NEWS

The Rise of Ransomware-as-a-Service: 14 Active Platforms

Security researchers identify 14 active RaaS platforms operating sophisticated affiliate programs, with entry costs as low as $40 per month lowering the...

Dylan H.

News Desk

February 4, 2026
4 min read
The Rise of Ransomware-as-a-Service: 14 Active Platforms

Ransomware Ecosystem Expands

A joint analysis by Recorded Future, Flashpoint, and Group-IB has identified 14 active Ransomware-as-a-Service (RaaS) platforms operating on dark web forums as of January 2026. The research reveals an increasingly professionalized criminal ecosystem with tiered subscription models, affiliate support systems, and even customer service portals for victims.

The RaaS model has lowered the technical barrier to launching ransomware attacks, enabling affiliates with minimal technical skills to deploy sophisticated encryption payloads against enterprise targets.


RaaS Market Overview

Active Platforms (January 2026)

PlatformActive SinceAffiliate CutClaimed Victims (2025-2026)
LockBit 4.02024 (rebrand)80%430+
Qilin202385%380+
Akira202380%290+
Play202275-80%270+
BlackSuit202380%210+
Medusa202370-80%195+
Hunters International202380%180+
RansomHub202490%165+
INC_RANSOM202375%140+
DragonForce202480%95+
Fog202480%85+
Lynx202475%70+
Cactus202380%65+
Cicada3301202485%45+

Business Model Tiers

Most RaaS platforms now offer tiered subscription models:

TierMonthly CostFeatures
Basic$40-100Pre-built payload, basic encryption, manual deployment
Professional$500-1,500Customizable payload, data exfiltration, admin panel
Enterprise$3,000-5,000Full platform access, negotiation support, DDoS capability
Private Build$10,000-50,000Custom-developed ransomware, exclusive use

Evolution of RaaS Tactics

Triple Extortion Standard

The majority of RaaS platforms now employ triple extortion as standard practice:

Layer 1: Data Encryption
├── Encrypt files with hybrid RSA/AES schemes
├── Target backup systems and shadow copies
└── Demand payment for decryption key
 
Layer 2: Data Exfiltration & Leak Threat
├── Exfiltrate sensitive data before encryption
├── Publish samples on leak sites
└── Threaten full data release
 
Layer 3: Harassment & DDoS
├── Contact customers, partners, regulators
├── Report data breaches to authorities
├── Launch DDoS against victim infrastructure
└── Short-sell victim's stock (financial sector)

Affiliate Recruitment

RaaS operators actively recruit on dark web forums with postings that read like legitimate job advertisements:

  • Technical requirements and skill assessments
  • Probationary periods with lower revenue shares
  • Performance bonuses for high-value targets
  • Restrictions on targeting certain countries or sectors (hospitals, critical infrastructure — though enforcement varies)

Defense Intelligence

Common Initial Access Vectors

VectorFrequencyTrend
Exploited public-facing applications38%↑
Phishing / social engineering27%→
Valid credentials (purchased/stolen)21%↑
Supply chain compromise9%↑
Insider threat5%→

Average Dwell Time

Metric20242026
Time to encryption5.3 days2.1 days
Time to exfiltration3.8 days16 hours
Fastest observed attack4 hours47 minutes

The compression of attack timelines means organizations have dramatically less time to detect and respond to intrusions before ransomware deployment.


Recommendations

Prevention

  1. Patch internet-facing systems within 48 hours of critical vulnerability disclosure
  2. Implement phishing-resistant MFA on all remote access and privileged accounts
  3. Deploy EDR on all endpoints with 24/7 monitoring capability
  4. Restrict RDP and remote access — disable where not required, enforce MFA where it is
  5. Monitor for credential exposure on dark web markets and paste sites

Detection

  1. Baseline normal network behavior and alert on anomalous data transfers
  2. Monitor for lateral movement patterns (PsExec, WMI, SMB, RDP internal)
  3. Alert on shadow copy deletion and backup tampering
  4. Deploy canary files and honeypots to detect early-stage encryption

Response

  1. Maintain offline backups tested with regular restoration exercises
  2. Establish incident response retainer with a qualified DFIR firm
  3. Pre-negotiate cyber insurance with clear ransomware coverage terms
  4. Document and practice ransomware playbook quarterly

Resources