- by x32x01 ||
The underground cybercrime economy is changing quickly. A 2026 study by Radware identified more than 3,000 different hacking and fraud tutorials across underground forums, while the number of newly published tutorials has increased sharply.
In 2024, researchers were seeing roughly 45 new tutorials per month. By 2026, that figure had reached approximately 110-140 new tutorials every month.
The important change is not just the volume of content. The topics attackers are teaching each other are changing too.
At the same time, content related to Black Hat SEO and fraudulent affiliate marketing fell from around 33% to 13%.
This points to a broader shift in the underground economy: activity is moving away from simply manipulating traffic and monetizing visits toward stealing identities, accounts, and data that can be turned directly into money.
There are several reasons these targets are valuable:
This does not mean AI has replaced experienced attackers. The more immediate effect is that producing, explaining, rewriting, and distributing technical content can become easier and faster.
That could lower the barrier for less-experienced individuals. Knowledge that previously required significant time and expertise to collect and organize can be turned into understandable content and distributed to a wider audience.
The subjects that Threat Actors are teaching each other can provide an early indication of where attack activity may be heading.
For example, if there is a sudden increase in tutorials focused on a particular type of fraud or technique, security teams can treat that activity as an Early Warning signal.
They can then review:
Monitoring changes in underground communities offers another possible source of early warning. Following what attackers are learning and discussing can help security teams build a more proactive defense strategy.
The techniques and topics attackers focus on today may become part of future campaigns. Understanding those interests can therefore help defenders identify which accounts, systems, and types of data may receive increased attention.
The bigger change is that offensive knowledge itself is becoming faster to produce and easier to distribute. Generative AI may accelerate that process even further.
At the same time, the same information can provide value to defenders. Monitoring what Threat Actors are learning, discussing, and prioritizing can become an important source of Threat Intelligence.
For security teams, this creates an opportunity to move from constantly reacting to attacks toward identifying emerging threats earlier and strengthening defenses before those threats become more widespread.
In 2024, researchers were seeing roughly 45 new tutorials per month. By 2026, that figure had reached approximately 110-140 new tutorials every month.
The important change is not just the volume of content. The topics attackers are teaching each other are changing too.
📈 The Focus Is Shifting Toward Identity and Account Theft
In 2024, carding and identity theft accounted for about 19% of the tutorials analyzed. By 2026, their share had increased to roughly 38%.At the same time, content related to Black Hat SEO and fraudulent affiliate marketing fell from around 33% to 13%.
This points to a broader shift in the underground economy: activity is moving away from simply manipulating traffic and monetizing visits toward stealing identities, accounts, and data that can be turned directly into money.
📱 Why Telecom and Social Media Are Major Targets
When the tutorials identified a specific company or platform, the telecommunications and social media sectors represented roughly two-thirds of the targeted content by industry.There are several reasons these targets are valuable:
- A phone number can be connected to authentication and login codes.
- A social media account can provide an identity, reputation, and access to other people.
- Stolen credentials can provide access to additional accounts and services.
🤖 Generative AI Is Lowering the Cost of Producing Attack Knowledge
The research also identified examples of Generative AI being used to help create tutorials and other content related to hacking.This does not mean AI has replaced experienced attackers. The more immediate effect is that producing, explaining, rewriting, and distributing technical content can become easier and faster.
That could lower the barrier for less-experienced individuals. Knowledge that previously required significant time and expertise to collect and organize can be turned into understandable content and distributed to a wider audience.
🧠 Underground Knowledge Can Become Threat Intelligence
Threat Intelligence is not limited to information collected after a cyberattack.The subjects that Threat Actors are teaching each other can provide an early indication of where attack activity may be heading.
For example, if there is a sudden increase in tutorials focused on a particular type of fraud or technique, security teams can treat that activity as an Early Warning signal.
They can then review:
- Security Controls
- Detection Rules
- Attack Surface
- Accounts and services related to the emerging threat
🛡️ Defense Does Not Have to Start After the First Incident
Traditional security operations often become highly active after an Incident occurs, followed by Incident Response, investigation, and containment.Monitoring changes in underground communities offers another possible source of early warning. Following what attackers are learning and discussing can help security teams build a more proactive defense strategy.
The techniques and topics attackers focus on today may become part of future campaigns. Understanding those interests can therefore help defenders identify which accounts, systems, and types of data may receive increased attention.
🎯 The Bigger Picture
The main concern is not simply that there may be more hackers.The bigger change is that offensive knowledge itself is becoming faster to produce and easier to distribute. Generative AI may accelerate that process even further.
At the same time, the same information can provide value to defenders. Monitoring what Threat Actors are learning, discussing, and prioritizing can become an important source of Threat Intelligence.
For security teams, this creates an opportunity to move from constantly reacting to attacks toward identifying emerging threats earlier and strengthening defenses before those threats become more widespread.