🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
Ransomware-as-a-service: why the affiliate model makes attacks relentless
Threat Intelligence

Ransomware-as-a-service: why the affiliate model makes attacks relentless

ERD Research TeamJul 5, 20266 min read

Key takeaways

  • Most enterprise ransomware runs on a franchise model: a core team builds the tooling and licenses it to affiliates who carry out intrusions and split the ransom.
  • Because affiliates vary wildly in tradecraft, defending against one group's published indicators is a losing game — defend the choke points every affiliate must pass through.
  • The realistic goal is to be more expensive to compromise and monetize than the next target, not to be unbreachable.

A franchise, not a gang

Ransomware-as-a-service (RaaS) splits the work. A core operator team builds and maintains the encryptor, the leak site, and the negotiation infrastructure, then licenses that toolkit to affiliates who do the actual break-ins. The ransom is split — often something like 70/30 or 80/20 in the affiliate's favor. This is why 'taking down a group' so rarely stops the attacks: the tooling and the people using it are separable, and both are quickly replaced.

Why this changes your defensive strategy

The same strain can arrive through wildly different tradecraft depending on which affiliate deployed it. Over-indexing on one group's published indicators of compromise is a trap — next week's intrusion uses a different affiliate, different tools, different infrastructure. The durable strategy is to defend the choke points every affiliate must pass through regardless of brand: initial access, privilege escalation, defense evasion, and exfiltration.

Fed from the front by access brokers

The ecosystem is supplied by initial access brokers who sell ready-made footholds into corporate networks. That means closing the front door — hardening identity, retiring exposed services, patching internet-facing edge devices — starves the model before an encryptor is ever chosen. You are not defending against one adversary; you're trying to make your organization uneconomical to monetize.

Think like the business it is

It helps to assume the attacker is a rational business optimizing return on effort. The realistic goal is not perfect prevention but being more expensive to compromise and cash out than the next target on the list. Every control that raises the attacker's cost or lowers their expected payout — MFA, segmentation, immutable backups, fast detection — shifts that calculation in your favor and, often, sends the affiliate looking elsewhere.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy