News

Ransomware as a Service and the Goliath Dark Web Sale

Updated 8 min read1788 words
Locky ransom note from February 2016: the Hall of Ransom shop sold Goliath next to a Locky decrypter
Locky ransom note from February 2016: the Hall of Ransom shop sold Goliath next to a Locky decrypter. Image: Unknown author via Wikimedia Commons, Public domain

In September 2022, a ransomware strain called Goliath appeared for sale on underground forums, advertised as a ready-to-deploy extortion toolkit. The listing was not unusual. What is ransomware as a service is exactly this: packaged malware sold or leased to affiliates who lack the technical skill to write their own code. Goliath joined dozens of similar offerings that turned ransomware from a specialist craft into a commodity anyone could buy. The sale illustrated how RaaS lowered the barrier to cybercrime and why even small businesses became targets.

What Ransomware as a Service Means

Ransomware as a service is a business model in which developers build encryption malware and rent or sell it to affiliates. The affiliate deploys the ransomware, collects ransom payments and splits the profit with the developer. The developer handles updates, payment infrastructure and sometimes negotiation support. The affiliate only needs to find a target and deliver the payload.

This model mirrors legitimate software-as-a-service platforms. Developers advertise on Russian-language forums, Telegram channels and invite-only marketplaces. Some RaaS operators vet affiliates to avoid law enforcement; others sell to anyone. Pricing varies: some charge a flat fee, others take a percentage of every ransom paid. The result is a supply chain that separates technical skill from criminal intent, allowing low-skill actors to launch sophisticated attacks.

RaaS ransomware as a service emerged around 2015 and became dominant by 2020. It explains why ransomware incidents surged even as the number of unique strains remained relatively stable. A single RaaS group can enable hundreds of attacks across different sectors and countries.

The Goliath Listing in September 2022

Goliath ransomware was advertised on a dark web forum in September 2022 as a fully featured toolkit. The seller offered a Windows executable that encrypted files, a decryption tool for paying victims and a ransom note template. The listing did not require technical expertise from buyers. The price and exact forum have been reported in security-vendor incident reports, but the key detail is that Goliath was marketed to first-time criminals.

The advertisement emphasized ease of use: no coding required, no server setup, no need to negotiate with victims. Buyers received a binary they could distribute via phishing emails or exploit kits. The seller claimed the ransomware used strong encryption and would not be detected by common antivirus software. Whether those claims were accurate is secondary to the fact that the listing existed and attracted interest.

Goliath was not a major player compared to LockBit or BlackCat, but its sale demonstrated how accessible ransomware had become. The listing disappeared within weeks, either because it sold out, was taken down by forum moderators or turned out to be a scam. The uncertainty around its fate is typical of dark web marketplaces, where trust is low and exit scams are common.

How Ransomware as a Service Groups Operate

Ransomware as a service groups function as criminal enterprises with defined roles. The core team writes the malware, maintains command-and-control servers and processes ransom payments in cryptocurrency. Affiliates are recruited through forums or referrals. Some groups require proof of past breaches; others accept anyone willing to pay an upfront fee or deposit.

Once accepted, an affiliate receives a custom build of the ransomware, often with a unique identifier so the developer can track which affiliate generated which ransom. The affiliate is responsible for gaining access to a target network, moving laterally to maximize damage and deploying the payload. After encryption, the victim sees a ransom note with payment instructions. The affiliate and developer split the payment, typically 70-30 or 80-20 in favor of the affiliate.

Some RaaS platforms offer dashboards where affiliates can monitor active infections, chat with victims and request technical support. Others provide leak sites where stolen data is published if the victim refuses to pay. This infrastructure mirrors legitimate customer-relationship management tools. The professionalization of ransomware as a service groups is one reason law enforcement has struggled to disrupt them: taking down one affiliate does not stop the core operation.

Tor payment page of the Locky ransomware family
Tor payment page of the Locky ransomware family. Image: Unknown author via Wikimedia Commons, Public domain

Why People Try to Buy Ransomware as a Service

Individuals search for ways to buy ransomware as a service for several reasons, most of them misguided. Some believe they can extort businesses with minimal risk. Others are curious or want to test security defenses. A few are researchers or penetration testers looking for samples, though legitimate researchers obtain malware through sandboxes and threat-intelligence feeds, not dark web purchases.

Buying ransomware on underground forums is risky for the buyer. Many listings are scams: the seller takes payment and disappears, or the ransomware is broken and fails to encrypt files. Even if the malware works, deploying it is a federal crime in most jurisdictions. Law enforcement agencies monitor forums where RaaS is sold, and undercover operations have led to arrests. Payment usually requires cryptocurrency, which is traceable if the buyer does not use mixing services or privacy coins correctly.

The appeal of RaaS to criminals is that it removes the need to learn programming or cryptography. But it also removes control. Affiliates depend on the developer to provide decryption keys, and some developers have withheld keys or sold the same ransomware to multiple buyers, causing conflicts. The trust problem in criminal markets makes RaaS a gamble even for those willing to break the law.

