Ransomware-as-a-service (RaaS)
In the criminal economy, ransomware-as-a-service (RaaS) is the model in which one group builds and maintains the encryption software, the leak site and the negotiation infrastructure, and other people, the affiliates, carry out the intrusions in exchange for a share of the payment. It is why two incidents under the same name can look nothing alike.
How it works
The operator supplies a product: an encryptor for several platforms, a control panel, a victim-facing negotiation portal, a leak site for publishing stolen data, and support. The affiliate supplies the intrusion, either by doing it or by buying access from an access broker. Payment is split according to an agreed percentage.
The consequence for defenders is that the brand is the software and the infrastructure, not the tradecraft. Affiliates work for several operators, move between them and bring their own habits, so the techniques observed in an incident describe the affiliate rather than the group whose name appears on the ransom note.
What goes wrong
Threat intelligence keyed on group names produces poor predictions for exactly that reason. Preparing for the techniques attributed to a brand means preparing for whatever affiliate was operating when the report was written. What generalises is the shape common to nearly all of them: access obtained through credentials or an exposed edge service, escalation through the directory, credential harvesting, deliberate destruction of backups, exfiltration for extortion, then encryption last.
That order is the point most defensive planning still misses. Encryption is the final step and the first one anybody notices, while the theft that supports the second extortion happened earlier. Recovering from a backup solves the encryption and does nothing about the data already taken, which is why a recovery plan that stops at restoration is answering half the problem.
The model also lowers the skill floor. Intrusion no longer requires the ability to build tooling, so the population of people capable of causing this outcome is much larger than the number capable of writing the software.
Where this shows up in an audit
Two places. In an exercise we emulate the affiliate’s path rather than the payload, because the encryption is the part with no defensive value to reproduce: the useful test is whether the estate detects the escalation, the credential harvesting and the attempt on the backup infrastructure. In intelligence work we watch leak sites for a client’s own name, their suppliers and their sector, since an appearance is confirmation rather than prediction. Immutable, isolated copies remain the control that decides the outcome. This is part of how we track the groups and leak sites relevant to your sector.