Most cybercrime doesn't start with a hooded genius writing amazing code in a dark room. It usually starts with pretty ordinary software, passwords that were stolen ages ago, rented infrastructure, and someone who is busy enough to click without thinking too hard.
That matters because criminals rarely rely on just one tool. They put together a mix of tools that help them find targets, get in, steal information, hide what they are doing, and turn stolen data into money. Some of those tools were built for crime. Others are legitimate programmes that security teams and system administrators use every day.
You don't need to learn how to operate any of them. For most people and organisations, the useful question is simpler: what does each tool help a criminal achieve, and what might it look like when it is being used?
Cybercrime has become a service business
Modern cybercrime looks a lot like a normal online economy. Different people specialise in different parts of an attack.
One person might collect email addresses. Another might build convincing login pages. An access broker might break into a company and then sell that access. A ransomware group might buy the access, steal data and encrypt systems. Then someone who specialises in laundering money helps move the profit.
This division of labour has made cybercrime more accessible. A criminal doesn't need to be an expert in everything. Ready-made phishing kits, malware subscriptions, stolen password marketplaces and rented botnets provide most of the infrastructure.
That is also why attacks can spread so quickly. When a criminal tool works well, it gets copied, rented, resold or bundled into a bigger package.
The tools and how they are used
Phishing kits
Phishing is still one of the most common ways criminals steal passwords and take over accounts. A phishing kit is a collection of files and services designed to copy a legitimate login page, payment portal or familiar website.
These kits might imitate banks, cloud storage services, social networks, delivery companies and major tech providers. More advanced versions can capture passwords, session information and one-time verification codes.
The criminal still needs to lure victims there. That usually happens through email, text messages, social media messages, dodgy advertisements or search results that lead to a fake site.
Some operations run as phishing as a service. Customers pay for access to templates, hosting, victim management panels and even technical support. That service model lets people with limited skills run convincing campaigns.
Common warning signs include unexpected urgency, unusual login links, slightly misspelled domains, requests for sensitive information, and messages that try to create fear or excitement. Spelling mistakes are no longer a reliable clue, though. Many modern phishing messages are polished, grammatically correct and tailored to the recipient.
The strongest defence is to avoid signing in through links in unexpected messages. Go to the known website directly, use a password manager, and turn on phishing-resistant authentication where you can.
Stolen password databases
A surprising amount of cybercrime relies on passwords that were stolen months or even years earlier.
After a data breach, collections of email addresses and passwords can be sold, traded or published. Criminals combine information from different breaches to build huge databases. They then test those credentials against email providers, retailers, financial services, social networks and business systems.
This works because many people reuse passwords. A password stolen from an old entertainment site might still unlock a current email account if the same password was used in both places.
Criminals also use automated tools for this:
- Credential stuffing: trying lots of stolen username and password combinations across different services, often rotating network addresses and mimicking normal browser behaviour
- Password spraying: trying a small number of common passwords across many accounts to avoid triggering lockouts
Unique passwords are the best defence here. A password manager makes that practical, and multi-factor authentication adds another layer. Organisations should also watch for unusual login locations, repeated failed attempts, and successful logins followed by quick changes to security settings.
Information stealing malware
Information stealers are designed to collect valuable data from infected computers and they have become one of the most widespread tools in the criminal ecosystem.
An information stealer might hunt for saved browser passwords, authentication cookies, financial details, wallet data, files, system information and login tokens. The stolen information is then sent to criminal infrastructure and sorted for resale or later attacks.
Browser cookies are especially valuable because some represent an authenticated session. If criminals get the right session information, they might be able to access an account without needing the password again. That is why changing a password does not always end an intrusion straight away. Active sessions may also need to be revoked.
Information stealers are often spread through fake software downloads, malicious email attachments, cracked programmes, game mods, deceptive ads and fake browser updates. Some campaigns impersonate popular business tools or meeting apps.
Warning signs can include unexpected browser logouts, security alerts from unfamiliar locations, disabled security software, unusual background processes and new account recovery details. Unfortunately many stealers are designed to run quietly, so you might not notice obvious symptoms.
Only download software from trusted sources and keep your operating system and browser up to date. If you suspect an information stealer, change passwords from a separate, trusted device after the affected machine has been cleaned or rebuilt.
Remote access trojans
A remote access trojan, often shortened to RAT, gives an attacker control over an infected device. Legitimate remote administration software can provide similar capabilities.
