Glossary · simply explained

Ransomware-as-a-Service (RaaS)

Ransomware-as-a-service (RaaS) is the business model behind most large extortion waves: developer groups build and maintain the malware including negotiation portals and leak sites; so-called affiliates rent the package, carry out the break-ins and share the ransoms with the operators.

This division of labour lowers the entry barrier dramatically: technical expertise is no longer required — criminal energy and purchased access suffice. That explains the volume and professionalism of today’s attacks.

The ecosystem behind RaaS

The chain is divided: initial access brokers sell captured access — VPN accounts, RDP, stolen sessions. Affiliates buy in, move through the network, exfiltrate data and trigger the encryption. The operators supply software, infrastructure, negotiation and brand names; settlement is percentage-based. Recruitment happens in relevant forums like in a franchise system.

For defenders this means: the adversary is a market, not a lone actor. Takedowns of individual brands work only briefly — affiliates switch to the next provider. What lasts is making every affiliate’s craft expensive: hardened access, segmentation, detection of the quiet phase.

Consequences for defence

  • Access is the commodity: phishing-resistant MFA and ZTNA devalue the brokers’ offering.
  • Exposed remote access and unpatched edge systems are the main procurement sources.
  • The playbooks of the big RaaS brands are documented — detection can be aligned to them.
  • Double extortion is standard: exfiltration detection is part of the basic kit.

Frequently asked questions about Ransomware-as-a-Service (RaaS)

How does the RaaS business model work?

Like a franchise: operators supply ransomware, infrastructure and negotiation portal; affiliates carry out attacks and hand over a percentage of the ransom. Specialised suppliers such as initial access brokers sell the matching entries.

What are initial access brokers?

Criminal traders selling captured corporate access — VPN and RDP accounts, stolen cookies, webshells. Their stock is fed by phishing, infostealers and scans for unpatched systems. For RaaS affiliates they are procurement, not an afterthought.

Why do ransomware groups disappear and reappear?

Rebranding is part of the model: after law enforcement pressure or internal disputes the brand changes, code and personnel move on. For defenders the group name matters less than the recurring techniques — and your own controls against them.

Does RaaS hit small and medium-sized companies too?

Especially them: affiliates work opportunistically and buy whatever the access market offers — often mid-sized companies with exposed remote access and thin monitoring. The ransom demand is then simply adjusted to company size.

What protects most effectively against RaaS attacks?

Dry up the procurement sources and shrink the loot: phishing-resistant login, no open remote access (ZTNA), consistent patching of edge systems, microsegmentation against spread, tested backups plus exfiltration detection against double extortion.

Wondering how this looks in your own network? Talk to KAEMI: we plan, build and manage the right solution with you.