Ransomware-as-a-service, or RaaS, is a business model in which one group builds and maintains the ransomware while a separate pool of affiliates rents it to carry out attacks, splitting the proceeds. It is the single biggest reason ransomware scaled from a specialist crime into an industry: the people who write the malware no longer need to break into networks, and the people who break into networks no longer need to write malware. Most of the prolific 2026 crews, from Qilin to DragonForce, run some version of this model, which is why understanding RaaS is the key to understanding the whole ecosystem.
How is RaaS structured?
A RaaS operation has two halves. The core operators develop the encryptor, run the leak site and negotiation infrastructure, manage the crypto payments, and provide affiliates with a control panel and support. The affiliates are the workforce. They obtain access to victim networks, deploy the ransomware, steal data and pressure the target. When a victim pays, the money is split, commonly with affiliates keeping the larger , often around 70 to 80 percent, and the operators taking the rest as their cut for supplying the platform. It is franchising, applied to extortion.
Where do affiliates get access?
Affiliates rarely start from zero. A whole upstream market feeds them entry points. Initial access brokers sell ready-made footholds into corporate networks, priced by revenue and access level. Infostealer logs supply the raw credentials that become those footholds. This supply chain is why the RaaS model is so resilient: an affiliate can buy access on Monday, deploy a rented encryptor on Tuesday, and split the proceeds by Friday, without ever having written a line of malware or found a single vulnerability themselves. The barrier to entry is money and opportunism, not skill.
Why does the model make attacks scale?
Specialisation compounds. When each layer of the operation focuses on one thing, each layer gets better and faster at it. Developers iterate on evasion and encryption speed. Access brokers industrialise credential harvesting. Affiliates refine the intrusion playbook. The result is more attacks, launched more quickly, by more people, than any single vertically integrated crew could manage. It also makes the ecosystem hard to disrupt. Arrest an affiliate and the platform survives. Seize a leak site and affiliates migrate to a rival. The model’s redundancy is a feature the operators designed in, which is why takedowns slow the ecosystem without stopping it.
Can law enforcement break a RaaS operation?
They can wound one, and 2024 through 2026 gave several examples. Operations against LockBit and others showed that seizing infrastructure, exposing operators and sanctioning the crypto plumbing all impose real costs. But the affiliate structure blunts the blow. When one brand collapses, its affiliates carry their skills and access to the , and new brands spin up to absorb them. Disruption works best when it targets the shared choke points, namely the money laundering, the bulletproof hosting and the operators themselves, rather than the interchangeable affiliates at the edge. The lesson of the takedowns is that RaaS is a hydra, and the neck, not the heads, is where pressure counts.
How does your own site score?
Run the same forty passive checks against your own domain: TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
Frequently asked questions
RaaS stands for ransomware-as-a-service. It is a model where core operators build and rent out ransomware and infrastructure to affiliates, who carry out the attacks and the ransom proceeds with the operators.
Splits vary by program, but affiliates commonly keep the larger , often around 70 to 80 percent, while operators take the remainder as payment for the platform, encryptor and support. Terms are advertised to attract skilled affiliates.
No. Most large crews run RaaS, but some, such as SafePay, operate a centralised model with no external affiliates. Centralised groups trade scale for tighter control and more consistent tradecraft.
The affiliate structure builds in redundancy. Arresting an affiliate leaves the platform intact, and seizing a leak site pushes affiliates to rival brands. Disruption works best against shared choke points like money laundering and hosting.
Many buy ready-made access from initial access brokers or use credentials harvested from infostealer logs. That upstream market lets affiliates skip the hardest part of an attack and move straight to deployment.
Sources and further reading
Chainalysis — Crypto Ransomware: 2026 Crime Report (payment data)
CISA #StopRansomware — official guidance and advisories
Ransomnews — Initial Access Brokers 2026
Ransomnews — LockBit, two years after Operation Cronos
Ransomnews — Threat-group catalogue
The Ransomnews Monthly
The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
