Skip to content

The Parallel System

Cybercrime isn’t anarchy, or a Hollywood movie. It’s a market with roles, prices and rules. How the system that hits thousands of companies every week works.

11 min read
Also inenit

Anatomy of organized cybercrime: markets, roles, economics and geopolitics of a phenomenon that, by some estimates, costs the world over $10 trillion a year

On December 30, 2022, about a month after attacking Camst, one of Italy’s largest collective catering groups, Hive Ransomware sends an email to the editorial team at Red Hot Cyber. They want to tell their side of the story.
They describe getting into the network, the lateral reconnaissance, the removal of the antivirus, the exfiltration of 370 gigabytes in forty minutes, the encryption of 99.9% of the infrastructure over two and a half days. The tone is that of a company that has completed a project and wants to document its skills for future clients.

Hive Ransomware is not a group of hackers. It’s a criminal business with an organizational structure, a business model, a reputation to protect and a sales pipeline to feed. That email to Red Hot Cyber is communication material. A case study for its own affiliates.

Understanding how this system works, how it’s structured, who makes it up, how it sustains itself financially, is not an academic exercise. It’s the prerequisite for truly understanding what you’re defending against.

Not anarchy. A market.

The popular image of the lone cybercriminal in a hoodie, driven by ideology or intellectual challenge, describes a reality that still exists, at the margins, but stopped being the center of the phenomenon at least ten years ago.

Contemporary organized cybercrime has a structure that looks far more like an industrial cluster than a band of pirates. There’s specialization, division of labor, subcontracting, risk sharing, reinvestment of profits. There’s competition and there are quality standards. There are reputations to build and to protect.

According to projections by Cybersecurity Ventures, the global cost of cybercrime reached around $10.5 trillion in 2025. To put that in perspective: Italy’s GDP is about $2.4 trillion. We’re talking about a cost more than four times the size of the entire Italian economy.

Note that this is an estimate of total damage, not of criminal earnings. It includes what victims lose to downtime, recovery and stolen data; only a share of that money ends up with the people behind the attacks. But that share doesn’t vanish into thin air: it moves, it gets laundered, it generates services and infrastructure. It has suppliers, customers, intermediaries. It has a geography, a geopolitics, a seasonality. It has internal crises, scandals, business failures.
It has, in a word, a structure.

The markets: where crime is bought and sold

The heart of the ecosystem is the dark web marketplaces: platforms accessible only through Tor or similar anonymous networks, where tools, access, data and services are bought and sold.
The biggest ones have polished interfaces, advanced search, clearly defined product categories. First-time visitors are struck not by the darkness but by the normality: they look like Amazon, with reviews, seller ratings, return policies, escrow systems to protect buyers and sellers in case of disputes.
Why is escrow necessary? Because even among criminals, the problem of trust exists. If I buy VPN access to an Italian manufacturing company and the access doesn’t work, I want to be able to dispute it. The marketplace appoints an arbitrator (a human moderator, paid for the job) who examines the evidence from both sides and decides. The seller who cheats loses their reputation, gets banned, loses their business. The system regulates itself.
This isn’t irony. It shows that when a market reaches a certain size, it spontaneously develops governance mechanisms, even when the product it sells is illegal.

Marketplaces don’t last forever. Law enforcement operations take them down periodically (AlphaBay in 2017, Hansa the same year, DarkMarket in 2021, Hydra in 2022). But every time one closes, three more open. The market doesn’t die: it moves. Users migrate, vendors reposition, reputations built up with great effort are transferred to the new channels.

Increasingly, the channels aren’t even traditional marketplaces. They’re private Telegram forums, invite-only Discord channels, trust networks based on vouching: someone already known who stands guarantor for the newcomer. The ecosystem spreads out, decentralizes, becomes more resilient to police operations.

The roles: a precise org chart

Inside this market operate specialized figures with distinct skills, reputations and compensation models. Specialization isn’t a stylistic choice, it’s an operational necessity. Doing everything yourself means being vulnerable on every front. Specializing means becoming indispensable at one.

