Ransomware As A Service
Ransomware as a Service (RaaS) is a criminal business model in which developers build and maintain ransomware and lease it to affiliates who carry out the attacks, splitting the proceeds.
What is Ransomware As A Service?
Definition
Ransomware as a Service (RaaS) is a criminal business model in which one group develops and maintains the ransomware, its infrastructure and its leak site, and leases all of it to affiliates who perform the intrusions and split the proceeds. The consequence for defenders is a separation of skills: whoever breaks into a network no longer needs to be able to write malware, which is a large part of why attack volume rose so sharply. In cybersecurity terms it also explains why the same ransomware family shows very different tradecraft from one incident to the next — the payload is shared, the affiliate is not.
Role in cybersecurity
Ransomware As A Service plays an important role in building organizational resilience against cyber threats. Implementing appropriate mechanisms in this area is required by regulations such as NIS2, DORA and ISO 27001.