To understand modern ransomware, stop picturing a lone hacker and picture a franchise. Ransomware-as-a-service (RaaS) groups — LockBit being the most notorious of the era before international police disrupted its infrastructure in 2024’s Operation Cronos — build the malware, run the leak sites and payment portals, and lease the kit to "affiliates" who perform the break-ins for a revenue share.
The division of labour
- Initial access brokers sell footholds: phished credentials, exposed remote desktops, unpatched VPNs — often for a few hundred dollars.
- Affiliates buy access, spread through the network, steal data, then detonate the encryption.
- The RaaS operator supplies tooling, negotiation portals and the leak site that pressures victims.
- Everyone takes a cut. It is, structurally, a logistics business.
Double extortion changed the maths
Modern crews steal your data before encrypting it. Even a perfect backup no longer ends the conversation, because the second threat is publication — client files, payroll, contracts on a public leak site. This is why prevention and detection now matter as much as recovery, and why "we have backups" is necessary but not sufficient.
Staying off the menu
- Close the access brokers’ inventory: MFA on remote access, no internet-exposed RDP, VPNs patched fast.
- Patch internet-facing systems within days, not months — affiliates scan constantly for known holes.
- EDR with 24/7 eyes: the pre-encryption phase (spreading, credential theft) is noisy and catchable.
- Immutable, tested backups so the encryption half of the extortion fails outright.
Police takedowns dent these groups, but the model regenerates — affiliates migrate to the next brand. The durable defence is being a bad investment: expensive to break into, quick to detect, impossible to hold hostage.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check