Ransomware-as-a-Service
On Feb 20, 2024, a multinational task force ("Operation Cronos," led by the UK's NCA with the FBI and Europol) seized the infrastructure of LockBit — for years the most prolific ransomware brand in the world, with 2,000+ claimed victims and $120M+ extorted. Investigators unmasked its operator "LockBitSupp" as a Russian national, Dmitry Khoroshev. Within eighteen months the market re-formed around new brands: by the end of 2025 Qilin had gone from 154 claimed victims in 2024 to 1,044, and Akira had become a $244M operation. RaaS is not a group but a business model, and the model survives the takedown of any one firm — which is a large part of why ransomware is a leading demand generator in cybersecurity. The sections below cover how the model makes money, who runs it now, why 2025 produced a "more attacks, less paid" pattern, and what each shift signals for defensive M&A.
What RaaS is: software franchising for crime
Ransomware-as-a-Service is the criminal economy's exact analog of SaaS plus franchising. A small core team (the operator/developer) builds and maintains the malware, the leak site, the negotiation portal, and the payment/escrow rails — and then licenses that platform to a distributed network of affiliates who do the actual breaking-in. The economics mirror a franchise: the affiliate, who supplies the labor and the risk, keeps the larger cut (70–80%); the operator, who supplies the product and the brand, takes 20–30% off the top of every paid ransom. Around this core sits a full supply chain — initial-access brokers who sell the entry (see 15b), negotiators, "support" staff, and money launderers — so that a low-skilled actor can rent every capability needed to run an enterprise-grade extortion campaign. This division of labor is precisely why the model is so resilient: takedowns remove a firm, not the capability stack, and the affiliates simply re-paper their contracts with the next operator.
How the money is split
The 2025 pattern: record attacks, falling payments
The defining feature of the 2025 ransomware year is a divergence: claimed victims rose roughly 50% year-over-year to the most active year on record, yet on-chain ransom payments fell ~8% to more than $820M (from ~$892M in 2024, per Chainalysis — a figure likely to revise upward toward ~$900M as attribution catches up). The share of victims who actually paid fell to an estimated ~28%, an all-time low. Behind the divergence is a market under pressure adapting on two fronts at once:
- Buyers (victims) are paying less often. Better backups, mature EDR/MDR, insurer discipline, sanctions risk on paying certain groups, and "don't pay" guidance have all pushed the pay-rate down. This is the demand side of defense working.
- Sellers (attackers) are compensating with volume and targeting. With each victim less likely to pay, groups ran more attacks and shifted down-market toward SMEs deemed more likely to pay — and the median ransom payment grew ~368% YoY to nearly $60,000 as groups optimized for the mid-market sweet spot rather than chasing megabreach jackpots. The result: flat-to-declining aggregate revenue spread across far more incidents and far more victims.
The pattern is a favorable read on defense rather than a bearish one. The criminal market is being forced to work harder for the same money — the financial fingerprint of a defensive ecosystem raising the attacker's cost. Demand for the controls that produce that pressure (backup/recovery, EDR/XDR, MDR, identity) is what the payment curve reflects.
The post-LockBit leaderboard
The current leaderboard tells three distinct stories about how RaaS competes. Qilin won on affiliate aggregation — when RansomHub abruptly closed in April 2025, Qilin recruited the orphaned affiliates and roughly doubled its monthly victim rate, finishing 2025 as by far the most prolific brand. Akira won on technical edge, mass-exploiting zero-day and n-day vulnerabilities on internet-facing edge devices (its SonicWall SSL VPN campaign was a signature 2025 move) to extort an estimated $244M by late 2025. Cl0p won on scale-through-supply-chain, eschewing affiliate volume to weaponize single file-transfer or platform vulnerabilities into mass-compromise events, adding 500+ victims in a year. Three different competitive strategies, one structural truth: there is always a next operator, because the affiliates and the access brokers are the durable assets, not the brand on the leak site.
Why RaaS is the master demand generator
Every defensive sub-segment with durable M&A activity traces back, directly, to a ransomware tactic:
| RaaS tactic (2025) | Defensive demand it creates | M&A read |
|---|---|---|
| Encryption + data theft ("double extortion") | Immutable backup / recovery; EDR/XDR; MDR | Rubrik/Cohesity scale; MDR roll-ups (04b) |
| Stolen-credential entry (the #1 vector) | IAM, PAM, MFA, ITDR, machine identity | The identity wave — Palo Alto–CyberArk (03a) |
| Edge-device mass exploitation (Akira/SonicWall) | Exposure management, CTEM, attack-surface mgmt | 03k consolidation; Tenable/Rapid7/Qualys |
| Supply-chain single-point compromise (Cl0p) | AppSec, SSCM, third-party risk | 03f; GRC/TPRM (03i) |
| Payment + recovery uncertainty | Cyber insurance; IR retainers | Cyber Insurance; DFIR (04e) |
Falsifiable bear case
The "ransomware guarantees permanent defensive demand" thesis is strong but not unconditional. (1) Sustained payment decline could de-fund the model. If the pay-rate keeps falling toward zero — driven by backups, regulation, and sanctions — affiliate ROI eventually breaks and the most capable actors migrate to other monetization (BEC, infostealers, crypto theft). Demand wouldn't vanish, but it would rotate away from the backup/IR cluster, repricing those sub-segments. (2) Law-enforcement and sanctions could raise friction faster than the model adapts — coordinated takedowns plus crypto-tracing plus OFAC designations have measurably degraded specific brands. (3) AI cuts both ways. AI lowers the affiliate's barrier (faster intrusion, better lures) and the defender's cost (autonomous detection/response). If defense compounds faster, the attacker's unit economics deteriorate. The bear case isn't "ransomware ends"; it's "the specific defensive pools tied to today's tactics get repriced as the tactics shift" — which is exactly why threat-tracking is an investment discipline, not a security one.
/ angle
→ The leak-site leaderboard is a sub-segment heat map. Which groups are rising, what they exploit, and which victim sizes they target is a 12–24-month leading indicator of where defensive budget — and therefore acquisition currency — flows next. Akira's edge-device focus predicts exposure-management and VPN-replacement demand; Cl0p's supply-chain focus predicts SSCM/TPRM demand. Reading the threat tape is reading the deal pipeline (Threat Economy).
→ The down-market shift is an SME-defense thesis. Groups moving toward SMEs "more likely to pay" is the demand signal under the MSSP/MDR roll-up and cyber-insurance-for-SMB theses — the exact white space where mid-market platforms consolidate (Service Providers, 24).
Sources: Chainalysis — Crypto Ransomware 2025 · The Record — ransomware payments dropped in 2025 · The Register — payments cratered, attacks did not (Feb 27 2026) · SOCRadar — Top 10 Ransomware Groups of 2025 · GuidePoint GRIT 2026 report · NCA — Operation Cronos / LockBit (Feb 20 2024) · WEF — How Operation Cronos disrupted LockBit
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.