What Is Ransomware-as-a-Service (RaaS)? How It Works

Ransomware-as-a-Service (RaaS) is a model where developers lease ransomware to affiliates who run attacks and share the ransom. Groups, economics, and defense.
Published on
Monday, September 21, 2026
Updated on
September 18, 2026

Ransomware-as-a-Service (RaaS) is a cybercrime business model in which developers build and maintain ransomware, then lease it to affiliates who break into victim networks and deploy it in exchange for a share of the ransom. Separating the people who write the malware from the people who run the intrusions is what distinguishes RaaS from earlier ransomware, where one actor did both.

That division of labor is the reason the model scaled. A single ransomware strain now powers attacks across dozens of industries and regions simultaneously, run by affiliates who never needed the skill to build an encryptor, and the resulting ecosystem behaves less like a criminal gang than like a software market with competing vendors, commission structures, and customer support.

How the RaaS Business Model Works

RaaS operates through three specialized roles, each of which can be filled by different people who never meet. That separation makes the ecosystem efficient and makes attributing any single attack considerably harder.

ransomware as a service roles

Operators and Core Developers

Operators engineer the ransomware itself, maintain command-and-control infrastructure, run data leak sites, and hold the encryption key databases. Backend dashboards give them a live view of every affiliate campaign, tracking victim status, negotiation progress, and decryption key issuance. Competitive pressure has pushed the leading operations to add services that mirror legitimate software vendors, including negotiation support, legal advice, and around-the-clock affiliate assistance.

Affiliates Who Execute Attacks

Everything a victim actually experiences is the work of an affiliate rather than the operator whose name appears on the leak site. Vetted applicants gain network access through phishing, exposed Remote Desktop Protocol services, unpatched vulnerabilities in internet-facing systems, or credentials bought outright, after which their work shifts to lateral movement, privilege escalation, data theft, encryption, and ransom negotiation. Affiliates move between platforms freely, and a crew dissatisfied with one operator’s payout or infrastructure reliability takes its access and techniques to a competitor within weeks.

Initial Access Brokers

Initial access brokers occupy a third lane, selling pre-compromised network access rather than deploying ransomware themselves. Their inventory includes valid VPN credentials, exposed RDP accounts, and cloud logins, which lets an affiliate skip the breach entirely and begin at privilege escalation. Broker pricing has fallen sharply as access pipelines industrialized, turning what was once the hardest stage of an attack into a purchasable commodity.

RaaS Affiliate Economics and Revenue Splits

Published RaaS commission structures advertise affiliate shares between 70% and 90% of each ransom, with operators keeping the remainder. Competition between platforms drove those figures upward, since the affiliate pool is mobile and the operators bid for it, and the headline split has become a recruitment tool as much as an accounting arrangement.

Payment data recovered from an actual operation tells a different story. CloudSEK’s investigation into an Aurora ransomware affiliate, which reconstructed months of operator activity from an exposed server and traced the resulting ransom payments on-chain with TRM Labs, found no consistent affiliate cut at all. The observed splits ran 35/65, 21/79, 46/54, and 40/60, with no ratio repeating. Direct engagement with the ecosystem pointed to the same conclusion: the affiliate share is negotiated per victim, scaled to the ransom size and the victim’s circumstances, rather than fixed in advance by the platform.

Advertised percentages therefore describe marketing rather than observed economics. The affiliate is a contractor negotiating each job, which explains both the mobility between platforms and the pressure operators face to keep headline terms attractive.

Ransom payments themselves move through Bitcoin or Monero, routed via anonymized wallets, with automated blockchain confirmation releasing decryption tools once the transfer clears. Downstream, the funds from what appear to be separate operator and affiliate shares converge in the same laundering clusters, which suggests established cash-out networks rather than isolated wallets.

Core Components of a RaaS Platform

The following infrastructure lets an affiliate with no development skills run a complete extortion campaign.

  • Payload builder. Generates ransomware executables with configurable encryption parameters and target file types, applying polymorphic generation so each build carries a different signature.
  • Command servers. Coordinate infected hosts and transmit encryption keys during execution over channels designed to resist network-level interception.
  • Leak portal. Publishes victim names and stolen data on a Tor site, using countdown timers and staged disclosure to escalate pressure during negotiation.
  • Payment gateway. Guides victims through the cryptocurrency transfer and verifies settlement on-chain before releasing a decryptor.
  • Key management backend. Issues a unique cryptographic key per victim, which prevents any universal decryptor from being built, and holds that key material until payment confirms.

How Ransomware‑as‑a‑Service Operates

A RaaS intrusion moves through six main stages built to maximize leverage before the victim knows anything is wrong.

ransomware as a service intrusion stages
  1. Initial access: Entry comes through phishing, exposed RDP, credential stuffing, or vulnerabilities in internet-facing applications, and access purchased from a broker removes this stage entirely.
  2. Privilege escalation: Misconfigurations and unpatched systems are exploited to reach administrative rights, which opens domain controllers, backup servers, and security management consoles.
  3. Lateral movement: Compromised credentials and legitimate remote administration tools carry the attacker across the network while discovery tooling maps file servers, databases, and virtualization hosts.
  4. Data exfiltration: Intellectual property, financial records, and personal data are compressed and moved to external storage before any encryption begins, securing leverage that survives a clean restore.
  5. Encryption deployment: Files are locked using strong algorithms such as AES with RSA key wrapping, the mechanics behind crypto ransomware, and backups, volume shadow copies, and restore points are disabled first to remove the recovery path.
  6. Ransom negotiation: Victims are directed to a Tor portal where deadlines, staged leaks, and threatened regulatory exposure sustain pressure until payment or publication.

Underneath the whole sequence sits double extortion, the tactic that made restoring from backup an incomplete answer. Stealing data before encrypting it means a victim who restores cleanly from backup still faces publication, which converts a recoverable technical incident into a disclosure and regulatory problem.

RaaS Compared With Traditional Ransomware

The following 6 attributes separate the service model from ransomware run by a single actor end to end.

Attribute Ransomware-as-a-Service Traditional Ransomware
Operating Model Developer builds and leases; affiliate executes One actor builds and deploys
Technical Barrier Low, no development skill required of affiliates High, requires malware engineering
Revenue Negotiated profit share between operator and affiliate Retained entirely by the single actor
Attack Volume One strain drives many simultaneous campaigns Limited by one actor’s capacity
Attribution Split across operator, affiliates, and access brokers Concentrated in one identifiable actor
Takedown Resilience High, affiliates migrate to another platform Low, removing the actor ends the operation

Major RaaS Groups and Why Takedowns Do Not Stop Them

Naming a RaaS group is useful only alongside what became of it, because these operations rarely disappear quietly. Most get disrupted, sanctioned, rebranded, or in one prominent case rebuilt entirely.

Group Active From Current Status
LockBit 2019 Infrastructure seized in 2024, relaunched as LockBit 5.0 in late 2025 and back in the top tier
REvil (Sodinokibi) 2019 Dismantled by Russia’s FSB in early 2022 with several members charged
DarkSide 2020 Shut down after Colonial Pipeline; developers relaunched as BlackMatter
Conti 2020 Collapsed in 2022 after an internal chat leak; members dispersed to other brands
Hive 2021 Infiltrated by the FBI and taken down in January 2023
Qilin (Agenda) 2022 Active and among the most prolific operations globally
DragonForce 2023 Active, operates a white-label model letting affiliates brand attacks as their own

LockBit: Seizure and Return

LockBit became the most prolific RaaS operation of its era on the strength of an automated affiliate program and dashboards that tracked infections and payments in real time. In February 2024 an international taskforce led by the UK National Crime Agency seized the group’s infrastructure, taking down 34 servers across eight countries, arresting two actors, freezing more than 200 cryptocurrency accounts, and recovering over 1,000 decryption keys.

Rebuilding took roughly eighteen months and happened anyway. LockBit resurfaced in late 2025 with a fifth-generation encryptor and a reopened affiliate program, and the brand re-entered the upper tier of active operations within months. The episode illustrates the limit of infrastructure seizure against a model where the people, the affiliate relationships, and the source code survive the servers.

Hive: Disruption From Inside the Network

Hive built its reputation targeting remote workforces and cloud services, and its takedown took a different shape. The FBI penetrated Hive’s systems in July 2022 and spent roughly seven months quietly capturing decryption keys and handing them to victims before announcing the operation, preventing more than $130 million in ransom demands across an operation that had targeted over 1,500 victims in more than 80 countries.

Why Attribution Stays Difficult

The affiliate running an intrusion is rarely the group that wrote the malware, and several unrelated affiliates deploy the same strain concurrently, so strain identification alone establishes very little. Tracking the operator-affiliate distinction is the specific work of ransomware threat intelligence, and generic feeds that report a strain name without the ecosystem behind it miss what actually determines how an intrusion will proceed. CloudSEK research on the Qilin ransomware operation shows the level of detail this requires, tracing attack agendas, tooling, and leaked data across a single operator over time.

What Is Driving RaaS Growth

Four forces keep lowering the barrier to entry while raising the returns.

  • Agentic AI inside live intrusions. The Aurora affiliate used an AI coding agent between April and May 2026 to plan reconnaissance, assess privileges, and work through exploitation paths in multiple victim environments, including a full Active Directory Certificate Services attack plan. AI functioned as an iterative technical assistant during the intrusion rather than as a standalone capability.
  • Commoditized initial access. Brokers supply working credentials and footholds as inventory, compressing attack timelines and removing the stage that previously required the most skill.
  • Role specialization. Operators refine malware, affiliates refine intrusion technique, brokers refine access acquisition, and each lane improves faster than a single actor covering all three could manage.
  • Consolidation and cooperation between groups. Dominant operations absorb affiliates displaced by law enforcement action against smaller rivals, concentrating capability rather than dispersing it.

