Ransomware as a service operates like a criminal franchise, separating tool development from execution and laundering. This division of labour ensures that takedowns disrupt brands but rarely dismantle the underlying economy. Defenders must analyse affiliate behaviour rather than chasing specific group names to understand the threat.
The modern ransomware threat is no longer defined by a single sophisticated hacker group operating in isolation. It functions as a structured industry, often described as ransomware as a service. This model separates the creation of malicious software from the actual intrusion and extortion. Developers build the tools, while a separate layer of actors handles the breach and the demands.
This division of labour creates a resilient ecosystem. When law enforcement disrupts one brand, the infrastructure remains intact. The developers simply rebrand their software, and new affiliates step in to use it. The economic incentives are strong, and the barriers to entry for low-skilled actors have never been lower.
Understanding this structure is essential for effective defence. Focusing solely on the name on a ransom note misses the underlying mechanics. The real threat lies in the supply chain of criminal services, the behaviour of affiliates, and the methods used to launder proceeds. By analysing these patterns, organisations can build controls that address the root causes of the attack lifecycle.
Roles in the ransomware economy
The ransomware economy relies on a clear separation of duties. This structure allows each participant to specialise, increasing efficiency and reducing the risk of detection for any single individual. The primary roles include developers, affiliates, brokers, and negotiators. Each group performs a distinct function within the criminal value chain.
Developers are responsible for engineering the encryption tools and the associated infrastructure. They maintain the command and control servers, manage the decryption keys, and update the malware to evade detection. Their success depends on the reliability and stealth of their software. They do not typically contact victims directly, allowing them to remain hidden behind layers of anonymity.
Affiliates are the operators who execute the attacks. They may have varying levels of technical skill, ranging from those who script simple intrusions to those who exploit complex vulnerabilities. They use the tools provided by developers to gain initial access, move laterally, and deploy the ransomware. In return for using the software, they pay a share of the profits to the developers.
Brokers facilitate the connection between developers and affiliates, or between affiliates and victims. They often sell access to compromised networks or provide intelligence on high-value targets. This role reduces the search costs for affiliates and ensures that the most capable operators get access to the best tools. Negotiators then handle the communication with victims, managing the extortion process and the eventual payment.
How revenue is split
The financial model of ransomware as a service is built on revenue sharing. This arrangement aligns the incentives of all participants, ensuring that each party has a stake in the success of the operation. The split varies depending on the level of involvement and the reputation of the group.
Developers typically take a significant percentage of the ransom payment. This fee covers the cost of maintaining the software, the infrastructure, and the ongoing development efforts. In some cases, developers may also charge an upfront fee or a subscription cost. The remaining portion is retained by the affiliates who performed the intrusion.
Affiliates must cover their own operational costs, such as the purchase of access or the time spent on reconnaissance. Their profit margin depends on their ability to maximise the ransom demand while minimising the risk of detection. Negotiators may take a cut of the final payment, especially if they are employed by the developer or a larger syndicate.
The complexity of the split increases when multiple parties are involved. A broker who provides initial access may take a percentage before the affiliate even begins the attack. This layered structure makes it difficult to trace the flow of funds, as money is distributed across numerous accounts and cryptocurrencies. The transparency of blockchain transactions does not necessarily reveal the identity of the beneficiaries.
Why takedowns rebrand rather than end groups
Law enforcement actions often result in the seizure of domains and the arrest of key figures. However, these takedowns rarely dismantle the underlying criminal organisation. The modular nature of the ransomware economy means that the loss of one component does not collapse the entire system.
Developers can simply rebrand their software and launch a new operation. The codebase remains largely unchanged, and the infrastructure can be rebuilt on new servers. Affiliates are loyal to the tool and the profit stream, not the specific brand name. They will quickly adopt the new iteration of the software.
Brokers and negotiators continue to operate independently of the developer. They maintain their networks and relationships with victims. When a new brand emerges, these actors are ready to integrate it into their existing processes. The knowledge and expertise within the ecosystem are not tied to a single entity.
This resilience is further strengthened by the decentralised nature of the internet. Criminals can easily migrate to new hosting providers and use encryption to hide their communications. The barrier to entry for starting a new ransomware group is low, ensuring a constant supply of new actors. Defenders must therefore focus on disrupting the economic incentives rather than just targeting specific brands.
