Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Understanding RaaS and preventing ransomware attacks

Diagram illustrating how Ransomware-as-a-Service (RaaS) works, showing operators leasing ransomware tools to affiliates who carry out attacks and prevention steps to stop ransomware

Quick answer: Ransomware-as-a-Service (RaaS) is a criminal business model where malware developers lease ransomware tools to affiliates who run the actual attacks, splitting each ransom payment between them. It matters because RaaS now drives most ransomware incidents industry-wide. The recommended action: harden identity and remote-access controls, monitor code-signing certificates, and keep tested offline backups before an affiliate reaches your network.

Key Takeaways

  • RaaS is an affiliate model: operators build and maintain the ransomware and payment infrastructure, affiliates run the intrusions, and both sides split each ransom, commonly reported in the 70/30 to 80/20 range favoring the affiliate.
  • Initial access brokers (IABs) are a separate specialist role that sells stolen credentials or network footholds to RaaS affiliates, shortening the time between compromise and encryption.
  • Double extortion, encrypting data and stealing a copy to threaten a public leak, is now the default RaaS playbook; some campaigns add a third pressure point, such as a DDoS threat or contacting the victim’s customers directly (triple extortion).
  • RansomHub, one of the most active RaaS brands of 2024 into early 2025, went dark on April 1, 2025; affiliates reportedly moved to Qilin, and other groups claimed pieces of its infrastructure.
  • Akira, Qilin, and Medusa were among the most active RaaS operations tracked through 2025, together accounting for a majority of observed ransomware incidents, while LockBit remains disrupted but not eliminated after law enforcement’s Operation Cronos in February 2024.
  • Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of breaches overall and in 88% of breaches at small and midsize businesses, even as reported average and median ransom payments fell in 2025.

Published: July 2023. Updated: August 2026. Reviewed by Encryption Consulting’s security team.

What Is Ransomware-as-a-Service (RaaS) and How Does the Affiliate Model Work?

Ransomware-as-a-Service (RaaS) is a criminal business model in which a group of developers, often called operators, builds and maintains ransomware, a negotiation and payment portal, and a data-leak site, then leases that toolkit to affiliates in exchange for a cut of every ransom collected. It is the malicious mirror of Software-as-a-Service: instead of subscribing to productivity software, an affiliate subscribes to a working ransomware kit and the infrastructure to run it, without needing to write a line of malware code themselves.

The RaaS supply chain typically involves three distinct roles. Operators develop the encryption payload, run the affiliate panel, host the leak site used to pressure non-paying victims, and often handle ransom negotiations. Affiliates are the attackers who actually break into a victim’s network, move laterally, disable backups, and deploy the payload; they keep the majority of each ransom, commonly reported in the 70/30 to 80/20 range in the affiliate’s favor, since the affiliate carries most of the operational risk. Initial access brokers (IABs) are a separate specialty: they compromise networks through phishing, exposed remote desktop protocol (RDP), vulnerable VPN appliances, or exposed remote monitoring and management (RMM) tools, then sell that access to affiliates on criminal marketplaces, which shortens the time between a network compromise and a ransomware deployment.

This division of labor is what makes RaaS dangerous: a low-skill affiliate who could never write functional ransomware can still launch a technically sophisticated, double-extortion attack against a well-defended organization, because the hard engineering work has already been done and sold as a service. Nearly all current RaaS operations use double extortion, encrypting the victim’s files while also exfiltrating a copy of sensitive data, then threatening to publish that data on a leak site if the ransom is not paid, which defeats the old defense of simply restoring from backup. Some campaigns escalate to triple extortion, adding a third pressure point such as a distributed denial-of-service (DDoS) threat against the victim’s public-facing systems or direct outreach to the victim’s customers, employees, or regulators.

RaaS-distributed ransomware is only one variant of a broader ransomware category that also includes scareware (fake malware alerts that trick a user into paying for a fraudulent fix), screen lockers (which lock device access rather than encrypt files), and standalone cryptoware built and run by a single group. RaaS is distinct from all three because it is a business model and distribution channel, not a payload type: the same RaaS platform can be used to deploy encryption, data theft, or both, depending on which affiliate is running the attack.

