vulnerability that allowed the intrusion but fails to find the web shell, the attacker may still be inside. Fixing the original weakness does not automatically remove persistence established before the patch.
Command and control traffic can also be difficult to identify. Malware may communicate through rented servers, compromised websites, cloud platforms, or frequently changing domains. The traffic might be encrypted and may resemble normal web activity.
Defenders therefore have to look for patterns rather than obvious labels. Repeated connections at fixed intervals, contact with newly registered domains, unexplained outbound transfers, and unusual activity outside normal working hours can all justify investigation.
Reliable logging is essential here. Without endpoint, authentication, network, and cloud service logs, it can be difficult to reconstruct what happened or determine how long an attacker had access.
Distraction can be part of the attack
The source article also includes FloodCRM, described as a service associated with large volumes of email, SMS messages, and phone calls. The goal of this type of activity may be to overwhelm a victim rather than directly compromise a computer.
This is an interesting example because it shows that attackers can target attention itself.
If someone suddenly receives hundreds of messages and calls, a real password reset notice, financial alert, or purchase confirmation can disappear inside the noise. The victim may focus on stopping the flood while another form of account abuse happens in the background.
A communication flood should therefore be treated as a possible security warning. It makes sense to check important email, banking, shopping, and cloud accounts through known applications or manually entered addresses. Unexpected callers should not be trusted simply because the situation feels urgent.
I would also approach references to specific cybercrime services carefully, especially when an article includes direct service links, referral parameters, or access information. Educational reporting should help readers understand threats without functioning as promotion or a convenient directory for abusive services.
AI changes the presentation more than the underlying scam
Artificial intelligence and deepfake technology receive a lot of attention, but the article makes a useful distinction: AI has not replaced traditional cybercrime techniques. It has improved the quality and scale of deception.
Generative AI can produce polished phishing messages, translate scams, imitate a person’s writing style, and create realistic profile images. Voice cloning can make a fraudulent phone call sound like it came from a family member, manager, or company executive.
The underlying manipulation is usually familiar. The attacker creates urgency, impersonates someone trusted, and asks the victim to ignore a normal process.
That is why verification procedures remain effective. An unusual payment request should be confirmed through a separate, trusted channel. Organizations should require more than one person to approve sensitive financial actions. Families can agree on a private verification question for emergency calls.
The important lesson is not to become suspicious of every voice or image. It is to avoid treating realism as proof of identity.
What defenders should learn from the full picture
The most practical takeaway is that defenders should focus on the behaviors and dependencies shared by many attacks.
Cybercriminals need a way to enter. They need credentials or exploitable systems. They need persistence, communication, privileges, and access to valuable data. They also need time to complete their work.
Each requirement creates an opportunity for detection or disruption.
For individuals, the highest value precautions are still straightforward:
- Use a password manager and create a unique password for every important account.
- Enable strong multi factor authentication, especially for email and financial accounts.
- Prefer security keys or passkeys when they are available.
- Install operating system, browser, and application updates promptly.
- Download software from official sources.
- Review active sessions, recovery options, and connected applications.
- Treat unexpected login links, attachments, and urgent requests cautiously.
- If information stealing malware is suspected, clean or rebuild the affected device before changing passwords from a trusted device.
Organizations have a wider set of responsibilities. They need an accurate inventory of systems, applications, public services, and accounts. Administrator privileges should be limited, monitored, and separated from ordinary work accounts. Remote access software should be approved and tracked.
Security teams should also watch for unusual archive creation, large outbound transfers, unexpected command line activity, unauthorized scanning, newly installed remote support tools, and suspicious authentication patterns.
Finally, incident response needs to be practiced. A written plan is useful, but teams should know how to isolate systems, preserve evidence, revoke sessions, reset credentials, restore backups, and communicate during a real incident.
Understanding the system behind the tools
The original article presents a broad catalog of technology associated with cybercrime, but its most valuable idea is the relationship between the tools.
A phishing kit, stolen password database, loader, remote access tool, scanner, credential dumper, archive utility, and ransomware payload can all belong to the same operation. Some components may be malware. Others may be ordinary programs used in an unauthorized way.
From my perspective as an IT student, this is a better way to study cybercrime than memorizing lists of dangerous software. Individual tool names change. Services disappear and new ones replace them. The underlying objectives remain much more consistent.
Attackers still need access, persistence, control, data, and money. Good cybersecurity makes each of those steps more difficult, more visible, and less profitable.
Original source:
https://medium.com/@maya_levi/16-common-cybercrime-tools-and-how-criminals-use-them-6773009dbed7