DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

It Takes a Buck to Make a Million on the Dark Web: What the 2017 Figures Really Mean

The 2017 “buck to a million” headline referred to cheap stolen credentials, not a one-dollar banking-crime operation. The reported campaign estimate was about $20,000, with major caveats around costs, returns, and current relevance.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The “buck” in the headline was the price of some stolen credentials—not the cost of a banking-crime operation. In 2017, Recorded Future described a small banking-trojan botnet campaign as requiring roughly $20,000 to start, while estimating a 400%–600% return on investment for botnet operations under the conditions it observed. Those were historical estimates, not a promise that a dollar could reliably become a million.

What the headline means—and what it does not

Dark Reading published “It Takes a Buck to Make a Million on the Dark Web” on November 6, 2017, reporting on Recorded Future’s analysis of cybercriminal costs. The dollar refers to some low-priced stolen account credentials. It does not describe the full cost of a banking-trojan campaign, and the million-dollar framing is not a documented typical outcome. Dark Reading’s 2017 report and Recorded Future’s underlying analysis are snapshots of underground offers and estimates from that period, not a current price list or audited set of criminal accounts.

The reported model concerned a banking-trojan operation: malware and related services were used to steal or exploit access to bank accounts, then convert that access into proceeds. A cheap credential was one possible commodity in a larger ecosystem involving specialized tools, distribution, infrastructure, and cash-out intermediaries.

What the reported operation cost

Recorded Future’s 2017 research described costs and services observed in underground sources. These figures are not a complete budget, and they varied with the target, country, scale, provider, and whether an operator already had access or infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Component Reported 2017 figure What it represented
Banking-trojan license $3,000–$5,000 Malware intended to steal banking credentials or facilitate account fraud.
Target-specific web injects About $150–$1,000 per set in Recorded Future’s analysis; Dark Reading summarized the range as about $100–$1,000 Tools designed to interact with targeted banking sessions. The reported prices differ by source and should not be treated as a single precise rate.
Bulletproof hosting $150–$200 per month Hosting marketed to criminals as resistant to complaints or takedown. The figure is from Dark Reading’s summary.
Payload obfuscation Up to $50 A service intended to make malicious software harder for security tools to identify.
Laundering or mule commission About 50%–60% of stolen funds A substantial share paid to intermediaries handling proceeds.
Additional delivery or payment fee About 5%–10% A possible charge for moving or converting money through routes such as Bitcoin or Western Union.
Phone-confirmation service $10–$15 per call Reported assistance with calls related to transaction confirmation or social engineering.
Some e-commerce credentials About $1–$5 Observed prices for certain credentials, not a universal price for account access.
Some PayPal credentials As little as $1 in Dark Reading’s summary A low-end example; it does not establish the validity, balance, or resale value of an account.
Malware installation resale About $1 per installation A reported price for selling access to an infected device to another criminal.

Recorded Future also reported historical examples of credit-card data at roughly $5–$10 per card and random botnet logs at about $20 per gigabyte. Those examples describe different products and cannot be added together as if they were line items in the same banking campaign.

SC Media reported the approximate $20,000 startup estimate for a small banking-trojan botnet campaign, describing a target scale of 10,000–20,000 infected computers. That estimate is a model of a particular operation, not a universal launch cost for cybercrime. SC Media’s report provides the context for the figure.

Why banking malware commanded higher prices

Banking malware was more complex than simply buying a list of passwords. A campaign could need tools tailored to particular financial institutions, ways to interact with changing login and transaction flows, means of reaching victims, and partners able to turn stolen access into spendable money. Recorded Future’s discussion of banking web injects explains their role in modifying or interacting with legitimate banking pages in real time. The economic point is that specialized capability costs more than an isolated record of stolen data.

These services were not necessarily reliable. A bank redesign or security change could make a target-specific tool obsolete; defenses could detect malware; and access might be invalid, duplicated, or already sold. The historical price tells readers what sellers advertised or researchers observed, not whether a buyer received a working product or earned money from it.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the 400%–600% return estimate tells us

Recorded Future’s Andrei Barysevich was reported by Dark Reading as estimating average botnet-operation ROI at 400%–600%. The reporting does not provide an audited sample or enough transparent calculation detail to independently verify that as a universal average. It should be read as an attributed estimate for the operations under discussion, not as a general rate of return on cybercrime.

