Cybercrime DB

RaaS Affiliate Program Structures and Recruitment

How ransomware operators run criminal enterprises using the startup playbook.

Senior Writer · · 9 min read
Cover illustration for “RaaS Affiliate Program Structures and Recruitment”
ransomware groups and operators · August 15, 2026 · 9 min read · 1,957 words

Ransomware-as-a-service has grown into a full industry, complete with operators, affiliates, service tiers, and a labor market that runs on the same logic as any staffing agency, just with worse HR. Understanding how that structure gets assembled, piece by piece, explains why RaaS is so hard to shut down and so easy to join.

The operator builds and maintains the product: the ransomware code, the servers behind it, the negotiation portals, the leak sites, the payment plumbing. Affiliates handle the messy part, picking targets, breaking in, and pulling the trigger on encryption. That split is a deliberate division of labor, and it's the reason the whole thing keeps running no matter how many arrests make headlines.

Scale tells you the model works. Ransomware made up 44% of all cybersecurity breaches in 2024. Publicly reported RaaS attacks hit 7,200 in 2025, a 47% jump over the year before. Researchers tracked 124 distinct groups operating in 2025, up 46% from the prior year. That growth is driven by how easy it has become to open an affiliate program and start recruiting, more than by any increase in people learning to write malware.

What the operator actually provides to affiliates

Operators do far more than hand over a virus and wish affiliates luck. What they actually deliver looks a lot like a software company's product stack: a ransomware codebase that gets patched and updated to dodge antivirus and EDR tools, victim dashboards, negotiation portals, hosting for the leak site where stolen data gets published, and payment infrastructure to collect the ransom once someone pays.

Then there's the support layer, and this is where it starts to feel uncomfortably like a SaaS company's customer success team. Technical help. Private forums where affiliates trade tips. Ransom note templates. Coaching on how to negotiate with a victim who's panicking, and in some cases the operator jumps into the chat and negotiates directly.

Operators also hand affiliates an actual sequence to follow: how to map out the network you just broke into, how to steal credentials, how to move sideways from one machine to the next, how to pull data out the door before you lock everything down. The affiliate runs an attack someone else already designed.

That's the whole trick. The operator eats all the hard engineering work, the cryptography, the infrastructure, the tooling that took real skill to build. The affiliate just needs to be good at breaking into networks. That talent pool dwarfs the pool of people who can write functioning ransomware from scratch, which is why the barrier to entry keeps dropping.

The four commercial models operators use to monetise the platform

Table: RaaS Commercial Models Compared. Compares Upfront Cost, Ongoing Support, Risk Bearer and Best Suits by Profit-Share, Subscription, One-Time Licence and Custom Build.

Operators don't all charge the same way. There are four models on the table, and each one changes who bears the risk.

The profit-share model is the big one. No upfront cost to the affiliate; the operator just takes a cut of whatever ransom comes in. It's the dominant setup because it lines up everyone's incentives. If the affiliate doesn't get paid, neither does the operator.

Subscription is the second model, and it's almost funny how cheap it can be. Some programs charge remarkably little a month for access to the toolkit and support. The operator gets paid whether or not the affiliate ever lands a hit, which flips the risk onto the affiliate's side of the table.

Then there's the one-time license: pay once, get unlimited access to the malware, no ongoing support. Lowest touch for the operator, appealing to affiliates who'd rather work alone without anyone looking over their shoulder.

And finally, custom builds: a ransomware strain made to order for one buyer, usually for a big, targeted campaign. Highest price tag, lowest volume, resembling a contractor hired for one job rather than a recurring program.

That low monthly figure deserves a second look. It's less than most people pay for a video streaming bundle, and it buys entry into a criminal enterprise capable of shutting down a hospital's IT system. Because the money moves through four different channels, there's no single financial choke point that stops all of them at once.

How profit splits are structured and what they signal about affiliate leverage

Baseline math: operators typically keep a minority share of a ransom, affiliates keep the rest. That gap is intentional. The operator makes money on volume across many affiliates; the affiliate is the one standing in the network at 2 a.m. taking all the operational risk.

LockBit's numbers, confirmed by the Department of Justice, show what that split looks like at scale. Developer Khoroshev took 20% per ransom, affiliates kept 80%, and Khoroshev alone pulled in at least $100 million in developer shares over the scheme's life. A minority cut, multiplied across enough attacks, adds up to a fortune.

RansomHub flipped the ratio in 2024, giving affiliates 90% and keeping just 10% for itself, the most affiliate-friendly split documented in the market. That reflected recruiting strategy more than generosity, aimed squarely at picking up affiliates left stranded after LockBit's troubles.

Medusa runs a sliding scale, starting at 70/30 and climbing to 90/10, but that top tier only kicks in on ransoms of $1 million or more, making the headline number an aspiration for most affiliates. Cloak offers 85/15 with no deposit required, an easy on-ramp built to pull in new recruits. Qilin pays up to 80% on ransoms at or under $3 million, and up to 85% above that. Anubis, advertised in late February 2025, went further and split its offering into three separate tracks: traditional ransomware deployment at 80% affiliate share, data-theft extortion without encryption at 60%, and access sales at 50%. That's an operator treating each stage of an attack as its own product with its own price tag.

Europol's 2023 threat assessment found some programs run tiered entry, starting new affiliates as low as 20-40% and raising their cut to 80% as they prove themselves. The split functions as a performance review dressed up as a paycheck. And the direction of travel since 2022 points one way: shares keep rising for affiliates, because operators outnumber the skilled intruders available to recruit.

