Ransomware-as-a-service: why the affiliate model makes attacks relentless
Key takeaways
- Most enterprise ransomware runs on a franchise model: a core team builds the tooling and licenses it to affiliates who carry out intrusions and split the ransom.
- Because affiliates vary wildly in tradecraft, defending against one group's published indicators is a losing game — defend the choke points every affiliate must pass through.
- The realistic goal is to be more expensive to compromise and monetize than the next target, not to be unbreachable.
A franchise, not a gang
Ransomware-as-a-service (RaaS) splits the work. A core operator team builds and maintains the encryptor, the leak site, and the negotiation infrastructure, then licenses that toolkit to affiliates who do the actual break-ins. The ransom is split — often something like 70/30 or 80/20 in the affiliate's favor. This is why 'taking down a group' so rarely stops the attacks: the tooling and the people using it are separable, and both are quickly replaced.
Why this changes your defensive strategy
The same strain can arrive through wildly different tradecraft depending on which affiliate deployed it. Over-indexing on one group's published indicators of compromise is a trap — next week's intrusion uses a different affiliate, different tools, different infrastructure. The durable strategy is to defend the choke points every affiliate must pass through regardless of brand: initial access, privilege escalation, defense evasion, and exfiltration.
Fed from the front by access brokers
The ecosystem is supplied by initial access brokers who sell ready-made footholds into corporate networks. That means closing the front door — hardening identity, retiring exposed services, patching internet-facing edge devices — starves the model before an encryptor is ever chosen. You are not defending against one adversary; you're trying to make your organization uneconomical to monetize.
Think like the business it is
It helps to assume the attacker is a rational business optimizing return on effort. The realistic goal is not perfect prevention but being more expensive to compromise and cash out than the next target on the list. Every control that raises the attacker's cost or lowers their expected payout — MFA, segmentation, immutable backups, fast detection — shifts that calculation in your favor and, often, sends the affiliate looking elsewhere.