Ransomware-as-a-Service
On Feb 20, 2024, a multinational task force ("Operation Cronos," led by the UK's NCA with the FBI and Europol) seized the infrastructure of LockBit — for years the most prolific ransomware brand in the world, with 2,000+ claimed victims and $120M+ extorted. Investigators unmasked its operator "LockBitSupp" as a Russian national, Dmitry Khoroshev. Within eighteen months the market re-formed around new brands: by the end of 2025 Qilin had gone from 154 claimed victims in 2024 to 1,044, and Akira had become a $244M operation. RaaS is not a group but a business model, and the model survives the takedown of any one firm — which is a large part of why ransomware is a leading demand generator in cybersecurity. The sections below cover how the model makes money, who runs it now, why 2025 produced a "more attacks, less paid" pattern, and what each shift signals for defensive M&A.
What RaaS is: software franchising for crime
Ransomware-as-a-Service is the criminal economy's exact analog of SaaS plus franchising. A small core team (the operator/developer) builds and maintains the malware, the leak site, the negotiation portal, and the payment/escrow rails — and then licenses that platform to a distributed network of affiliates who do the actual breaking-in. The economics mirror a franchise: the affiliate, who supplies the labor and the risk, keeps the larger cut (70–80%); the operator, who supplies the product and the brand, takes 20–30% off the top of every paid ransom. Around this core sits a full supply chain — initial-access brokers who sell the entry (see 15b), negotiators, "support" staff, and money launderers — so that a low-skilled actor can rent every capability needed to run an enterprise-grade extortion campaign. This division of labor is precisely why the model is so resilient: takedowns remove a firm, not the capability stack, and the affiliates simply re-paper their contracts with the next operator.
How the money is split
The 2025 pattern: record attacks, falling payments
The defining feature of the 2025 ransomware year is a divergence: claimed victims rose roughly 50% year-over-year to the most active year on record, yet on-chain ransom payments fell ~8% to more than $820M (from ~$892M in 2024, per Chainalysis — a figure likely to revise upward toward ~$900M as attribution catches up). The share of victims who actually paid fell to an estimated ~28%, an all-time low. Behind the divergence is a market under pressure adapting on two fronts at once:
- Buyers (victims) are paying less often. Better backups, mature EDR/MDR, insurer discipline, sanctions risk on paying certain groups, and "don't pay" guidance have all pushed the pay-rate down. This is the demand side of defense working.
- Sellers (attackers) are compensating with volume and targeting. With each victim less likely to pay, groups ran more attacks and shifted down-market toward SMEs deemed more likely to pay — and the median ransom payment grew ~368% YoY to nearly $60,000 as groups optimized for the mid-market sweet spot rather than chasing megabreach jackpots. The result: flat-to-declining aggregate revenue spread across far more incidents and far more victims.
The pattern is a favorable read on defense rather than a bearish one. The criminal market is being forced to work harder for the same money — the financial fingerprint of a defensive ecosystem raising the attacker's cost. Demand for the controls that produce that pressure (backup/recovery, EDR/XDR, MDR, identity) is what the payment curve reflects.
Victim-size data published in August 2026 places a boundary on how far down-market that shift actually runs. Analysing 13,336 disclosed incidents since January 2023, Black Kite found 73% of ransomware attacks in North America and Europe fell on companies with $10M–$1B in revenue, a share that held while incident volume grew 44% between 2023 and 2025. Within that band the movement was toward the lower end — victims in the $10M–$50M band rose from 1,391 in 2024 to 1,821 in 2025 and the $50M–$500M band from 970 to 1,474, while the $500M–$1B band fell from 126 in 2023 to 45 in 2025. The population the groups converged on is therefore the mid-market rather than the small-business tier, which is bought and defended through a different route to market (Buyer Tiers).
The post-LockBit leaderboard
The current leaderboard tells three distinct stories about how RaaS competes. Qilin won on affiliate aggregation — when RansomHub abruptly closed in April 2025, Qilin recruited the orphaned affiliates and roughly doubled its monthly victim rate, finishing 2025 as by far the most prolific brand. Akira won on technical edge, mass-exploiting zero-day and n-day vulnerabilities on internet-facing edge devices (its SonicWall SSL VPN campaign was a signature 2025 move) to extort an estimated $244M by late 2025. Cl0p won on scale-through-supply-chain, eschewing affiliate volume to weaponize single file-transfer or platform vulnerabilities into mass-compromise events, adding 500+ victims in a year. Three different competitive strategies, one structural truth: there is always a next operator, because the affiliates and the access brokers are the durable assets, not the brand on the leak site.
Exploitation speed as a competitive position
The three brands above compete on affiliate aggregation, technical edge and supply-chain scale. A fourth position is documented in the joint advisory on the Medusa operation, first published on March 12, 2025 and revised on August 18, 2026, with the Department of Health and Human Services added as a co-author alongside the FBI and CISA. Medusa was first identified in June 2021, operated as a closed variant, and moved to an affiliate model in at least early 2023; ransom negotiation is still controlled centrally by the developers rather than by affiliates.
The advisory records over 500 victims across critical-infrastructure sectors as of April 2026, against over 300 as of February 2025 in the original version. Both are floors rather than counts, so the interval between them supports no growth rate; what it establishes is that the operation stayed active and kept accumulating victims across fourteen months. The industries named are medical, education, legal, insurance, technology and manufacturing.
