The most important thing to understand about ransomware in 2026 is not a piece of malware. It is a business model.
Ransomware-as-a-service, or RaaS, took the single most disruptive category of cybercrime and turned it into a franchise. The people who write the ransomware mostly do not deploy it. The people who deploy it mostly cannot write it. Between them sits a marketplace with revenue splits, affiliate recruitment, customer support, and dashboards, and it behaves so much like a legitimate software company that the easiest way to explain it is by analogy to the software-as-a-service products you already use. The ransomware as a service business model, in other words, is a real economy, with suppliers, resellers, and margins.
That analogy is where most explainers stop. This one keeps going, because the interesting part is what the business did next. In the last two years the power flipped from the operators to the affiliates, household-name brands collapsed to zero almost overnight while the market barely noticed, and a growing share of "ransomware" attacks stopped bothering to encrypt anything at all. If you want to understand the threat, you have to understand the economy behind it. Here is how it actually works.

TL;DR
- RaaS splits every ransom between two specialists: operators build and maintain the platform (roughly 20 to 30 percent), affiliates run the actual attack and keep the rest (roughly 70 to 80 percent).
- Competition for skilled affiliates has flipped the power balance. Some groups now offer 90/10 splits in the affiliate's favor, and a leaked affiliate panel showed entry-tier access selling for as little as $777.
- Analysts tracked around 124 distinct ransomware groups into 2026, average breach cost sits near $4.9 million, and total ransom payments held roughly flat in 2025 even as named victims rose 44 percent.
- Taking down a brand does not shrink the market. When LockBit and RansomHub fell, their affiliates and tooling migrated to Akira, Qilin, Safepay, and DragonForce within weeks.
- A growing share of attacks skip encryption entirely and rely on pure data-theft extortion, because it is quieter, simpler, and immune to backups.
What Ransomware-as-a-Service Actually Is
Ransomware-as-a-service is a subscription or commission-based model in which one group, the operators, builds and maintains the ransomware and its infrastructure, and rents access to other criminals, the affiliates, who carry out the actual attacks in exchange for the larger cut of each ransom. It mirrors the legitimate SaaS model closely enough that CrowdStrike, Group-IB, and others describe it in exactly those terms.
The division of labor is the whole point. Operators specialize in what they are good at, developing the encryption software, running the command-and-control servers, hosting the victim payment portals, issuing decryptors, and providing what amounts to technical support. Affiliates specialize in the other half, selecting targets, breaking in, moving laterally, stealing data, and deploying the payload. Neither has to be good at the other's job, which is precisely why the model has been so destructive. It removed the skill barrier. A criminal who could never write working ransomware can now rent it and be operational in an afternoon.
None of this is new in concept. RaaS was first identified around 2012 with the Reveton strain, GandCrab pioneered the modern affiliate model in 2018, and REvil and Maze introduced double extortion, stealing data and threatening to leak it, in 2019. What has changed is the scale and the professionalism. What began as a niche tactic is now a mature industry with dedicated leak sites, sophisticated affiliate networks, and a supporting cast of specialized services.
The SaaS Playbook, Applied to Extortion
Spend any time looking at how these operations present themselves and the startup resemblance becomes uncanny.
RaaS kits are advertised on dark web forums and Telegram channels much the way products are advertised on the legitimate web, and the packages come with the trappings of real software businesses: 24/7 support, bundled offers, user reviews, and community forums. The more sophisticated platforms give affiliates a user-friendly dashboard where they can monitor active infections, track ransom payments in real time, view encrypted files, and manage their operations. Some provide onboarding tutorials for new affiliates and marketing materials for the group. There are performance metrics, customer service for victims to "restore" their files after paying, and reputation systems.
This professionalization is not cosmetic. It is what lets the model scale, because it means an affiliate needs no infrastructure and no deep expertise, only the willingness to break into networks. The operator has effectively productized the hard parts.
Who Does What: The Roles
The ecosystem runs on a handful of specialized roles, and understanding who is responsible for what is the foundation of tracking these groups.
| Role | Responsibility | Economics |
|---|---|---|
| Operator (developer) | Builds and maintains malware, C2, payment portals, dashboards, support | Keeps roughly 20 to 30% of ransoms |
| Affiliate | Target selection, initial access, lateral movement, exfiltration, deployment | Keeps roughly 70 to 80% |
| Initial access broker | Breaches networks and sells the access, removing the recon phase | Paid upfront, typically $500 to $3,000 |
| Supporting services | Bulletproof hosting, packer and EDR-killing tools, money laundering | Rented or bought as needed |
The role that ties this article to the rest of the ecosystem is the initial access broker. IABs eliminate the slowest and riskiest part of an attack by selling affiliates a ready-made foothold, which is why they are best understood alongside RaaS rather than separately. We cover them in depth in the initial access broker ecosystem, and the short version is that they are the supplier the affiliate buys from before the ransomware ever gets deployed.
Follow the Money: The Affiliate Power Shift
Here is the single most important development in the RaaS business model, and the one most explainers miss: the balance of power has tilted decisively toward the affiliates.
It used to be that operators held the leverage. They owned the malware, so they set the terms. But the market got crowded. So many RaaS platforms now compete for a limited pool of skilled affiliates that the affiliates, not the operators, increasingly call the shots. According to Halcyon's Ransomware Research Center, most RaaS programs now offer affiliates 70 to 80 percent of ransom proceeds. When a group called The Gentlemen splintered off from the Qilin operation in mid-2025 after a payment dispute, it raised the stakes to a 90/10 split in the affiliates' favor, and within months claimed nearly 300 victims across 66 countries, one of the fastest scaling groups ever tracked. That is what competing for talent looks like.
The barrier to entry at the bottom has collapsed too. When LockBit's affiliate panel leaked in May 2025, it revealed that access to a lower-tier "Lite" version of the platform could be had for roughly $777. Skilled affiliates now shop between operators the way a contractor picks which general contractor to work for, and that competitive dynamic shapes everything from the revenue splits to the quality of the "support" operators provide.

The Numbers Behind the Model
The scale is what turns an interesting business structure into a genuine crisis.
Analysts were tracking around 124 distinct ransomware groups across 2025 and into 2026. Publicly reported RaaS incidents surged roughly 47 percent in 2025, and the count of victims named on leak sites reached record highs, with one Symantec analysis putting claimed attacks at 4,737 for the year, the most ever recorded. ReliaQuest observed activity spread across roughly 90 groups and 99 countries in a single quarter of 2026, with the United States absorbing close to half of all victim activity. The average cost to a breached organization runs in the region of $4.9 million. And demand for affiliates is climbing: Group-IB recorded a 44 percent increase in dark web advertisements seeking RaaS affiliates in 2024 compared with 2023.
One number cuts against the grain in an encouraging way. TRM Labs found that while victim postings on leak sites rose 44 percent in 2025, total ransom payments held roughly steady at around $850 million, which means more victims are refusing to pay. The extortion is landing on more organizations, but a shrinking share of them are handing over money. That refusal is quietly reshaping the model, and it is part of what pushed the pivot described later in this article.

Brands Collapse, the Market Does Not
If you only followed the headlines, you would think law enforcement has been winning. Marquee brands really have fallen. LockBit, responsible for around a quarter of all documented ransomware incidents at its 2023 peak, had its infrastructure seized in Operation Cronos in February 2024, and most analysts wrote it off as collapsed. RansomHub entered 2025 as the single most prolific group, with more than 700 named victims at the end of 2024, and then its leak site simply went dark on 31 March 2025 with no public explanation, its victim count evaporating to zero. Black Basta collapsed. On paper, a very bad year for ransomware operators.
Except the market did not shrink. It reshuffled. When RansomHub and LockBit fell, their affiliates did not retire. They migrated, and other operators, Akira, Qilin, Safepay, and DragonForce, expanded rapidly to absorb them. The banner changes, the infrastructure changes, the name is new, but the hands behind the keyboard are often the same. This is the defining feature of the RaaS business model from a defender's point of view: because the value lives in the affiliates and the ecosystem rather than in any single brand, taking down a brand relocates the talent instead of removing it.
