# What is Ransomware as a Service (RaaS)?

> Ransomware as a service (RaaS) is a criminal service model in which a provider develops or maintains ransomware capabilities and makes them available to other operators, often called affiliates, who conduct intrusions or extortion.

- Canonical URL: https://yellowcube.eu/glossary/ransomware-as-a-service/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The provider may supply malware, infrastructure, administration panels, victim communications, or support in return for fees, subscriptions, profit sharing, or another criminal arrangement.

Roles vary. Affiliates may obtain access themselves or from other criminals, choose targets, move through networks, steal data, and deploy the provider’s ransomware, while the provider maintains shared capabilities. Some groups keep work in-house or collaborate without offering a service, so several participants do not by themselves establish RaaS.

### Key points

- **Defensive significance:** Shared tooling can produce similar artifacts across unrelated affiliates, while entry paths and hands-on activity differ. Scope the full intrusion instead of attributing every action to the named ransomware provider.
- **Investigation:** Relate access, identities, lateral movement, data theft, payload deployment, communications, and infrastructure over time; preserve uncertainty about which participant performed each action.
- **Risk reduction and response:** Apply the same layered ransomware protections and incident plan used for other operations, including strong identity controls, segmentation, protected backups, evidence preservation, and recovery from trusted sources.
- **Important limitation:** RaaS describes organization and delivery, not a separate ransomware effect or guaranteed division of labor. Public brands, affiliate claims, leak sites, and malware matches can be deceptive, shared, renamed, or incomplete.

### Related terms

[Ransomware](<https://yellowcube.eu/glossary/ransomware/>) · [Cyber extortion](<https://yellowcube.eu/glossary/cyber-extortion/>) · [Malware](<https://yellowcube.eu/glossary/malware/>) · [Dark web](<https://yellowcube.eu/glossary/dark-web/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>)

### Sources

[UK NCSC: Ransomware, Extortion and the Cyber Crime Ecosystem](https://www.ncsc.gov.uk/paper/ransomware-extortion-and-the-cyber-crime-ecosystem) · [CISA: Understanding Ransomware Threat Actors—LockBit](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

