Ransomware-as-a-Service is a criminal business model in which the developers of ransomware sell or lease access to their malware, leak sites, payment portals, and support infrastructure to affiliates. The operators usually keep a cut of the ransom while affiliates handle intrusion, deployment, and extortion.
RaaS matters because it lowers the barrier to entry for cybercrime and scales attacks across many targets. It also makes attribution harder: the public brand may stay the same even when different affiliates use different tactics, such as phishing, stolen credentials, exposed remote access tools, or unpatched software. Defenders often focus on the operator brand, affiliate techniques, and indicators from leak-site claims, but they should verify those claims with endpoint, network, and identity evidence before assuming a real compromise.