The competitive distinction is in timing and sourcing. The agencies state that Medusa actors leverage newly announced exploits within 24 hours and have been observed using exploits up to a week before public vulnerability disclosure. They also state there is no indication the actors develop their own zero-day or N-day vulnerabilities, preferring to obtain advance access to exploits from unknown sources or to move on newly announced ones before victims can patch. Targeting is described as opportunistic — organisations running unpatched software, rather than a chosen sector or company — and successful exploitation is confirmed using Interactsh dynamic URLs, which identify which hosts responded.
Two consequences follow, and the commercially useful one is narrower than a demand tailwind.
First, capability is bought rather than built, so the exploit market's delivery speed — not the technical depth of any single group — sets the practical patch window. Controls sold on a periodic cadence (scheduled scanning, monthly patch cycles, quarterly assessment) sit outside that window by construction. The spending effect is a reallocation inside the exposure line rather than an expansion of it: budget moves from assessment toward continuous validation and remediation workflow. That favours vendors priced on outcomes over those priced per scanned asset, and it is deflationary to the standalone scanner, whose function the platforms already bundle. It is a share shift rather than a pricing event, which is consistent with exposure management continuing to trade below identity and cloud on EV/ARR despite a demand narrative that sounds supportive (Exposure Management, Valuation by Sub-Segment).
Second, opportunistic targeting selects on posture rather than on size or sector, which concentrates the exposure in the population least able to act on a finding. Among mid-market firms externally scanned in 2026, 55% carried a significant patch-management finding on public-facing software and 28% carried at least one known exploited vulnerability (Buyer Tiers). Highest incidence against lowest internal capacity is the condition under which detection and response is bought as a service rather than staffed, so the incremental dollar reaches the MSP and MDR channel before it reaches the product vendor (MDR).
Source: CISA/FBI/HHS — #StopRansomware: Medusa Ransomware (AA25-071A, updated Aug 18, 2026) · advisory PDF · Infosecurity Magazine (Aug 19, 2026)
Why RaaS is the master demand generator
Every defensive sub-segment with durable M&A activity traces back, directly, to a ransomware tactic:
| RaaS tactic (2025) | Defensive demand it creates | M&A read |
|---|---|---|
| Encryption + data theft ("double extortion") | Immutable backup / recovery; EDR/XDR; MDR | Rubrik/Cohesity scale; MDR roll-ups (04b) |
| Stolen-credential entry (the #1 vector) | IAM, PAM, MFA, ITDR, machine identity | The identity wave — Palo Alto–CyberArk (03a) |
| Edge-device mass exploitation (Akira/SonicWall) | Exposure management, CTEM, attack-surface mgmt | 03k consolidation; Tenable/Rapid7/Qualys |
| Supply-chain single-point compromise (Cl0p) | AppSec, SSCM, third-party risk | 03f; GRC/TPRM (03i) |
| Same-day and pre-disclosure exploitation (Medusa) | Continuous exposure discovery, virtual patching, rapid asset inventory | 03k; edge and appliance hardening (03d) |
| Payment + recovery uncertainty | Cyber insurance; IR retainers | Cyber Insurance; DFIR (04e) |
Falsifiable bear case
The "ransomware guarantees permanent defensive demand" thesis is strong but not unconditional. (1) Sustained payment decline could de-fund the model. If the pay-rate keeps falling toward zero — driven by backups, regulation, and sanctions — affiliate ROI eventually breaks and the most capable actors migrate to other monetization (BEC, infostealers, crypto theft). Demand wouldn't vanish, but it would rotate away from the backup/IR cluster, repricing those sub-segments. (2) Law-enforcement and sanctions could raise friction faster than the model adapts — coordinated takedowns plus crypto-tracing plus OFAC designations have measurably degraded specific brands. (3) AI cuts both ways. AI lowers the affiliate's barrier (faster intrusion, better lures) and the defender's cost (autonomous detection/response). If defense compounds faster, the attacker's unit economics deteriorate. The bear case isn't "ransomware ends"; it's "the specific defensive pools tied to today's tactics get repriced as the tactics shift" — which is exactly why threat-tracking is an investment discipline, not a security one.
/ angle
→ The leak-site leaderboard is a sub-segment heat map. Which groups are rising, what they exploit, and which victim sizes they target is a 12–24-month leading indicator of where defensive budget — and therefore acquisition currency — flows next. Akira's edge-device focus predicts exposure-management and VPN-replacement demand; Cl0p's supply-chain focus predicts SSCM/TPRM demand. Reading the threat tape is reading the deal pipeline (Threat Economy).
→ The down-market shift is an SME-defense thesis. Groups moving toward SMEs "more likely to pay" is the demand signal under the MSSP/MDR roll-up and cyber-insurance-for-SMB theses — the exact white space where mid-market platforms consolidate (Service Providers, 24).
Sources: Chainalysis — Crypto Ransomware 2025 · The Record — ransomware payments dropped in 2025 · The Register — payments cratered, attacks did not (Feb 27 2026) · SOCRadar — Top 10 Ransomware Groups of 2025 · GuidePoint GRIT 2026 report · NCA — Operation Cronos / LockBit (Feb 20 2024) · WEF — How Operation Cronos disrupted LockBit
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.