Someone looking to misuse an account, a phone, or a company’s data may not need advanced technical skills. They can hire cyber mercenaries, buy a ready-made service, or use credentials exposed in data breaches.
That is the uncomfortable message behind a dark web demonstration with David Bombal and Colin Ellis. Everyone knows enough to be dangerous, from opportunistic users to cyber mercenaries. Attackers often need only one weak account or believable message to get started. The wider cyber-threat ecosystem also includes advanced surveillance tools such as Pegasus spyware, though it wasn’t part of the demonstration or a typical dark web listing.
Key Takeaways
- Cyber abuse is accessible to more people than many expect: nontechnical users can pay for services, while script kiddies can deploy ready-made tools.
- Dark web listings, leak sites, and ransomware claims are not automatically trustworthy. Sellers may be scammers, claims may be unverified, and buyers risk exposure, theft, or investigation.
- Tor and Tails can provide privacy, but they do not make activity lawful, safe, or impossible to trace. Commercial spyware such as Pegasus is a separate, professionalized threat category and should not be confused with ordinary account-takeover listings.
- Unique passwords, disciplined offboarding, reduced public information, vulnerability assessments, and multi-factor authentication can block many common opportunities for cyber mercenaries.
The barrier to cyber abuse is lower than many expect
Cyber mercenaries are people or groups paid to provide offensive access, surveillance, disruption, or related services. Colin Ellis is an onboarding engineering manager at ThreatLocker, where he handles product implementation and client training. In his conversation with David Bombal, Ellis focused on making security understandable for technical teams and everyday users alike. His point was direct: attackers do not all fit one profile.
The demonstration placed cyber mercenaries within a broader discussion, then separated three attacker profiles by capability and motivation:
- A nontechnical person with harmful intent who wants to pay malicious hackers to do the work.
- A “script kiddie” who can deploy existing tools or purchased payloads but cannot build them.
- A programmer who can create tools but needs target lists, credentials, or leaked data, sometimes using social engineering to make access requests seem believable.
Legitimate ethical hackers for hire work under written authorization, a defined scope, and clear rules of engagement, often through penetration testing. By contrast, cyber mercenaries offering unlawful services may use phrases such as “Professional Hacker For Hire” and “Hacking Services.” The wording alone proves nothing, so businesses seeking security help should use a formal, authorized security assessment process.
The commercial spyware market, including NSO Group and its Pegasus spyware, is separate from authorized penetration testing. It should not be conflated with ordinary dark web listings. Initiatives such as the Pall Mall Process promote responsible handling of commercial cyber intrusion capabilities.
In the United States, unauthorized access may implicate the Computer Fraud and Abuse Act and expose someone to criminal prosecution. This is general information, not individualized legal advice.
Public reporting shows how frequently attacks surface
Ransomware Live, a public site created by Julien Muscat, tracks ransomware attacks and publishes organizations that appear on leak sites. During the demonstration, Ellis used it as a starting point. It shows how quickly paid ransomware operators, access brokers, and cyber mercenaries can surface claims.
A name shown on a leak feed is an allegation and investigative lead, not proof. It may indicate alleged data breaches or extortion claims while the affected organization is still investigating.
A compromise can become public before the victim understands what happened.
Organizations should verify each claim against internal evidence and begin incident response procedures when warranted. Because the feed can change, it should serve as one threat intelligence lead, not a complete incident record.
The feed can refresh often, with new organizations appearing during a short session. That pace shows how quickly cyber mercenaries can bring claims into public view. Ransomware isn’t a distant threat reserved for large global brands.
The dark web is still part of the internet
The dark web can sound obscure, yet its services remain connected to the wider internet. Tor provides access to onion services, but it doesn’t automatically open access to darknet markets. Tails is a Linux-based operating system that can run from a USB drive and leaves fewer traces after a session ends. Some cyber mercenaries may use these privacy tools for research, but they don’t make activity lawful or invisible.
Ellis described using Tails to keep research separate from his usual computer environment. That separation reduces exposure, although it doesn’t remove legal or security risk.

Privacy tools, criminal listings, and professional surveillance
Tor and Tails are privacy tools, while illicit markets and commercial spyware are separate categories. Unlike a typical dark web listing, commercial spyware may be developed and sold through a formal company. Commercial spyware can be marketed as a professional capability, with documentation, contracts, and technical support.