Diagram: How Operators Split the Ransom: Six Programmes Compared. Visualizes: Visualise the affiliate revenue-share percentages across six documented RaaS programmes to show the competitive drift toward higher affiliate cuts.

Where and how operators find affiliates

Most recruiting happens on a small handful of dark web forums, XSS, Exploit, and RAMP being the main three, and each one has its own house rules about what you're allowed to say out loud.

XSS at its peak had more than 50,000 registered users and over 110,000 threads, and groups like LockBit, REvil, ALPHV/BlackCat, and DarkSide all used it to advertise and coordinate. On XSS and Exploit, the word itself is banned, so operators phrase it as looking for "pentesters," a wink-and-nod euphemism everyone on the forum understands. RAMP, by contrast, let operators post full program details openly, no code words needed, at least until the FBI seized it on January 28, 2026.

RAMP had its own gate before that: join with either an established reputation on XSS or Exploit (two-plus months of tenure, ten-plus posts) or pay a $500 registration fee. That's a bouncer at the door checking IDs before you even get to the part where a specific program screens you.

Group-IB tracked 39 separate advertisements for RaaS programs on dark web forums in 2024, a 44% increase over 2023. Operators are competing for talent out in the open, or as open as a banned-word forum gets.

Beyond the forums, recruiting happens through Telegram, Jabber, private invites into closed groups, and reputation-based outreach. The biggest operations have dedicated affiliate managers, essentially recruiters with a criminal org chart. Smaller or newer programs skip the org chart entirely and the developer just handles recruiting personally.

LockBit did something stranger: aspiring affiliates had to DM the group directly, because the LockBit name itself was the recruiting pitch. The group even paid $1,000 to any forum user willing to get a LockBit logo tattoo, and at least three people took the deal. Brand loyalty, tattooed on.

How operators screen affiliates before granting access

Every operator wants more affiliates, because more affiliates means more attacks and more revenue. But a sloppy or careless affiliate is a liability, the kind who gets caught and drags attention back to the operator. Vetting exists to manage that trade-off.

RansomHub's 2024 intake process ran on four possible paths: a recommendation from an existing affiliate, proof of forum reputation, evidence of past RaaS work, or a refundable deposit, which was returned after the affiliate's first successful payout. Starting in June 2024, unknown applicants with no track record had to put down a substantial deposit just to get in the door.

RAMP's $500 fee and reputation requirement worked the same way, a screen before the actual screening even started. Some of the bigger-name groups go further still, running interviews and digging through a candidate's digital footprint before granting access. It's HR, run by criminals, and it works about the way HR works anywhere: annoying, but functional.

Reputation is the real currency here. A glowing review from a trusted forum voice can fill an operator's recruiting pipeline overnight. The reverse is just as true. DarkSide is the documented case: an affiliate filed an arbitration complaint on a forum, won, and the fallout cost DarkSide its forum deposit and scared off future recruits.

Not every program can afford to be picky. A name like LockBit can turn people away and still fill its ranks. Smaller programs loosen the bar just to stay staffed, Cloak's approach of running an interview but skipping the deposit is a good example of trying to build trust without scaring off recruits. And every so often, operators reach past the forums entirely, posting fake IT job listings on freelance platforms to scout or test candidates, a small channel, but one that blurs the line between the criminal labor market and the legitimate one.

Why the programme structure makes RaaS organisations hard to dismantle

Venn diagram: RaaS: Operators vs. Affiliates. Compares Operators and Affiliates; overlap: Shared.

Split the risk across two layers and you split the enforcement problem too. Law enforcement has to reach the developer, who's usually pseudonymous and hopping between jurisdictions, and the affiliates, who are scattered across countries and operating independently of each other. Hitting one doesn't touch the other.

Affiliate churn barely matters to the platform. Arrest a dozen affiliates and the operator's code, infrastructure, and leak sites are all still sitting there, ready for the next recruiting round. Data leak sites published 5,066 attacks in 2024, 10% above 2023's 4,583, and that happened in the same year law enforcement ran some of its biggest actions against named groups. The attacks didn't slow down. They kept climbing.

Payments told a different story than attacks did. Total ransomware payments dropped 35% to $813.55 million in 2024 even as attack volume rose, which suggests operators and affiliates adjusted their playbook rather than backing off, smaller ransoms, spread across more victims, instead of fewer big scores.

Programs are also portable in a way that makes brand takedowns almost pointless. When one gets dismantled, its affiliates just move to the next program advertising the best terms. RansomHub's aggressive 90/10 split and open recruiting in 2024 was built for exactly this, scooping up affiliates who'd lost their home after LockBit and ALPHV ran into trouble. Affiliates are loyal to whoever is paying the biggest share this quarter.

The recruiting pipeline is outrunning the takedowns, too. Thirty-nine new program ads in 2024, up 44% from 2023, landed during the same stretch as the most aggressive law enforcement actions RaaS has ever seen. New supply is arriving faster than enforcement can clear it out.

Which is really the whole story in one sentence: disrupting RaaS means squeezing development infrastructure, payment rails, recruiting forums, and individual affiliates all at once, because the model was built from day one to absorb the loss of any single component.

Sources

  1. darkowl.com
  2. vectra.ai
  3. sophos.com
  4. sophos.com
  5. group-ib.com
  6. paubox.com
  7. paloaltonetworks.com

More in ransomware groups and operators