The threat landscape in the second half of 2023 was dominated by as-a-Service attacks, with MaaS infections identified as the biggest threat to organizations [1] [3], according to a Darktrace report [1] [3]. These infections combine malware loaders, such as remote access trojans (RATs) [1] [3], with information-stealing malware [1] [2] [3] [4], making them more dangerous [1] [3]. Notable examples of this combination include ViperSoftX, an information stealer and RAT malware that targets privileged information like cryptocurrency wallet addresses and passwords [3], and the Black Basta ransomware [1] [3], which spreads the Qbot banking trojan for credential theft [1] [2] [3]. The report also mentions the dismantling of Hive ransomware, leading to the emergence of new threats like ScamClub and AsyncRAT [4]. Additionally, the report emphasizes the evolving nature of malware and ransomware threats, as well as the changing tactics and techniques employed by attackers. It notes that attackers are utilizing generative AI tools to create more convincing phishing campaigns, effectively bypassing organizations’ defenses [3]. The report does not provide specific details on the most commonly observed MaaS tools during the investigated period [1].


The study reveals that malware loaders make up 77% of investigated threats, followed by cryptominers at 52% and botnets at 39%. Information-stealing malware accounts for 36% of threats, while proxy botnets make up 15%.