(02-02-2021, 04:25 PM)ueax Wrote: Lol yeah. That'll be up to me to find those places. Found this forum with some Google search operators, shouldn't be too different unless its a darknet site.
There are ways to perform OSINT on the Darknet as well though, if you want to try and find some underground marketplaces.
In the interest of transparency, i'll freely admit i don't have a lot of experience with DeepWeb/Darknet OSINT but i find that for all things OSINT
this resource is generally the best place start.
As to your original question personally i am not in the business of selling malware or providing malware as a service. However as DeepLogic said, it stands to reason that individual malware authors would prefer to sell to a broker in order to create some distance between them and the action so to speak. I'd imagine the broker would want to buy the complete source code and then use that as the basis of their Malware as a Service enterprise. It would also stand to reason that the broker would want to sell a complete product to the end user. Not only because it's more user friendly that way and opens up a bigger market of less skilled individuals that may be interested in such services, but also because in essence the broker bought the intellectual property from the original author and it would be in their interest to protect that intellectual property. The broker may even add their own obfuscation as well in order to protect that intellectual property.
There are however blackhat enterprises that function very much like any other enterprise, with in-house R&D, people that handle sales, tech support and may offer many additional services such as methods of spreading the malware. They may for instance provide mail servers and email lists in order to spread the malware through MalDocs or what have you.
To conclude, it's not even a requirement to go full blackhat, if you want to be successful by authoring and selling malware. You may remember Hacking Team? They had their own malware suites with extended customer support as well, much like the bigger blackhat enterprises. However they sold their product to governments all across the world.