Ransomware-as-a-Service: The Cybercrime Franchise Model That Scales Attacks
Ransomware-as-a-Service (RaaS) is a business model in which core criminal developers lease their ransomware tooling and infrastructure to independent affiliates, who then carry out attacks and split the ransom. This franchise-like structure lets a small group of operators scale to thousands of victims by outsourcing the riskiest work — initial access, lateral movement, and data theft — to a distributed pool of specialists and paying them 70–80% of each payout. Understanding this division of labor is the only way to explain why takedowns of individual RaaS brands have failed to reduce overall attack volume.
Ransomware-as-a-Service is not a piece of software; it is a way of organizing criminal labor. And it has done for cybercrime roughly what franchising did for fast food. The model explains why a single brand like LockBit could claim thousands of victims across dozens of countries while its core team numbered perhaps a few dozen people. It also explains why, despite law-enforcement wins against LockBit, Hive, and ALPHV/BlackCat, ransomware attacks continue to rise: the affiliate pool simply migrates to the next brand.
This article presents a benchmark analysis of the RaaS ecosystem, based on the most reliable available intelligence as of early 2026. It examines the structure, economics, and operational dynamics of RaaS, then draws actionable insights for defenders. Because hard quantitative data on criminal operations is inherently limited, this benchmark relies on the most recent, credible sources available, including Ransomnews, Huntress, and ThreatClaw Intelligence. Where estimates are given, they are drawn directly from those sources.
Benchmark Metrics at a Glance
The following table summarizes the key structural and operational metrics of the RaaS model, drawn from the three primary intelligence sources.
| Metric | Value | Source |
|---|---|---|
| Typical affiliate revenue share | 70–80% of ransom | |
| Core operator cut | 20–30% (platform fee) | |
| Reported LockBit core team size | A few dozen | |
| Reported LockBit victim count | Thousands, across dozens of countries | |
| Top-tier affiliate negotiation | Toward the higher end of the compensation spectrum | |
| Displaced affiliate migration time | "Almost in real time" | |
| Major RaaS brands that absorbed affiliates | RansomHub, Akira, Play, Medusa | |
| Notable disruption operations | Cronos (LockBit, 2024); Hive infiltration (2023); ALPHV/BlackCat collapse | |
| Structure | Tripartite: core developers, affiliates, initial access brokers (IABs) | |
| Business analogy | Fast-food franchising |
Key Findings Summary
The RaaS ecosystem has matured into a tripartite supply chain: core developers, affiliates, and initial access brokers. This specialization reduces individual exposure while increasing collective throughput. The profit split — 70–80% to affiliates — rewards the riskiest work and keeps the affiliate pool motivated and adaptable.
Disruption of a single RaaS brand does not eliminate the threat. The affiliate pool migrates to the next brand almost immediately. The rise of RansomHub, Akira, Play, and Medusa after LockBit and ALPHV takedowns illustrates this resilience.
RaaS separates the payload from the intrusion. That means two attacks using the same ransomware family can look completely different before encryption hits. Defenders cannot rely on ransomware family signatures alone; they must detect pre-encryption behavior such as credential misuse, remote tool abuse, and staging activity.
The model has reached a maturity level in recruitment, operational security, financial infrastructure, and targeting precision that represents a genuine escalation, according to ThreatClaw Intelligence. This maturity makes the ecosystem more resilient, more profitable, and harder to disrupt than earlier ransomware operations.
Detailed Results: The Anatomy of a Cybercrime Franchise
How Does the RaaS Revenue Split Work, and Why Does It Matter?
The economics of RaaS are deliberately designed to align incentives. Affiliates — the independent intruders who use the operator’s malware to attack victims — handle initial access, lateral movement, data theft, and the actual encryption. In exchange, they keep most of the ransom, typically 70 to 80 percent, and pay the rest to the operator as a "platform fee". This split rewards affiliates for the riskiest, most operationally intensive phase of the attack.
The core developers, meanwhile, function primarily as software vendors and infrastructure operators. They provide the malware, the negotiation portals, the leak sites, and sometimes even customer support. Their cut — 20–30% — is smaller per incident but scales across many affiliates. This is the franchise model in action: the franchisor provides brand, tooling, and playbooks; the franchisee does the daily work and keeps the majority of revenue.
This split is not arbitrary. It reflects the risk profile. Affiliates face the greatest risk of detection and arrest, since they are the ones inside victim networks. The higher payout compensates for that risk and ensures a steady supply of skilled intruders. Meanwhile, the core group can remain small and relatively insulated.
What Does the Tripartite Supply Chain Look Like?
ThreatClaw Intelligence describes the RaaS model as a tripartite supply chain with three distinct roles.
