← Glossary

Ransomware-as-a-Service

A criminal business model where ransomware developers lease their malware to affiliates who carry out attacks, splitting the ransom. Phishing is the model's main entry point.

Updated

Key facts

  • The model mirrors legitimate SaaS: subscriptions, profit sharing, affiliate panels, documentation and even "customer support" for victims paying ransoms.
  • Because affiliates need initial access, phishing and stolen credentials are the dominant entry points, purchasable from access brokers who themselves often got in by email.
  • Double extortion is standard: data is stolen before encryption, and leak threats pressure payment even where backups exist.

The RaaS supply chain

Developers maintain the malware and leak sites. Initial access brokers compromise organizations, frequently via phishing, spear phishing or exploited zero-day attacks, and sell the access. Affiliates buy access, deploy the ransomware, and negotiate. Each layer specializes, which is why defense against "ransomware" is mostly defense against its entry points, weeks before any encryption begins.

How to defend

Harden the entry points: email security against the phishing that starts most chains, MFA so stolen credentials are insufficient, patched perimeter systems, segmented networks and least privilege to limit spread, and offline-tested backups plus an incident plan for the worst case. By the time files encrypt, the important defenses have already succeeded or failed.

How Sentaro helps

Sentaro guards the front of the chain: the credential phishing that feeds access brokers, the malicious attachments and links that drop loaders, and the account-takeover behavior that precedes deployment. Ransomware is the last step of the attack; email is usually the first, and the first step is the cheap place to stop it.

Questions we get asked.

What does RaaS mean?

Ransomware-as-a-Service: ransomware offered like a subscription product, where developers supply the malware and affiliates execute attacks for a share of the ransom.

How do RaaS attacks usually start?

Through initial access, most commonly phishing emails, stolen credentials or unpatched systems, often acquired by specialized access brokers and sold to affiliates.

Should ransomware victims pay?

Law enforcement generally advises against paying: it funds the ecosystem, guarantees nothing, and may raise legal issues depending on sanctions. Prevention, backups and an exercised incident plan are the reliable strategy.

Why is RaaS important to understand?

Because it explains the volume: attacks no longer require skilled attackers. Any organization reachable by a convincing phishing email is reachable by a RaaS affiliate.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.