The Business of Breaking In: How Ransomware-as-a-Service Works in 2026
Grab your coffee, because we need to talk about something that’s fundamentally changed in cybersecurity. Remember when ransomware attacks were the domain of elite hacker collectives—groups with specialized skills who built their own malware from scratch? Those days are gone.
Today, ransomware operates like a tech startup ecosystem. There are developers, affiliates, customer support teams, and even legal departments (yes, really). The whole operation runs on what we call Ransomware-as-a-Service, or RaaS, and it’s turned what used to require serious technical chops into something accessible to anyone with a credit card and questionable ethics.
Let me walk you through how this underground economy actually works, the major players defining the landscape in 2026, and—most importantly—what you can actually do about it.
How RaaS Ecosystems Actually Work
Think of RaaS like Uber for cybercrime. You’ve got the platform operators who build and maintain the malware, the negotiation infrastructure, and the leak sites. Then you’ve got the affiliates—the “drivers” in this analogy—who actually carry out the attacks.
Here’s how the money flows: affiliates typically keep 70-85% of ransom payments, while the core operators take their cut for providing the tools and infrastructure. Qilin, for instance, offers affiliates 80-85%, making it one of the most attractive programs for attackers. LockBit historically operated on a similar split.
The beauty (from the criminal perspective) of this model is specialization. You don’t need to be a coder to launch a devastating ransomware attack anymore. You just need to buy access to a compromised network—which is itself a flourishing market—or possess some social engineering skills.
The operators provide something that looks almost like enterprise software: a browser-based dashboard where affiliates can configure ransom amounts, customize exclusion rules, and build custom payloads. There’s usually a Tor-based leak site for public shaming, negotiation chat interfaces, and even “customer support” for when things go sideways.
But 2026 has brought some interesting shifts. The old franchise model—where a handful of dominant RaaS platforms like LockBit, BlackCat, and Cl0p controlled the landscape—has fractured. Trust broke down. Operators started withholding affiliate payments, exiting scams became common, and smart affiliates realized that depending on a single syndicate made them vulnerable.
The result? A wave of independent operations launched by former affiliates who carried active network access from their previous programs. When RansomHub’s infrastructure went dark, DragonForce publicly claimed it had absorbed their entire operation. When a Qilin affiliate got stiffed on a $48,000 commission, they broke away and founded The Gentlemen—now one of the fastest-growing operations of 2026.
This fragmentation means defenders now face more diverse threats, but it also means something else: the criminal underground is becoming less stable and predictable, which creates its own opportunities for defense and disruption.
The Major RaaS Groups of 2026
Let’s meet the companies you definitely don’t want doing business with your organization.
Qilin: The Undisputed Leader
If there’s a baseline ransomware threat in 2026, it’s Qilin. Originally launched in 2022 as Agenda, the operation rewrote its payload in Rust and rebranded before expanding into a mature RaaS platform. Rust matters here—it makes the malware faster, harder to analyze, and capable of targeting multiple platforms.
Qilin recorded 1,062 incidents in 2025 and maintained dominance through the first quarter of 2026 with 389 attacks posted to leak sites. That’s nearly 50% above their prior year’s pace.
What makes Qilin particularly concerning is their extortion model. They’re not just encrypting files and demanding payment. In June 2025, they announced they were building a “legal department” to prepare evidence of victims’ regulatory violations for submission to tax agencies, law enforcement, and other government authorities. They’ve also launched a call center operating in seven languages to contact victims’ clients directly, pressure them into legal action against the breached company, and threaten to hand stolen personal data to dark web criminals for fraud.
It’s a pressure campaign that combines technical compromise with psychological warfare and legal threats. And it works.
Their primary attack vector? Fortinet edge devices. If your organization runs Fortinet and your patching cycle exceeds days, you’re in their targeting profile. They’re exploiting CVE-2024-21762 and CVE-2024-55591—critical authentication bypass vulnerabilities that give them a foothold before you even know they’re there.
LockBit: The Operation That Refuses to Die
LockBit was the most dominant RaaS operation globally until law enforcement took it down in early 2024. But here’s the thing about criminal organizations: they don’t stay down.
