Dissecting the Dark Web
AdvancedCybercrimeMalwareThreat Intelligence

Dissecting the Dark Web

Reverse Engineering the Tools of the Underground Economy

4 / 5

HUMAN Security's VP of Threat Intelligence tears down real malware-as-a-service offerings sold on dark web forums, chapter by chapter, from stealers and loaders to ransomware and living-off-the-land post-exploitation kits.

Buy on Amazon

As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.

Published
2026
Publisher
No Starch Press
Pages
400
Language
English

Read this if

Threat intelligence analysts and reverse engineers who want technical breakdowns of what's actually sold on dark web forums, not a policy or law-enforcement overview of the dark web as a phenomenon. Kaye is a working malware analyst, and the chapters mirror a MaaS buyer's catalog: stealers, banking trojans, packers, C2 frameworks, post-exploitation toolkits, ransomware.

Skip this if

Readers wanting an investigative or sociological account of dark web marketplaces (closer to Dark Wire or American Kingpin); this is reverse-engineering technique applied to underground tooling, not narrative journalism.

Key takeaways

  • Organized around the actual malware-as-a-service economy structure, treating the dark web as a supply chain to be torn down tool by tool.
  • Covers the full toolkit lifecycle sold underground: delivery, stealers, packers, C2, post-exploitation, and both Windows and Linux/ESXi ransomware.
  • Living-off-the-land technique gets dedicated treatment, reflecting how much underground tooling now avoids custom malware entirely.

Notes

The reverse-engineering counterpart to this catalog's narrative dark-web and cybercrime books (Dark Wire, American Kingpin, Spam Nation) — those tell the human and investigative story, this one tears down the actual tools being sold. Pairs naturally with Practical Malware Analysis and Evasive Malware for the analysis technique applied here.