Ransomware-as-a-Service: How the Underground Economy Threatens Your Business
Ransomware has undergone a fundamental transformation. What began as crude malware distributed through mass spam campaigns has evolved into a sophisticated criminal enterprise structured like a legitimate software business. Ransomware-as-a-Service (RaaS) has lowered the barrier to entry for cybercriminals, democratized access to advanced attack capabilities, and created an underground economy that generates billions of dollars in annual revenue. Understanding the RaaS ecosystem (its business model, its key players, its economics, and its infrastructure) is essential for building defenses that address the real threat rather than outdated assumptions.
The RaaS Business Model
The RaaS model mirrors the legitimate Software-as-a-Service industry. It separates the development of the ransomware tool from the execution of attacks, creating specialization and efficiency that benefits both parties. The ecosystem consists of distinct roles that work together to maximize profit while distributing risk.
Operators
Operators are the developers and maintainers of the ransomware platform. They write the malware code, develop the encryption algorithms, build the payment infrastructure (Tor-based portals, cryptocurrency wallets, chat systems for negotiation), and provide operational support to their affiliates. Operators invest significant resources in development: modern ransomware supports multiple encryption modes, anti-analysis techniques, lateral movement capabilities, and evasion of security tools. They maintain affiliate dashboards that track infections, payments, and negotiation status. The operator role requires advanced technical skills but relatively low risk, as they rarely interact directly with victims.
Affiliates
Affiliates are the operators who conduct the actual attacks. They purchase or receive access to the ransomware platform, then use their own skills and infrastructure to compromise victims. Affiliates handle initial access, network reconnaissance, privilege escalation, data exfiltration, and payload deployment. Many affiliates are experienced penetration testers or network intruders who have pivoted to criminal activity. The affiliate role carries higher risk (they are the ones interacting with victims, negotiating ransoms, and potentially facing law enforcement) but also higher reward.
Profit-Sharing Arrangements
The typical RaaS profit split gives 70% to 80% of ransom payments to the affiliate, with the operator retaining 20% to 30%. Some groups offer higher percentages to affiliates who generate more revenue or who demonstrate a track record of successful attacks. LockBit, for example, offered up to 80% to affiliates, while BlackCat/ALPHV offered a similar structure. These arrangements incentivize affiliates to target high-value organizations and maximize ransom demands. The predictable revenue stream attracts skilled operators who might otherwise pursue legitimate careers in penetration testing.
Major RaaS Groups
The RaaS landscape is dominated by a handful of highly active groups, each with distinct characteristics, target preferences, and operational methods.
LockBit
LockBit emerged in 2019 and quickly became one of the most prolific ransomware operations in history. LockBit 3.0 introduced advanced features including Zcash payment options, a bug bounty program inviting researchers to find vulnerabilities in their software, and automated negotiation tools. LockBit targeted organizations across all sectors and geographies, with a particular focus on manufacturing, healthcare, and professional services. The group operated a highly professional affiliate program with clear rules, rapid payouts, and extensive operational documentation. In February 2024, an international law enforcement operation disrupted LockBit’s infrastructure, seizing servers and decryptor keys, though the group attempted to reconstitute operations.
BlackCat/ALPHV
BlackCat, also known as ALPHV, was the first major ransomware written in Rust, giving it cross-platform capabilities and making it harder to reverse-engineer. BlackCat affiliates were known for aggressive double and triple extortion tactics: encrypting data, threatening to publish stolen data, and launching DDoS attacks against victims who refused to pay. The group targeted high-profile organizations including MGM Resorts and Caesars Entertainment. In late 2023, BlackCat executed an exit scam against its own affiliates, seizing approximately $22 million in ransom payments that were owed to affiliates for the Change Healthcare attack. This betrayal highlighted the inherent instability of criminal enterprises built on mutual self-interest.