How Has RaaS Evolved as a Criminal Business Model? A Timeline

RaaS did not appear overnight; it evolved from single-operator ransomware into a specialized, multi-party criminal economy over roughly a decade, with each major disruption reshaping which groups dominate next.

  • 2016: Cerber is among the first widely documented ransomware families marketed explicitly as a service, letting affiliates lease the payload and infrastructure for a revenue share.
  • 2018 to 2019: GandCrab becomes one of the most prolific RaaS operations of its era; its operators publicly announced retirement in 2019, and security researchers subsequently linked much of GandCrab’s affiliate network and code lineage to the RaaS group that became known as REvil (Sodinokibi).
  • 2020 to 2021: REvil and DarkSide popularize double extortion as the RaaS default. DarkSide’s May 2021 attack on Colonial Pipeline pushes RaaS from a niche security topic into mainstream national security attention.
  • July 2021: REvil affiliates exploit a zero-day in Kaseya VSA, a remote monitoring and management tool, to push ransomware to roughly 60 managed service providers and up to 1,500 downstream businesses in a single supply chain attack; see Encryption Consulting’s case study on the Kaseya VSA attack for the full verified timeline.
  • 2022: Internal chat logs from the Conti RaaS group leak publicly after Conti’s stance on the Russia-Ukraine war, exposing the internal affiliate economics, tooling, and management structure of a major RaaS operation in unprecedented detail.
  • February 2024: An international law enforcement coalition led by the UK’s National Crime Agency, called Operation Cronos, seizes LockBit’s infrastructure, affiliate panel, and decryption keys, disrupting what had been the most active RaaS brand at the time; elements of the group continued limited activity afterward.
  • April 1, 2025: RansomHub, one of the most active RaaS brands through 2024 and early 2025, goes dark; affiliates reportedly move to Qilin, while other groups claim to have absorbed parts of its infrastructure.
  • 2025 into 2026: Akira, Qilin, and Medusa emerge among the most active tracked RaaS operations, together linked to more than half of observed ransomware incidents in 2025, even as reported average and median ransom payments decline from 2024 levels.

What Technologies and Systems Do RaaS Affiliates Typically Target?

RaaS affiliates target whatever gives them the fastest path to broad, privileged access, most often internet-facing remote access infrastructure and identity systems rather than individual endpoints. Common targets include exposed RDP and VPN appliances, remote monitoring and management (RMM) tools used by managed service providers, Active Directory and other identity infrastructure, backup and snapshot systems (disabled or deleted first, to remove the free recovery path), cloud storage and SaaS data used for the exfiltration side of double extortion, and code-signing certificates and keys, which attackers steal or fraudulently obtain to make a malicious payload or update look legitimately signed, as documented in Encryption Consulting’s coverage of the 2023 MSI code-signing key theft.

What Is the Real Business Impact of a RaaS Attack?

A RaaS attack’s cost extends well beyond the ransom demand itself, spanning downtime, recovery labor, legal exposure, and reputational damage, and current data shows both the frequency and the financial shape of that impact shifting year over year.

  • Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of breaches overall, a 37% increase over the prior year, and in 88% of breaches specifically affecting small and midsize businesses versus 39% at larger organizations.
  • Sophos reported the average ransom payment in 2025 at roughly $1 million, a 50% decrease from the roughly $2 million average reported in 2024, while Palo Alto Networks’ 2025 research put the median ransom payment at $267,500.
  • Overall ransomware attack volume kept rising through 2025 even as payment amounts fell, which threat researchers generally attribute to more organizations refusing to pay, alongside continued growth in the number of active RaaS affiliates and groups.
  • Beyond the direct payment, organizations absorb costs from incident response, system rebuilding, regulatory notification, customer churn, and, in double extortion cases, the ongoing risk of leaked data being reused in follow-on fraud or a second extortion attempt.

What Are the Early Warning Signs of a RaaS Attack in Progress?

