Preventing Crime-as-a-Service with Cutting-Edge Tools and Intelligence

Call ID

HORIZON-CL3-2023-FCT-01

Duration

01.09.2024 – 31.08.2027

Total Budget
0 M€
Partners
0
Countries
0
Use Cases
0

The Vision

Crime-as-a-Service (Caas)

CaaS represents a worrying evolution in the cyber threat landscape, transforming criminal activities into organised and commercialised enterprises. Similar to legitimate Software-as-a-Service (SaaS) platforms, CaaS offers on-demand illicit services such as malware rentals and fraud platforms. This shift lowers barriers to entry for cybercriminals, enabling individuals without technical skills to engage in activities like identity theft and payment card fraud through digital means. The consequence is a significant amplification of criminal operations’ scale and impact.

Our Aim

SafeHorizon aims to tackle the emerging threat of Crime-as-a-Service (CaaS) by harnessing intelligence from various sources including the clear web, deep web, dark web, public dumps, and law enforcement datasets. By integrating these data streams with machine learning technologies, the project seeks to extract actionable evidence for legal use.

Use Cases

Monitoring transnational crime networks

Monitoring activities of actors in crime networks including ongoing malicious campaigns that may span across different jurisdictions and developing a set of dedicated crawlers which will provide insight and visibility of real-time activity of malicious online activity.

Criminal marketplace analysis

In order to assess the efficacy of the crawlers and the correlation engine, this use case is dedicated to the analysis of criminal marketplaces, and includes testing of the usefulness of SafeHorizon tools to identify crime networks and investigate their members.

Child sexual abuse and trafficking

This use case presents a comprehensive overview of the distribution channels and of the release dates of child sexual abuse material (CSAM).

Malware-as-a-Service

Malware-as-a-Service (MaaS) is a business model under which cybercriminals provide access to malicious software and related infrastructure for a fee, and in this use case we monitor and analyse ongoing malicious campaigns that may target organisations or individuals.

Partners

Coordinated by the Athena Research Center, SafeHorizon is a multidisciplinary research and development initiative spearheaded by an international consortium comprising 13 partners from 11 countries. Carefully selected consortium is gathering outstanding R&D centers and universities, businesses and Law enforcement agencies (LEAs) to ensure the perspective of developers, cybersecurity practitioners, researchers, and machine learning experts focusing on technical areas between security and development. Committed to contributing to cybercrime prevention improvement, the Consortium will ensure provision of a comprehensive toolbox of underdevelopment and enhanced open-source solutions for combating cybercrime designed to be user-friendly and easily adaptable.

Latest News

  • 5 December 2025|Blog|6 min|

    In the labyrinth of cybercrime money laundering

    The laundering of money from cybercrime involves a complex network of transfers, and investigators tracking these funds navigate a maze of cryptocurrency transactions and conversions.

  • 5 December 2025|Blog|5.8 min|

    Online data thieves: how the cybercrime bazaar works

    Cybercrime has evolved into a complex business ecosystem, where malicious tools and stolen data are sold like services. The lone hacker myth is gone, CaaS now fuels today’s digital crime.

  • 27 November 2025|Blog|1.8 min|

    The Role of Blockchain Analytics in the Fight Against Crime-as-a-Service

    Blockchain poses challenges for law enforcement, offering both anonymity for criminals and full transparency through permanent transaction records. With blockchain analytics, investigators can trace fund flows, link related wallets, and track movements across chains, revealing criminal networks and identifying touchpoints with the traditional financial system.

  • 22 November 2025|Blog|1.7 min|

    How Ransomware Actors Leverage Cryptocurrency: A Real-World Use Case

    Ransomware is among today’s most disruptive cyber threats, with cryptocurrency payments enabling attackers to operate globally, quickly, and with relative anonymity.

  • 22 November 2025|Blog|2.5 min|

    The Evolving Phishing Threat: Why Traditional MFA is Failing

    Phishing kits like Tycoon 2FA bypass traditional MFA at scale, exposing a shift toward Phishing-as-a-Service and the need for stronger authentication.

  • 22 November 2025|Blog|2.2 min|

    The Innovation Gap: How Cybercriminals Exploit Emerging Tech Before Law Enforcement Can Respond

    Cybercriminals adopt new tech faster than regulators. Closing the gap means investing in expertise, AI, and global public–private collaboration.

  • 19 November 2025|Blog|1.1 min|

    From Files to Networks: Disrupting CSAM Distribution at Its Source

    Recent arrests highlight how CSAM is distributed at scale. Targeting the digital infrastructure behind it is key to dismantling networks and protecting children.

  • 6 November 2025|Blog|2.2 min|

    Crime-as-a-Service and Malware-as-a-Service: The Professionalisation of Cyber Crime

    Cybercrime has evolved into a professional underground economy driven by Crime-as-a-Service (CaaS) and Malware-as-a-Service (MaaS), where even non-experts can launch sophisticated attacks. These “cybercrime-for-hire” models are reshaping the threat landscape, demanding stronger defences and global cooperation.

  • 22 October 2025|Blog|1.3 min|

    Operation SIMCARTEL: Inside the Infrastructure Powering Crime-as-a-Service

    Operation SIMCARTEL exposes the hidden infrastructure of Crime-as-a-Service, showing why dismantling criminal tools is key to preventing fraud.

  • 22 October 2025|Blog|0.9 min|

    From Chaos to Clarity: Real-Time Crypto Crime Intelligence with NOVA Internal AI

    NOVA detects crypto crime reports in real time, extracts wallets with AI, and sends alerts to investigators, cutting delays, errors, and fund losses.

Events