LockBit 5.0 came roaring back in 2026, posting 163 victims in Q1—a 106% increase from the previous quarter. They climbed to fourth place globally, proving that brand recognition matters even in the criminal underground.
What made LockBit successful was operational sophistication. They maintained a formal affiliate vetting process, a dedicated administrative panel for managing attacks and negotiations, automated tools for exfiltrating victim data, and a public-facing leak site that served both extortion and marketing purposes.
The takedown disrupted them, but it didn’t destroy the affiliate network. Those displaced operators needed somewhere to go, and many ended up with competitors. Others waited for LockBit’s infrastructure to come back online—which it did.
BlackCat (ALPHV): The Cautionary Tale
BlackCat, also known as ALPHV or Noberus, represents both the potential scale and the inherent instability of RaaS operations. The group compromised over 1,000 victims worldwide and collected nearly $300 million in ransom payments before law enforcement disruption in late 2023.
What made BlackCat technically interesting was that it was built from the ground up in Rust—a significant departure from the C/C++ family most ransomware was written in. This improved attack performance and made detection harder. They also pioneered what we call “triple extortion”: encryption, data theft, and DDoS attacks against victims who refused to pay.
In April 2026, two Americans who attacked multiple U.S. victims using ALPHV BlackCat ransomware were sentenced to prison. They’d agreed to pay the administrators a 20% share of ransoms in exchange for access to the ransomware and extortion platform. These were the “affiliates”—and the fact that they received real prison sentences is an important precedent.
BlackCat’s infrastructure went dark in early 2024 after collecting a $22 million ransom from Change Healthcare—money they never shared with the affiliate who actually conducted the attack. That kind of infighting is becoming more common in the RaaS ecosystem, and it’s one of the few things giving criminals pause.
Vect: The Open-Door Experiment
If you want to understand where ransomware is heading in 2026, look at Vect.
Launched in late 2025 with an affiliate program that went active in early 2026, Vect represents a departure from the traditional RaaS model. Historically, elite ransomware groups operated like closed franchises—LockBit maintained only 73 affiliate accounts before its disruption. Small, vetted affiliate pools let operators control targeting, maintain negotiation quality, and avoid law enforcement attention.
Vect threw that model out the window.
In March 2026, Vect announced a formal partnership with BreachForums, one of the most trafficked cybercriminal communities on the internet, with a claimed membership of over 300,000 users. They offered every BreachForums member an automatic Vect affiliate key.
Think about what that means. Where traditional RaaS carefully vetted technically skilled affiliates, Vect attempted to turn an entire criminal social network into a ransomware workforce. Even if a small fraction of those 300,000 members activated, it could represent one of the largest coordinated ransomware mobilizations ever observed.
Technically, Vect is sophisticated. Developed independently in C++ (not derived from leaked source code, meaning existing signatures are less useful), it targets Windows, Linux, and ESXi environments. It disables Windows Defender, deletes Volume Shadow Copies, clears Windows event logs, and establishes persistence through registry keys. Lateral movement happens via embedded PowerShell scripts over CIM sessions.
But there’s a catch. In April 2026, researchers discovered that Vect 2.0 had an encryption flaw that made data recovery impossible even if victims paid the ransom. The Cloud Security Alliance reported that “Paying the Ransom Cannot Recover Enterprise Data.”
For defenders, this is actually terrifying. It suggests that some of these operations are becoming so chaotic that even the basic premise—pay us and you’ll get your data back—is breaking down.
Double Extortion: When Backup Isn’t Enough
Here’s something that surprises a lot of people: modern ransomware attacks often don’t start with encryption.
The new playbook is exfiltration-first. Affiliates gain access, spend days or weeks moving through your network, and systematically steal sensitive data before a single file gets encrypted. By the time you see ransom notes on your screens, they’ve already got your data.
This is double extortion: encrypt files AND threaten to publish stolen data.
It fundamentally changes the calculus. Even organizations with robust, tested backups—long considered the gold standard for ransomware recovery—can’t simply restore and move on. The attackers now have leverage beyond operational disruption. They’ve got customer data, financial records, intellectual property, employee information, and communications that could be embarrassing or legally compromising.
Some groups have pushed this further. Qilin’s three-stage process involves negotiation, public announcement on their leak site, and then data release if demands aren’t met. The threat isn’t just about your operations—it’s about your reputation, your regulatory standing, and your relationships.