Depending on the malware, a criminal might be able to view files, record keystrokes, capture screenshots, activate a camera or microphone, install extra programmes and control the computer remotely.
These tools are useful to criminals because they allow long-term access. Instead of stealing one file and leaving, an attacker can watch how a victim works, wait for valuable information, or use the compromised computer to reach other systems.
The challenge for defenders is that legitimate remote support tools are common in workplaces. Criminals sometimes install genuine administration software because it is trusted by security products and looks normal to network administrators.
Organisations should keep an approved list of remote access applications and investigate anything outside that list. Unexpected remote support prompts, unknown background services, unexplained camera activity and unfamiliar software are all worth checking.
FloodCRM
FloodCRM is a tool associated with coordinated email, SMS and phone call flooding. It is accessible through both the regular web and Tor onion services, which makes it available through more than one type of online infrastructure.
Criminals may use this kind of service to overwhelm a victim with a huge volume of messages and calls. The point is usually distraction rather than direct access to a system. It creates confusion and makes it harder to notice legitimate security alerts, account notifications or other important communications.
A sudden flood of unexpected messages or calls can therefore be a warning sign, particularly if it happens at the same time as suspicious account activity. During such an event, avoid responding to unexpected requests and verify any important account or financial activity through trusted, known channels.
Malware loaders
A loader's main job is to install or launch other malware. It is essentially the delivery vehicle for an attack.
A loader might appear to do very little at first. Once it runs, it can contact criminal infrastructure and fetch an information stealer, remote access trojan, ransomware or another malicious component.
Separating the initial infection from the final payload gives criminals flexibility. They can decide what to deliver based on the victim. A home computer might get an information stealer, while a device on a valuable business network might get tools for deeper access.
Loaders are commonly hidden in email attachments, fake installers, compromised websites and unauthorised software. That is why a seemingly minor infection should not be ignored. What looks harmless today might be setting up a more serious attack tomorrow.
Ransomware
Ransomware is probably the most well-known criminal tool. It encrypts files or disrupts systems and demands payment for recovery.
Current operations often go beyond encryption. Attackers might spend days or weeks exploring a network, stealing sensitive data and disabling backups before triggering the ransomware. They then threaten to publish the stolen information if the victim refuses to pay.
This is commonly called double extortion. Some groups add pressure by contacting customers, employees or business partners.
Ransomware is rarely the first tool used. It is usually the final stage of a longer intrusion involving stolen passwords, remote access tools, network discovery software and data theft utilities.
Backups are still essential, but they need to be isolated, protected and regularly tested. A backup that attackers can delete is not a reliable backup. Organisations also need strong identity controls, network segmentation, prompt patching and a rehearsed incident response plan.
Paying a ransom does not guarantee recovery. Criminals might provide faulty recovery tools, keep copies of the data, or return later with another demand.
Botnets
A botnet is a network of infected devices controlled by someone else. That can include personal computers, servers, routers, security cameras and other internet-connected equipment.
Criminals use botnets to send spam, distribute malware, test stolen passwords, generate fake advertising activity, hide malicious traffic and overwhelm websites with requests.
Many device owners never realise their equipment is part of a botnet. The device might keep working normally while quietly doing jobs for a criminal operator.
Internet-connected devices are attractive targets when they use default passwords, outdated software or poorly secured management interfaces. Some devices stop receiving security updates long before people stop using them.
Changing default credentials, installing updates, disabling unnecessary remote access and replacing unsupported equipment all help reduce the risk. Unexpected bandwidth use, degraded performance and connections to unfamiliar destinations can also justify investigation.
Network scanners
Network scanning tools identify computers, services, ports and software that are reachable across a network. Security teams use them to find vulnerabilities and keep an accurate inventory. Criminals use them for similar discovery, but with a different intent.
An attacker might scan the public internet for exposed remote access systems, outdated web applications, database servers or devices with known weaknesses. After getting into a company network, the attacker might scan again to map its internal structure.
Tools such as Nmap are widely used by legitimate administrators and security researchers. The tool itself is not malicious. Context determines whether the activity is routine maintenance or part of an intrusion.
Defenders can reduce risk by limiting which services are exposed to the internet. Organisations should know what public-facing systems they run and remove anything that is no longer needed. Unexpected scanning from an employee device can also be a sign that an attacker is exploring the network.
Vulnerability scanners and exploit frameworks
Vulnerability scanners look for missing updates, unsafe settings and known software flaws. Companies use them to improve security. Criminals might use the same type of tool to find easy entry points.
