Ransomware-as-a-service, or RaaS, is a business model in which one group builds and maintains the ransomware while a separate pool of affiliates rents it to carry out attacks, splitting the proceeds. It is the single biggest reason ransomware scaled from a specialist crime into an industry: the people who write the malware no longer need to break into networks, and the people who break into networks no longer need to write malware. Most of the prolific 2026 crews, from Qilin to DragonForce, run some version of this model, which is why understanding RaaS is the key to understanding the whole ecosystem.
How is RaaS structured?
A RaaS operation has two halves. The core operators develop the encryptor, run the leak site and negotiation infrastructure, manage the crypto payments, and provide affiliates with a control panel and support. The affiliates are the workforce. They obtain access to victim networks, deploy the ransomware, steal data and pressure the target. When a victim pays, the money is split, commonly with affiliates keeping the larger share, often around 70 to 80 percent, and the operators taking the rest as their cut for supplying the platform. It is franchising, applied to extortion.
Where do affiliates get access?
Affiliates rarely start from zero. A whole upstream market feeds them entry points. Initial access brokers sell ready-made footholds into corporate networks, priced by revenue and access level. Infostealer logs supply the raw credentials that become those footholds. This supply chain is why the RaaS model is so resilient: an affiliate can buy access on Monday, deploy a rented encryptor on Tuesday, and split the proceeds by Friday, without ever having written a line of malware or found a single vulnerability themselves. The barrier to entry is money and opportunism, not skill.
Why does the model make attacks scale?
Specialisation compounds. When each layer of the operation focuses on one thing, each layer gets better and faster at it. Developers iterate on evasion and encryption speed. Access brokers industrialise credential harvesting. Affiliates refine the intrusion playbook. The result is more attacks, launched more quickly, by more people, than any single vertically integrated crew could manage. It also makes the ecosystem hard to disrupt. Arrest an affiliate and the platform survives. Seize a leak site and affiliates migrate to a rival. The model’s redundancy is a feature the operators designed in, which is why takedowns slow the ecosystem without stopping it.
Can law enforcement break a RaaS operation?
They can wound one, and 2024 through 2026 gave several examples. Operations against LockBit and others showed that seizing infrastructure, exposing operators and sanctioning the crypto plumbing all impose real costs. But the affiliate structure blunts the blow. When one brand collapses, its affiliates carry their skills and access to the next, and new brands spin up to absorb them. Disruption works best when it targets the shared choke points, namely the money laundering, the bulletproof hosting and the operators themselves, rather than the interchangeable affiliates at the edge. The lesson of the takedowns is that RaaS is a hydra, and the neck, not the heads, is where pressure counts.
Frequently asked questions
What does RaaS stand for?
RaaS stands for ransomware-as-a-service. It is a model where core operators build and rent out ransomware and infrastructure to affiliates, who carry out the attacks and share the ransom proceeds with the operators.
How do RaaS operators and affiliates split the money?
Splits vary by program, but affiliates commonly keep the larger share, often around 70 to 80 percent, while operators take the remainder as payment for the platform, encryptor and support. Terms are advertised to attract skilled affiliates.
Is every ransomware group a RaaS?
No. Most large crews run RaaS, but some, such as SafePay, operate a centralised model with no external affiliates. Centralised groups trade scale for tighter control and more consistent tradecraft.
Why is RaaS so hard to shut down?
The affiliate structure builds in redundancy. Arresting an affiliate leaves the platform intact, and seizing a leak site pushes affiliates to rival brands. Disruption works best against shared choke points like money laundering and hosting.
How do affiliates get into victim networks?
Many buy ready-made access from initial access brokers or use credentials harvested from infostealer logs. That upstream market lets affiliates skip the hardest part of an attack and move straight to deployment.
