Skip to main content

Ransomware and the RaaS economy

Estimated read: 20-30 minutes · Builds on: M7: Threats & social engineering

This is a fast-moving topic

Briefings give you the durable shape of a trend, not breaking news. Gang names, leak sites and "top variants" churn constantly; the business model below is what stays stable. For the latest, see Staying current.

What you'll get from this briefing

  • Why ransomware is best understood as an industry, not a virus.
  • The RaaS (Ransomware-as-a-Service) model: operators, affiliates, and the criminal supply chain.
  • Double and triple extortion: why "we have backups" stopped being a complete answer.
  • The Australian picture: reporting channels, payment guidance, and new legal obligations.
  • The defences that actually move the needle (you've already learned them).

1. From nuisance to industry

Early ransomware was spray-and-pray: infect whoever clicks, demand a small payment, hope. Modern ransomware is targeted, patient and professional: operators research victims, pick targets that can pay (or can't afford downtime: logistics, healthcare, manufacturing, schools), spend days-to-weeks inside the network first, and time the encryption for maximum leverage (long weekends are a classic).

The single most useful reframe: ransomware is a business with a product, suppliers, distributors and customer service. Understand the business and the defences pick themselves.


2. The RaaS model: crime's franchise economics

Ransomware-as-a-Service splits the crime into specialised roles, exactly like legitimate software-as-a-service:

RoleWhat they doLegitimate-economy analogue
Operators (the "brand")Build and maintain the ransomware platform: the malware, payment portals, leak sites, even "victim support" chatThe SaaS vendor
Affiliates"License" the platform and run the actual intrusions; hand over a percentage of each ransomFranchisees / resellers
Initial access brokers (IABs)Break into organisations (phishing, stolen credentials, unpatched edge devices) and sell the access on criminal marketsLead-generation vendors
Supporting servicesMoney laundering, negotiation, malware crypting, bulletproof hostingThe rest of the supply chain

Why this matters to a defender:

  • The skill floor drops. An affiliate doesn't need to write malware. They rent it. More attackers, more attacks.
  • Access is a commodity. By the time ransomware detonates, the initial break-in may have happened weeks earlier via a broker. Your stolen VPN password might simply be for sale. This is why identity hygiene and monitoring logins (M6) is ransomware defence, even though it doesn't look like it.
  • Takedowns rarely kill the business. Disrupt one brand and the affiliates migrate to another. The model survives. Expect churn in names, stability in method.

3. Double and triple extortion

Backups broke the original business model, so the business model adapted:

  1. Single extortion (classic): encrypt the data, sell the key. Beaten by good backups.
  2. Double extortion (now standard): steal the data first, then encrypt. Refuse to pay and they publish it on a leak site. Backups restore your systems. They don't un-publish your customers' records. This turns a ransomware incident into a data breach, with everything M5 taught about the Notifiable Data Breaches scheme following close behind.
  3. Triple extortion (pressure stacking): add a third lever: harassing the victim's customers or patients directly, DDoS attacks during negotiation, or threatening regulators and media contact.

The professional touches are real: negotiation portals, countdown timers, "proof packs" of stolen files, and discounts for fast payment. It's psychological pressure engineered as a product.


4. The Australian picture

  • Reporting: ransomware incidents affecting Australians should be reported via ReportCyber, ASD's online reporting service at cyber.gov.au, and ASD's annual Cyber Threat Report consistently discusses ransomware among the most damaging threats facing Australian organisations. Reading its latest edition is one of the fastest ways to sound current (see Staying current).
  • Should you pay? ASD advises against paying ransoms. Payment funds the industry, marks you as a payer, and (crucially) guarantees nothing: you're relying on a criminal's customer service. There can also be legal exposure (for example, sanctions law if payment reaches a sanctioned entity).
  • Payment reporting is now law for many businesses. Under Australia's Cyber Security Act 2024 (and the Ransomware Payment Reporting Rules that commenced 30 May 2025), a covered business that pays a ransom must report the payment to government within 72 hours. It applies to businesses above an annual turnover threshold (around A$3 million) plus critical-infrastructure entities. Always confirm the current thresholds and process at cyber.gov.au, but knowing this obligation exists is the point.
  • For a GRC-track learner, this cluster (NDB scheme + payment reporting + "should we pay" policy) is a genuinely Australian interview topic that most generic courses never touch.

5. The defences that actually work

No silver bullet: just the fundamentals you've already learned, prioritised by how ransomware actually unfolds:

Attack stageDefenceWhere you learned it
Initial access (phishing, stolen creds, unpatched edge)Phishing defences, MFA everywhere, patch cadenceM7, M6, M5: Essential Eight
Foothold → spreadLeast privilege, restricting admin rights, network segmentationM5/M6
Living in the network (days-weeks)Logging + detection. This dwell time is the SOC's window to catch themM8
Encryption eventRegular, tested, offline/immutable backups (an untested backup is a hope, not a control)M5: Essential Eight
Data theft / extortionData minimisation, encryption at rest, an incident-response plan rehearsed before the bad dayM5, M8, M10

Notice something: the Essential Eight reads like an anti-ransomware checklist: patching, MFA, admin restriction, application control, backups. That's not a coincidence; it's substantially what it was tuned against. When an interviewer asks "how would you defend an organisation against ransomware?", walking the kill chain with the Essential Eight is a distinctly Australian, distinctly credible answer.


Self-check

Q1. Explain the RaaS model in two sentences, including why it increased the volume of attacks.

Ransomware-as-a-Service splits the crime into specialised roles: operators build and rent out the ransomware platform, affiliates run the intrusions for a revenue share, and initial access brokers sell the break-ins. Because affiliates don't need to build anything themselves, the skill floor dropped and far more attackers can run sophisticated attacks.

Q2. Your organisation has excellent, tested backups. Why might a modern ransomware crew still have leverage over you?

Double extortion: they stole the data before encrypting. Backups restore systems but can't un-publish customer records threatened for leak, which also makes the incident a data breach engaging the NDB scheme (M5). Triple extortion adds further pressure (contacting customers, DDoS).

Q3. What is ASD's position on paying ransoms, and what legal obligation now exists around payments in Australia?

ASD advises against paying: it funds the industry, invites repeat targeting, and guarantees nothing (plus possible sanctions exposure). Under the Cyber Security Act 2024, payment-reporting obligations commenced in 2025: covered businesses that do pay must report the payment to government. Current thresholds and details at cyber.gov.au.


References & further reading