skip to content

Extortion as a Service

Extortion is supplied as a service, with one crew writing the encryptor and another bringing the intrusion, so a clean rebuild answers only half the demand. Interviewers use it to test that shift.

on this pageshow

explore

questions

4

In ransomware-as-a-service, what work does the affiliate do that the developer never touches?

level: juniorimportance: must knowfreq 72%

answer

  1. product versus operation
  2. the intruder is not the author
  3. the split favours whoever carries the risk
  4. entry can be bought as a separate good
  5. nobody in this chain can sue anybody

basics

~20 s

The developer builds and maintains the encryptor, the builder and the affiliate panel and rents it out. The affiliate runs the intrusion itself - entry, spread, staging, launch - and keeps the larger share of whatever is paid.

solid answer

~50 s

Ransomware-as-a-service splits a product from an operation. The developer writes the encryptor and its builder, runs the affiliate panel that issues per-victim keys, hosts the leak infrastructure and the payment plumbing, and never touches a victim network. The affiliate is the intruder: they obtain or buy entry, move through the estate, work out what is worth taking, and pull the trigger. Payment is a revenue split, commonly quoted around 70-80% to the affiliate, with the remainder to the developer for the platform. Around those two sit specialists who are also not the intruder: access brokers who sell a way in and stop there, negotiators hired per engagement, and launderers who move the proceeds. The consequence that matters in interviews is that a payload brand names the *product*, not the crew, and says almost nothing about how the intrusion was run.

go deeper

for a junior

Be ready to name the split cleanly: one party builds and rents the encryptor, panel and payment plumbing; another party does the breaking in. Know that access brokers and negotiators exist as separate paid roles.

for a middle

Explain why the revenue share sits where it does, and what the platform actually supplies - builder, per-victim keys, leak infrastructure, a negotiation desk - so you can say precisely which parts of an intrusion the brand did not shape.

for a senior

Show what the split changes about your reading of an intrusion: brand tells you the product, not the crew, and the skill floor is set by the platform rather than by the person who used it.

for a principal

Own the argument that the chain is severable and that control spend should aim at the layer that is bought and sold - entry - rather than at the shared payload that arrives after every meaningful decision has already been made.

## The one sentence that explains the whole model Ransomware-as-a-service (RaaS) is the separation of a **product** from an **operation**. One party builds and rents the extortion machinery; a different party breaks into victims and uses it. Almost every confusing thing about modern extortion follows from that split. ## The roles, and what each one actually owns **The developer (the operator of the brand).** Writes the encryptor, the builder that stamps out per-victim samples, and the affiliate panel where an affiliate registers a victim, gets keys, tracks the negotiation and sees their cut. Also runs the leak site and the payment rails, and does the branding. Crucially, this party may never have touched a victim network in their life. Their risk is exposure of the platform; their asset is the platform's reputation among criminals. **The affiliate (the intruder).** Buys or obtains entry, escalates, moves through the estate, finds what matters, and launches. They are the ones with hands on keyboards inside your environment. They are also the volume: one brand can have dozens of affiliates, each with their own habits, skill level and preferred entry route. **The access broker.** Sells a working way in - a valid remote-access credential, an exposed management interface, a foothold on an edge device - and then stops. They do not extort anyone. They are inventory suppliers, and their listings are priced by the victim's revenue, sector and country. **The negotiator.** Hired per engagement to run the chat with the victim. Often the most professional-sounding party in the whole chain, sometimes working several unrelated cases at once. **The launderer.** Converts proceeds into something spendable, and takes a percentage for it. This is the role most exposed to sanctions and to payment-rail enforcement. ## The money, and why the split is the interesting part The split is commonly quoted as roughly 70-80% to the affiliate and 20-30% to the developer, with the exact number negotiated by how much volume an affiliate brings. Read it as an incentive design, not trivia: - The **affiliate carries the operational risk** (being inside a network, being caught in the act) and is paid accordingly. - The **developer earns on volume**, so the platform is optimised for an affiliate to move fast with little skill: a builder that produces a working sample, a panel that handles keys, a ready-made negotiation desk. - Because the developer is paid per successful extortion, the platform invests in the parts that raise the *payment rate* - the leak infrastructure, the negotiation tooling, the reliability of the decryptor - not in the intrusion. ## Reputation is the only contract None of these parties can sue each other. The whole market therefore runs on reputation: a brand that stiffs affiliates on payouts loses them, a brand whose decryptor does not actually restore data loses payment rates, an affiliate who burns a broker's access without paying gets blacklisted. This is why **exit scams and rebrands are ordinary market events** rather than mysteries: when a brand's reputation collapses - through non-payment, an unreliable decryptor, or heat - the platform closes, the proceeds do not get distributed, and a very similar platform appears under a new name with much of the same code and much of the same affiliate list. ## What the split predicts Three things worth being able to say out loud: 1. **A payload brand names the product.** Two victims hit by the same brand may have been hit by two affiliates with nothing in common. 2. **Skill is not uniform behind one brand.** The platform lowers the skill floor, so the same encryptor arrives at the end of a clumsy smash-and-grab and at the end of a patient, quiet operation. 3. **The chain is severable.** Because entry is a separate purchasable good, the control classes that remove the *purchase* - phishing-resistant authentication, no internet-reachable single-factor remote access, third-party access that cannot be resold - subtract a whole layer of the market, while anything aimed at the encryptor itself is downstream of every decision the affiliate has already made. ## The common wrong answer The wrong answer is to describe RaaS as "criminals selling malware to other criminals", as though it were a software licence. It is closer to a franchise with a revenue share and a shared back office: the platform is not sold, it is rented per engagement, and the platform's owner is paid only when the operation the affiliate ran actually succeeds.

  • Why does the affiliate take the larger share rather than the party who wrote the code?
    Because the affiliate carries the operational risk and does the scarce, non-reusable work. The encryptor is written once and rented many times, so the developer earns on volume across every affiliate; the affiliate spends real time inside one estate and is the party who can actually be caught in the act. The split prices that asymmetry.
  • What holds this market together when no participant can enforce a contract?
    Reputation, and nothing else. Affiliates choose platforms that pay out and whose decryptor really works; brokers sell to buyers who pay; victims pay brands believed to honour the deal. When reputation collapses the usual outcome is an exit scam followed by a rebrand under a new name with much of the same code and the same affiliate list.
  • Does the developer choose which organisations get hit?
    Generally no. Affiliates and brokers select victims; the platform usually only sets exclusions - regions or sectors it will not touch, often to avoid attention or prosecution. Victim selection is therefore an economic decision made by whichever party is closest to the inventory, not a strategic choice made by the brand.

It is a franchise, not a software sale: head office supplies the brand, the machinery and the back office, the franchisee does the actual trading, and head office takes a cut of each sale.

saying these in an interview costs you the question

  • Describes one gang that writes the code and runs every intrusion
  • Calls it a software sale rather than a rented platform with a revenue split
  • Assumes the developer picks the victims
  • Treats the revenue split as trivia rather than the incentive design
  • Thinks the affiliate needs deep skill because the platform is sophisticated

context

open as a page

Why do two intrusions with the identical ransomware build show completely different tradecraft?

level: middleimportance: must knowfreq 58%

basics

~20 s

Because the encryptor is a rented product shared by many affiliates, while the intrusion is each affiliate's own work. Identical payload with divergent entry and movement is the predicted signature of a service model, not a contradiction to explain away.

open as a page

An access broker listed your VPN account for sale weeks before the extortion - how were you chosen?

level: seniorimportance: should knowfreq 44%

basics

~20 s

You were selected twice by two different parties: a broker picked you because your access was sellable, then a buyer picked your listing because the price fitted their margin. Neither selection was about you specifically.

open as a page

Ransomware affiliates buy access on economics - what do you tell a board that hardening will change?

level: principalimportance: should knowfreq 38%

basics

~20 s

Commit to what the economics support: hardening takes you out of the cheap inventory volume buyers shop from, so it genuinely diverts them. It does not deter a crew whose payout is priced against your revenue.

open as a page