🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
Ransomware-as-a-Service (RaaS) is a cybercrime business model in which developers build and maintain ransomware, then lease it to affiliates who break into victim networks and deploy it in exchange for a share of the ransom. Separating the people who write the malware from the people who run the intrusions is what distinguishes RaaS from earlier ransomware, where one actor did both.
That division of labor is the reason the model scaled. A single ransomware strain now powers attacks across dozens of industries and regions simultaneously, run by affiliates who never needed the skill to build an encryptor, and the resulting ecosystem behaves less like a criminal gang than like a software market with competing vendors, commission structures, and customer support.
RaaS operates through three specialized roles, each of which can be filled by different people who never meet. That separation makes the ecosystem efficient and makes attributing any single attack considerably harder.

Operators engineer the ransomware itself, maintain command-and-control infrastructure, run data leak sites, and hold the encryption key databases. Backend dashboards give them a live view of every affiliate campaign, tracking victim status, negotiation progress, and decryption key issuance. Competitive pressure has pushed the leading operations to add services that mirror legitimate software vendors, including negotiation support, legal advice, and around-the-clock affiliate assistance.
Everything a victim actually experiences is the work of an affiliate rather than the operator whose name appears on the leak site. Vetted applicants gain network access through phishing, exposed Remote Desktop Protocol services, unpatched vulnerabilities in internet-facing systems, or credentials bought outright, after which their work shifts to lateral movement, privilege escalation, data theft, encryption, and ransom negotiation. Affiliates move between platforms freely, and a crew dissatisfied with one operator’s payout or infrastructure reliability takes its access and techniques to a competitor within weeks.
Initial access brokers occupy a third lane, selling pre-compromised network access rather than deploying ransomware themselves. Their inventory includes valid VPN credentials, exposed RDP accounts, and cloud logins, which lets an affiliate skip the breach entirely and begin at privilege escalation. Broker pricing has fallen sharply as access pipelines industrialized, turning what was once the hardest stage of an attack into a purchasable commodity.
Published RaaS commission structures advertise affiliate shares between 70% and 90% of each ransom, with operators keeping the remainder. Competition between platforms drove those figures upward, since the affiliate pool is mobile and the operators bid for it, and the headline split has become a recruitment tool as much as an accounting arrangement.
Payment data recovered from an actual operation tells a different story. CloudSEK’s investigation into an Aurora ransomware affiliate, which reconstructed months of operator activity from an exposed server and traced the resulting ransom payments on-chain with TRM Labs, found no consistent affiliate cut at all. The observed splits ran 35/65, 21/79, 46/54, and 40/60, with no ratio repeating. Direct engagement with the ecosystem pointed to the same conclusion: the affiliate share is negotiated per victim, scaled to the ransom size and the victim’s circumstances, rather than fixed in advance by the platform.
Advertised percentages therefore describe marketing rather than observed economics. The affiliate is a contractor negotiating each job, which explains both the mobility between platforms and the pressure operators face to keep headline terms attractive.
Ransom payments themselves move through Bitcoin or Monero, routed via anonymized wallets, with automated blockchain confirmation releasing decryption tools once the transfer clears. Downstream, the funds from what appear to be separate operator and affiliate shares converge in the same laundering clusters, which suggests established cash-out networks rather than isolated wallets.
The following infrastructure lets an affiliate with no development skills run a complete extortion campaign.
A RaaS intrusion moves through six main stages built to maximize leverage before the victim knows anything is wrong.

Underneath the whole sequence sits double extortion, the tactic that made restoring from backup an incomplete answer. Stealing data before encrypting it means a victim who restores cleanly from backup still faces publication, which converts a recoverable technical incident into a disclosure and regulatory problem.
The following 6 attributes separate the service model from ransomware run by a single actor end to end.
Naming a RaaS group is useful only alongside what became of it, because these operations rarely disappear quietly. Most get disrupted, sanctioned, rebranded, or in one prominent case rebuilt entirely.
LockBit became the most prolific RaaS operation of its era on the strength of an automated affiliate program and dashboards that tracked infections and payments in real time. In February 2024 an international taskforce led by the UK National Crime Agency seized the group’s infrastructure, taking down 34 servers across eight countries, arresting two actors, freezing more than 200 cryptocurrency accounts, and recovering over 1,000 decryption keys.
Rebuilding took roughly eighteen months and happened anyway. LockBit resurfaced in late 2025 with a fifth-generation encryptor and a reopened affiliate program, and the brand re-entered the upper tier of active operations within months. The episode illustrates the limit of infrastructure seizure against a model where the people, the affiliate relationships, and the source code survive the servers.