Malware developers sit at the top of the technical pyramid. They write ransomware, trojans, loaders, antivirus evasion tools. They don’t carry out attacks: they produce weapons. The best ones earn through subscription-style service models: the customer gets access to the up-to-date version of the malware, receives patches when security vendors start detecting it, and has a control panel to manage active infections.
Ransomware-as-a-Service, in its most mature form, works exactly like this.
The developer who wrote the ransomware takes a percentage, typically 20-30%, of every payment generated by their affiliates. With dozens of affiliates active at the same time, the numbers quickly become significant.

Initial Access Brokers (IABs, in industry jargon) do just one thing: get first access to a corporate network and sell it. They don’t steal data, they don’t deploy ransomware. They find the open door, get in just far enough to confirm the access is real and working, and sell the keys.
The methods vary: credential stuffing on breach databases, exploits of known vulnerabilities on exposed systems, targeted phishing, buying credentials from disloyal employees. That last channel deserves attention: on the dark web there are ads explicitly looking for employees of specific companies willing to sell their VPN credentials. Payment ranges from a few hundred to a few thousand euros. It’s recruitment, complete with job ads and selection processes.

According to Rapid7’s report on access brokers, corporate access starts at around $500, most listings go for under $1,000, and the average asking price is just over $2,700. The price depends on the sector, the size, the privileges of the compromised account. Access to a pharmaceutical company is worth more than access to an accounting firm. A Domain Admin account is worth far more than a standard user account.
What makes IABs special is their operational invisibility. They almost never show up in incident statistics: their work is done before the real attack begins. They’re the first link in the chain, and often the hardest to trace.
Ransomware affiliates buy access from IABs, use the developers’ tools and carry out the actual attack: internal reconnaissance, lateral movement, privilege escalation, exfiltration, encryption. They’re operators, in the military sense of the word. They work on commission: the standard cut is 70-80% of the ransom collected, and the rest goes to the group running the infrastructure.
They aren’t necessarily technically sophisticated. Modern kits are designed to be used even by people who can’t program: graphical interfaces, guided procedures, detailed operational playbooks. Some groups provide in-house training to their affiliates.

Money mules and laundering specialists close the cycle. The ransom is paid in cryptocurrency (almost always Bitcoin or Monero) and has to be converted into usable money without leaving a trail to the real beneficiaries. It’s a non-trivial problem: blockchains are public and traceable, and law enforcement has developed significant skills in analyzing crypto transactions. The solution goes through mixers, chain hopping between different cryptocurrencies, unregulated exchanges, and finally conversion into cash through networks of money mules: people recruited, often unwittingly, to receive and move funds onward.
Laundering is the ecosystem’s bottleneck. It’s where many groups expose themselves the most, and it’s often where investigations find the thread to pull.

The real economy: how much they earn

The ecosystem’s numbers take on a different meaning when you translate them into individual terms.
A ransomware affiliate who runs two or three attacks a month against European SMBs (ransoms in the range of $100,000 to $200,000 each, with fewer than one victim in four paying, according to Coveware data) can generate an annual income in the range of a few hundred thousand dollars. All while operating from countries where the average monthly salary is a few hundred dollars.
This isn’t abstract wealth. It’s the concrete explanation of why the ecosystem attracts technical talent in certain parts of the world, and why it’s so hard to dismantle: the economic gap between working in crime and working in the legal market is simply too wide.

In Italy the figures are higher. According to the Sophos State of Ransomware 2025 report, the median ransom paid by Italian companies was $2.06 million, double the global median of $1 million. And when Italian companies pay, they pay on average 97% of what’s demanded, against 85% for the global average.

In May 2024, the US Department of Justice made public the financial details of LockBit, one of the most active ransomware groups of recent years, whose infrastructure had been seized the previous February in Operation Cronos. In more than four years of activity, LockBit had generated over $500 million in ransom payments, with more than 2,500 victims in at least 120 countries. The group’s leader, identified as Dmitry Khoroshev, had personally accumulated at least $100 million.
A hundred million dollars. One person. Over four years. From an operation built on the Ransomware-as-a-Service model, with affiliates recruited online.

