Glossary
Ransomware-as-a-Service (RaaS)
RaaS is ransomware franchising. Developers build the malware, affiliates deploy it against victims, and they split the profits. It lets unskilled criminals launch sophisticated attacks.
What is Ransomware-as-a-Service (RaaS)?
A business model where ransomware developers lease their malware to affiliates who conduct attacks in exchange for a percentage of ransom payments.
Why Should You Care?
RaaS has eliminated the technical barrier to deploying sophisticated ransomware attacks, enabling even unskilled criminals to target critical infrastructure like hospitals and power grids. Organizations face both encryption and data extortion threats, as RaaS operators use double-extortion tactics (stealing data and threatening publication) to pressure victims into paying ransom. The fragmented RaaS ecosystem—with new affiliate groups emerging constantly as others are disrupted—means businesses cannot rely on learning from a single threat actor's patterns, forcing security teams to defend against constantly evolving attack campaigns.
Is your business exposed?
Real-World Example
The 2021 Colonial Pipeline incident involved DarkSide RaaS affiliates who encrypted systems and stole roughly 100GB of data, forcing the shutdown of critical fuel distribution infrastructure across the U.S. East Coast. The incident demonstrated how RaaS platforms turn ransomware from a difficult technical operation into a plug-and-play criminal service: DarkSide developed and maintained the malware and ran an affiliate program, while individual operators deployed it against targets and split the resulting ransom payments with the developers.
How to Protect Against Ransomware-as-a-Service (RaaS)
- 1.
Implement robust backup strategy
- 2.
Train employees on phishing prevention
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required