How the Ecosystem Actually Behaves

Public law-enforcement press releases describe RaaS takedowns as temporary disruptions rather than permanent victories. When the FBI dismantled the Hive ransomware infrastructure in early 2023, affiliates migrated to other platforms within days. The decentralized nature of RaaS means no single arrest or server seizure can eliminate the model. This matters because organizations cannot rely on law enforcement alone to reduce ransomware risk.

Security-vendor incident reports show that most RaaS attacks succeed through weak passwords, unpatched vulnerabilities or phishing emails, not through zero-day exploits. The technical sophistication of the malware is less important than the affiliate's ability to gain initial access. This means basic security hygiene, such as multi-factor authentication and regular backups, blocks the majority of RaaS attacks. The gap between perception and reality is significant: ransomware feels unstoppable, but most incidents exploit preventable mistakes.

Court records from prosecuted RaaS cases reveal that affiliates are often young, inexperienced and motivated by financial desperation rather than ideology. Sentences range from probation to decades in prison, depending on the damage caused. The legal risk is real and growing as international cooperation improves. For readers considering any involvement, the consequences are severe and the chances of getting caught are higher than dark web forums suggest.

What Changed After the Goliath Sale

The Goliath listing in 2022 was one data point in a larger trend. Since then, several high-profile RaaS operations have been disrupted, but new ones have launched to replace them. The RaaS model has not disappeared; it has adapted. Some groups now require affiliates to prove their technical skill before granting access, reducing the risk of attracting law enforcement or incompetent criminals who draw attention.

Payment methods have also evolved. Early RaaS operations accepted Bitcoin directly; newer groups prefer Monero or require mixing services to obscure transaction trails. Some have moved away from public forums entirely, recruiting affiliates through private Telegram channels or invite-only communities. This makes it harder for researchers and law enforcement to monitor activity, but it also fragments the ecosystem and increases the chance of scams.

For ordinary users and businesses, the lesson from the Goliath sale is that ransomware threats are not limited to nation-state actors or elite hacking groups. Any criminal with a few hundred dollars and basic computer skills can attempt an attack. This democratization of cybercrime means every organization, regardless of size, needs a response plan that includes offline backups, incident-response contacts and a policy on whether to pay ransoms.

What You Should Do With This Information

Understanding ransomware as a service does not require you to visit dark web forums or purchase malware samples. The value is in recognizing that ransomware is now a commodity, not a rare threat. If you manage a network, prioritize offline backups that cannot be encrypted by malware. If you are a home user, enable automatic updates and use unique passwords for every account. If you are researching cybersecurity, rely on threat-intelligence platforms and academic papers rather than attempting to buy samples from criminals.

The Goliath sale and similar listings are reminders that the barrier to entry for cybercrime is lower than most people assume. That reality should inform how you assess risk and allocate resources. Treat ransomware as a when-not-if scenario and prepare accordingly. The most effective defense is not sophisticated detection software but a recovery plan that assumes encryption will happen and ensures you can restore operations without paying.

If you want to verify whether a forum or marketplace is legitimate, check the Useful Resources page on this site for guidance on PGP verification and how to spot phishing clones. Do not trust any .onion address posted in a forum without independent confirmation. The safest approach is to assume that any offer to buy ransomware as a service is either a scam or a law-enforcement honeypot.

Frequently asked questions

What is ransomware as a service?

Ransomware as a service is a business model where malware developers lease or sell encryption tools to affiliates who deploy them against targets. The developer handles the technical infrastructure and payment processing, while the affiliate finds victims and delivers the ransomware. Profits are split between the two parties, typically favoring the affiliate. This model allows low-skill criminals to launch sophisticated attacks without writing code.

How do ransomware as a service groups recruit affiliates?

RaaS groups recruit through Russian-language forums, Telegram channels and invite-only marketplaces. Some require proof of past breaches or technical skill to avoid attracting law enforcement. Others accept anyone willing to pay an upfront fee. Recruitment messages emphasize profit potential and ease of use. Once accepted, affiliates receive a custom ransomware build and access to support infrastructure.

Is buying ransomware on the dark web illegal?

Yes, purchasing ransomware with the intent to deploy it is a federal crime in most countries, including the United States and European Union. Even possessing ransomware without authorization can lead to prosecution under computer fraud and abuse laws. Law enforcement monitors forums where ransomware is sold and has conducted undercover operations that resulted in arrests. The legal risk is high and sentences can be severe.

Can you trust ransomware sellers on dark web forums?

No. Many ransomware listings on dark web forums are scams where the seller takes payment and disappears or delivers broken malware. Even if the ransomware works, the seller may withhold decryption keys or sell the same tool to multiple buyers. Trust is low in criminal markets, and there is no recourse if a transaction goes wrong. Law enforcement also operates honeypots that pose as sellers to identify buyers.

What happened to Goliath ransomware after the sale?

The Goliath ransomware listing disappeared from the forum within weeks of being posted in September 2022. It is unclear whether it sold out, was removed by moderators or turned out to be a scam. Goliath did not become a widely reported strain in subsequent attacks, suggesting it was either a minor operation or never functioned as advertised. The uncertainty is typical of dark web marketplaces where exit scams and false advertising are common.

what is ransomware as a serviceraas ransomware as a serviceransomware as a service groupsbuy ransomware as a serviceransomware affiliate programsransomware business modeldark web ransomware salesransomware encryption malware