loader image

OUTSOURCING CRIME TO DUMMIES. (March 2026)

Ransomware-as-a-Service (RaaS)

How Cybercrime Became a Global Business Model

First published in 2026

Outsourcing crime to dummies is a big trend in 2026 for sure!

I think it’s time I talk about Ransomware-as-a-Service (RaaS for short), which has become a major thing in our modern cybercrime landscape, functioning as a business model pyramid scheme where skilled malware developers provide their ransomware tools to less experienced e-criminals.

These lesser scoundrels, or affiliates (as the industry phrases it), carry out attacks without needing any extensive technical skills. Just about anyone can make a go at it! Available are RaaS kits, which offer everything a fledgling e-criminal might need, from a step-by-step guide to technical support, mirroring the functionality seen in legitimate software service offerings!

Can you believe it?

Ransomware as a Service

The structure of the RaaS industry is impressive and comprises different roles and revenue models. Sort of like an insurance or banking brochure? Operators are the expert developers and brains behind the malware (nasty code), creating and also managing the necessary infrastructure such as payment portals and leak sites. Affiliates are the attackers who leverage these tools to infect targets, operating under several revenue schemes.

Operators often work on a profit-sharing system, where they take a percentage of each ransom payment, typically ranging from 20% to 40%! This could be a real sweet payout when you do the math. The largest single ransomware payment ever recorded was at a whopping $75 million, paid in early 2024 to the Dark Angels ransomware group.

Other models include subscription fees (subscription economy!) for continuous access and one-time licenses for indefinite use. All very civilized.

This trend is not something new; it has, however, evolved considerably since its early days. Originally, RaaS consisted of a few isolated and technically sophisticated hacks, but today it has turned into an industrialized economy of cybercrime. Cybercrime, by the way, might very well be the third biggest global economy right now!

The RaaS roots can be traced back to 2012 with Reveton, which utilized a novel “police locker” strategy to extort victims. The model rapidly commercialized between 2015 and 2016 with strains like Tox and Cerber, introducing affiliate systems with user-friendly interfaces. (User experience is always important, colleagues, in any product development). In recent years, innovations in extortion tactics have surfaced, such as Maze’s “double extortion” approach, which encrypts data while stealing very sensitive files which then increases the chances of their bullying out a nice payday.

Some things worth a Google, if you have time are Qilin (aka Agenda) who have a victim count of 697. Akira has a victim count of 740. Play (PlayCrypt) 350 victims. SafePay 340. These are just a few that can be mentioned from the last year and a bit, but the list goes on and on.

If you think this is not happening right here in South Africa, you would be wrong.  The historical average payout in South Africa, with the information I have from 2024 is at R17.9 million. In January 2025 RansomHub hit the South African Weather Service which caused a disruption to its ICT systems. Then LockBit did its bit in February 2024 on South Africa’s Government Pensions Administration Agency (GPAA), resulting in a temporary system shutdown – and you know those people have been waiting hours already in queues. The BlackCat (not the yummy bread spread) attacked the African Union with a cyber assault. HelloKitty or DeathKitty was linked to the massive July 2021 attack on Transnet  which apparently forced the company to declare force majeure at several major ports!

As we make our way through the early parts of 2026, the RaaS environment is starting to look slightly more fragmented, with a significant uptick in active groups, totalling 124 unique teams in 2025. Despite these signs of fragmentation, a few groups maintain dominance. Qilin, Akira, LockBit, Play, SafePay, and DragonForce top the list of gangs, no doubt wearing their badges with pride for high victim counts and consistent operations. Each has their niche and employs unique strategies, such as Qilin’s industrial-scale attacks on healthcare sectors or Akira’s methodical negotiations, sometimes providing victims with security advice post-attack – the audacity!

The RaaS affiliates are also evolving, having expanded their reach by targeting critical vulnerabilities, especially in “edge” infrastructure like VPNs and firewalls, to breach initial security measures. They exploit vulnerabilities across virtualization platforms, networking systems, and file management software to gain unauthorized access.

The rapid and ever increasing evolution and adaptation in attack vectors include these e-criminals employing tactics beyond technical exploits, and also focusing on identity abuse and social engineering, including leveraging AI for voice cloning and recruiting insiders for information access. You may want to consider getting rid of your voicemail on your cell phone, as it’s a common source for cloning your voice.

Certain sectors remain priority targets for these attacks, particularly those where downtime is costly or unfortunately threatens lives (the criminals don’t care), such as healthcare, manufacturing, and critical infrastructure. Some groups now bypass encryption altogether, focusing solely on the threat of leaking stolen data as an extortion strategy.

I believe we will in the coming months and years see the rise of “supergroups” that leverage pooled expertise for impactful operations.

ransomware-group

The bottom line. The financial impacts of RaaS attacks are monumental, with ransomware payments amounting to multimillions of dollars annually. The average ransom payment skyrocketed between 2023 and 2024, increasing by 500%, with single payouts reaching record highs. This trajectory of growth I have no doubt will continue because I cannot think of a counter force to stop it right now. Groups like Ryuk have amassed fortunes from their victims, emphasizing the lucrative nature of this cybercrime model. These criminals even have their own islands to avoid jurisdiction and prosecution.

To conclude, let me quickly share two emerging ‘entry vectors’ on my radar right now. Initial Access Brokers (IABs), specialized e-criminals who sell pre-breached access (often via RDP or VPN) to RaaS affiliates, and MFA Circumvention, which involves using “adversary-in-the-middle” (AiTM) phishing to bypass multi-factor authentication, particularly targeting Microsoft 365 accounts. The other is that these scoundrels are now actively recruiting corporate employees (insiders) to provide “valid” credentials in exchange for a cut of the ransom. No trust policy is the way to go.

Preventing and mitigating RaaS attacks requires a robust, multi-layered security strategy. At this point, I want to remind you that I work at www.cyberdefenders.co.za – and the prevention and mitigation of e-crime is literally what we do. Regular backups, employing comprehensive patch management practices, using multi-factor authentication, and staff awareness workshops and training are vital.

The END.

WANT TO READ MORE ARTICLES?

Who is Jean-Pierre Murray-Kline?

Jean-Pierre is a South African serial e-entrepreneur, published author, and change champion who has worked in over 300 types of industries in some capacity or another. His own online businesses have generated millions of Rands and involved sectors such as law, web & app development, events & entertainment, property, technical services, media, and tourism.

He has traveled to over 180 cities worldwide and is extremely active as a business and environmental technologist. In addition to his own projects, he researches and consults on all things online: marketing, reputation, compliance, law, and e-security, and also offers strategy workshops and scenario sessions on future thinking with a key focus on technology, the environment, and global influences.

Jean-Pierre is often asked to be a guest speaker on a variety of subjects he continuously studies and writes about.

Disclaimer:

  • While I attempt to ensure information is accurate and up-to-date at time of publication, I will not accept liability should information be used, and found to be incorrect. If you do see an error, please let me know.
  • The links, images, videos and/ or text from this article are not necessarily under my direct management, ownership or care. Should you be the owner or manager of any content herein, and wish for the content to be removed, please let me know and it will be done.