The geopolitics: where criminals are tolerated, and why

The cybercrime ecosystem isn’t evenly distributed around the world. It has a precise geography, and that geography is no accident.
The unwritten rule that has governed the most active ransomware groups in recent years is simple: don’t hit targets in your own country or in allied countries. LockBit, BlackCat/ALPHV, REvil and Conti (all predominantly Russian-speaking in origin) systematically avoided targets in the Commonwealth of Independent States. Some versions of their malware included automatic checks to stop running if they detected a system configured in Russian or Ukrainian.
It’s no coincidence. It’s an implicit agreement with the local authorities: operate abroad all you like, just don’t cause trouble at home. In exchange, the state turns a blind eye, or both.
This selective tolerance has allowed organized criminal ecosystems to thrive for years in certain jurisdictions. The international police operations that took down groups like REvil in 2021 or LockBit in 2024 were possible only thanks to extraordinary cooperation between agencies in different countries, and they often led to arrests only when the criminals moved to countries with extradition treaties.

The war in Ukraine has complicated this balance. The most striking case was Conti in 2022: after the group sided with Russia, a Ukrainian researcher made its internal chats public. Those documents (over 60,000 messages, more than a year of communications) offered an unprecedented look inside a cybercriminal organization.
You could read discussions about HR: how to handle unproductive employees, how to structure bonuses. Discussions about marketing: how to improve the group’s reputation to attract quality affiliates. Discussions about R&D: which new techniques to develop to bypass the most widespread security products. It was, in every respect, the inner life of a company. The only difference was that the product was ransomware and the customers were the victims.

The crises: when the system eats itself

A complex ecosystem also develops its own internal pathologies.
Exit scams (a marketplace or a vendor that builds up a reputation and then disappears with its customers’ funds) are endemic. Escrow systems exist precisely to counter them, but they don’t eliminate the risk: whoever runs the escrow can disappear too.

Wars between groups for control of certain markets or niches have produced episodes that would make sense in any story of traditional organized crime: reciprocal DDoS attacks, leaks of confidential information about competitors, aggressive poaching of other groups’ affiliates.

Infiltration by law enforcement is a constant threat. The operation that took down Hansa in 2017 became a case study: after quietly taking control of the marketplace, the Dutch authorities ran it for a full month, gathering information on vendors and buyers before shutting it down. The message to criminals was clear: you never know who is on the other side of the screen.

Why all this matters to an Italian SMB

Understanding the structure of this ecosystem leads to a conclusion that changes how you think about defense.
In most cases, it’s not about stopping a motivated threat actor who has decided to target you specifically. It’s about understanding that you are part of an industrial system, probably without knowing it, one that processes you along with thousands of other companies every week.

IABs have probably already scanned your network. If they find something interesting, they put it up for sale. The buyer doesn’t know who you are, doesn’t know what you do, has no personal interest in you whatsoever. All they know is that they’ve bought access and need to decide how to monetize it before someone notices.

Most of the time, the parallel system doesn’t choose its victims carefully. It processes them efficiently.

All the organizations mentioned (LockBit, Hive Ransomware, Conti, AlphaBay, Hansa, DarkMarket, Hydra) are real. The financial data cited comes from official press releases from the US Department of Justice and Europol, and from reports by Cybersecurity Ventures, Sophos (including the Italy-specific data from the State of Ransomware 2025 report), Rapid7 and Coveware. The Camst case is documented by Red Hot Cyber (December 2022).

Send threat actorsfrom your network into ours.

From €145 per decoy per month. Free trial available, no hardware, no setup fees.

Join The Hive

Threat intel from our own decoys, first-hand. Not another newsletter.

  • Intel from our network. What our decoys catch: the credentials threats try, the tools they bring, the techniques that are new. First-hand, not recycled.
  • Alerts, when it matters. When something we see is worth acting on, you hear it from us, with what to do.
  • Attack stories. The story behind the intel: a real attack, narrated step by step from the offensive side.

Low volume, high quality.

Plus occasional Hoxey news, and we remember your visits. Unsubscribe anytime.

Get in touch

Write to us here and we'll email you back.

We'll reply by email. Privacy policy Prefer a call? Book one