Core developer groups are successors to LockBit, ALPHV/BlackCat, and Cl0p lineages. They function primarily as software vendors and infrastructure operators. They build and maintain the ransomware payload, the victim negotiation portal, and the data-leak infrastructure. They also manage the brand and recruit affiliates.
Affiliates are the field sales force. They are independent operators who buy into the RaaS program, gain access to the tooling, and carry out attacks. They specialize in enterprise-network intrusion, lateral movement, data exfiltration, and deployment.
Initial access brokers (IABs) serve as the lead generation layer. They compromise networks and sell access to the highest bidder, often an affiliate. IABs allow affiliates to focus on post-access work, further increasing efficiency.
This division of labor reduces individual exposure while dramatically increasing collective throughput. Each participant specializes, which means each can get better at their phase of the attack chain. The result is a more productive, more resilient criminal enterprise.
Why Does RaaS Make Attribution and Defense Harder?
RaaS separates the payload from the rest of the intrusion. This has profound implications for defenders. Two attacks tied to the same ransomware family can look very different before encryption hits. One affiliate might gain access through phishing, another through exposed remote desktop services, another through a supply-chain compromise. The ransomware payload is just the final step.
This separation means that detecting a specific ransomware binary is too late. By the time the payload executes, data has likely been stolen and encryption is underway. Defenders need to detect earlier stages: suspicious access, credential misuse, remote tool abuse, staging activity, and data theft often show up before the ransom note does. These signals are not specific to any ransomware family, which makes them more reliable indicators of an intrusion in progress.
Analysis by Category
Category 1: Recruitment and Affiliate Specialization
The RaaS model has matured in recruitment and operational security. Core groups recruit affiliates through underground forums and private channels, often requiring applications or referrals. Top-tier affiliates demonstrating consistent enterprise-network specialization reportedly negotiate toward the higher end of the compensation spectrum. That means the best intruders can command a larger share than the standard 70–80%, further incentivizing skill development.
This recruitment pipeline creates a professional class of intruders. Unlike the lone-wolf hackers of earlier eras, these affiliates treat cybercrime as a business. They invest in tools, training, and operational security. The result is a more consistent success rate against complex, mission-critical systems.
Category 2: Operational Resilience and Brand Migration
The migration of affiliates after a takedown is the single most important dynamic in the RaaS ecosystem. Operation Cronos (LockBit, 2024), the FBI’s Hive infiltration (2023), and the apparent collapse of ALPHV/BlackCat after the Change Healthcare breach all point in the same direction: it is possible to disrupt a single RaaS brand decisively, but the affiliate pool simply migrates to the next one.
Recent rises of RansomHub, Akira, Play, and Medusa have absorbed displaced LockBit and ALPHV affiliates almost in real time. This means that law-enforcement actions, while valuable for intelligence gathering and temporary disruption, do not reduce the overall number of skilled intruders. The affiliates simply rebrand and continue operating.
Category 3: Targeting Precision and Mission-Critical Systems
RaaS groups have achieved a level of targeting precision that represents a genuine escalation. Affiliates specialize in enterprise-network intrusion, which means they know how to find and exfiltrate high-value data from complex environments. They target systems that businesses rely on to keep the lights on. The result is more attacks that hit mission-critical systems, where downtime is unacceptable and ransom payment is more likely.
This precision is a direct result of specialization. When affiliates can focus on a single phase of the attack chain, they get better at it. They learn which systems to target, which data to steal, and how to pressure victims into paying.
Category 4: Financial Infrastructure and Maturity
The financial infrastructure of RaaS has also matured. Core groups manage cryptocurrency wallets, negotiate ransoms, and handle payouts to affiliates. They provide a level of financial sophistication that allows affiliates to focus on intrusion. This infrastructure is part of what makes RaaS a true franchise: the franchisor handles back-office functions, while the franchisee focuses on operations.
The maturity in financial infrastructure also makes the ecosystem more resilient. Even if one payment channel is disrupted, others can be used. The core group can adapt quickly, while affiliates continue their work.
Visualizing the RaaS Ecosystem
Chart description: A flow diagram showing the tripartite supply chain. At the top, a box labeled "Core Developer Group" (with sub-labels: payload development, leak site, negotiation portal, recruitment). Arrows point down to two boxes: "Affiliates" (with sub-labels: initial access, lateral movement, data theft, encryption) and "Initial Access Brokers" (with sub-label: sell access). An arrow from IABs to Affiliates is labeled "access sold." An arrow from Affiliates back to Core Developers is labeled "70–80% ransom share." An arrow from Core Developers to Affiliates is labeled "tooling and infrastructure." At the bottom, an arrow from Affiliates points to "Victims" with labels "encryption" and "extortion." This chart illustrates how each participant specializes and how the profit split works.