Most RaaS intrusions leave detectable signals well before encryption begins, and catching them at this stage is far cheaper than post-incident recovery. Security teams should treat each of the following as a high-priority indicator, not routine noise:

  • Unexpected installation or use of legitimate remote access or RMM tools that were not deployed by IT.
  • New or modified administrative accounts, or privilege escalation events outside a change window.
  • Security tooling, EDR agents, or backup agents being disabled, uninstalled, or tampered with.
  • Unusual outbound data transfers or connections to unfamiliar cloud storage endpoints, consistent with data staged for exfiltration ahead of encryption.
  • A spike in failed authentication attempts followed by successful lateral movement between systems.
  • An unexpected or newly issued code-signing certificate, or a signing key used from an unfamiliar location or system.
  • Test files renamed or partially encrypted on a small number of systems, often the last visible signal before a full-scale deployment.

How Can Organizations Prevent and Remediate RaaS Attacks? A Numbered Checklist

No single control stops every RaaS variant, since affiliates choose whichever access path is easiest against a given target. The following steps close the specific gaps that RaaS affiliates and initial access brokers rely on most, drawing on Encryption Consulting’s broader guidance on ransomware and how to prevent ransomware attacks.

  1. Enforce multi-factor authentication (MFA) on every remote access path, including RDP, VPN, and RMM consoles, and remove direct internet exposure of management interfaces wherever possible.
  2. Apply least-privilege access controls and segment the network so a single compromised account or tenant cannot reach every other system.
  3. Maintain offline or immutable backups and test full restoration regularly; a backup that has never been restored in a drill is not a verified recovery path.
  4. Monitor and inventory code-signing certificates and private keys, and treat an unexpected or newly issued signing certificate as a possible indicator of compromise rather than routine activity.
  5. Keep RMM, VPN, and edge infrastructure patched on a real service-level agreement tied to vendor advisories, since these are the tools RaaS affiliates and IABs target first.
  6. Deploy endpoint detection and response (EDR) or extended detection and response (XDR) tuned to flag backup-deletion commands, mass file renaming, and disabled security agents.
  7. Run regular phishing simulations and security awareness training, since phishing remains one of the most common entry points IABs use to harvest the credentials they later sell.
  8. Use secure web gateways to identify malicious ads and drive-by download sites that lead users toward ransomware droppers.
  9. Schedule timely vulnerability assessments and penetration testing against internet-facing systems to close the exposures IABs scan for.
  10. Build and rehearse an incident response plan before an attack, including how to isolate affected systems, shut down identified backdoors, and notify regulators and customers within required timeframes.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

Update Log

This post originally ran in July 2023 as a general explainer of ransomware types and RaaS basics. As of August 2026, it has been substantially rewritten: it now leads with a direct answer, adds a primary-source timeline of RaaS’s evolution as a business model, an impact assessment grounded in 2025 breach and payment data, a detection-actions section, a numbered remediation checklist, a decision table on notable RaaS groups’ current status, a limitations section, an FAQ, and refreshed schema markup. Group names and status have been updated to reflect the current threat landscape as of late 2025 and mid-2026, including RansomHub’s April 2025 shutdown and the continued disruption of LockBit following Operation Cronos, replacing outdated 2021-era framing. This post is the general explainer of how the RaaS business model works; for a detailed retrospective on one real-world RaaS-adjacent supply chain incident, see Encryption Consulting’s Kaseya VSA case study.

Notable RaaS Groups: Status as of Late 2025 and Mid-2026

RaaS GroupStatus (Most Recent Verified Reporting)Notes
LockBitDisrupted, not eliminatedInfrastructure and affiliate panel seized in law enforcement’s Operation Cronos, February 2024; limited activity under the LockBit name has continued since.
RansomHubWent darkOne of the most active RaaS brands of 2024 into early 2025; operations stopped on April 1, 2025, with affiliates reportedly moving to Qilin and other groups.
QilinActive, high volumeRose sharply in prominence after RansomHub’s April 2025 collapse and was among the most active tracked RaaS operations through 2025.
AkiraActive, high volumeConsistently ranked among the most active RaaS operations by incident volume through 2025.
MedusaActiveNamed among the most active RaaS operations tracked in 2025 threat reporting.