Cl0p
Cl0p differentiated itself by specializing in zero-day exploitation of file transfer and collaboration platforms. The group exploited vulnerabilities in Accellion FTA, GoAnywhere MFT, and MOVEit Transfer to compromise hundreds of organizations in rapid succession. Cl0p’s strategy of targeting widely-used enterprise software amplified the impact of each vulnerability, enabling mass exploitation campaigns that affected thousands of victims simultaneously. The MOVEit campaign alone impacted over 2,500 organizations and exposed data belonging to over 67 million individuals.
Play
Play ransomware emerged in 2022 and rapidly gained prominence by targeting government agencies, healthcare organizations, and critical infrastructure. Play operators were known for their patience, sometimes spending months inside a network before deploying ransomware. The group adopted novel techniques including exploiting Microsoft Exchange vulnerabilities, using custom tools to evade detection, and employing intermittent encryption to speed up the encryption process while still rendering files unusable.
The RaaS Underground Economy
The RaaS ecosystem does not operate in isolation. It is supported by a broader underground economy that provides specialized services at every stage of the attack lifecycle. This division of labor makes the entire ecosystem more efficient and resilient.
Initial Access Brokers
Initial Access Brokers (IABs) specialize in gaining access to corporate networks and then selling that access to the highest bidder. IABs advertise on underground forums, listing access to specific organizations along with details about the network: number of hosts, domain admin status, revenue, industry, and geographic location. Prices range from a few hundred dollars for access to a small business to tens of thousands of dollars for access to a large enterprise. IABs provide a crucial service to RaaS affiliates who may lack the skills or patience for initial compromise but excel at lateral movement and payload deployment.
Malware-as-a-Service for Initial Infection
The initial infection phase is supported by a separate ecosystem of malware-as-a-service providers. Infostealers like RedLine, Raccoon, and Vidar harvest credentials, session cookies, and system information from infected hosts. These harvested credentials are sold on underground markets and used by RaaS affiliates to gain initial access. Malware loaders like Emotet, Qakbot, and BazarLoader deliver the initial payload and establish persistence, then sell access to the infected host to RaaS operators. This specialization means that the initial infection, network access, and ransomware deployment may be performed by entirely different criminal groups.
Ransomware Negotiation Services
The ransom negotiation process has become professionalized. Some RaaS groups employ dedicated negotiators who communicate with victims through Tor-based chat portals. These negotiators follow scripts, offer discounts for quick payment, and use psychological pressure tactics including countdown timers and threats of data publication. On the victim side, specialized negotiation firms like Coveware and CyberScout represent organizations during ransom negotiations, attempting to reduce demands, verify decryption capabilities, and manage communication with attackers.
Cryptocurrency Laundering Services
Ransom payments are made in cryptocurrency, primarily Bitcoin and Monero. Converting cryptocurrency to fiat currency without attracting law enforcement attention requires sophisticated laundering techniques. Mixing services, chain-hopping (converting between different cryptocurrencies), and the use of privacy coins like Monero help obscure the flow of funds. Some RaaS groups operate their own laundering infrastructure, while others rely on third-party services. Despite these efforts, blockchain analysis firms like Chainalysis have achieved notable successes in tracing ransom payments and supporting law enforcement seizures.
Attack Economics
The economics of ransomware attacks are rational from the attacker’s perspective, which is precisely why the problem persists. Understanding the cost-benefit analysis helps explain why RaaS continues to grow despite increased law enforcement attention.
Average Ransom Demands
Ransom demands vary widely based on the victim’s size, industry, and perceived ability to pay. Small businesses typically face demands ranging from $50,000 to $500,000. Mid-market companies see demands in the $1 million to $10 million range. Large enterprises and critical infrastructure organizations have faced demands exceeding $50 million. Demands have trended upward over time as attackers become more confident in their ability to extract payment and as organizations become more reliant on digital systems that cannot tolerate extended downtime.
Payment Rates
According to various industry reports, approximately 40% to 50% of organizations that are hit with ransomware pay the ransom. Payment rates vary by industry, with healthcare and critical infrastructure organizations paying at higher rates due to the life-safety implications of extended downtime. Some organizations pay because they lack adequate backups. Others pay because the threat of data publication creates regulatory and reputational consequences that exceed the cost of the ransom. The payment decision is complex, involving legal, ethical, operational, and financial considerations.