A second visualization would be a timeline showing the migration of affiliates after major takedowns. The timeline would start with LockBit and ALPHV/BlackCat as dominant brands, then show Operation Cronos and the ALPHV collapse, followed by the rapid rise of RansomHub, Akira, Play, and Medusa. This timeline reinforces the finding that brand disruption does not eliminate the affiliate pool.
Recommendations: How Should Defenders Respond to RaaS?
The RaaS model changes the defensive equation. Because the payload is separate from the intrusion, defenders must focus on early-stage detection. The following recommendations are derived from the evidence and from standard security practice.
First, prioritize detection of pre-encryption behavior. Huntress notes that suspicious access, credential misuse, remote tool abuse, staging activity, and data theft often show up before the ransom note does. Security teams should build detections for these signals rather than relying solely on ransomware family signatures. This means monitoring for unusual login patterns, abnormal use of administrative tools, and large-scale data transfers.
Second, adopt a defense-in-depth strategy that accounts for affiliate variation. Because two attacks from the same RaaS family can look different before encryption, defenders cannot assume a single playbook. Instead, they should implement layered controls: strong identity and access management, network segmentation, endpoint detection and response, and data loss prevention. Each layer addresses a different phase of the attack chain.
Third, understand the business model to anticipate attacker behavior. Affiliates are motivated by profit and risk. They target mission-critical systems because downtime increases pressure to pay. Defenders should identify their own mission-critical systems and ensure they have the strongest controls and the most tested recovery plans. This is not just an IT issue; it is a business continuity issue.
Fourth, participate in threat intelligence sharing. The RaaS ecosystem moves fast, and affiliates migrate between brands quickly. Organizations that share indicators and tactics can help each other detect new affiliate activity. Infosecurity Magazine provides timely cybersecurity news and expert analysis to support this effort.
Fifth, recognize the limits of takedowns. Law-enforcement actions can disrupt a brand, but they do not eliminate the affiliate pool. Defenders should not assume that a takedown reduces their risk. They should continue to harden their environments and monitor for the next brand.
One caveat: these recommendations depend on the organization’s risk profile and resources. A small business may not have the budget for advanced detection tools, in which case basic hygiene — patching, backups, and employee training — becomes even more critical. A large enterprise may need a dedicated threat-hunting team. The key is to match controls to the actual threat, which is a professional, specialized affiliate, not an opportunistic script kiddie.
Frequently Asked Questions
What is the difference between RaaS and traditional ransomware?
Traditional ransomware is often a one-person or one-group operation. The same actor develops the malware, gains access, and executes the attack. RaaS disaggregates these roles. Core developers build the tooling, affiliates carry out the intrusions, and IABs supply access. This specialization increases scale, repeatability, and success rate.
Why do affiliates get most of the ransom?
Affiliates take on the highest risk and the most labor-intensive work: initial access, lateral movement, data theft, and encryption. The 70–80% share compensates them for that risk and ensures a steady supply of skilled intruders. The core group keeps a smaller cut but scales across many affiliates.
How quickly do affiliates migrate after a takedown?
According to Ransomnews, the affiliate pool simply migrates to the next brand almost in real time. The rise of RansomHub, Akira, Play, and Medusa absorbed displaced LockBit and ALPHV affiliates rapidly. This means takedowns do not reduce the overall number of attacks.
What should security teams monitor to detect RaaS attacks early?
Focus on pre-encryption behaviors: suspicious access, credential misuse, remote tool abuse, staging activity, and data theft. These signals often appear before the ransom note. Detecting them requires visibility across identity, endpoint, and network layers.
Conclusion
Ransomware-as-a-Service has transformed cybercrime into a franchise industry. The model’s power lies in its division of labor: core developers build the tooling, affiliates execute the attacks, and initial access brokers supply entry points. The 70–80% revenue share for affiliates ensures that the riskiest work is rewarded, which keeps the affiliate pool motivated and skilled.
The most important insight for defenders is that disrupting a single RaaS brand does not eliminate the threat. When LockBit was hit by Operation Cronos in 2024, and when ALPHV/BlackCat collapsed after the Change Healthcare breach, the affiliates did not disappear — they migrated to RansomHub, Akira, Play, and Medusa. This resilience means that security teams cannot rely on law enforcement alone. They must focus on early detection of pre-encryption activity, harden mission-critical systems, and share intelligence.
The maturity of RaaS in recruitment, operational security, financial infrastructure, and targeting precision represents a genuine escalation. Affiliates are not amateurs; they are specialists who treat cybercrime as a business. Defenders must match that professionalism with layered controls, continuous monitoring, and a realistic understanding of the threat. The franchise model has scaled ransomware. Defense must scale with it.
For more on related threats, see our guides to Understanding Cyber Threats and Attack Vectors: A Complete Guide and Top Ransomware Trends and Predictions for 2025. To understand the vulnerabilities that affiliates often exploit, read Zero-Day Vulnerabilities: How They Work and How to Defend Against Them.