And here’s the really concerning evolution: in 2026, encryption is becoming optional. A growing number of operators have pivoted to extortion-only models built around stolen data. Hunters International formalized this by rebranding as “World Leaks” and providing affiliates with exfiltration-only tools. SnowTeam launched Leak Bazaar, a marketplace that processes stolen corporate data into buyer-ready categories and resells it repeatedly.
Even when victims refuse to pay, the data gets monetized. Your breach becomes someone’s business model.
Technical Capabilities: What These Groups Actually Do
Let’s get into the technical weeds for a moment, because understanding how these attacks work is essential to defending against them.
Volume Shadow Copy Deletion
Volume Shadow Copies are Windows’ built-in backup mechanism—point-in-time snapshots that let you recover previous versions of files. They’ve long been a lifeline for ransomware recovery.
Unsurprisingly, ransomware operators target them aggressively. The most common method uses the VSSAdmin tool built into Windows:
vssadmin.exe delete shadows /all /quiet
But that’s the obvious approach, and modern detection tools watch for it. More sophisticated ransomware uses alternative techniques:
- WMIC:
wmic shadowcopy delete /nointeractive - PowerShell: Wrapping WMI calls in PowerShell for stealth
- DiskShadow: Using this Windows utility for shadow copy management
- COM VSS Coordinator: A newer technique discovered by VMware that interfaces directly with VSS through the Component Object Model, bypassing traditional detection
Some ransomware doesn’t delete shadow copies directly—it resizes the maximum storage space to zero, forcing Windows to delete them to free up space. It’s indirect, and it works.
Safe Mode Booting
One of the more insidious techniques involves forcing Windows to boot into Safe Mode. Why? Because in Safe Mode, most security software doesn’t load.
Qilin’s affiliate panel includes this capability. The ransomware schedules a forced reboot into Safe Mode, where it then executes encryption with minimal interference from endpoint protection. By the time the system boots normally again, files are encrypted and the attackers are cleaning up their tracks.
This is why behavioral detection matters more than signature-based detection. You’re not looking for a specific piece of malware—you’re looking for the anomalous behavior of a system booting into Safe Mode unexpectedly and then executing suspicious processes.
Defense Evasion Techniques
Modern ransomware goes to significant lengths to blind detection:
- BYOVD (Bring Your Own Vulnerable Driver): Attackers load known-vulnerable but legitimately signed drivers, then exploit those drivers to terminate endpoint detection processes. Qilin has been observed using DLL sideloading to terminate hundreds of EDR drivers before encryption.
- WSL Execution: Running Linux encryptors inside Windows Subsystem for Linux, bypassing Windows-native detection that doesn’t monitor WSL processes.
- Living off the Land: Using built-in system tools like PowerShell, WMI, and scheduled tasks for malicious purposes—hiding in the noise of legitimate administrative activity.
- Event Log Clearing: Systematically deleting Windows event logs to hinder forensic investigation and incident response.
Credential theft happens early and often. Mimikatz dumps credentials from memory. Chrome credential files get harvested. Domain controllers become primary targets because compromising Active Directory gives attackers the keys to everything.
Exfiltration happens before encryption—and detection built around encryption events alone completely misses the most consequential part of the attack.
Defense and Recovery: What Actually Works
Let’s talk about what you can actually do. I’ll be honest: there’s no silver bullet. But there are concrete steps that dramatically reduce risk and improve recovery outcomes.
The Foundation: Identity and Access
Here’s the uncomfortable truth: in most modern attacks, hackers don’t break in. They log in.
Credential-based attacks account for the highest frequency of initial access. Exposed RDP services, unprotected VPN portals, and credentials available on dark web markets appear often enough across sectors to make this a universal concern.
That means identity protection is your first line of defense:
- MFA everywhere. Despite techniques like push bombing, multi-factor authentication remains the most effective way to prevent account compromise. For high-risk environments, use phishing-resistant MFA with hardware security keys.
- Identity Threat Detection and Response (ITDR). Assume credentials will eventually be compromised. Monitor account behavior for anomalies—impossible travel, unusual privilege escalation—and automatically respond by requiring step-up authentication or disabling accounts.