Hive built its reputation targeting remote workforces and cloud services, and its takedown took a different shape. The FBI penetrated Hive’s systems in July 2022 and spent roughly seven months quietly capturing decryption keys and handing them to victims before announcing the operation, preventing more than $130 million in ransom demands across an operation that had targeted over 1,500 victims in more than 80 countries.
The affiliate running an intrusion is rarely the group that wrote the malware, and several unrelated affiliates deploy the same strain concurrently, so strain identification alone establishes very little. Tracking the operator-affiliate distinction is the specific work of ransomware threat intelligence, and generic feeds that report a strain name without the ecosystem behind it miss what actually determines how an intrusion will proceed. CloudSEK research on the Qilin ransomware operation shows the level of detail this requires, tracing attack agendas, tooling, and leaked data across a single operator over time.
Four forces keep lowering the barrier to entry while raising the returns.
Cooperation between rival operations has since become explicit rather than tacit. In late 2025, DragonForce publicly proposed a coalition with LockBit and Qilin to share techniques, infrastructure, and affiliates, and the groups announced the arrangement as a cartel intended to reduce conflict between them and set market terms. Earlier ransomware history offers a precedent worth noting: the LockBit and Maze collaboration in 2020 introduced double extortion, a tactic that then spread across the entire ecosystem.
Defense works by closing the paths affiliates actually use and removing the leverage extortion depends on. Six controls carry most of the weight.
Backups alone stopped being sufficient once double extortion became standard. An organization that restores cleanly still faces publication of whatever left the network first, which makes detecting exfiltration as important as surviving encryption.
Most ransomware controls operate inside the network, and the decisions that determine whether an organization becomes a target happen outside it: which sectors a group is prioritizing, which vulnerabilities its affiliates are weaponizing, and whether credentials for the environment are already for sale. CloudSEK Threat Intelligence covers that external layer, tracking ransomware groups, their affiliates, exploited CVEs, leak site activity, and threat actor tooling across the open, deep, and dark web.
Depth in that tracking comes from original investigation rather than aggregated feeds. The Aurora investigation reconstructed an affiliate’s full workflow from an exposed server, from AI-assisted planning through domain compromise to the on-chain payment split, which is the kind of primary evidence that corrects assumptions the public reporting had settled on. Intelligence of this kind shortens the gap between a group changing its behavior and defenders adjusting for it.
External intelligence complements rather than replaces endpoint detection, backup strategy, and incident response. It answers a question internal tooling cannot: what the adversary is doing before the intrusion reaches the network.
Ransomware-as-a-Service turned extortion into an industry with vendors, contractors, suppliers, and now open coalitions between competitors. Treating any single group as the threat misreads that structure, because the affiliates who conduct the intrusions outlast the brands they operate under, and the infrastructure a takedown removes is the most replaceable part of the operation.
Watching this ecosystem going forward means watching two developments in particular. Agentic AI has moved into live intrusions as a working tool rather than a talking point, compressing the reconnaissance and privilege analysis that used to require experienced operators. Meanwhile, the economics keep shifting in ways published affiliate terms do not reveal, which makes primary evidence from inside these operations more valuable than the advertised numbers the ecosystem puts on display.
Entry terms vary by platform. Some operations charge a monthly subscription or a one-time license fee, and the dominant model takes no upfront payment at all, instead retaining a percentage of each successful ransom, which shifts the operator’s risk onto affiliate performance.
Charges differ by role and jurisdiction. Operators face charges tied to building and distributing the malware and to running the criminal enterprise, while affiliates are prosecuted for the specific intrusions they conducted, which is why indictments name individual attacks rather than the strain as a whole.
Yes. Russian-speaking operations routinely exclude Commonwealth of Independent States targets, enforcing it through keyboard-layout and locale checks in the encryptor and through explicit exclusion of CIS address ranges during targeting.
No. RaaS platforms generate a unique key per victim, so a decryptor works only for the environment it was issued against.
RaaS operations encrypt systems and steal data. Extortion-only groups skip encryption entirely, stealing data and threatening publication, which avoids the engineering effort of a reliable encryptor and the operational noise that mass encryption creates.
No guarantee exists. Payment buys a decryptor and a promise of deletion that cannot be verified, and groups have re-extorted victims using data they claimed to have destroyed. Regulators treat the exposure as a reportable breach regardless of payment.
