What is ransomware as a service (RaaS)?
Ransomware as a service (RaaS) is a criminal business model in which one group builds and maintains ransomware, along with its payment and leak sites, and leases it to affiliates who carry out the attacks in return for a share of each ransom. The developers never break into a network themselves, and the affiliates never write malware.
Operators, affiliates and access brokers
The model divides the work three ways:
- Operators develop the encryptor, run the payment portal and the leak site, and sometimes handle the negotiation.
- Affiliates break in, gain administrator access, destroy recovery options and launch the encryption.
- Initial access brokers compromise networks and sell that access on, without attacking further themselves.
Each ransom is split at a percentage the program sets, and the affiliate usually keeps the larger share. Affiliates choose their own methods and switch programs when one closes or pays poorly, so taking down an operator removes a brand without removing the people who used it. The split also explains the volume of attacks: affiliates earn per victim, which rewards hitting many reachable organizations over studying a few chosen ones.
Because the operator hosts the leak site, data theft and publication come built in for every affiliate, which turned double extortion from a specialty into the default. Negotiation is often run by operator staff working from scripts, so the tone of a ransom chat says little about who actually broke in.
Playbooks written for common backup consoles
Affiliates arrive with step-by-step guides for the products they expect to meet. Those guides cover where the major backup consoles run, how to delete jobs and restore points, how to shorten retention, and where backup software keeps the credentials and S3 keys it uses to reach a repository. An installation whose protection depends on the attacker not knowing the product offers little resistance to someone following instructions written for that exact product.
Every affiliate in a program receives the same playbook, so mid-sized organizations see intrusions as methodical as those against large enterprises. Size changes the odds of being found through an exposed VPN or a reused password. It does not change how carefully the backup system is taken apart once someone is inside. Giving the backup server an unusual hostname or port delays such an attacker by minutes at most, because the same discovery tools that map the network find it anyway.
The resale price of access that reaches the backup server
Brokers price access by what it opens. A foothold that includes a domain administrator account sells for more than an ordinary user login, and in a network where that account also signs in to the backup server, the hypervisor and the repository, the buyer is paying for the backups as well. That reach is the account's administrative blast radius, and the market rewards whoever can offer the widest one.
Handoffs are quick. Access often changes hands within hours, so the gap between a stolen password and deleted restore points can be shorter than a weekend. Managed service providers carry an extra exposure: access to a remote management platform that reaches every client lets one affiliate run many attacks from a single purchase.
Against a buyer holding valid credentials and a product manual, the protection that holds is the kind the storage enforces whoever logs in.
ARTESCA and ransomware as a service
On ARTESCA, the S3 keys given to a backup application can be limited to particular buckets and actions, which lowers the value of a key lifted from the backup server. Its accounts sit outside the production directory, so a broker selling domain administrator access is not selling a login to the backup storage, and compliance-mode S3 Object Lock retention on each restore point outlasts every account until the date it was set to.
None of this changes how an affiliate gets in or what it does to production systems. It changes what the purchased access is worth against the backups.
Related terms
- Ransomware: the attacks RaaS affiliates carry out.
- Credential theft: the source of most of the access brokers sell.
- Administrative blast radius: the reach that sets the price of a stolen account.
- Ransomware kill chain: the stages an affiliate works through once inside.
