Ransomware as a service (RaaS) is a criminal business model in which ransomware developers rent their malware and infrastructure to “affiliates” who carry out the attacks in exchange for a share of the ransom.
How RaaS works
The operators build and maintain the encryptor, decryptor, payment portal, negotiation chat and data leak site. Affiliates break into victims’ networks – often buying access from initial access brokers or using credentials stolen by infostealers – and deploy the ransomware. Ransom payments are split, typically with 70–80% going to the affiliate. Some programmes have recruitment ads, support teams and rules such as bans on attacking certain countries or sectors.
Why RaaS matters for security
RaaS turned ransomware into an industry: the most skilled developers no longer need to hack anyone, and affiliates with average skills get professional tools. Well-known programmes include REvil, DarkSide, Conti, LockBit and BlackCat (ALPHV). When one brand is taken down, affiliates simply move to another, so the number of attacks barely drops.
Law enforcement has had notable successes: in February 2024 Operation Cronos seized LockBit’s infrastructure and leak site and released decryption keys, and BlackCat collapsed in an exit scam after taking a reported $22 million ransom from Change Healthcare. Because affiliates use different entry techniques, attacks under the same brand can look very different.
How to defend
- Focus on common entry points: exposed RDP and VPN, unpatched edge devices, stolen credentials.
- Monitor for signs of hands-on intrusion before encryption: new admin accounts, remote tools, mass data transfers.
- Maintain isolated backups and an incident response retainer.
- Report attacks to the police: seized infrastructure sometimes yields free decryptors.