Blog

How Ransomware as a Service Has Changed

How Ransomware as a Service Has Changed
Ransomware-as-a-service has transformed who can launch a ransomware attack and how. Learn how the RaaS model works and how to defend your supply chain.

Ransomware remains one of the most damaging threats your organization faces. But the version your security team is dealing with today looks very different from what emerged a decade ago. The shift to ransomware-as-a-service (RaaS) has changed who can launch ransomware attacks, how often they occur, and how difficult they are to stop. Understanding how the RaaS model works and how it has evolved is one of the most practical steps your team can take to defend against it.

What is Ransomware-as-a-Service?

Ransomware-as-a-service is a cybercrime business model in which ransomware developers build, maintain, and lease out ransomware tools and infrastructure to affiliates. In return, affiliates share a portion of every ransom payment. Think of it as a mirror image of legitimate software-as-a-service. The developer handles the ransomware code and backend infrastructure. Affiliates handle distribution. The developer typically takes 20-30% of each successful ransom payment.

This affiliate model dramatically lowered the barrier to entry for ransomware attackers. Before RaaS programs existed, executing a successful ransomware campaign required significant technical skill. A threat actor had to write ransomware code, build command-and-control infrastructure, handle encryption, manage ransom negotiations, and process payments — all while staying anonymous. The RaaS model eliminated much of that complexity by packaging it into an accessible service.

A RaaS affiliate without deep technical knowledge could suddenly access and deploy ransomware that sophisticated developers had spent months building. The ability to launch ransomware without writing a single line of malicious code is what makes RaaS such a consequential threat category.

What makes this model distinct from earlier cybercrime is the separation of roles. Ransomware operators no longer execute attacks directly. They build the platform, sell access to affiliates, and collect a cut of every successful operation. It functions like a franchise. The brand, the tools, and the infrastructure belong to the developer. The affiliate provides the distribution.

How the RaaS Model Developed

The early ransomware families operated in a closed manner. Groups like Dharma ransomware ran controlled campaigns where developers handled everything themselves. That changed when criminal entrepreneurs recognized that selling access to ransomware tools could generate more revenue than running attacks directly.

Threat actors who had previously operated solo began to see greater upside in building platforms others could use. The RaaS market began to formalize. Providers started offering RaaS kits that included ransomware tools, technical support, ransom negotiation services, and dashboards for tracking infections.

DarkSide ransomware became one of the most documented examples of this model in practice. The DarkSide group operated as a full-service RaaS provider, offering affiliates access to tools and infrastructure along with professional support. Affiliates paid for access and received everything they needed to launch attacks at scale.

The Colonial Pipeline attack in 2021, carried out by a DarkSide affiliate, showed how the RaaS model enables catastrophic incidents with limited technical overhead on the attacker’s side. A single strain of ransomware, deployed by an affiliate who purchased access, was enough to shut down critical infrastructure serving millions of people. The ransomware threat had professionalized.

SecurityScorecard’s deep dive into Black Basta ransomware shows how that professionalization continued. The group ran a highly organized double-extortion operation that affected over 90 organizations within months of emerging.

The RaaS Ecosystem Today

Today’s threat landscape looks more fragmented and competitive than it did five years ago. Law enforcement actions have disrupted several prominent ransomware groups, but new RaaS groups have consistently filled the vacuum. According to SecurityScorecard’s 2025 Global Third-Party Breach Report, RansomHub has emerged as the most dominant non-C10p ransomware group. It likely filled the gap left by AlphV/BlackCat’s disbanding and law enforcement actions against LockBit. This pattern of disruption and replacement is now a defining feature of the RaaS market.

The Ransomware Variants in Circulation Have Multiplied

When a RaaS operation is shut down, the ransomware code and techniques frequently survive. Affiliates carry them to new platforms. A RaaS variant doesn’t disappear when its parent group does. Affiliates take their techniques, their targeting knowledge, and sometimes the actual ransomware code to whichever new provider they migrate to.

Many RaaS affiliates work across multiple programs simultaneously. They apply the same tradecraft with whichever provider offers the best terms at a given time. The proliferation of ransomware attacks this produces is not incidental. It is the predictable outcome of a business model designed to scale.

Current RaaS operators offer affiliate programs that include:

  • Compiled ransomware code ready to deploy
  • Command and control infrastructure
  • Ransom negotiation and payment processing support
  • Affiliate dashboards to track active campaigns
  • Technical support for ransomware incidents
  • Revenue splits of 70 to 80 percent for active affiliates

The sophistication gap between RaaS developers and affiliates is now significant. Developers create and maintain the ransomware, handle updates, and manage the backend. Affiliates deploy it against targets they’ve identified independently. When law enforcement disrupts the developer side, affiliates find a new platform, often within weeks.

How RaaS Operators Now Use Third Parties to Scale

The most consequential shift in the ransomware threat over the last several years isn’t the business model itself. It’s the deliberate use of third-party attack vectors to scale. Our Global Third-Party Breach Report found that 41.4% of ransomware and extortion incidents had a third-party breach component. That figure isn’t coincidental. It reflects a strategic choice by RaaS groups to exploit supply chain access because it delivers scalability that direct attacks cannot match.

