Key facts
- The model mirrors legitimate SaaS: subscriptions, profit sharing, affiliate panels, documentation and even "customer support" for victims paying ransoms.
- Because affiliates need initial access, phishing and stolen credentials are the dominant entry points, purchasable from access brokers who themselves often got in by email.
- Double extortion is standard: data is stolen before encryption, and leak threats pressure payment even where backups exist.
The RaaS supply chain
Developers maintain the malware and leak sites. Initial access brokers compromise organizations, frequently via phishing, spear phishing or exploited zero-day attacks, and sell the access. Affiliates buy access, deploy the ransomware, and negotiate. Each layer specializes, which is why defense against "ransomware" is mostly defense against its entry points, weeks before any encryption begins.
How to defend
Harden the entry points: email security against the phishing that starts most chains, MFA so stolen credentials are insufficient, patched perimeter systems, segmented networks and least privilege to limit spread, and offline-tested backups plus an incident plan for the worst case. By the time files encrypt, the important defenses have already succeeded or failed.
How Sentaro helps
Sentaro guards the front of the chain: the credential phishing that feeds access brokers, the malicious attachments and links that drop loaders, and the account-takeover behavior that precedes deployment. Ransomware is the last step of the attack; email is usually the first, and the first step is the cheap place to stop it.