[GAME THEORY] Ransomware Did Not Need a Better Exploit. It Needed a Better Business Model.
RaaS wins on repeatable access and recovery pressure. Here is how defenders can break the cheap path before encryption.
Ransomware affiliates are not paid for novelty. They are paid when ordinary access becomes reliable extortion.
That is the core judgment. The defender tension is that the decisive weaknesses often sit outside the malware team’s lane: exposed remote access, reusable credentials, reachable backup administration, weak segmentation, and recovery plans that have never met a hostile domain admin. The practical payoff is better than another family profile: map the attacker’s conversion funnel, then make its cheapest steps unreliable.
The encryptor matters. It is just not the center of gravity.
TL;DR
- Public reporting on Gunra, Akira, and ransomware response cases shows recurring use of remote access, valid accounts, known vulnerabilities, lateral movement, data theft, and recovery inhibition.
- We assess that repeatability—not technical novelty—is a likely economic advantage for RaaS affiliates. Public data does not directly measure affiliate decision-making, so treat that causal claim as an assessment, not an observed fact.
- Recovery is mostly a post-access bargaining asset. Strong restoration reduces dependence on a decryptor, but it does not erase stolen-data pressure.
- Defenders get leverage by breaking the cheap path from edge access to privileged identity, backup control, and business impact.
The key judgment
Ransomware-as-a-service turns intrusion tradecraft into a marketplace problem.
Operators provide infrastructure, payloads, payment and negotiation machinery, documentation, and a brand. Affiliates and access brokers supply intrusion capacity. Victims supply the uncertain part of the equation: whether access can be converted into enough operational and disclosure pressure to produce payment.
The model rewards workflows that are reusable across organizations. An exposed VPN, a compromised remote-access account, an internet-facing appliance with a known vulnerability, or poorly separated backup administration may not impress a malware analyst. It may still offer exactly what an affiliate wants: a familiar route into a new environment with enough room to learn whether the victim is worth pursuing.
Observed behavior is consistent with that model. It does not prove that every affiliate explicitly calculates “payout per hour,” and public reporting often cannot cleanly separate operator, affiliate, and broker actions. The narrower conclusion is stronger: ordinary enterprise access weaknesses and recovery pressure recur across RaaS-linked operations because they support a repeatable access-to-extortion sequence.
The game after access
Before compromise, the attacker does not know the victim’s real recovery state, the sensitivity of accessible data, or how much downtime the organization can absorb.
Access changes that.
Once inside, the attacker can update the bet. Can privileged identities reach backup consoles? Are primary and disaster-recovery systems administered through the same trust path? Is sensitive data easy to stage? Can the environment be segmented quickly? Will restoration work if ordinary production credentials and storage are unavailable?
That makes ransomware a sequential game under incomplete information:
- Select a plausible access route or buy access from someone who already did.
- Establish enough control to inspect identity, network, data, and recovery conditions.
- Choose the continuation path: exfiltrate, encrypt, attempt recovery sabotage, combine tactics, resell access, or leave.
- Apply pressure where the victim appears least able to absorb it.
Recovery maturity is therefore not usually a visible pre-attack shield. It changes the continuation game after access. A victim that can restore critical services has a stronger outside option and less need for a decryptor. But stolen data preserves leverage, and recovery sabotage may still pay if the attacker can materially worsen the effective recovery state.
That distinction matters. “We have backups” is not the same as “the attacker cannot administer, delete, poison, or outlast our recovery path.”
What the evidence actually shows
Sophos reviewed 661 selected IR and MDR cases handled from November 2024 through October 2025. Across all intrusion types, identity-related root causes appeared in 67.32% of cases; compromised credentials alone accounted for 42.06%, while vulnerability exploitation accounted for 16.04%. Those are not ransomware-only figures, but they show how often ordinary identity failure sits at the front of real intrusions.
In Sophos’s ransomware observations, 51 brands appeared. The five most common—Akira, Qilin, SafePay, Inc, and Play—were described as RaaS brands and accounted for 51% of ransomware incidents. Sophos called ransomware brands “flags of convenience,” a useful warning against mistaking payload branding for the people and access paths behind it.
Coveware’s Q4 2025 cases tell a similar process story. Remote-access compromise remained the dominant initial-access vector. Lateral movement appeared in 65% of cases, exfiltration was directly observed in 61%, impact tactics appeared in 41%, and encryption was confirmed in 68%. Coveware reported an approximate payment rate of 20%.
That is not a representative census of the whole market. It is still hard to square with a payload-only model. The extortion process includes access, identity control, movement, collection, operational impact, and recovery pressure. Encryption is one branch, not the whole tree.
The August 2026 CISA/FBI Gunra advisory makes the service-market structure explicit. The agencies reported that Gunra expanded into a formal RaaS program, supplied affiliates with a management panel, builder, payloads, and documentation, and recruited penetration testers and “ethical hackers” as initial-access brokers. Observed access included known vulnerabilities in internet-facing VPN and firewall devices. In one victim, the operation deleted backups and archived data at both primary and disaster-recovery sites.
CISA and FBI reporting on Akira documents a comparable chain: VPN and RDP infrastructure, valid accounts, known-CVE exploitation, data exfiltration, recovery inhibition, and backup-server targeting.
Observed: these operations repeatedly combine familiar access paths with actions intended to increase post-compromise leverage.
Assessed: repeatability and lower operational friction likely help explain why those paths remain attractive.
Unknown: how consistently affiliates select a route because of explicit cost calculations, and which role—operator, affiliate, or broker—made each choice in a given intrusion.
The incentive map
RaaS operators need affiliates, stable infrastructure, usable tooling, and a reputation that the service converts access into revenue. Reliability recruits labor.
Affiliates need access that can be repeated without rebuilding the playbook for every victim. Familiar VPN, RDP, edge-device, identity, and remote-management paths reduce uncertainty.
Initial-access brokers benefit when access can be packaged, priced, and sold. A reusable route into a reachable enterprise control plane is inventory.
Victims want to restore operations without financing the market, while managing stolen-data, legal, regulatory, safety, and communications pressure.
Governments and law enforcement try to raise attacker cost through advisories, arrests, sanctions, seizures, and pressure on payment and infrastructure.
Insurers influence which recovery and access practices become economically mandatory, although checklists can become theater when restoration is not tested under hostile conditions.
Each player can behave rationally and still preserve the market. Operators professionalize. Affiliates choose familiar access. Organizations divide ownership across edge, identity, network, backup, legal, and executive teams. The attacker only needs the seams to remain cheaper than the controls.
Practical gut-check: if an intruder gained one privileged remote-access account tonight, which team would notice the first attempted hop toward backup administration—and which team would own stopping it?
Below the tear line: how to make the attacker’s access-to-extortion pipeline less reliable, what signals show the market is adapting, and one clean win for this week.
Where does your environment make extortion unusually reliable: remote access, privileged identity, segmentation, recovery administration, or the decision process after data theft?