Hacking News All articles
Opinion

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Hacking News
Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Photo: ransomware cybercrime dark web cryptocurrency underground hacker, via a57.foxnews.com

At some point in the last decade, ransomware stopped being a crime and started being a business. Not a shady, disorganized racket — an actual, structured business with revenue targets, affiliate commissions, brand reputation management, and in some documented cases, a legitimate-looking customer support experience for victims trying to figure out how to pay their ransom.

If that sounds absurd, welcome to the current threat landscape. The Ransomware-as-a-Service model — RaaS, as it's commonly abbreviated — has fundamentally changed who can launch devastating cyberattacks and how often they happen. And US enterprises are bearing the brunt of it.

The Franchise Model, Explained

Think of RaaS the way you'd think about a fast-food franchise. The core operators — the developers and architects of the ransomware platform — build the malware, maintain the infrastructure, and handle payment processing through cryptocurrency channels. They're the franchisor. Then they recruit affiliates: other criminals who handle the actual intrusion work, deploying the ransomware against specific targets in exchange for a cut of whatever ransom gets paid.

The typical split runs somewhere around 70/30 or 80/20 in favor of the affiliate, which makes sense — the affiliate is doing the risky operational work of breaching a network. The platform operators collect their cut passively across dozens or hundreds of active campaigns simultaneously.

This model solved the biggest bottleneck in scaling ransomware attacks: you no longer needed to be a skilled malware developer to run a devastating campaign. If you had social engineering chops, credentials to sell, or access to a corporate VPN, you could plug into an established RaaS platform and start generating revenue. The barrier to entry collapsed.

What $50 Million Actually Looks Like Underground

Estimating the total size of the RaaS economy is inherently imprecise — these aren't organizations filing 10-Ks — but the numbers that researchers and law enforcement have pieced together are jarring. Blockchain analytics firms tracking known ransomware payment addresses have documented hundreds of millions of dollars flowing through major RaaS operations over their active lifespans.

The Conti group, before its chaotic implosion following the leak of its internal chat logs in 2022, was pulling in revenues that analysts estimated in the hundreds of millions annually. LockBit, which dominated the ransomware landscape for much of 2022 and 2023 before a major law enforcement takedown, claimed over 1,000 victims on its leak site — and those are only the ones who didn't pay. The ones who paid quietly never make the list.

Breaking it down further, the $50 million figure attached to individual RaaS operations in a given year often represents just one mid-tier player in a crowded ecosystem. The top-tier groups operate at multiples of that.

Why US Companies Are the Preferred Target

This isn't random. US enterprises get hit disproportionately for a few interconnected reasons, and it's worth being honest about them.

First, the money is here. American companies, hospitals, school districts, and municipal governments tend to have the resources — or the insurance policies — to pay meaningful ransoms. A threat actor running cost-benefit calculations on targets is going to prioritize the ones most likely to produce a payout.

Second, the cyber insurance industry inadvertently turbocharged the problem. When organizations could file a claim and have their ransom payment covered, the rational response to a ransomware infection often became "just pay it." This created a reliable revenue signal for RaaS operators that US targets were worth pursuing. The insurance market has since tightened significantly, with carriers pushing harder on security requirements and sublimits on ransomware payouts, but the damage to incentive structures was done.

Third, the sheer complexity of US enterprise IT environments — legacy systems, sprawling cloud footprints, M&A-driven network chaos — creates abundant attack surface. RaaS affiliates often gain initial access through months-old unpatched vulnerabilities or purchased credentials. The bigger and messier the network, the more entry points exist.

The Operators: Who's Actually Running These Things?

The public narrative tends to focus on Russian-speaking cybercriminal groups, and while that's a significant part of the picture, the RaaS ecosystem is more geographically diverse than most headlines suggest. Active operators and affiliates have been traced to Eastern Europe broadly, parts of Southeast Asia, and increasingly, individuals in Western countries who joined affiliate programs.

What's notable about the more sophisticated operators is how deliberately they've adopted legitimate business structures as operational models. Conti's leaked internal communications revealed HR processes, performance reviews, and a management hierarchy. LockBit ran a bug bounty program — paying researchers to find flaws in their own malware. Some groups maintain PR contacts and will negotiate with journalists.

This isn't cosplay. It's functional organizational design that makes these operations harder to disrupt, because the institutional knowledge and tooling doesn't disappear when individual members get arrested or infrastructure gets seized.

What Law Enforcement Takedowns Actually Accomplish

Here's where I'll give you the honest, slightly uncomfortable take: law enforcement actions against RaaS groups matter, but their impact is more limited than the press releases suggest.

The disruption of LockBit's infrastructure in early 2024 by a coalition of agencies including the FBI and Europol was a genuine operational win. Decryption keys were recovered, infrastructure was seized, and the group's reputation took a hit. But within weeks, LockBit's operators were publicly claiming to be rebuilding. Some affiliates migrated to competing platforms. The ransomware ecosystem didn't contract — it shifted.

This pattern has repeated with nearly every major RaaS takedown. REvil gets disrupted, affiliates scatter to Conti and LockBit. Conti implodes, talent disperses to BlackCat/ALPHV, Royal, and a dozen smaller operations. The underlying labor pool, the cryptocurrency infrastructure, the access broker market that feeds initial intrusions — none of those get meaningfully disrupted by seizing a few servers and arresting a handful of mid-level operators.

What does move the needle: sanctions that make it harder to cash out cryptocurrency ransoms, international cooperation that reduces safe harbor for operators, and — most critically — raising the cost of successful intrusion by improving baseline enterprise security posture across the US.

The Defender's Reality

For security teams at US organizations, the practical implication of the RaaS franchise model is that you're not just up against one group — you're up against an ecosystem with depth. If one affiliate doesn't have the right tooling to exploit your specific environment, another one might.

The defenses that consistently matter: MFA everywhere (especially on remote access infrastructure), aggressive patch cadence for internet-facing systems, network segmentation that limits lateral movement, tested and offline backup strategies, and endpoint detection capable of catching the pre-ransomware behaviors — credential dumping, lateral movement, data staging — that precede the encryption event.

Ransomware-as-a-Service succeeded because it made attacking at scale easier than defending at scale. Closing that gap is the actual mission. The FBI press conferences are good news — but they're not a substitute for hardening your own environment.

All Articles

Related Articles

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub