In ransomware-as-a-service, what work does the affiliate do that the developer never touches?
answer
- product versus operation
- the intruder is not the author
- the split favours whoever carries the risk
- entry can be bought as a separate good
- nobody in this chain can sue anybody
basics
~20 sThe developer builds and maintains the encryptor, the builder and the affiliate panel and rents it out. The affiliate runs the intrusion itself - entry, spread, staging, launch - and keeps the larger share of whatever is paid.
solid answer
~50 sRansomware-as-a-service splits a product from an operation. The developer writes the encryptor and its builder, runs the affiliate panel that issues per-victim keys, hosts the leak infrastructure and the payment plumbing, and never touches a victim network. The affiliate is the intruder: they obtain or buy entry, move through the estate, work out what is worth taking, and pull the trigger. Payment is a revenue split, commonly quoted around 70-80% to the affiliate, with the remainder to the developer for the platform. Around those two sit specialists who are also not the intruder: access brokers who sell a way in and stop there, negotiators hired per engagement, and launderers who move the proceeds. The consequence that matters in interviews is that a payload brand names the *product*, not the crew, and says almost nothing about how the intrusion was run.
go deeper
Be ready to name the split cleanly: one party builds and rents the encryptor, panel and payment plumbing; another party does the breaking in. Know that access brokers and negotiators exist as separate paid roles.
Explain why the revenue share sits where it does, and what the platform actually supplies - builder, per-victim keys, leak infrastructure, a negotiation desk - so you can say precisely which parts of an intrusion the brand did not shape.
Show what the split changes about your reading of an intrusion: brand tells you the product, not the crew, and the skill floor is set by the platform rather than by the person who used it.
Own the argument that the chain is severable and that control spend should aim at the layer that is bought and sold - entry - rather than at the shared payload that arrives after every meaningful decision has already been made.
## The one sentence that explains the whole model Ransomware-as-a-service (RaaS) is the separation of a **product** from an **operation**. One party builds and rents the extortion machinery; a different party breaks into victims and uses it. Almost every confusing thing about modern extortion follows from that split. ## The roles, and what each one actually owns **The developer (the operator of the brand).** Writes the encryptor, the builder that stamps out per-victim samples, and the affiliate panel where an affiliate registers a victim, gets keys, tracks the negotiation and sees their cut. Also runs the leak site and the payment rails, and does the branding. Crucially, this party may never have touched a victim network in their life. Their risk is exposure of the platform; their asset is the platform's reputation among criminals. **The affiliate (the intruder).** Buys or obtains entry, escalates, moves through the estate, finds what matters, and launches. They are the ones with hands on keyboards inside your environment. They are also the volume: one brand can have dozens of affiliates, each with their own habits, skill level and preferred entry route. **The access broker.** Sells a working way in - a valid remote-access credential, an exposed management interface, a foothold on an edge device - and then stops. They do not extort anyone. They are inventory suppliers, and their listings are priced by the victim's revenue, sector and country. **The negotiator.** Hired per engagement to run the chat with the victim. Often the most professional-sounding party in the whole chain, sometimes working several unrelated cases at once. **The launderer.** Converts proceeds into something spendable, and takes a percentage for it. This is the role most exposed to sanctions and to payment-rail enforcement. ## The money, and why the split is the interesting part The split is commonly quoted as roughly 70-80% to the affiliate and 20-30% to the developer, with the exact number negotiated by how much volume an affiliate brings. Read it as an incentive design, not trivia: - The **affiliate carries the operational risk** (being inside a network, being caught in the act) and is paid accordingly. - The **developer earns on volume**, so the platform is optimised for an affiliate to move fast with little skill: a builder that produces a working sample, a panel that handles keys, a ready-made negotiation desk. - Because the developer is paid per successful extortion, the platform invests in the parts that raise the *payment rate* - the leak infrastructure, the negotiation tooling, the reliability of the decryptor - not in the intrusion. ## Reputation is the only contract None of these parties can sue each other. The whole market therefore runs on reputation: a brand that stiffs affiliates on payouts loses them, a brand whose decryptor does not actually restore data loses payment rates, an affiliate who burns a broker's access without paying gets blacklisted. This is why **exit scams and rebrands are ordinary market events** rather than mysteries: when a brand's reputation collapses - through non-payment, an unreliable decryptor, or heat - the platform closes, the proceeds do not get distributed, and a very similar platform appears under a new name with much of the same code and much of the same affiliate list. ## What the split predicts Three things worth being able to say out loud: 1. **A payload brand names the product.** Two victims hit by the same brand may have been hit by two affiliates with nothing in common. 2. **Skill is not uniform behind one brand.** The platform lowers the skill floor, so the same encryptor arrives at the end of a clumsy smash-and-grab and at the end of a patient, quiet operation. 3. **The chain is severable.** Because entry is a separate purchasable good, the control classes that remove the *purchase* - phishing-resistant authentication, no internet-reachable single-factor remote access, third-party access that cannot be resold - subtract a whole layer of the market, while anything aimed at the encryptor itself is downstream of every decision the affiliate has already made. ## The common wrong answer The wrong answer is to describe RaaS as "criminals selling malware to other criminals", as though it were a software licence. It is closer to a franchise with a revenue share and a shared back office: the platform is not sold, it is rented per engagement, and the platform's owner is paid only when the operation the affiliate ran actually succeeds.
- Why does the affiliate take the larger share rather than the party who wrote the code?Because the affiliate carries the operational risk and does the scarce, non-reusable work. The encryptor is written once and rented many times, so the developer earns on volume across every affiliate; the affiliate spends real time inside one estate and is the party who can actually be caught in the act. The split prices that asymmetry.
- What holds this market together when no participant can enforce a contract?Reputation, and nothing else. Affiliates choose platforms that pay out and whose decryptor really works; brokers sell to buyers who pay; victims pay brands believed to honour the deal. When reputation collapses the usual outcome is an exit scam followed by a rebrand under a new name with much of the same code and the same affiliate list.
- Does the developer choose which organisations get hit?Generally no. Affiliates and brokers select victims; the platform usually only sets exclusions - regions or sectors it will not touch, often to avoid attention or prosecution. Victim selection is therefore an economic decision made by whichever party is closest to the inventory, not a strategic choice made by the brand.
It is a franchise, not a software sale: head office supplies the brand, the machinery and the back office, the franchisee does the actual trading, and head office takes a cut of each sale.
saying these in an interview costs you the question
- Describes one gang that writes the code and runs every intrusion
- Calls it a software sale rather than a rented platform with a revenue split
- Assumes the developer picks the victims
- Treats the revenue split as trivia rather than the incentive design
- Thinks the affiliate needs deep skill because the platform is sophisticated