A low-cost listing may promise account access or basic disruption. These sellers may be opportunists, rather than cyber mercenaries with professional operations. At the other end, some cyber mercenaries market specialized services to clients.
Public reporting on nso group’s pegasus spyware describes it as a tool for targeted device surveillance. Pegasus spyware is not the same as an account-takeover listing, which generally promises access to one account.
nso group shouldn’t be presented as a darknet-market seller simply because its technology appears in cyber abuse reporting. Claims about pegasus spyware require careful sourcing, especially when reports use the term broadly. Reports about pegasus spyware may describe a professional capability, not a low-cost service.
Governance efforts matter here: the pall mall process addresses the responsible proliferation and use of cyber intrusion capabilities. Some advanced tools may rely on zero-day exploits, or undisclosed flaws, but that doesn’t make every listing sophisticated.
Onion addresses also change often, while sites disappear, move, or return under new addresses. Directories and link lists attempt to track a changing dark web marketplace. A sudden disappearance may be an exit scam. Research material such as Verified Tor Onion Links may help explain how Tor sites are organized, but easy to find does not mean safe or legal.
Tor can reduce a user’s location exposure, but it doesn’t make cyber mercenaries or anyone else impossible to trace. Marketplaces can log activity, law enforcement can investigate, and anonymous sellers can easily scam buyers. Tor also doesn’t exempt unauthorized activity from laws such as the computer fraud and abuse act.
Readers should treat claims about cyber mercenaries and these products with caution. The commercial spyware industry also raises oversight risks when professional capabilities reach customers without clear accountability. Pegasus spyware shouldn’t be casually compared with a low-cost account-takeover listing.
Dark web listings can resemble ordinary online shopping
The most disturbing part of the demonstration was how familiar the listings looked. Categories, prices, descriptions, feedback, and service menus made darknet markets resemble ordinary online shopping. A dark web marketplace could therefore appear legitimate, even when its claims were unverified.
Some paid sellers presented themselves as cyber mercenaries, but these were unverified claims, not reliable services or recommendations.
One listing advertised remote control and takeover of a phone for $700. Another listing claimed that cyber mercenaries could provide social media hacking and account access for around $500. The targets mentioned included:
- Facebook accounts
- Instagram accounts
- Other personal social media profiles
Account takeover can enable social media hacking, stalking, harassment, relationship abuse, and fraud. A separate listing advertised the ability to “ruin someone’s life” for $1,700, while another claimed to offer 30 days of full-time work for $7,500.
Criminal catalogues may also advertise services involving distributed denial of service attacks, but that doesn’t confirm any specific listing. These low-cost account listings are not the same category as commercial spyware such as Pegasus spyware, which is associated with NSO Group.
None of those claims should be treated as trustworthy. Anonymous sellers may be fraudsters. A marketplace operator could stage an exit scam, and an apparent seller could be part of a law enforcement operation. The buyer also risks theft, exposure, or investigation.
Ready-made tools widen the pool of attackers
The “script kiddie” profile is equally concerning. Cyber mercenaries can sell ready-made tools to people who can’t create malware or phishing campaigns from scratch. You do not need to build the tool to misuse it.
One WhatsApp-related offering shown in the demonstration advertised a starting price of about CAD $9.90. Ellis connected that example to social engineering in family group chats, where familiar images, forwarded messages, and attachments can feel harmless. He recalled receiving a WhatsApp message tied to the television show Passions, which felt personal and believable because it came from his mother. Similar messages can direct recipients toward credential harvesting.
That trust is the point. Relationship-based social engineering makes a compromised account’s message more persuasive. A compromised account can send a plausible message to friends, relatives, colleagues, or former co-workers. Facebook, Instagram, LinkedIn, email, and WhatsApp can all give cyber mercenaries relationships to exploit, making professionalized abuse easier to scale.
Leaked data gives attackers a stronger target list
Ransomware groups such as Clop add another layer to the problem. The group has used a public “wall of shame” to list alleged victims and pressure them during extortion attempts. Access brokers, professionalized ransomware services, and cyber mercenaries occupy related but distinct roles. Access brokers sell stolen credentials or network access, while cyber mercenaries may provide paid support. Ellis also described an earlier U.S. and South Korean operation that reportedly disrupted Clop’s site briefly. The site returned soon after, according to that account.