The logic is straightforward. Rather than hit separate targets one at a time, a RaaS group can compromise a single widely used software vendor and reach every customer of that vendor simultaneously. C10p’s exploitation of file transfer software vulnerabilities,including Cleo Common Vulnerabilities and Exposures (CVE)-2024-50623 and CVE-2024-55956, is the clearest recent example. C10p was responsible for 41.5% of all attributable third-party breaches in the dataset. A small number of vulnerability exploits in file transfer software caused 63.5% of all vulnerability-based breaches. One RaaS operation, one set of vulnerabilities, hundreds of victims.

This is the scalability advantage that makes the supply chain so attractive to ransomware operators. Third-party data exposed in ransomware attacks also creates additional pressure on victims. Compromised data from customers, vendors, and partners raises the reputational stakes of non-payment. The ransom payment decision becomes harder when the threat isn’t limited to your own data.

How RaaS Has Changed the Threat for Defenders

Defending against ransomware in a RaaS era requires a different frame than the one most organizations built their defenses around. Traditional ransomware attacks came from a known threat actor group with a recognizable variant. Your security team could track strains, study ransomware families, and build defenses tuned to specific code. The RaaS affiliate model breaks that pattern.

When many affiliates use the same tools across different campaigns, the ransomware variant becomes a less reliable signal of who is behind an attack or how the attacker delivered it. Two organizations hit by the same ransomware variant may have been targeted through completely different vectors by different affiliates who purchased access to the same RaaS kit. That diversity of delivery makes it harder to detect and block ransomware at the perimeter based on signatures alone.

RaaS attackers rely on exactly that confusion. Defenders focused on signature-based detection will struggle to connect campaigns that share ransomware code but differ entirely in how attackers gained access. Preventing ransomware in this environment means thinking less about specific strains and more about the access paths affiliates exploit before they ever deploy the payload.

The third-party angle adds another layer. Most organizations have invested in controls to prevent ransomware that arrives through phishing, compromised credentials, or direct exploitation of their own systems. Fewer have equivalent visibility into third-party risks lurking in their vendor ecosystem. By the time ransomware deploys in your environment, the actual compromise often happened weeks earlier at a supplier.

Protecting Against Ransomware in a RaaS Environment

Preventing RaaS attacks requires layering controls across both your internal environment and your extended vendor ecosystem. These measures give your security team the highest leverage at the level where the threat currently operates.

  • Maintain offline, tested backups. Ransomware is effective primarily because it destroys your ability to access your own data. Verified, air-gapped backups remove the attacker’s primary source of leverage and reduce pressure to pay the ransom.
  • Patch file transfer software and perimeter services aggressively. File transfer software has been the single most exploited category in third-party breaches for two consecutive years. Prioritize patches for these systems and audit which vendors use them in their own infrastructure.
  • Implement network segmentation. Even when a RaaS affiliate gains initial access, segmentation can prevent lateral movement to the high-value systems needed to launch ransomware across the environment.
  • Apply multi-factor authentication across all remote access. Credential abuse remains one of the most common initial access vectors for ransomware. Multi-factor authentication (MFA) doesn’t prevent every incident, but it eliminates the easiest path in.
  • Map your vendor ecosystem for concentration risk. If multiple vendors in your supply chain use the same file transfer platform or share a common infrastructure provider, a single RaaS campaign against that provider creates cascading exposure across all of them.

That last point is where most traditional ransomware defense programs fall short. If you’ve addressed your internal ransomware risks through backup strategies, patching cadences, and endpoint controls, you may still have limited visibility into whether your vendors apply those same standards. A vendor that doesn’t patch in time or reuses credentials becomes an entry point that bypasses all of your internal defenses. That’s how RaaS affiliates reach their intended targets without ever attacking them directly. Building a mature vendor risk management program is one of the most direct ways to close that gap.

How TITAN AI Addresses the Ransomware Supply Chain Problem

Identifying ransomware risks that originate in your vendor ecosystem requires visibility that periodic questionnaires and annual assessments can’t provide. By the time a RaaS affiliate has exploited a zero-day vulnerability in a vendor’s file transfer software, no questionnaire response reflects that exposure. The window between a vulnerability being weaponized and ransomware deploying in your environment is measured in days, not months.

TITAN AI addresses this from the outside in. By continuously scanning 4.1 billion IP addresses and domains, TITAN Watch surfaces the security posture of every vendor in your ecosystem in real time. It flags exposures such as unpatched services, misconfigured remote access, and degraded security scores  that RaaS affiliates actively scan for when selecting targets. Rather than waiting for a vendor to disclose a compromise, TITAN Watch detects the signals early on.

For organizations that need to move from foundational visibility to proactive defense, TITAN Secure adds the proactive layer. By mapping Internet Intelligence data — active threat actor signals and adversary infrastructure — directly to your vendor ecosystem, your team can get ahead of active RaaS campaigns before they reach you. When a new campaign targets file transfer software vulnerabilities, you can identify which vendors in your ecosystem are exposed and prioritize engagement before the ransomware deploys.

Ransomware remains a serious and growing threat. The organizations best positioned to defend against it are the ones with full visibility into their attack surface, including the parts that live within their vendors.

Ready to see your vendor ransomware exposure before it becomes an incident? Book a demo with SecurityScorecard.