- Identity posture management. Configurations and permissions drift over time. Former employee accounts stay active. Regular auditing and hardening reduces your attack surface.
Endpoint Detection and Response
Traditional antivirus looks for known malicious files. Modern ransomware is often custom-made or polymorphic, changing its code with every execution. Attackers use fileless malware and living-off-the-land techniques to hide in plain sight.
You need behavioral detection that monitors for suspicious activity—processes spawning unusual child processes, credential dumping tools running unexpectedly, or encryption activity starting without corresponding business justification.
EDR platforms can deploy “ransomware canaries”—files that trigger immediate alerts if someone starts trying to encrypt them. Some platforms can automatically isolate infected devices and terminate malicious processes before encryption spreads.
Backup Resilience
The old 3-2-1 backup rule (3 copies, 2 different media types, 1 off-site) has evolved into 3-2-1-1-0:
- 3 copies of data
- 2 different media types
- 1 off-site copy
- 1 immutable copy—This is the critical addition. An immutable backup is write-once, read-many. It can’t be changed or deleted, even by someone with administrative credentials.
- 0 errors—Verified, tested recovery. A backup is only a backup if you know it works.
And here’s something many organizations miss: backup infrastructure itself is a target. Qilin specifically targets Veeam backup infrastructure. Domain accounts shouldn’t have access to backup systems—that way, when Active Directory is compromised, your backups aren’t compromised too.
Patching Edge Devices
If you’re running Fortinet appliances, this is non-negotiable. Qilin, The Gentlemen, and other groups are actively exploiting CVE-2024-21762 and CVE-2024-55591—authentication bypass vulnerabilities that give them direct access to your network.
Your patching cycle needs to be measured in days, not weeks or months. Attackers are stockpiling pre-exploited devices—the group behind The Gentlemen maintains approximately 14,700 compromised FortiGate devices ready for deployment.
Monitoring and Detection
Centralized logging brings security data from cloud platforms, servers, firewalls, and endpoints into a single source of truth. But you need to be watching for the right things:
- Volume Shadow Copy deletion attempts
- Unexpected Safe Mode reboots
- RMM tool usage (AnyDesk, ScreenConnect, Splashtop, TeamViewer) outside legitimate contexts
- Exfiltration activity—large data transfers to cloud storage, unusual DNS queries, or VPN connections from unexpected locations
- By the time encryption starts, data may have already left your environment. Detection built around encryption events alone misses the attack entirely.
Incident Response Planning
The median dwell time for ransomware attacks—how long attackers are in your network before you know—is just five days. In many cases, payloads deploy within hours.
That means your response needs to be fast and coordinated. Your incident response plan should:
- Involve legal, finance, business continuity, and disaster recovery teams—not just IT
- Include decision trees for communication, including regulatory notification
- Be tested regularly through tabletop exercises
- Account for identity recovery, not just data recovery
Active Directory and Entra ID recovery should be your RTO anchor. If identity systems are compromised, you can’t trust any system in your environment.
The Question of Payment
Law enforcement agencies and cybersecurity experts overwhelmingly advise against paying. Payment doesn’t guarantee data recovery or deletion (as Vect’s encryption flaw demonstrates). It funds further criminal operations. And depending on the jurisdiction and sanctioned status of the threat actor, it may expose your organization to legal risk.
If you do receive a ransom note, don’t engage directly before consulting your incident response team, legal counsel, and cyber insurer (if applicable). Preserve all evidence. Notify law enforcement. Modern ransom notes are designed to create urgency and narrow your perceived options—having a pre-established plan prevents decision-making under pressure.
The Bottom Line
Ransomware in 2026 is more accessible to attackers, more sophisticated in execution, and more diverse in its threats. The franchise model has fractured into something less predictable but no less dangerous. Groups like Qilin, LockBit, and Vect are constantly evolving their techniques.
But here’s the thing: the attack chain gives defenders multiple opportunities to interrupt it. Credential protection can prevent initial access. Behavioral detection can catch lateral movement. Immutable backups can defeat encryption. Effective monitoring can spot exfiltration before it’s complete.
The organizations that weather these attacks successfully aren’t the ones with perfect security—they’re the ones with layered, tested defenses that work together.
Now finish that coffee. You’ve got work to do.