DragonForce illustrates where the model is heading. It spent 2025 behaving less like a gang and more like a conglomerate running a rollup strategy, systematically eliminating competitors and absorbing their affiliates. In March 2025 it exploited a vulnerability on a rival's leak site, defaced the infrastructure, and effectively destroyed the competitor. It publicly announced that RansomHub had "moved to our infrastructure," a claim RansomHub angrily disputed. It ran high-profile attacks on the UK retailers Marks & Spencer, Co-op, and Harrods. And it built genuinely novel affiliate services, including a data audit service that analyzes stolen datasets larger than 300 gigabytes to flag the highest-value information for extortion leverage, and a focus on compromising managed service providers so that a single intrusion can cascade to dozens of downstream victims.

The Big Evolution: Encryption Became Optional
The most consequential change to the model is also the most counterintuitive. A growing share of "ransomware" groups have stopped encrypting.
The logic is straightforward once you think in business terms. Encryption is loud. It trips detections, it is operationally complex, it can go wrong, and if the victim has good backups it achieves nothing. Stealing the data and threatening to leak it, on the other hand, is quieter, simpler, and still gives the attacker leverage, because no backup can un-leak your customers' records. So operators increasingly skip the encryption step entirely and run pure data-theft extortion. As Group-IB put it, encryption became optional and refusal became irrelevant.
This is not a fringe tactic. Symantec's analysis found that while encryption-based attacks have held roughly flat for years, the number of extortion attacks relying on data theft alone has jumped sharply, and it credits the success of Cl0p, also tracked as Snakefly, and the ShinyHunters ecosystem with creating a template other attackers are now copying. Cl0p in particular built its reputation on mass exploitation of file-transfer vulnerabilities, hitting hundreds of organizations at once and often never deploying encryption at all. The group known as Everest went further still, running a data-only extortion operation alongside a corporate-insider recruitment program that pays employees at target organizations for remote access, and claiming a breach of Iron Mountain in early 2026 involving roughly 1.4 terabytes of data.
The market is splitting as a result, into what Group-IB describes as a visible tier of opportunistic, high-volume access and an invisible tier of premium, pre-vetted partnerships. Encryption or not, the product being sold is the same: leverage.
The Shared Toolbox
One more feature reveals just how connected this ecosystem is: the groups share tools, even when they are supposedly rivals.
A tool called EDRKillShifter, originally built by RansomHub to disable security software using the "bring your own vulnerable driver" technique, later turned up in attacks by Medusa, BianLian, and Play, none of which had any formal affiliation with RansomHub. An evolved version of that same EDR-killer has since been observed in use by at least eight separate groups, including BlackSuit, Qilin, DragonForce, and Lynx. Legitimate tools dominate the rest of the kit: affiliates lean heavily on living-off-the-land techniques, staging payloads with encoded PowerShell, bypassing AMSI, and exfiltrating data with commercial file-sync utilities like rclone and MEGAsync. Symantec's reporting stresses that the vast majority of tools used in these attacks are legitimate software, which is exactly what makes them hard to catch.
For a defender, that cross-pollination is a gift and a warning. A gift because a behavior you learn to detect in one group's attacks will often catch several others. A warning because affiliation and attribution are slippery when everyone is using the same tooling.
How Defenders and Analysts Track RaaS
Because the brand is the weakest thing to target, the smart money has moved to two other approaches, and both are where a CTI function earns its keep.
The first is to attack the supply chain rather than the group. TRM Labs argues that the services the ecosystem depends on, the initial access brokers, the bulletproof hosters, the credential tool vendors, operate with weaker operational security than the ransomware operators themselves, which makes them a more disruptible layer. The same analysis notes that the RaaS model has dispersed operators across more countries, including some in extraditable jurisdictions, widening law enforcement's options. Disrupting the plumbing scales better than chasing one leak site at a time.
The second is to detect behaviors, not brands. Since the affiliates rotate between platforms and the tooling is shared, the durable signals are the actions common to nearly every RaaS attack: initial access via valid accounts, remote-service abuse, identity compromise, lateral movement, privilege escalation, defense evasion, and data staging before exfiltration or encryption. There is almost always a window between the initial intrusion and the final payload, and that window is where detection has to happen. For the CTI analyst specifically, the job is tracking affiliate migration, mapping which groups share which tools, monitoring leak sites and recruitment ads, and recognizing a rebrand for what it is rather than treating each new name as a new threat.
