SardineCon SF/2026

Learn More

¿Qué es Ransomware-as-a-service?

SUBSCRIBE

Ransomware-as-a-service is a criminal business model where developers build and maintain the ransomware and lease it to affiliates who run the attacks, then split the proceeds. It lowers the skill needed to launch attacks, which is why one strain can show up across many unrelated victims, and its payment splits leave a signature investigators can follow.

What is ransomware-as-a-service, in plain English?

Ransomware-as-a-service, often shortened to RaaS, takes the software-as-a-service idea and applies it to crime. A skilled group builds and maintains the ransomware, including the malware, the payment infrastructure, and sometimes a victim-support portal, and then leases it to affiliates who carry out the actual attacks. When a ransom is paid, the developers and the affiliate split the money on agreed terms.

The effect is to lower the barrier to entry. An attacker no longer needs to write malware or run payment systems; they just need access to victims and the willingness to deploy someone else's tool. That division of labor is exactly why a single ransomware strain can appear across many unrelated victims in different industries and countries at the same time.

For investigators, the payment structure is the useful part. Because the proceeds split between affiliate and operator wallets, RaaS activity shows up on-chain as a recognizable split pattern. Following those splits lets analysts attribute attacks to a strain and map the network behind it, rather than treating each incident as an isolated event.

How the model operates

The pieces mirror a legitimate software business, turned to extortion:

  1. Build — Developers make the tool. A core group writes and maintains the malware and the payment infrastructure behind it.
  2. Recruit — Lease to affiliates. Affiliates sign up to use the strain in exchange for a cut of any ransoms they collect.
  3. Attack — Affiliates hit victims. Affiliates find targets and deploy the ransomware, so one strain spreads across many victims.
  4. Split — Divide the proceeds. Paid ransoms split between affiliate and operator wallets, leaving a distinctive on-chain pattern.

Who is involved?

Who

Their role

The operators

Core developers who build, maintain, and lease the ransomware and run the payment infrastructure.

The affiliates

Attackers who use the leased strain against victims and take a share of each ransom.

The victims

Organizations across many industries hit by the same strain deployed by different affiliates.

Investigators

Use the split payment pattern to attribute attacks and map the wider network behind a strain.

What it looks like in practice

In practice

Over a few months, a hospital, a logistics firm, and a school district are all hit by what looks like the same ransomware, even though nothing connects the victims. That is the RaaS signature: one strain, many affiliates, many unrelated targets.

An analyst tracing the ransom payments notices each one splits at the receiving address, with a large share going to one persistent cluster and a smaller share peeling off to different wallets. The persistent cluster is the operator; the changing wallets are individual affiliates. By mapping those splits across incidents, the analyst attributes the separate attacks to a single operation and builds a network view that no single victim's case could have revealed.

Why it matters to operators

RaaS changes how you should read a cluster of attacks. Because one strain is deployed by many independent affiliates, treating each incident as separate misses the point: the shared infrastructure and the payment splits are what tie them together. Recognizing the model lets you connect otherwise unrelated victims into a single operation, which is far more useful for attribution and disruption.

It also means the on-chain split is a gift to investigators. The recurring division between operator and affiliate wallets is a fingerprint you can trace across incidents, exposing the persistent core behind the changing cast of attackers. For compliance teams at exchanges, funds arriving from either side of that split are the point where the money meets a regulated venue and can be flagged, frozen, and reported.

What to watch for

  • Split payment pattern. Ransoms dividing between a persistent operator cluster and changing affiliate wallets are the core RaaS on-chain signature.
  • One strain, many victims. The same ransomware hitting unrelated organizations points to a leased tool, not a single lone attacker.
  • Persistent core cluster. A stable wallet cluster receiving a share of many different attacks is likely the operator behind the strain.
  • Do not silo incidents. Link cases through shared infrastructure and payment splits rather than treating each attack in isolation.
  • Cash-out at exchanges. Funds from either side of the split eventually reach regulated venues, where they can be screened and reported.

Quick questions

How is RaaS different from ransomware?

Ransomware is the malware and the attack itself. Ransomware-as-a-service is the business model behind it, where developers lease the tool to affiliates who run attacks and split the proceeds. RaaS is why one strain hits many victims.

Why does it lower the barrier to entry?

Affiliates do not need to write malware or run payment systems. They just need access to victims and the willingness to deploy someone else's tool, so far more people can launch capable attacks.

What is the split pattern?

When a ransom is paid, the proceeds divide between the affiliate who ran the attack and the operator who built the tool. That recurring on-chain split is a fingerprint investigators use to attribute activity.

How does the split help attribution?

A persistent cluster taking a share across many otherwise unrelated attacks reveals the operator behind a strain, while the changing wallets identify affiliates. Mapping the splits ties separate incidents into one operation.

Why treat multiple attacks as connected?

Because the shared malware, infrastructure, and payment splits link them even when the victims have nothing in common. Siloing incidents hides the network; connecting them exposes the operation.

What can an exchange do about it?

Screen deposits against known ransomware and operator clusters, freeze and report matches on either side of the split, and cooperate with investigators tracing the funds toward cash-out.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.

Qué saber junto con Ransomware-as-a-service