What is RaaS (Ransomware as a Service)?
What is RaaS?
Ransomware as a Service, or RaaS, is a business model in which ransomware developers or operators sell or rent malware and management infrastructure. Operators provide these resources in exchange for subscription fees, licensing fees, or a share of the profit and affiliates use them to carry out attacks.
RaaS lowers the technical barriers as attackers can use ready-made tools and infrastructure 새 carry out attacks. Developers can profit through multiple affiliates without having to directly carry out attack campaigns
Difference Between Ransomware and RaaS
Ransomware is a malware or attack method that attackers use to encrypt systems or data, block access, and demand payment for recovery. RaaS is an operating model that divides the attack process with different roles. In other words, ransomware refers to the malicious tool and activity, while RaaS describes how criminals monetize it.
| Category | Ransomware | Ransomware as a Service |
|---|---|---|
| Developer | Developers within the attacking group | RaaS operator or separate development team |
| Attacker | Usually the same organization that develops the ransomware | Affiliates who purchase the service |
| Technical barrier to entry | Requires in-house development and operational expertise | Relatively low as affiliates can use ready-made attack tools |
| Revenue model | Direct profit | Subscriptions, licensing fees, revenue sharing, etc |
| Attack characteristics | The organization uses relatively consistent tactics | Initial access methods and tactics vary among affiliates |
| Defense approach | Tracking a specific group and the characteristics of its malware | Monitoring the entire attack path, including accounts, vulnerabilities, lateral movement, and data exfiltration |
Roles and Revenue Models in the RaaS Ecosystem
The RaaS ecosystem functions as a supply chain, with operators, affiliates, and initial access brokers handling separate parts of an attack.
RaaS Operators and Developers
RaaS operators and developers build and maintain the malware and infrastructure, manage victims, operate data leak sites, recruit affiliates, and distribute profits. Some operators also provide technical support. Not every RaaS operation has a sophisticated management structure. The scope and maturity of these services vary by group.
Affiliates
Affiliates use tools provided by the RaaS operator to attack and deploy ransomware. They gain access to the target through phishing, compromised accounts, exposed remote access services, or unpatched vulnerabilities. They then perform internal reconnaissance, privilege escalation, data theft, and system encryption.
Initial Access Brokers
Initial access brokers (IAB) sell access to compromised accounts and networks. Affiliates can purchase such access from these brokers to reduce the time required for initial access.
Revenue Models
The revenue models of RaaS services differ among operators. Four common models have been identified.
- Subscription: Recurring payment to use the tools and infrastructure.
- License purchase: A one-time purchase for a particular ransomware build or kit.
- Affiliate: Operators and affiliates divide the profit made from attacks.
- Hybrid: A combination of multiple payment models.
These models separate the roles of operators and affiliates while giving both parties profit in successful attacks. Operators expand their revenue without the need of conducting intrusions themselves, while affiliates can concentrate on executing attacks. This structure has contributed to the growth of RaaS.
RaaS Attack Process
Specific tactics may vary by affiliate, but RaaS attacks generally follow the following sequence.
- Initial access
Affiliates gain access through compromised accounts, phishing, exposed services, or unpatched vulnerabilities. - Internal reconnaissance
Once inside, they identify the network structure, critical servers, account privileges, backup environment, and security products status. - Privilege escalation and lateral movement
Affiliates obtain privileged accounts and expand their access - Data exfiltration
Sensitive data is exfiltrated from the organization - Recovery disruption
Affiliates disable or damage backups and security controls to hinder recovery. - Encryption and extortion
Files or systems are encrypted, followed by demands for payment in exchange for decryption or preventing the disclosure of stolen data.
Real-world attacks might not always follow this sequence. Some affiliates steal data and demand payment without encrypting systems. Others focus on operational disruption through encryption without exfiltrating data.
Why RaaS Attacks Are Difficult to Defend Against
Attack patterns show different tactics, techniques, and procedures across affiliates using the same ransomware. Initial access methods, supporting tools, and attack sequences can vary significantly from one affiliate to another. RaaS operations also allow affiliates to purchase specific capabilities separately, adding further complexity. Affiliates can also use a different ransomware service to target the same organization again.
Defense that focus on IoC (indicators of compromise) of known malwares may fail to detect new affiliates or modified attack methods. Organizations should monitor malicious behavior throughout the attack path, including initial access, account misuse, lateral movement, data exfiltration, and persistence
RaaS attacks also combine file encryption with data exfiltration and threats of public disclosure. Restoring systems from backups does not remove the risk of exposure for stolen personal or confidential information.
