Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Explainers

What is RaaS? Ransomware-as-a-service, explained

Ransomnews Research TeamBy Ransomnews Research TeamJuly 20, 2026Updated:July 20, 2026No Comments5 Mins Read39 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
What is RaaS? Ransomware-as-a-service explained, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ransomware-as-a-service, or RaaS, is a business model in which one group builds and maintains the ransomware while a separate pool of affiliates rents it to carry out attacks, splitting the proceeds. It is the single biggest reason ransomware scaled from a specialist crime into an industry: the people who write the malware no longer need to break into networks, and the people who break into networks no longer need to write malware. Most of the prolific 2026 crews, from Qilin to DragonForce, run some version of this model, which is why understanding RaaS is the key to understanding the whole ecosystem.

How is RaaS structured?

A RaaS operation has two halves. The core operators develop the encryptor, run the leak site and negotiation infrastructure, manage the crypto payments, and provide affiliates with a control panel and support. The affiliates are the workforce. They obtain access to victim networks, deploy the ransomware, steal data and pressure the target. When a victim pays, the money is split, commonly with affiliates keeping the larger share, often around 70 to 80 percent, and the operators taking the rest as their cut for supplying the platform. It is franchising, applied to extortion.

The RaaS division of labour ransomnews.com CORE OPERATORS – build encryptor– run leak site– handle negotiation– launder payments– take ~20-30% cut AFFILIATES – buy/gain access– deploy ransomware– exfiltrate data– pressure victim– keep ~70-80% rents kit splits ransom Specialisation is the multiplier: neither side needs the other’s skill set.

Where do affiliates get access?

Affiliates rarely start from zero. A whole upstream market feeds them entry points. Initial access brokers sell ready-made footholds into corporate networks, priced by revenue and access level. Infostealer logs supply the raw credentials that become those footholds. This supply chain is why the RaaS model is so resilient: an affiliate can buy access on Monday, deploy a rented encryptor on Tuesday, and split the proceeds by Friday, without ever having written a line of malware or found a single vulnerability themselves. The barrier to entry is money and opportunism, not skill.

Why does the model make attacks scale?

Specialisation compounds. When each layer of the operation focuses on one thing, each layer gets better and faster at it. Developers iterate on evasion and encryption speed. Access brokers industrialise credential harvesting. Affiliates refine the intrusion playbook. The result is more attacks, launched more quickly, by more people, than any single vertically integrated crew could manage. It also makes the ecosystem hard to disrupt. Arrest an affiliate and the platform survives. Seize a leak site and affiliates migrate to a rival. The model’s redundancy is a feature the operators designed in, which is why takedowns slow the ecosystem without stopping it.

Can law enforcement break a RaaS operation?

They can wound one, and 2024 through 2026 gave several examples. Operations against LockBit and others showed that seizing infrastructure, exposing operators and sanctioning the crypto plumbing all impose real costs. But the affiliate structure blunts the blow. When one brand collapses, its affiliates carry their skills and access to the next, and new brands spin up to absorb them. Disruption works best when it targets the shared choke points, namely the money laundering, the bulletproof hosting and the operators themselves, rather than the interchangeable affiliates at the edge. The lesson of the takedowns is that RaaS is a hydra, and the neck, not the heads, is where pressure counts.

RaaS supply chain, end to end ransomnews.com Infostealerlogs Accessbroker Affiliate +rented RaaS Extortion +leak site Each stage is a separate market; defenders can intervene at any of them.

Frequently asked questions

What does RaaS stand for?

RaaS stands for ransomware-as-a-service. It is a model where core operators build and rent out ransomware and infrastructure to affiliates, who carry out the attacks and share the ransom proceeds with the operators.

How do RaaS operators and affiliates split the money?

Splits vary by program, but affiliates commonly keep the larger share, often around 70 to 80 percent, while operators take the remainder as payment for the platform, encryptor and support. Terms are advertised to attract skilled affiliates.

Is every ransomware group a RaaS?

No. Most large crews run RaaS, but some, such as SafePay, operate a centralised model with no external affiliates. Centralised groups trade scale for tighter control and more consistent tradecraft.

Why is RaaS so hard to shut down?

The affiliate structure builds in redundancy. Arresting an affiliate leaves the platform intact, and seizing a leak site pushes affiliates to rival brands. Disruption works best against shared choke points like money laundering and hosting.

How do affiliates get into victim networks?

Many buy ready-made access from initial access brokers or use credentials harvested from infostealer logs. That upstream market lets affiliates skip the hardest part of an attack and move straight to deployment.

Sources and further reading

  • Chainalysis — Crypto Ransomware: 2026 Crime Report (payment data)
  • CISA #StopRansomware — official guidance and advisories
  • Ransomnews — Initial Access Brokers 2026
  • Ransomnews — LockBit, two years after Operation Cronos
  • Ransomnews — Threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleWhat is BYOVD? Bring your own vulnerable driver, explained
Next Article What is intermittent encryption? A 2026 guide
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

What is intermittent encryption? A 2026 guide

July 20, 2026

What is BYOVD? Bring your own vulnerable driver, explained

July 20, 2026

What is double extortion ransomware? An explainer for non-technical executives in 2026

May 10, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.