Ransomware-as-a-Service is a crime like any other

Criminal division of labour, externalisation of constraint and governance mechanisms

Anirudh Dhawan, Sean Foley et Vito Mollica, dans leur article « Splitting the spoils: The economics of Ransomware-as-a-Service » (2025), offer a particularly incisive economic analysis of a phenomenon that is still too often approached exclusively from a technical perspective. By treating ransomware-as-a-service (RaaS) as an organisation structured by incentives, rules and reputational considerations, they shift the central question: what distinguishes ransomware operations is not the sophistication of their code, but their capacity to persist over time.

One of the article’s primary strengths lies in its methodological rigour. Rather than attempting to reconstruct the full organisational chart of an attack, the authors focus on what can be empirically observed from available data. Based on on-chain transactions, a recurrent pattern emerges: ransom payments are redistributed overwhelmingly towards two main destinations, following an average split of approximately 85% for the affiliate and 15% for the developer. This opposition is not presented as an exhaustive description of all actors involved, but as a deliberate abstraction grounded in financial traces. It captures the measurable economic core of the arrangement, without prejudging subsequent redistributions or the actual multiplicity of roles mobilised.

This analytical focus allows us to show that the division of labour observed in RaaS is not merely a rational segmentation of the value chain. Certain tasks are delegated not because they are secondary, but because they pose a problem for developers. Direct extortion, pressure on victims and coercive escalation expose actors to legal, political and reputational risks perceived as significant. They involve a form of coercion that developers seek to keep at arm’s length.

The exercise of this constraint is therefore externalised: an activity that may be awkward within a pseudo-ethical register of justification, but above all a risk deemed too costly within a rational choice framework. Affiliates bear the operational and symbolic burden alone, while developers retain control over the infrastructure and the continuity of a stable segment of the RaaS value chain.

Re-situating ransomware within conventional structures of crime

This externalisation of constraint immediately raises a structuring question: how can inherently opportunistic criminal affiliates be governed? It is at this point that the analysis proposed by Dhawan et al. must be placed in perspective with Akers (2017). For Akers, crime never develops in isolation. It rests on trajectories, social learning processes, shared norms and reinforcement mechanisms. The governance of criminal actors therefore does not simply consist in setting formal rules, but in framing behaviours that originate in other segments of the illegal economy, where actors have already been socialised into specific practices.

Read in this light, the analysis by Dhawan et al. gains in scope. The data show that ransomware operations pursuing rapid growth by attracting affiliates en masse, with little control, generate a larger number of attacks but disappear more quickly. Conversely, those that restrict access, impose rules and sanction excesses survive longer and extract more value per attack. Governance thus appears no longer as a mere organisational choice, but as a condition of survival in a criminal environment where affiliates import norms, techniques and logics of action acquired elsewhere.

This articulation between Dhawan et al. and Akers leads to a more general conclusion. RaaS is a crime like any other. It is not an autonomous market, but a device that, in order to develop sustainably, must embed itself within hybrid criminal ecosystems combining fraud, extortion, corruption, money laundering and illicit financial services. In this respect, it corresponds closely to the broader model of Crime-as-a-Service.

The question therefore becomes empirical: do we actually observe such embedding? In theory, it should be visible. In practice, the answer remains more nuanced. The evidence is still fragmented, and ransomware continues to appear as a relatively compartmentalised activity. This may be less an exception than a particular stage of development, inviting close observation of the future trajectories of these criminal activities.

Finally, this issue of the embedding of RaaS within broader criminal ecosystems directly connects to current European research agendas. The ENSEMBLE is explicitly situated within this perspective, combining data collection with AI-augmented analysis of cybercriminal phenomena at scale. One of its objectives is to re-situate these phenomena within a continuum of hybrid criminal practices, grounded in robust theoretical frameworks drawn from the social sciences.

Written by Paul Labic. Laboratory for theoretical and applied economics (BETA), CNRS UMR 7522. Associate researcher at the research lab of the French police academy (ENSP)


REFERENCES

Akers, R. (2017). Social learning and social structure: A general theory of crime and deviance. Routledge.

Dhawan, A., Foley, S., & Mollica, V. (2025). Splitting the spoils: The economics of ransomware as a service. https://ssrn.com/abstract=5110191

Similar Posts