Cost-Benefit Analysis from the Attacker’s Perspective
From the attacker’s perspective, the economics are compelling. An affiliate who conducts a ransomware attack against a mid-sized company may invest a few thousand dollars in initial access, infrastructure, and tools. If the ransom demand is $2 million and the affiliate retains 80%, the return on investment is enormous. Even with a 50% payment rate and occasional law enforcement disruption, the expected value of an attack campaign far exceeds the costs. This is why RaaS continues to attract skilled operators despite the risks.
Defensive Strategies
Defending against RaaS requires a layered approach that addresses the entire attack chain, from initial access to ransom payment. No single control is sufficient, but a combination of preventive, detective, and responsive measures can significantly reduce both the likelihood and impact of a successful attack.
Preventing Initial Access
The most cost-effective point to stop a ransomware attack is before the attacker gains initial access. This means hardening the attack vectors that RaaS affiliates rely on most: securing RDP with MFA and network-level access controls, patching externally-facing applications promptly, implementing email security with URL rewriting and attachment sandboxing, enforcing MFA on all remote access and cloud services, and monitoring for credential theft indicators. Since RaaS affiliates increasingly purchase access from IABs, preventing initial access disrupts the entire supply chain.
Network Segmentation to Limit Blast Radius
When prevention fails, containment becomes critical. Network segmentation limits the attacker’s ability to move laterally across the environment and access critical systems. Implement segmentation between business units, between IT and OT environments, and between user workstations and server infrastructure. Use identity-based micro-segmentation to enforce least-privilege access at the workload level. The goal is to ensure that a compromised workstation in marketing cannot reach the domain controller or the backup server.
Immutable Backups as the Last Line of Defense
Backups are the ultimate safety net against ransomware, but only if they survive the attack. Ransomware operators actively seek out and destroy backups before deploying their payload. They target backup servers, delete shadow copies, and encrypt backup repositories. Immutable backups (backups that cannot be modified or deleted for a defined retention period) are the last line of defense. Use air-gapped backups, write-once-read-many (WORM) storage, or cloud-based immutable storage to ensure that at least one copy of your data survives even a sophisticated attacker. Test your restore procedures regularly, because a backup that cannot be restored is worthless.
Cyber Insurance Considerations
Cyber insurance can help offset the financial impact of a ransomware attack, but it is not a substitute for security controls. Insurers are increasingly requiring specific security measures (MFA, EDR, patching cadence, backup testing) as conditions of coverage. Some insurers have excluded certain attack types or reduced coverage limits. Organizations should view cyber insurance as a risk transfer mechanism that complements their security program, not as a primary defense. Understand your policy’s coverage for ransomware payments, business interruption, data recovery, regulatory fines, and legal costs.
The Debate Around Ransomware Payment Bans
There is ongoing debate about whether governments should ban ransomware payments. Proponents argue that payments fund criminal enterprises, incentivize future attacks, and do not guarantee data recovery or prevent data publication. Opponents argue that bans would force organizations to absorb the full cost of attacks, potentially driving some out of business, and would push payments underground where they are harder to track. Some security experts advocate for mandatory reporting of ransomware payments rather than outright bans, enabling law enforcement to track the flow of funds and identify criminal networks. Regardless of policy positions, organizations should prepare for the possibility that they will not pay (or will be prohibited from paying) by investing in prevention, detection, and recovery capabilities.
Conclusion
Ransomware-as-a-Service has transformed cybercrime into a scalable, profitable, and resilient enterprise. The specialization of roles, the professionalization of operations, and the supportive underground economy create an ecosystem that is far more dangerous than individual hackers operating alone. Defending against this threat requires understanding the attacker’s business model and disrupting it at every stage: preventing initial access, containing lateral movement, protecting backups, and preparing incident response capabilities. The RaaS economy will continue to evolve, and so must your defenses. Organizations that treat ransomware as a technical problem to be solved with a single tool or policy will find themselves outmatched. Those that build layered, tested, and continuously improving defenses will survive.