Browse Definitions :
Definition

ransomware as a service (RaaS)

Contributor(s): Matthew Haughn

Ransomware as a service (RaaS) is the offering of pay-for-use malware created for extortion over stolen or encrypted data, known as ransomware.

The author of the ransomware makes the software available to customers called affiliates who can use the software to hold people’s data hostage with relatively little technical skill. The use of RaaS allows affiliates to enter an area of extortion practices that was previously exclusive to the authors themselves.

For the malware author, the business model allows them to scale their earnings from their software with less personal risk than incurred if they use it themselves. Offering their software to others removes them from the final crime by having another perform the act of ransom.

An uptick in the number of ransomware infections has been attributed by many security experts to the advent of RaaS. McAfee security researchers claim that the RaaS model has an ability to create vast affiliate networks, enabling ransomware such as CTB-Locker to increase their impact.

While affiliates might take the chance of paying for RaaS via credit card, cryptocurrency is often used as payment.

This was last updated in December 2018

Continue Reading About ransomware as a service (RaaS)

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

SearchCompliance

  • risk assessment

    Risk assessment is the identification of hazards that could negatively impact an organization's ability to conduct business.

  • PCI DSS (Payment Card Industry Data Security Standard)

    The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures intended to ...

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

SearchSecurity

SearchHealthIT

SearchDisasterRecovery

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

  • cloud disaster recovery (cloud DR)

    Cloud disaster recovery (cloud DR) is a combination of strategies and services intended to back up data, applications and other ...

SearchStorage

Close