logo

Ransomware-as-a-Service, Rogue Affiliates, and What’s Next

ID: bbbc4e29-a875-5549-bdba-b10153bc4564

STIX ID: report--bbbc4e29-a875-5549-bdba-b10153bc4564

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2021-05-20

Date Updated: 2026-04-29

...
...

This report analyzes the Ransomware-as-a-Service (RaaS) model using the DarkSide/Colonial Pipeline incident as a case study, describing the roles of operators, affiliates, and Initial Access Brokers (IABs), the risks of outsourced access leading to critical infrastructure attacks, and subsequent industry and criminal-forum responses—such as bans and changes to affiliate rules (e.g., REvil restricting targets)—while highlighting how RaaS may evolve under increased law enforcement and media scrutiny.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.