Cooperation between rival operations has since become explicit rather than tacit. In late 2025, DragonForce publicly proposed a coalition with LockBit and Qilin to share techniques, infrastructure, and affiliates, and the groups announced the arrangement as a cartel intended to reduce conflict between them and set market terms. Earlier ransomware history offers a precedent worth noting: the LockBit and Maze collaboration in 2020 introduced double extortion, a tactic that then spread across the entire ecosystem.

How to Defend Against RaaS Attacks

Defense works by closing the paths affiliates actually use and removing the leverage extortion depends on. Six controls carry most of the weight.

  • Phishing-resistant multi-factor authentication. A purchased or stolen credential stops being sufficient on its own, which devalues the broker inventory affiliates buy from.
  • Hardened external access. VPN concentrators, RDP services, and edge appliances receive priority patching, because these remain the dominant entry points across active operations.
  • Endpoint detection and response. Behavioral detection catches lateral movement, shadow copy deletion, and mass encryption while an intrusion is still running rather than after files lock.
  • Offline, immutable backups. Recovery without payment removes half the extortion leverage, provided the backups sit outside the domain the attacker will compromise.
  • Network segmentation and least privilege. Segmentation limits how far an affiliate travels after initial access, and it protects the virtualization and backup infrastructure encryptors target first.
  • Exfiltration monitoring. Data theft precedes encryption, so egress anomalies and unexpected cloud transfers give warning during the window when intervention still prevents the extortion stage.

Backups alone stopped being sufficient once double extortion became standard. An organization that restores cleanly still faces publication of whatever left the network first, which makes detecting exfiltration as important as surviving encryption.

Tracking RaaS Operators with CloudSEK Threat Intelligence

Most ransomware controls operate inside the network, and the decisions that determine whether an organization becomes a target happen outside it: which sectors a group is prioritizing, which vulnerabilities its affiliates are weaponizing, and whether credentials for the environment are already for sale. CloudSEK Threat Intelligence covers that external layer, tracking ransomware groups, their affiliates, exploited CVEs, leak site activity, and threat actor tooling across the open, deep, and dark web.

Depth in that tracking comes from original investigation rather than aggregated feeds. The Aurora investigation reconstructed an affiliate’s full workflow from an exposed server, from AI-assisted planning through domain compromise to the on-chain payment split, which is the kind of primary evidence that corrects assumptions the public reporting had settled on. Intelligence of this kind shortens the gap between a group changing its behavior and defenders adjusting for it.

External intelligence complements rather than replaces endpoint detection, backup strategy, and incident response. It answers a question internal tooling cannot: what the adversary is doing before the intrusion reaches the network.

Final Thoughts: Where RaaS Is Heading

Ransomware-as-a-Service turned extortion into an industry with vendors, contractors, suppliers, and now open coalitions between competitors. Treating any single group as the threat misreads that structure, because the affiliates who conduct the intrusions outlast the brands they operate under, and the infrastructure a takedown removes is the most replaceable part of the operation.

Watching this ecosystem going forward means watching two developments in particular. Agentic AI has moved into live intrusions as a working tool rather than a talking point, compressing the reconnaissance and privilege analysis that used to require experienced operators. Meanwhile, the economics keep shifting in ways published affiliate terms do not reveal, which makes primary evidence from inside these operations more valuable than the advertised numbers the ecosystem puts on display.

Frequently Asked Questions

How much does it cost to join a RaaS program?

Entry terms vary by platform. Some operations charge a monthly subscription or a one-time license fee, and the dominant model takes no upfront payment at all, instead retaining a percentage of each successful ransom, which shifts the operator’s risk onto affiliate performance.

Are RaaS affiliates and ransomware operators prosecuted differently?

Charges differ by role and jurisdiction. Operators face charges tied to building and distributing the malware and to running the criminal enterprise, while affiliates are prosecuted for the specific intrusions they conducted, which is why indictments name individual attacks rather than the strain as a whole.

Do RaaS groups avoid certain countries?

Yes. Russian-speaking operations routinely exclude Commonwealth of Independent States targets, enforcing it through keyboard-layout and locale checks in the encryptor and through explicit exclusion of CIS address ranges during targeting.

Can a decryptor from one victim unlock another victim’s files?

No. RaaS platforms generate a unique key per victim, so a decryptor works only for the environment it was issued against.

What is the difference between RaaS and an extortion-only group?

RaaS operations encrypt systems and steal data. Extortion-only groups skip encryption entirely, stealing data and threatening publication, which avoids the engineering effort of a reliable encryptor and the operational noise that mass encryption creates.

Does paying a ransom remove the stolen data?

No guarantee exists. Payment buys a decryptor and a promise of deletion that cannot be verified, and groups have re-extorted victims using data they claimed to have destroyed. Regulators treat the exposure as a reportable breach regardless of payment.

Related Posts
What is Pastebin? Uses, Risks, and How It Works
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
What is Personally Identifiable Information (PII)?
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.
What Is the National Vulnerability Database (NVD)?
The National Vulnerability Database (NVD) is NIST's public repository of CVE data with severity scores. How the NVD works and its 2026 triage shift.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.