  • Revenue is money received from stolen funds or resale of access.
  • Costs may include malware, hosting, distribution, labor, laundering fees, replacement infrastructure, and failed attempts.
  • Profit is what remains after costs and losses; the reported summary does not establish a complete net-profit calculation.
  • ROI depends on the formula used, including whether the initial investment is included in the denominator. A percentage alone does not reveal the campaign’s scale or the amount ultimately kept.

Consequently, multiplying a roughly $20,000 startup estimate by a return percentage to announce a dependable payout would overstate what the source establishes. The headline’s “million” is rhetoric about potential upside, not a reported average or guarantee.

Why the underground worked as a service ecosystem

The central economic finding was specialization. Instead of one operator building every capability, separate participants could supply malware, web injects, hosting, spam or traffic distribution, credentials, phone assistance, money mules, and payment or laundering services. Recorded Future described an underground economy in which people focused on narrow functions. This resembles legitimate outsourcing in one limited sense: a central operator can combine services without personally developing each skill.

That modularity lowered some technical barriers, but it did not make campaigns easy or safe. Buyers could be defrauded, providers could vanish, forums could be infiltrated or shut down, and payment routes could be traced or frozen. Depending on partners also meant surrendering control and sharing proceeds. A service listing was not proof of a functioning service or a successful transaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Dark Reading described a shift, as of 2017, toward a more polished and specialized criminal ecosystem. That period-specific observation should not be mistaken for a single unified “dark web” marketplace. Criminal activity also uses private forums, messaging channels, broker networks, compromised sites, and ordinary internet infrastructure; not every cybercrime transaction occurs through Tor or a public marketplace.

How representative were the prices?

The figures apply to a reported banking-trojan model, not to every kind of cybercrime. A denial-of-service service, phishing operation, account takeover, ransomware campaign, and banking botnet have different inputs, risks, and revenue models. A separate 2017 SecurityWeek report cited DDoS services at widely varying prices, including a $10-per-hour example; that is not comparable to the cost stack for banking malware. SecurityWeek’s report illustrates why prices from one service category should not be merged with another.

Nor does an observed listing establish a completed sale. Underground offers can be stale, duplicated, fraudulent, or posted as advertising. Symantec’s 2018 threat report cautioned that underground price lists could include unverifiable or fraudulent offers. Its report is a reminder that listings are evidence of claims and asking prices, not necessarily settled transaction values.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the 2017 numbers are not a 2026 benchmark

Recorded Future’s representative said the available evidence did not provide reliable metrics to determine whether most underground prices had changed significantly over the preceding period. Some prices appeared relatively stable in the observations, while stronger defenses could raise distribution costs or push criminals toward more capable tools. That is not a long-term price index, and it does not establish what services cost in 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prices also depend on target geography, the specific institution, tool quality, provider reputation, and campaign scale. Without comparable, verified transactions over time, a historical list cannot establish current market rates or trend direction.

What defenders and account holders can take from the economics

When criminal work is divided among specialists, disrupting one seller or forum may not eliminate the other capabilities. For organizations, the relevant defensive view is a connected chain: credential theft, malware delivery, account takeover, and movement of funds. Controls should cover both access and transactions.

  • For individuals: use unique passwords and a password manager, enable phishing-resistant authentication where available, keep devices and software updated, and turn on bank transaction alerts.
  • For financial institutions: combine transaction monitoring with device and behavioral signals, and maintain rapid fraud response processes. Multi-factor authentication can reduce the usefulness of stolen passwords, though sophisticated malware and social engineering may target authentication workflows.
  • For organizations: treat exposed credentials as a signal to assess account risk, not conclusive proof of a current compromise. Data may be old, duplicated, or already invalid; verify exposure and look for account activity or other indicators before deciding on response.

The lesson is not that a dollar reliably buys a fortune. It is that a low-cost stolen record can be one input into a much larger, outsourced operation—and that every additional service, partner, and cash-out step adds cost, uncertainty, and a point defenders can disrupt.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.