Khabar 24h SIMPLE EXPLAINERS ON WORLD AFFAIRS, SCIENCE, HEALTH AND MORE.

KHABAR 24H

Simple explainers on world affairs, science, health and more.

All news under one minute

Cybersecurity & Privacy Read in one minute

Ransomware-as-a-Service: How Cybercrime Became a Subscription Business

Modern ransomware is less like a lone hacker’s virus and more like a franchise business. In the criminal underworld, there is now a supply chain with developers, sales channels, marketing, customer support — even profit-sharing agreements. It is called ransomware-as-a-service (RaaS), and it is one of the main reasons ransomware attacks have exploded in frequency and scale.

This explainer unpacks how the RaaS model works, who does what in it, and how organisations defend themselves against it.

The SaaS analogy

Ransomware-as-a-service is the criminal mirror of legitimate software-as-a-service. In the legal world, a company builds a software product and rents access to it through a subscription; in RaaS, a core team of criminals builds the ransomware, the payment infrastructure, and the extortion machinery, then leases it to other criminals — called affiliates — who carry out the actual attacks.

The operators provide everything a would-be attacker needs: ready-made encryption malware, control panels and dashboards that track infections and payments (usually hosted on anonymised dark-web networks), documentation, and even customer support — including, in some operations, support for the victims themselves, walking them through the ransom payment process to make sure the money arrives. Subscription fees, one-time licences, or profit-sharing deals are the common payment terms, and developers often take around 20 to 40 per cent of each ransom paid.

The result is a dramatically lowered barrier to entry: attackers no longer need to be skilled programmers to launch a sophisticated ransomware campaign. They need distribution skills and a willingness to break the law.

The players: operators, affiliates, and brokers

Three roles define the modern RaaS ecosystem. Operators (developers) write and update the malware, run the payment and leak-site infrastructure, and recruit affiliates. They function like a product company, shipping bug fixes and feature upgrades to keep their “customers” successful.

Affiliates are the ones who actually carry out attacks: they gain access to victim networks, steal data, deploy the encryption payload, and negotiate the ransom. Modern affiliate kits make this doable for lower-skill actors, which is precisely why operators take a cut rather than doing the intrusions themselves.

A third specialist has become entrenched in the supply chain: initial access brokers. These middlemen harvest or buy stolen credentials, deploy info-stealing malware, or exploit exposed services — then sell that ready-made foothold to affiliates, who can skip the break-in work entirely. An affiliate might simply purchase access to a company’s network on an underground market and move straight to the encryption stage.

Double and triple extortion

RaaS changed the economics of ransom demands. The classic attack encrypts a victim’s files and offers a decryption key for payment. But many RaaS operations now practise double extortion: they first steal sensitive data, then threaten to publish it on a public “leak site” if the ransom is not paid — a pressure tactic that works even against organisations that can restore encrypted files from backups.

Some groups have gone further with triple extortion: piling on distributed denial-of-service (DDoS) attacks against the victim’s infrastructure, or directly contacting the victim’s customers and partners to spread the pressure. Each layer exists to make “just restore from backup” an insufficient answer.

Real-world examples: takedowns and exit scams

The scale of RaaS is visible in law enforcement records. LockBit was one of the most prolific RaaS operations; in February 2024, an international action dubbed Operation Cronos — involving the FBI, the UK’s National Crime Agency, and Europol — seized its infrastructure, exposed affiliate data and decryption keys, and led to arrests. Before the takedown, US victims had reportedly paid more than $91 million in ransoms to LockBit affiliates.

ALPHV/BlackCat collapsed around the same time after its administrators reportedly pocketed an estimated $22 million ransom paid by healthcare company Change Healthcare and vanished without paying their affiliates’ share — an exit scam that defrauded the group’s own criminal workforce. Other operations, like Hive, were dismantled by the FBI in early 2023 after authorities infiltrated its infrastructure and quietly provided decryption keys to more than 300 active victims.

Yet takedowns have not shrunk the market. Security analysts describe a familiar pattern: affiliates simply migrate to competing platforms, code is reused, and new brands absorb the displaced talent. The FBI’s Internet Crime Complaint Center (IC3) reported receiving more than 3,600 ransomware complaints in 2025 alone, with reported losses exceeding $32 million — a reminder that the RaaS economy keeps running even as individual brand names rise and fall.

How organisations defend themselves

Because RaaS attacks typically exploit known weaknesses rather than exotic zero-days, cybersecurity professionals emphasise a set of layered, unglamorous defences:

  • Backups that survive the attack: regular, tested, and — critically — kept offline or isolated, since many ransomware strains deliberately seek out and destroy backups before encrypting anything else.
  • Patching and email filtering: affiliates commonly gain entry through phishing emails and unpatched public-facing applications, so prompt patching and mail filtering cut off the cheapest routes in.
  • Endpoint security and network segmentation: strong endpoint protection plus segmented networks make it harder for an intruder to move laterally once inside.
  • Employee training: because phishing remains a primary delivery method, a staff member who recognises a malicious attachment is a meaningful line of defence.
  • Multi-factor authentication: stolen passwords are the stock-in-trade of initial access brokers, and MFA makes those stolen credentials far less useful.

Equally important is planning for the worst case: rehearsed incident-response plans, so that if encryption begins, the organisation knows whom to call and what to disconnect.

FAQs

Should victims pay the ransom?
Law enforcement agencies generally advise against paying. Payment funds the criminal ecosystem, there is no guarantee the stolen data will be deleted or that decryption will fully work — researchers have documented cases where affiliates provided faulty decryptors and ignored victims after payment — and organisations that pay are sometimes targeted again.

What is the difference between RaaS and “regular” ransomware?
Traditional ransomware was built and deployed by a single attacker or group. RaaS splits the work: operators build the tools, affiliates run the attacks, and brokers supply the access. That division of labour is what makes RaaS scalable, frequent, and harder to attribute.

Who gets targeted by RaaS attacks?
Anyone, but affiliates follow the money: hospitals, schools, local governments, small and mid-size businesses, and multinational corporations have all been hit. Critical-infrastructure providers are also frequent targets because downtime there creates maximum pressure to pay.

Can law enforcement actually stop RaaS?
Takedowns like Operation Cronos are real and disruptive — infrastructure seized, affiliates arrested, decryption keys recovered. But they fragment rather than end the ecosystem: displaced affiliates migrate to surviving platforms. The honest assessment from researchers is that enforcement disrupts capacity while the market adapts, which is why defence at the organisational level remains essential.

Compiled by the Khabar 24h Editorial Desk from publicly available sources.

Written by
Khabar 24h Space & Cyber Desk

Staff writer at Khabar 24h — covering daily news in under a minute.

More from this author →

Leave a Reply

Your email address will not be published. Required fields are marked *