There’s something almost funny about watching security vendors spend fifteen years lecturing the industry on productizing defense, only to discover the criminals got there first. This week gave us a tidy little demonstration: a bank fraud kit renting for $300 a month on Telegram, a phishing operation selling three hundred scam templates like a stock photo library, and a county government that just wired a cyber extortion group a cool million dollars. None of this is technically new. What’s new is how routine it’s become, how businesslike. Cybersecurity teams built to stop a lone hacker in a hoodie are now up against subscription businesses with release notes and customer support.

The Subscription Model Beat Us To It

Zimperium’s zLabs researchers just pulled the cover off RedWing, an Android malware operation being rented out on Telegram as a ready-made bank-fraud service. It looks like a variant of Oblivion, another rent-a-trojan that’s been going for roughly $300 a month. For that fee, a criminal with zero development skill gets a tool that takes over a victim’s phone, harvests banking logins, and grabs the one-time codes meant to stop exactly this kind of theft.

Sit with that price tag for a second. Three hundred bucks a month is less than a lot of companies spend on a single SaaS seat, and it buys the same convenience: someone else wrote the code, someone else patches it, and the customer just points it at a victim. The skill floor for committing serious bank fraud has effectively dropped to “can you use Telegram.”

Illustration of an Android banking trojan being distributed through a Telegram channel
RedWing is rented out on Telegram like any other software subscription, complete with a monthly fee.

Even The Scam Templates Have QA

Meanwhile Google is suing an outfit it calls Outsider Enterprise, a phishing-as-a-service group operating through Telegram that reportedly offered close to 300 scam templates and step-by-step instructions on using Google’s own Gemini AI to build convincing fakes of Google, YouTube, and government sites like New York’s E-ZPass. The pitch was aimed squarely at people who aren’t technically savvy enough to stand up a fraudulent site on their own. That’s the phishing-as-a-service value proposition in one sentence: you don’t need to know HTML, you just need a subscription and a target list.

Separately, a phishing campaign is going after marketing professionals’ Google accounts using nested redirects to dodge detection, specifically dressed up as jobs at big-name brands. Different crew, same logic. Both operations treat the phishing kit as a product with a roadmap, not a one-off hack.

Person looking at a phishing email on a laptop, representing a fake job offer scam
Nested redirects buy phishing kits just enough time to slip past detection before takedown.

The Economics Favor the Guy Who Never Wrote a Line of Code

Then there’s the money. A small Ohio county reportedly paid a cyber extortion group about $1 million to keep stolen data from going public. Say what you want about the decision, but look at what it funds: every ransom payment refills the operating budget of an industry that rents out its tools to whoever can afford the subscription. The county’s incident presumably started the same way most do, a foothold, some lateral movement, data staged for exfiltration, and then a negotiation that ended in a wire transfer instead of a fight.

That’s the loop. Rental malware and phishing kits lower the cost of getting in. Extortion payments raise the payout for getting caught doing it. Put those two trends next to each other and you get a criminal economy that behaves less like a cybersecurity threat and more like a functioning vertical market, complete with vendors, resellers, and customers.

What Actually Slows These Guys Down

None of this means defense is hopeless, it means the defense has to assume the attacker is renting professional-grade tooling, not improvising. A few things actually move the needle:

  • Stop treating SMS one-time codes as your strongest MFA factor. RedWing exists specifically to intercept them; app-based authenticators and hardware keys don’t have that weakness.
  • Put real brute-force and credential-stuffing protection in front of every login surface, not just the obvious ones. Rate limiting and lockout thresholds are cheap and they work.
  • Treat marketing, social, and ad-platform accounts as privileged identities. They’re not an afterthought when a phishing kit is built specifically to target them.
  • Build an incident response playbook that requires confirming actual data exfiltration before anyone discusses paying. A negotiation is not the same thing as verification.
  • Tune threat detection for behavior, not just signatures. Impossible travel, sudden device changes, and session anomalies catch account takeover long before malware detection ever will.
  • Practice defense in depth on the assumption that a phone or browser will eventually be compromised, so no single stolen credential unlocks the whole account.

Security hardening isn’t glamorous work, and it doesn’t come with a subscription tier or a slick Telegram storefront. It’s the boring stuff, patch cadence, MFA choices, segmentation, that actually raises the cost of doing business for a $300-a-month crime kit. The attackers already professionalized. Defense needs to catch up.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.