Examples of RaaS
LockBit and Hive are examples of RaaS operations in which ransomware developers and the attackers conducting intrusions had separate roles. In attack cases, researchers observed different intrusion methods across the affiliates.
LockBit
LockBit operators recruited affiliates and provided ransomware tools and attack management infrastructure as a service. Affiliates used those resources to compromise organizations, steal data, and encrypt systems. Affiliates associated with LockBit operated independently resulting in different initial access methods, attack tools, and activities within victim’s environments.
Hive
Hive also separated the roles of developers and affiliates. Developers managed the ransomware and supporting infrastructure, while affiliates selected targets, conducted intrusions, and deployed the ransomware. Hive affiliates gained initial access through compromised remote access accounts, phishing, and vulnerabilities in internet-facing systems. In some attacks, they stole data before encrypting systems and demanded payment for decryption and an agreement not to disclose the stolen information.
RaaS Defense strategies
In order to defend against RaaS attacks, organizations need security controls for every stage of the attack, from initial access and lateral movement to data theft, encryption, and disruption of recovery mechanisms.
Manage Internet-Facing Assets and Vulnerabilities
Identify internet-facing servers, VPNs, remote desktop services, and management systems. Review whether each service is necessary, remove unused services, and restrict access to systems that require external connectivity.
Organizations should also regularly look for systems missing from the asset inventory or lacking a clearly assigned owner. Also, Prioritize security patches according to asset criticality and vulnerability.
Prevent Privilege Escalation and Lateral Movement
Segment networks and administrative environments so that compromising one endpoint does not give an attacker direct access to critical servers or backup systems. Monitor for activities such as obtaining administrative privileges, executing remote management tools, rapidly logging into multiple systems, creating unusual accounts, and disabling security controls. Centralize logs from endpoints, servers, and authentication systems, then correlate events chronologically to reconstruct the attack.
Monitor Data Exfiltration
Identify where sensitive data resides and who has access to it. Remove access from accounts that do not require the data for business purposes. Monitor for indicators such as bulk file access, large-scale compression, transfers to previously unused external storage services, and data movement at unusual times. Evidence of account compromise or unauthorized data transfers requires a separate data breach investigation even when no ransomware execution or file encryption has been detected.
Maintain Backup and Recovery Capabilities
Store backups separately from the production environment. Configure them so that attackers cannot delete or modify them through the same administrative accounts used for production systems. Offline or immutable backups reduce the risk of attackers damaging recovery data. Organizations should regularly test whether they can restore critical systems within the required timeframe. These exercises should also validate the accounts and procedures needed for recovery.
Whitepaper
Unified Security for Optimal Ransomware Protection
Response Procedures for a RaaS Incident
When an organization detects ransomware infection or evidence of data exfiltration, it should activate its incident response process immediately and take the following steps to limit the damage.
- Isolate affected systems
Disconnect network and remote access connections to prevent the attack from spreading to other systems. - Determine the scope
Investigate encrypted endpoints, compromised accounts, servers, cloud environments, backups, and evidence of data exfiltration. - Preserve evidence
Collect ransom notes, malicious files, authentication records, security system logs, data transfer records, and documentation of response actions. - Remove the intrusion path
Remediate exploited vulnerabilities and replace compromised credentials. Identify and block any additional access mechanisms left by the attackers. - Review reporting and notification obligations
Determine which legal and contractual requirements apply, including reports to relevant authorities and personal data breach notifications. - Restore systems
Confirm that no malware, attacker access mechanisms, or other threats remain. Verify backup integrity, then restore systems according to business priorities. - Monitor for renewed intrusion
After recovery, monitor for reused credentials, misuse of exposed data, and additional intrusion attempts.
Payment does not ensure that attackers will provide working decryption or delete stolen data. Any decision involving payment requires broader review of legal obligations, sanctions, insurance terms, and the continuing risk of information exposure.
FAQ
Is RaaS a Type of Ransomware Malware?
RaaS is a criminal operating model rather than a type of malware. Operators provide ransomware tools and infrastructure to affiliates in exchange for payment or a share of the proceeds.
Can Someone Participate in a RaaS Attack Without Coding Skills?
Ready-made ransomware removes much of the development burden. Conducting an intrusion still requires the ability to gain access, escalate privileges, and move through the target environment, or the attacker must purchase existing access.
Do Offline Backups Provide Complete Protection?
Offline backups support system recovery, but they do not retrieve data that attackers have already exfiltrated. Organizations also need data loss monitoring and an established incident response capability.
Does Paying the Attackers Guarantee Data Recovery and Deletion?
Recovery is not guaranteed. The decryption tool might not work properly, and the victim has no reliable way to verify that the attackers deleted every copy of the stolen data.