Exploit frameworks bring together code and methods for testing security weaknesses. Metasploit is a well-known example of a legitimate framework used in authorised security assessments and training. Like many dual-purpose tools, it can also be misused.
Criminals generally prefer reliable, repeatable methods. They don't always need a new or sophisticated vulnerability. Older flaws remain useful when organisations delay updates or leave forgotten systems online.
That is why patch management is more than just admin. Organisations need to identify critical vulnerabilities, understand which systems are exposed, and prioritise updates based on actual risk. A complete inventory is essential because you cannot patch a server you don't know exists.
Command and control infrastructure
Malware often needs a way to receive instructions and send stolen information. The systems that provide this communication are known as command and control infrastructure.
A compromised device might connect to a server, website, cloud service or another infected machine. The attacker can then issue commands, update the malware or collect data.
Criminals frequently change this infrastructure to avoid being blocked. They might use compromised websites, rented servers, rapidly changing domain names or legitimate online platforms. Traffic is often encrypted so its contents are hard to inspect.
Defenders can still look for patterns. A computer contacting a newly registered domain at regular intervals might deserve attention. So might a device that suddenly starts sending large amounts of data outside normal business hours.
Network monitoring, domain filtering, endpoint security and reliable logs all help investigators understand these communications.
Web shells
A web shell is a malicious script placed on a web server. It can provide ongoing access to the server even after the original weakness has been fixed.
Criminals use web shells to run commands, modify files, steal information and move further into a network. Because the script can be small and hidden among legitimate website files, it might remain unnoticed for a long time.
A web shell is especially dangerous when an organisation patches the initial vulnerability but does not check whether the system was already compromised. Closing the front door does not remove someone who came in before it was locked.
Website owners should monitor file changes, review administrative activity, restrict unnecessary permissions and investigate unexpected scripts or modified pages. After a confirmed server intrusion, simply applying an update is rarely enough. You need to determine what changed and whether persistent access remains.
Tools that dump credentials
Once criminals get into a computer, they often search for extra passwords and authentication material. Credential dumping tools try to extract this information from memory, stored files or operating system components.
Mimikatz is one of the best known names in this area. It was created for security research and has helped reveal weaknesses in how authentication information is handled. It has also been widely abused by attackers.
Credential theft can turn one compromised employee account into a much larger network breach. If an administrator signs in to an infected computer, valuable authentication material might become available to the attacker.
Organisations can reduce this risk by limiting administrative access, separating administrator accounts from normal work accounts, and preventing highly privileged users from signing in to unnecessary devices. Endpoint monitoring can also detect suspicious attempts to access protected credential storage.
Living off the land tools
Not every attack needs obvious malware. Criminals often misuse programmes that are already installed on a computer. This approach is called living off the land.
Built-in scripting tools, system utilities, cloud administration features and remote management software can all be abused. PowerShell is a common example. It is a powerful and legitimate Windows administration tool, but attackers might use it to run commands, collect information or download extra content.
This technique helps criminals blend in with normal activity. Blocking every administrative tool is usually unrealistic because businesses genuinely need them.
The more practical solution is to control who can use powerful tools, record their activity and watch for unusual behaviour. A scripting utility launched by a finance team member at midnight has a different risk profile from the same utility used by an authorised administrator during scheduled maintenance.
Data compression and transfer tools
Before stealing a large set of files, criminals often organise and compress the data. Common archive programmes make information easier to move and can reduce the number of network transfers needed.
Attackers might then use cloud storage, file sharing services, web connections or custom transfer tools to remove the data. Again, many of these services are legitimate, which makes misuse harder to pick up.
Useful warning signs include unusual archive files, large transfers to personal storage services, unexpected use of command-line compression tools, and a sudden increase in outbound traffic.
Companies can reduce exposure by limiting access to sensitive data, monitoring large transfers and applying rules to approved cloud services. The goal is not to block every file upload. It is to recognise activity that does not fit the user, device or business process.
Anonymity and proxy services
Cybercriminals need infrastructure that makes them harder to identify. They might use virtual private networks, proxy services, anonymous networks, compromised servers or infected consumer devices to route their traffic.
These technologies also have legitimate privacy and security uses. A virtual private network can protect remote employees, while anonymity tools can help journalists and people living under censorship. Their presence alone does not prove criminal behaviour.
Residential proxy networks are particularly attractive to fraudsters because traffic appears to come from ordinary home connections. Some of these networks are powered by infected devices. Others are associated with applications that quietly resell a user's internet connection.
Organisations should evaluate login behaviour rather than relying only on a network address. Device identity, login time, account history, geographic changes and requested actions provide better context.
Cryptocurrency wallets and laundering services
Cryptocurrency is not inherently criminal, but it has become part of many cybercrime payment systems. Ransomware groups, data sellers and illegal online marketplaces might use digital currency because transactions can cross borders quickly.
Criminals still face the problem of turning those funds into money they can safely spend. They might move funds through many wallets, use swapping services, involve money mules or try to hide the transaction history.
Blockchain activity is often more traceable than criminals assume. Public transaction records have helped investigators follow payments and seize assets. The hardest part is usually connecting a digital wallet to a real person.
For individuals, the main lesson is that demands for cryptocurrency should be treated cautiously. Government agencies, legitimate technical support companies and reputable employers do not normally demand urgent payments to a digital wallet.
Artificial intelligence and deepfake tools
Artificial intelligence has not replaced traditional cybercrime tools, but it has made several forms of deception easier.
Criminals can use generative systems to improve phishing messages, translate scams, imitate writing styles, create fake profile images and produce convincing audio. Voice cloning can make an urgent call appear to come from an executive, relative or trusted business partner.
The core scam is often familiar. The criminal creates urgency, impersonates someone trusted and asks the victim to bypass a normal process. The difference is that the voice, image or message might now feel more convincing.
A sensible defence is to verify sensitive requests through a separate channel. If an executive sends an unusual payment request, call a known number or confirm it through an established approval process. Families can also agree on simple verification questions for emergency calls.
Why legitimate tools show up in criminal attacks
It is tempting to make a list of dangerous programmes and block every item on it. In practice, that rarely works.
Many tools used by attackers are also used by defenders. Network scanners help administrators manage systems. Remote access software supports employees. Scripting tools automate routine work. Encryption protects sensitive data.
The issue is not just which tool appears. It is who is using it, where it is running, what it is accessing, and whether that behaviour fits the situation.
Good security monitoring focuses on behaviour and context. A trusted tool can still be risky when it appears on the wrong device or runs under an unexpected account.
What ordinary people can do
Most individuals don't need expensive security products or deep technical knowledge. A few habits prevent a large proportion of common attacks.
- Use a password manager and create a different password for every important account
- Turn on multi-factor authentication, especially for email, financial services, cloud storage and social media
- Install updates promptly
- Download software from official sources
- Be cautious with unexpected attachments and login links
Email deserves special protection because it is often the key to other accounts. If a criminal controls an email inbox, password reset messages can provide access to shopping, social media and financial services.
It is also worth reviewing active sessions and connected applications from time to time. Remove devices and services you no longer recognise or use.
What organisations should prioritise
Organisations cannot buy one security product and consider the problem solved. The most effective approach combines prevention, visibility and preparation.
Start with an accurate inventory of systems, software, user accounts and public-facing services. Protect administrator accounts and reduce unnecessary privileges. Require strong authentication. Patch systems based on risk. Keep protected backups and test restoration.
Logging is equally important. When an incident occurs, investigators need records showing who signed in, what ran, which files changed and where data travelled. Without those records, even a capable response team might struggle to understand the damage.
Employee education also needs to be practical. Telling people to avoid suspicious messages is not enough. Training should show how modern impersonation works, how to report a concern quickly, and why normal approval processes must still be followed during an apparent emergency.
Finally, organisations should practise their response. A written plan is useful, but a tested plan is much better. Teams should know who makes decisions, how affected systems will be isolated, when legal or law enforcement contacts are needed, and how customers will be informed.
The bigger lesson
The most common tools used by cybercriminals are not magical. They are practical tools selected to solve specific problems: finding victims, stealing access, maintaining control, collecting data, hiding activity and making money.
That is encouraging in a way. Defenders do not have to predict every new piece of malware. They can focus on the behaviours criminals repeatedly rely on.
Cybercriminals need accounts. They need devices. They need communication channels. They need time inside a network. They need a way to move data and receive payment. Every one of those needs creates an opportunity for detection or disruption.
The goal is not perfect security. Perfect security does not exist. The goal is to make attacks harder, notice them sooner, limit the damage and recover without panic. Understanding the tools is a useful first step, not because we want to think like criminals, but because we want fewer surprises when they come looking for an easy target.
Top comments (0)