The video used a University of Miami listing to illustrate how stolen organizational information can support social engineering. Once attackers have names, job titles, email addresses, or documents, they can connect them with LinkedIn profiles and previous employers. Reused credentials exposed in data breaches can make that target list more useful. Cyber mercenaries may use those lists. Public profiles can also help cyber mercenaries pursue impersonation, social media hacking, and targeted abuse.
A separate threat model involves commercial spyware, sold as a surveillance product rather than a ransomware tool. Reporting from Amnesty International and Citizen Lab has documented alleged cases involving NSO Group’s Pegasus spyware and targeted-device surveillance. Unlike ransomware, Pegasus spyware is designed for targeted access, not public leak-site extortion. Commercial spyware operates in a professionalized market that deserves separate scrutiny. Those reports concern Pegasus spyware, not Clop or Akira activity.
Ransomware Live also showed an Akira negotiation record involving a claimed $200,000 ransom. The record and amount remain reported, not independently verified. Akira is discussed here as a ransomware operation, not a commercial spyware vendor or a Pegasus spyware operator. The post-attack review pointed back to familiar weaknesses: poor password practices, incomplete offboarding, and accounts left active after employees depart.
An attacker does not always need to deploy ransomware to cause harm. Cyber mercenaries can create harm through exposed records, impersonation, reputational damage, or old-account access without deploying ransomware. Pegasus spyware is associated with NSO Group, but nothing here connects it to the Clop or Akira leak sites.
Basic digital hygiene blocks many easy attacks

The strongest lesson is not complicated. Basic controls close common security vulnerabilities. Use a unique, strong password for every account, especially work accounts and email. Change passwords after suspected exposure, and don’t reuse credentials between employers or services, which limits opportunities for cyber mercenaries.
Companies also need a disciplined offboarding process. Disable old accounts, remove local access, and review permissions when someone leaves. Periodic vulnerability assessments can uncover overlooked access gaps that cyber mercenaries might exploit. Personal users should reduce their digital footprint and public profile information. A smaller public profile limits clues for security questions and social engineering attempts, giving cyber mercenaries fewer opportunities to impersonate them.
Multi-factor authentication adds an extra barrier when a password leaks. MFA can help protect accounts when credentials are exposed through common attacks. ThreatLocker sponsored the discussion, and its security platform and free-trial resource is one option for organizations reviewing their controls.
MFA should not be a debate; it is necessary.
Frequently Asked Questions
What are cyber mercenaries?
Cyber mercenaries are people or groups paid to provide services such as unauthorized access, surveillance, disruption, or social engineering. Their capabilities range from opportunistic sellers to professionalized operators.
Are dark web hacker-for-hire listings legitimate?
Not necessarily. Listings can be scams, staged services, unverified claims, or even part of a law enforcement operation, so they should never be treated as trustworthy recommendations.
Does using Tor or Tails make cyber activity legal or untraceable?
No. Tor and Tails can provide privacy and reduce some forms of exposure, but they do not make unauthorized activity lawful or impossible to investigate. Marketplaces may log activity, and law enforcement can pursue investigations.
How can individuals and businesses reduce the risk of cyber abuse?
Use a unique, strong password for every account and enable multi-factor authentication wherever possible. Businesses should also disable former employees’ accounts, review permissions, assess vulnerabilities, and limit unnecessary public information.
Is Pegasus spyware the same as a dark web account-takeover service?
No. Pegasus spyware is associated with a professional commercial spyware market and targeted-device surveillance, while account-takeover listings generally promise access to a particular account. These categories require separate analysis and careful sourcing.
Security Starts Before an Attack Becomes Public
The demonstration showed that cyber abuse can look alarmingly accessible, even without deep technical skills. Some listings may be fraudulent, but they reflect markets where cyber mercenaries offer stolen data, account access, or social engineering. That accessibility doesn’t mean every listing is credible or every threat is low-level.
Strong passwords, careful offboarding, smaller public digital footprints, and MFA remove many easy opportunities. Commercial spyware, including Pegasus spyware, represents a different and more advanced threat category, so basic hygiene can’t stop every attack. In the U.S., unauthorized access may also implicate the Computer Fraud and Abuse Act, depending on the circumstances.
Basic security habits are often the difference between a failed attempt and a costly incident. They reduce opportunities for cyber mercenaries and other forms of paid abuse before an attack becomes public.