This is exactly the kind of ecosystem literacy CTI Academy's Hunter track is built to develop, and it is the reason our NullBase environment exists: a simulated underground where you can practice tracking actors, reading affiliate recruitment and leak-site activity, and following the connections between roles, without operating on live criminal infrastructure. A SOC simulator and a phishing simulator are also on the CTI Academy roadmap, which will add the operational, detection-side reps that pair with this intelligence work. If you want to learn to read the ransomware economy the way an analyst has to, start with the Hunter track.
Common Misconceptions
Four beliefs about RaaS are wrong often enough to correct directly.
"Taking down a group ends the threat." No. As LockBit and RansomHub showed, the affiliates and the tooling migrate, and other operators absorb them within weeks. Brand takedowns relocate the problem more than they solve it.
"Ransomware always encrypts your files." Not anymore. A large and growing share of attacks are pure data-theft extortion with no encryption at all, because leaking stolen data provides leverage that backups cannot undo.
"It is one group doing everything." No. RaaS is a supply chain of specialists: access brokers, operators, affiliates, launderers, and tool vendors, each doing one part. Attribution to a single "group" often obscures how many separate hands were involved.
"Paying makes it go away." Increasingly not, and fewer victims believe it. Payments held flat while attacks rose in 2025, and paying funds the next campaign while offering no guarantee against a second extortion over the same stolen data.
Frequently Asked Questions
What is the ransomware-as-a-service business model?
Ransomware-as-a-service (RaaS) is a commission-based model where operators build and maintain the ransomware and its infrastructure, and affiliates rent access to it and carry out attacks, splitting the ransom. It mirrors legitimate software-as-a-service, complete with dashboards, support, and affiliate programs, and it removed the skill barrier to launching ransomware.
How is ransom money split between operators and affiliates?
Most RaaS programs now give affiliates 70 to 80 percent of each ransom, with the operator keeping 20 to 30 percent. Competition for skilled affiliates has pushed splits higher, and one 2025 group, The Gentlemen, offered a 90/10 split in the affiliates' favor. Initial access brokers are paid separately, usually $500 to $3,000 for access.
What is the difference between a ransomware operator and an affiliate?
The operator is the developer: they build and maintain the malware, command-and-control servers, payment portals, and affiliate dashboards. The affiliate is the attacker: they select targets, break in, move laterally, steal data, and deploy the payload. The operator provides the platform; the affiliate does the intrusion and keeps the larger share.
Why do ransomware groups keep coming back after takedowns?
Because the value in the RaaS model lives in the affiliates and the shared tooling, not in any single brand. When a group like LockBit or RansomHub is disrupted, its affiliates migrate to other operators such as Akira, Qilin, or DragonForce, who expand to absorb them. The name changes, but the people and infrastructure often continue.
What is encryptionless or data-only extortion?
It is an extortion attack that steals sensitive data and threatens to leak it, without ever encrypting the victim's files. It has grown sharply because it is quieter, simpler, and harder to defend against with backups. Groups like Cl0p and Everest have built operations around data theft alone, and it now rivals traditional encryption-based ransomware.
How do initial access brokers fit into RaaS?
Initial access brokers breach networks and sell that access to ransomware affiliates, removing the slowest and riskiest phase of an attack. An affiliate can buy a ready-made foothold for a few hundred to a few thousand dollars and move straight to deploying ransomware, which is why IABs are considered a core supplier in the RaaS supply chain.
How do organizations defend against RaaS attacks?
By detecting attacker behaviors rather than specific brands, since affiliates rotate platforms and share tools. Key signals include valid-account abuse, identity compromise, remote-service abuse, lateral movement, privilege escalation, and data staging. There is usually a window between initial access and the final payload, and strong identity controls, monitoring, and an assume-compromise posture aim to catch the attack inside it.
Sources
- Group-IB: Ransomware-as-a-Service and High-Tech Crime Trends 2026
- Vectra AI: How Ransomware as a Service Helps Attackers Scale
- TRM Labs: New Disruption Opportunities in the Evolving Ransomware Ecosystem
- Symantec / Security.com: Ransomware: Tactical Evolution Fuels Extortion Epidemic
- ReliaQuest: Ransomware and Cyber Extortion in Q2 2026
- CrowdStrike: What is Ransomware as a Service (RaaS)?