Affiliate habits defenders can see
While the brands change, the behaviour of affiliates often remains consistent. Observing these patterns can provide valuable insights for defence. Affiliates tend to follow similar methodologies for initial access, lateral movement, and data exfiltration.
Many affiliates rely on common vectors such as phishing emails and exposed remote desktop protocols. They often prioritise speed over stealth, deploying ransomware quickly to maximise pressure on the victim. This aggressive approach can leave detectable traces in network logs and endpoint telemetry.
The choice of targets also reveals patterns. Affiliates often focus on organisations with poor backup hygiene or limited incident response capabilities. They may also target specific industries where downtime is particularly costly. Understanding these preferences can help organisations prioritise their security investments.
For an explanation of supply chain compromises, see this essay. By compromising a trusted vendor, affiliates can gain access to multiple victims simultaneously. This approach increases their efficiency and reduces the need for individual reconnaissance. Defenders should monitor their supply chains for signs of compromise.
What this means for your controls
The franchise model of ransomware demands a shift in defensive strategy. Traditional perimeter-based security is insufficient against an adversary that operates with such division of labour. Organisations must adopt a more holistic approach that addresses the entire attack lifecycle.
Strong identity management is critical. Many breaches begin with compromised credentials. Implementing multi-factor authentication and monitoring for anomalous login behaviour can prevent initial access. Enforcing long, unique passwords or passkeys, alongside the principle of least privilege, reduces the attack surface.
Network segmentation limits the ability of affiliates to move laterally. By isolating critical systems and restricting communication between network zones, defenders can contain the impact of a breach. This approach makes it harder for attackers to reach their targets and exfiltrate data.
Backup integrity is paramount. Offline or immutable backups provide a reliable recovery option that does not rely on paying the ransom. Regular testing of backup restoration processes ensures that data can be recovered quickly and completely. Defenders must also be aware of hidden infrastructure risks that may bypass traditional security controls.
Where disruption actually bites
Disruption is possible, but it requires targeting the economic foundations of the ransomware economy. Law enforcement efforts should focus on the laundering of proceeds and the infrastructure that supports the operations. Disrupting the financial flows reduces the profitability of the enterprise.
Cooperation between the public and private sectors is essential. Sharing threat intelligence allows organisations to identify common indicators of compromise and adapt their defenses. Industry-wide initiatives can also raise the cost of doing business for ransomware groups.
Defenders must recognise that defending against organized crime is a continuous process. There is no silver bullet that will eliminate the threat. Instead, organisations must build resilience through robust security practices and rapid incident response capabilities.
The focus should be on reducing the attractiveness of the target. By making it difficult and expensive to attack, organisations can deter affiliates. This includes maintaining up-to-date software, training employees to recognise social engineering, and having a clear plan for responding to incidents.
Questions people ask
What is ransomware as a service model?
Ransomware as a service is a business model where developers create and maintain ransomware tools, which are then rented to affiliates. Affiliates use these tools to breach systems and encrypt data, sharing a portion of the ransom with the developers. This separation of roles allows for greater specialisation and scalability within the criminal ecosystem.
How do ransomware groups make money?
Ransomware groups make money by extorting payments from victims who have had their data encrypted or stolen. The revenue is split among developers, affiliates, brokers, and negotiators based on their contribution to the attack. Payments are typically made in cryptocurrencies to obscure the trail of funds and avoid detection.
Why do ransomware gangs keep coming back?
Ransomware gangs keep coming back because the economic incentives are strong and the barriers to entry are low. When a specific brand is disrupted, developers can rebrand their software, and new affiliates can step in to use it. The modular nature of the ransomware economy ensures that the underlying infrastructure and expertise remain intact, allowing the threat to persist.
Close
The ransomware threat is not a fleeting problem but a structured industry. Its resilience lies in the division of labour and the economic incentives that drive it. Takedowns of specific brands are visible, but they do not dismantle the underlying system. The developers, brokers, and negotiators continue to operate, adapting to new circumstances.
Defenders must look beyond the headlines and analyse the mechanisms of the attack. By understanding the roles and revenue streams, organisations can identify vulnerabilities in their own defences. The focus should be on reducing the attack surface, strengthening identity controls, and ensuring backup integrity.
This approach requires a long-term commitment to security. There is no single solution that will eliminate the threat. However, by building resilience and disrupting the economic foundations of ransomware, organisations can significantly reduce their risk. The goal is not to win a war that cannot be won, but to make the cost of attack too high for the criminals to sustain.
