Ransomware Economy

Ransomware-as-a-Service (RaaS): How the Criminal Franchise Model Works

The franchise model that industrialised ransomware — developers lease payloads, affiliates run intrusions, and negotiation infrastructure handles the rest. Understanding RaaS is the prerequisite to defending against it.

Last updated October 8, 2026

Overview

Ransomware-as-a-Service (RaaS) is the single most important structural change in the ransomware threat landscape over the past decade. Instead of a single group developing malware, deploying it, and collecting ransoms, RaaS splits the operation into two specialised roles: a developer who maintains the encryptor, leak site, and negotiation portal, and a network of affiliates who conduct the intrusions and receive a revenue share (typically 70–80%).

This franchise model dramatically lowered the technical barrier to entry. An attacker no longer needs to write malware or maintain a Tor hidden service — they need only initial access and basic intrusion skills. Groups like LockBit, BlackCat/ALPHV, RansomHub, and Cl0p professionalised the model with affiliate portals, profit dashboards, and even customer support, treating ransomware like a legitimate SaaS business.

The defensive implication is significant: takedown of a single brand rarely eliminates the threat. After Operation Cronos disrupted LockBit in February 2024, affiliates migrated to competing platforms within weeks. The developers and affiliates are interchangeable; the ecosystem persists. Defenders must therefore target the common intrusion patterns — initial access, credential theft, lateral movement — rather than chasing individual brand names.

Key Points

Affiliate economics

Developers take 20–30% of ransoms; affiliates keep the majority, creating financial incentive to conduct more intrusions and a self-scaling operator base.

Leak-site extortion

Every major RaaS operates a Tor leak site publishing stolen data of non-payers, compounding encryption with reputational and regulatory damage.

Rapid brand reconstitution

When one brand is disrupted, developers and affiliates rebrand within weeks — LockBit re-emerged after Cronos, ALPHV affiliates split into RansomHub and others.

Professional support

Affiliate portals include negotiation tooling, multi-language ransom notes, and helpdesk-style support, lowering operational friction for non-technical operators.

Initial access dependency

RaaS affiliates rarely develop their own access; they buy it from Initial Access Brokers or exploit edge VPN/RDP vulnerabilities, making access hygiene the highest-leverage control.

Latest Intelligence

Frequently Asked Questions

Defensive Intelligence

Encrygma produces defensive intelligence only. This analysis is derived from public reporting, government advisories, and OSINT — no exploit code or attack instructions.

Sovereign Defense Solutions
Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.