Ransomware-as-a-service (RaaS) is the business model behind most large extortion waves: developer groups build and maintain the malware including negotiation portals and leak sites; so-called affiliates rent the package, carry out the break-ins and share the ransoms with the operators.
This division of labour lowers the entry barrier dramatically: technical expertise is no longer required — criminal energy and purchased access suffice. That explains the volume and professionalism of today’s attacks.
The ecosystem behind RaaS
The chain is divided: initial access brokers sell captured access — VPN accounts, RDP, stolen sessions. Affiliates buy in, move through the network, exfiltrate data and trigger the encryption. The operators supply software, infrastructure, negotiation and brand names; settlement is percentage-based. Recruitment happens in relevant forums like in a franchise system.
For defenders this means: the adversary is a market, not a lone actor. Takedowns of individual brands work only briefly — affiliates switch to the next provider. What lasts is making every affiliate’s craft expensive: hardened access, segmentation, detection of the quiet phase.
Consequences for defence
- Access is the commodity: phishing-resistant MFA and ZTNA devalue the brokers’ offering.
- Exposed remote access and unpatched edge systems are the main procurement sources.
- The playbooks of the big RaaS brands are documented — detection can be aligned to them.
- Double extortion is standard: exfiltration detection is part of the basic kit.