Limitations

RaaS group names, affiliations, and operational status change quickly: groups rebrand, splinter after internal disputes, or resurface under new names following a law enforcement takedown, so the status listed above reflects the most recent verified public reporting available at the time of this update and is not guaranteed to be current by the time a reader reaches this page. Revenue-split percentages between operators and affiliates are also not standardized across the industry; the 70/30 to 80/20 range cited here is the range most commonly reported by security researchers, not a figure disclosed by any group itself. Ransom payment averages and medians vary significantly by data source, industry, and organization size, so the figures above should be read as directional trends rather than precise universal benchmarks. Readers evaluating current risk should confirm group status against a live threat intelligence feed, such as CISA’s #StopRansomware advisories, rather than relying solely on this article.

What Would Encryption Consulting Recommend?

RaaS attacks succeed by combining stolen access with abused trust, whether that trust sits in a remote access tool, an identity system, or a code-signing certificate. Encryption Consulting works with organizations to close exactly those gaps:

  • HSM-as-a-Service keeps encryption and backup keys in FIPS 140-3 validated hardware, giving organizations a resilient key backup and recovery path against ransomware-driven data destruction rather than a single point of failure an affiliate can reach.
  • PKI-as-a-Service and CertSecure Manager give security teams continuous visibility into every certificate in the environment, so an unauthorized or anomalous certificate used to sign a malicious payload is detected instead of trusted.
  • CodeSign Secure centralizes code-signing keys and enforces verification before code executes, helping block malicious payloads that rely on a stolen or fraudulently obtained signing identity.
  • Encryption Advisory services help organizations build the segmentation, least-privilege access, and incident response runbooks this checklist calls for, backed by our ISO/IEC 27001:2022 and SOC 2 certified delivery practices.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

Frequently Asked Questions

What does RaaS stand for and how is it different from ordinary ransomware? RaaS stands for Ransomware-as-a-Service. Ordinary ransomware is built and deployed by the same group; RaaS separates those roles, with operators building and leasing the ransomware and affiliates running the actual attacks in exchange for a share of each ransom, similar in structure to how Software-as-a-Service separates the software vendor from the end user.

How do RaaS affiliates get paid, and what is the typical revenue split? Affiliates typically keep the majority of each ransom payment, commonly reported in the 70/30 to 80/20 range in the affiliate’s favor, with the remainder going to the operator group for the ransomware, infrastructure, and negotiation portal. The exact split varies by group and is not publicly standardized.

What is the difference between double extortion and triple extortion? Double extortion combines file encryption with data theft, so a victim faces both an operational outage and the threat of stolen data being leaked publicly, even if they can restore from backup. Triple extortion adds a third pressure point on top of that, such as a DDoS threat against public-facing systems or direct contact with the victim’s customers, employees, or regulators.

Which ransomware groups are currently the most active RaaS operations? Based on the most recent verified public reporting, Akira, Qilin, and Medusa were among the most active tracked RaaS operations through 2025, with Qilin gaining significant volume after the RaaS group RansomHub went dark in April 2025. LockBit remains disrupted following law enforcement’s Operation Cronos in February 2024 but has not been fully eliminated. Because groups rebrand and law enforcement activity is ongoing, current status should be confirmed against a live threat intelligence source.

What is the single most effective step an organization can take to reduce RaaS risk? There is no single fix, but tested, offline or immutable backups combined with multi-factor authentication on every remote access path address the two failure points RaaS affiliates rely on most: the ability to move in undetected and the ability to force payment by destroying the victim’s only copy of its data.

Conclusion

Ransomware-as-a-Service turned ransomware from a technical skill into a purchasable service, and that shift is why attack volume keeps climbing even as individual groups get taken down. Understanding the affiliate model, the initial access broker economy, and double and triple extortion is what lets a security team recognize a RaaS attack’s early signals instead of only its final ransom note. The groups named in this article will keep changing; the underlying playbook, stolen access sold to an affiliate who encrypts and steals data for a cut of the payment, has stayed remarkably consistent for a decade, which is exactly why the controls that defeat it (identity hardening, tested backups, and certificate and key monitoring) remain the right investment regardless of which brand is active this year.

References