The Business of Cyber Security

Ransomware-as-a-Service

On Feb 20, 2024, a multinational task force ("Operation Cronos," led by the UK's NCA with the FBI and Europol) seized the infrastructure of LockBit — for years the most prolific ransomware brand in the world, with 2,000+ claimed victims and $120M+ extorted. Investigators unmasked its operator "LockBitSupp" as a Russian national, Dmitry Khoroshev. Within eighteen months the market re-formed around new brands: by the end of 2025 Qilin had gone from 154 claimed victims in 2024 to 1,044, and Akira had become a $244M operation. RaaS is not a group but a business model, and the model survives the takedown of any one firm — which is a large part of why ransomware is a leading demand generator in cybersecurity. The sections below cover how the model makes money, who runs it now, why 2025 produced a "more attacks, less paid" pattern, and what each shift signals for defensive M&A.

What RaaS is: software franchising for crime

Ransomware-as-a-Service is the criminal economy's exact analog of SaaS plus franchising. A small core team (the operator/developer) builds and maintains the malware, the leak site, the negotiation portal, and the payment/escrow rails — and then licenses that platform to a distributed network of affiliates who do the actual breaking-in. The economics mirror a franchise: the affiliate, who supplies the labor and the risk, keeps the larger cut (70–80%); the operator, who supplies the product and the brand, takes 20–30% off the top of every paid ransom. Around this core sits a full supply chain — initial-access brokers who sell the entry (see 15b), negotiators, "support" staff, and money launderers — so that a low-skilled actor can rent every capability needed to run an enterprise-grade extortion campaign. This division of labor is precisely why the model is so resilient: takedowns remove a firm, not the capability stack, and the affiliates simply re-paper their contracts with the next operator.

How the money is split

RaaS is a franchise: the affiliate keeps the bigger cut, the operator owns the brand A single paid ransom is split across a specialized, revenue-shared supply chain Access broker sells the entry paid up front Affiliate runs the attack 70–80% of ransom Operator / dev builds platform + brand 20–30% of ransom Launderer mixers · OTC cash-out fee The operator never touches a victim — it sells tooling, support, and a leak-site "brand," exactly like a SaaS vendor. Source: Chainalysis; Sophos; Trend Micro. Exhibit: The Business of Cyber Security.
Because the operator's asset is the *platform and brand* — not any single intrusion — a law-enforcement takedown removes a firm but not the model. Affiliates re-contract with the next operator within weeks. See [Threat Economy](15-threat-economy.md).

The 2025 pattern: record attacks, falling payments

The defining feature of the 2025 ransomware year is a divergence: claimed victims rose roughly 50% year-over-year to the most active year on record, yet on-chain ransom payments fell ~8% to more than $820M (from ~$892M in 2024, per Chainalysis — a figure likely to revise upward toward ~$900M as attribution catches up). The share of victims who actually paid fell to an estimated ~28%, an all-time low. Behind the divergence is a market under pressure adapting on two fronts at once:

The pattern is a favorable read on defense rather than a bearish one. The criminal market is being forced to work harder for the same money — the financial fingerprint of a defensive ecosystem raising the attacker's cost. Demand for the controls that produce that pressure (backup/recovery, EDR/XDR, MDR, identity) is what the payment curve reflects.

The post-LockBit leaderboard

After LockBit fell, the franchise re-formed around new brands Claimed victims posted to leak sites, 2024 vs 2025 (illustrative; counts vary by tracker) 300 600 900 1,200 0 1,044 Qilin ~717 Akira ~500+ Cl0p collapsed LockBit seized Feb 2024 2024 2025 Source: Chainalysis; SOCRadar; GuidePoint GRIT; vendor leak-site trackers. Exhibit: The Business of Cyber Security.
Qilin rose ~6.8× to ~1,044 claimed victims and absorbed affiliates after **RansomHub closed (Apr 2025)**; Akira specialized in mass-exploiting perimeter devices (notably SonicWall SSL VPNs); Cl0p ran supply-chain "single-point-of-failure" campaigns. The brands rotate; the model persists.

The current leaderboard tells three distinct stories about how RaaS competes. Qilin won on affiliate aggregation — when RansomHub abruptly closed in April 2025, Qilin recruited the orphaned affiliates and roughly doubled its monthly victim rate, finishing 2025 as by far the most prolific brand. Akira won on technical edge, mass-exploiting zero-day and n-day vulnerabilities on internet-facing edge devices (its SonicWall SSL VPN campaign was a signature 2025 move) to extort an estimated $244M by late 2025. Cl0p won on scale-through-supply-chain, eschewing affiliate volume to weaponize single file-transfer or platform vulnerabilities into mass-compromise events, adding 500+ victims in a year. Three different competitive strategies, one structural truth: there is always a next operator, because the affiliates and the access brokers are the durable assets, not the brand on the leak site.

Why RaaS is the master demand generator

Every defensive sub-segment with durable M&A activity traces back, directly, to a ransomware tactic:

RaaS tactic (2025) Defensive demand it creates M&A read
Encryption + data theft ("double extortion") Immutable backup / recovery; EDR/XDR; MDR Rubrik/Cohesity scale; MDR roll-ups (04b)
Stolen-credential entry (the #1 vector) IAM, PAM, MFA, ITDR, machine identity The identity wave — Palo Alto–CyberArk (03a)
Edge-device mass exploitation (Akira/SonicWall) Exposure management, CTEM, attack-surface mgmt 03k consolidation; Tenable/Rapid7/Qualys
Supply-chain single-point compromise (Cl0p) AppSec, SSCM, third-party risk 03f; GRC/TPRM (03i)
Payment + recovery uncertainty Cyber insurance; IR retainers Cyber Insurance; DFIR (04e)

Falsifiable bear case

The "ransomware guarantees permanent defensive demand" thesis is strong but not unconditional. (1) Sustained payment decline could de-fund the model. If the pay-rate keeps falling toward zero — driven by backups, regulation, and sanctions — affiliate ROI eventually breaks and the most capable actors migrate to other monetization (BEC, infostealers, crypto theft). Demand wouldn't vanish, but it would rotate away from the backup/IR cluster, repricing those sub-segments. (2) Law-enforcement and sanctions could raise friction faster than the model adapts — coordinated takedowns plus crypto-tracing plus OFAC designations have measurably degraded specific brands. (3) AI cuts both ways. AI lowers the affiliate's barrier (faster intrusion, better lures) and the defender's cost (autonomous detection/response). If defense compounds faster, the attacker's unit economics deteriorate. The bear case isn't "ransomware ends"; it's "the specific defensive pools tied to today's tactics get repriced as the tactics shift" — which is exactly why threat-tracking is an investment discipline, not a security one.

/ angle

The leak-site leaderboard is a sub-segment heat map. Which groups are rising, what they exploit, and which victim sizes they target is a 12–24-month leading indicator of where defensive budget — and therefore acquisition currency — flows next. Akira's edge-device focus predicts exposure-management and VPN-replacement demand; Cl0p's supply-chain focus predicts SSCM/TPRM demand. Reading the threat tape is reading the deal pipeline (Threat Economy).

The down-market shift is an SME-defense thesis. Groups moving toward SMEs "more likely to pay" is the demand signal under the MSSP/MDR roll-up and cyber-insurance-for-SMB theses — the exact white space where mid-market platforms consolidate (Service Providers, 24).


Sources: Chainalysis — Crypto Ransomware 2025 · The Record — ransomware payments dropped in 2025 · The Register — payments cratered, attacks did not (Feb 27 2026) · SOCRadar — Top 10 Ransomware Groups of 2025 · GuidePoint GRIT 2026 report · NCA — Operation Cronos / LockBit (Feb 20 2024) · WEF — How Operation Cronos disrupted LockBit


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.