July 31, 2026
Ransomware Stopped Being Malware. It Became a Business.
The most important thing to understand about ransomware in 2026 is not a strain or a payload. It is an economy, and it behaves more like a s

By CTI Academy
4 min read
In 2025, one of the most prolific ransomware groups on earth went from more than 700 named victims to zero in a matter of months. The market barely noticed.
That single fact tells you almost everything about how ransomware actually works now. The group was RansomHub, and when its leak site went dark on 31 March 2025 with no explanation, its affiliates did not retire. They moved to other operators, who expanded to absorb them within weeks. The brand died. The business rolled on.
Ransomware-as-a-service, or RaaS, took the single most disruptive category of cybercrime and turned it into a franchise. The people who write the ransomware mostly do not deploy it. The people who deploy it mostly cannot write it. Between them sits a marketplace with revenue splits, affiliate recruitment, customer support, and real-time dashboards. If you want to understand the threat, you have to understand the economy behind it.
The division of labor
RaaS mirrors legitimate software-as-a-service closely enough that CrowdStrike, Group-IB, and others describe it in exactly those terms. There are two core specialists.
Operators are the developers. They build and maintain the ransomware, run the command-and-control servers, host the victim payment portals, issue decryptors, and provide what amounts to technical support. Affiliates are the attackers. They select targets, break in, move laterally, steal data, and deploy the payload.
Neither has to be good at the other's job, which is exactly why the model has been so destructive. It removed the skill barrier. A criminal who could never write working ransomware can now rent it and be operational in an afternoon. And they rent more than malware: a supporting cast of initial access brokers, bulletproof hosters, and money launderers sells every other part of the operation as a service too.
Follow the money, and watch the power flip
Here is the development most explainers miss. The balance of power has tilted decisively toward the affiliates.
It used to be that operators held the leverage, because they owned the malware. But the market got crowded. So many RaaS platforms now compete for a limited pool of skilled affiliates that the affiliates increasingly call the shots. According to Halcyon's Ransomware Research Center, most programs now offer affiliates 70 to 80 percent of ransom proceeds. When a group called The Gentlemen splintered off from Qilin in mid-2025 after a payment dispute, it raised the stakes to a 90/10 split in the affiliates' favor, and within months claimed nearly 300 victims across 66 countries.
The barrier to entry at the bottom collapsed too. When LockBit's affiliate panel leaked in May 2025, it showed that access to a lower-tier "Lite" version could be had for roughly $777. Skilled affiliates now shop between operators the way a contractor picks which firm to work for.
The numbers
Analysts were tracking around 124 distinct ransomware groups into 2026. One Symantec analysis put claimed attacks at 4,737 for 2025, the most ever recorded, and the average cost to a breached organization runs near $4.9 million.
But one number cuts against the grain. TRM Labs found that while victims named on leak sites rose 44 percent in 2025, total ransom payments held roughly steady at around $850 million. More organizations are getting hit, but a shrinking share of them are paying. That refusal is quietly reshaping the entire model.
Brands collapse, the market does not
If you only followed the headlines, you would think law enforcement is winning. LockBit, responsible for around a quarter of all documented ransomware incidents at its 2023 peak, had its infrastructure seized in Operation Cronos in February 2024. RansomHub collapsed to zero. Black Basta collapsed. On paper, a terrible year for ransomware operators.
Except the market did not shrink. It reshuffled. Akira, Qilin, Safepay, and DragonForce expanded rapidly to absorb the displaced affiliates. The banner changes, the infrastructure changes, the name is new, but the hands behind the keyboard are often the same.
This is the defining feature of RaaS from a defender's point of view: because the value lives in the affiliates and the tooling rather than in any single brand, taking down a brand relocates the talent instead of removing it. DragonForce took this to its logical conclusion in 2025, behaving like a conglomerate running a rollup, defacing a rival's leak site to destroy the competitor and absorb its affiliates, and running high-profile attacks on the UK retailers Marks & Spencer, Co-op, and Harrods.
The biggest shift: encryption became optional
The most consequential change is also the most counterintuitive. A growing share of "ransomware" groups have stopped encrypting anything.
The logic is pure business. Encryption is loud. It trips detections, it is operationally complex, and if the victim has good backups it achieves nothing. Stealing the data and threatening to leak it is quieter, simpler, and still gives the attacker leverage, because no backup can un-leak your customers' records. As Group-IB put it, encryption became optional and refusal became irrelevant.
Symantec credits the success of Cl0p, also tracked as Snakefly, and the ShinyHunters ecosystem with creating a data-theft template that other attackers are now copying. Cl0p built its reputation on mass exploitation of file-transfer vulnerabilities, hitting hundreds of organizations at once and often never deploying encryption at all. Encryption or not, the product being sold is the same: leverage.
What this means for defenders
Because the brand is the weakest thing to target, the smart money has moved to two approaches.
First, attack the supply chain rather than the group. The services the ecosystem depends on, the access brokers, the bulletproof hosters, the credential vendors, operate with weaker operational security than the operators themselves, which makes them a more disruptible layer.
Second, detect behaviors, not brands. Since affiliates rotate between platforms and share tooling, the durable signals are the actions common to nearly every RaaS attack: valid-account abuse, identity compromise, lateral movement, privilege escalation, defense evasion, and data staging before exfiltration. There is almost always a window between the initial intrusion and the final payload, and that window is where detection has to happen. For the cyber threat intelligence analyst specifically, the job is tracking affiliate migration, mapping which groups share which tools, and recognizing a rebrand for what it is rather than treating each new name as a new threat.
This is a condensed version. The full analysis, including the shared-toolbox cross-pollination between rival groups, four common misconceptions worth correcting, a detailed FAQ, and all sources, is on the CTI Academy blog:
→ The Ransomware-as-a-Service Business Model, Explained
CTI Academy is a cyber threat intelligence training platform. If you want to learn to read this ecosystem the way an analyst has to, start with the Hunter track.