Most cybercrime doesn't start with a hooded genius writing amazing code in a dark room. It usually starts with pretty ordinary software, passwords that were stolen ages ago, rented infrastructure, and someone who is busy enough to click without thinking too hard.

That matters because criminals rarely rely on just one tool. They put together a mix of tools that help them find targets, get in, steal information, hide what they are doing, and turn stolen data into money. Some of those tools were built for crime. Others are legitimate programmes that security teams and system administrators use every day.

You don't need to learn how to operate any of them. For most people and organisations, the useful question is simpler: what does each tool help a criminal achieve, and what might it look like when it is being used?

Cybercrime has become a service business

Modern cybercrime looks a lot like a normal online economy. Different people specialise in different parts of an attack.