Produced in association with SafeHorizon, the Horizon Europe project on detecting and disrupting crime-as-a-service, in which Scorechain is the blockchain-analytics partner.
Ransomware stopped being a lone-hacker problem years ago. Today it is a service industry, with developers renting out malware, affiliates running the attacks, and a supply chain of launderers moving the proceeds. That industrialisation is what makes ransomware-as-a-service so scalable, and it is also its weak point, because almost every ransom is paid in cryptocurrency, and every one of those payments is recorded on a public ledger. Blockchain intelligence turns that record into leads, and law-enforcement collaboration turns leads into disruption.
Ransomware-as-a-service (RaaS) is a business model in which ransomware developers lease their malware and infrastructure to affiliates, who carry out attacks and share the proceeds. The developer maintains the code, the leak site, and the payment infrastructure; the affiliate breaches victims and deploys the ransomware. Payment is almost always demanded in cryptocurrency, and revenue is split between the parties, often on a percentage basis.
This division of labour is why ransomware scaled. An attacker no longer needs to write malware, only to rent it, which widens the pool of offenders and turns ransomware into a repeatable, franchised operation rather than a one-off crime. Most modern RaaS operations now use double extortion, encrypting a victim's data and also threatening to leak it on a public site unless the ransom is paid, which keeps pressure on even when the victim has clean backups.
Ransomware runs on cryptocurrency because it needs a payment method that is fast, cross-border, and does not depend on a bank that could freeze the transfer. That reliance is also the investigator's opening: every ransom leaves a permanent on-chain trail from the victim's payment to the operator's wallets, which is why the payment rail is the most traceable part of the whole operation.
The scale is significant and documented by public bodies. In its targeted report on decentralised finance, published July 21, 2026, the Financial Action Task Force (FATF) identified ransomware operators among the criminal actors exploiting permissionless access and transaction anonymity across crypto and decentralised finance. The same public ledger that enables those payments also records them, and reporting from law-enforcement and cyber agencies points to a widening gap between the number of attacks and the number of victims who actually pay, in part because tracing and enforcement have raised the cost of cashing out.
Blockchain intelligence disrupts RaaS by turning the ransom payment into a thread that unwinds the whole operation. Starting from the payment address a victim was given, investigators can expand outward and map the actors behind it. The main techniques are:
None of this decrypts a victim's files, and it does not undo an attack. What it does is convert an anonymous demand into attributable evidence, and repeated tracing across cases links affiliates to the operators they work for, which is how a whole RaaS programme, not just one affiliate, becomes a target.
Paying a ransom is not automatically illegal, but it can breach sanctions law, and that risk is now central to any ransomware response. Several ransomware operators, and the mixers they use to launder proceeds, have been designated by authorities including the US Office of Foreign Assets Control (OFAC) and sanctioning bodies in the EU and UK. A payment that reaches a designated entity can expose the victim, and anyone who facilitates the payment, to sanctions liability regardless of intent.
This is where screening becomes essential rather than optional. Before any payment is even considered, the destination and its on-chain counterparties should be screened against current sanctions lists, and the exposure documented. Blockchain intelligence is what makes that check possible in the moment, and it is why sanctions screening and ransomware response are now inseparable. This is general information, not legal advice; sanctions obligations vary by jurisdiction and should be assessed with counsel.
No single organisation sees the whole ransomware picture, which is why disruption depends on collaboration. A victim's payment sits with one firm, the exchange KYC record with another, the malware infrastructure with a national CERT, and the seizure powers with law enforcement. Only by pooling on-chain intelligence with off-chain evidence across these parties does a full case come together.
The most effective recent actions against ransomware, takedowns of leak sites, seizures of wallets, and arrests of affiliates, have been coordinated operations that combined blockchain analytics providers, exchanges, national police, and international bodies such as Europol. Public-private collaboration is not a nicety here; it is the mechanism. Blockchain intelligence supplies the shared, verifiable layer that lets these parties work from the same facts, and structured cooperation frameworks turn that shared picture into synchronised enforcement.
Scorechain gives investigators and compliance teams the tooling to trace ransomware proceeds and screen for sanctioned counterparties in one workflow. Scorechain Investigator follows a ransom payment across swaps, bridges, decentralised exchanges, and mixers on multiple blockchains, clusters the addresses an operator or affiliate controls, and matches them against a database of more than 1 million labelled on-chain entities, all on Scorechain's Digital Asset Intelligence graph. It takes an analyst from the single payment address a victim was given to a documented case, the wider practice of crypto investigation applied to ransomware.
Wallet Screening checks an address and its counterparties against sanctions lists and known high-risk entities before funds move further, and a transparent, auditable risk score, on a scale of 0 to 100 where a lower score signals higher risk, shows the reasoning behind every rating rather than hiding it in a black box. Flux Analysis visualises the fund flows and indirect exposure that tracing surfaces, and the Blockchain Analytics API feeds that intelligence into an agency's own case-management systems, so the shared, verifiable layer that collaboration depends on is available to every party. Coverage spans 25+ blockchains with 2,800+ VASP entries, giving investigators the cross-chain and counterparty reach ransomware cases demand.
Ransomware became a service to scale itself. The same industrial structure, paid on a public ledger and disrupted through shared intelligence, is what makes it traceable, and increasingly, disruptable.
If your team is building ransomware investigation or AML capability, book a Scorechain demo to see payment tracing, sanctions screening, and cross-chain attribution applied to your own cases.
Ransomware-as-a-service is a business model in which developers lease ransomware and infrastructure to affiliates, who run the attacks and share the proceeds, usually paid in cryptocurrency. The developer maintains the malware, leak site, and payment infrastructure; the affiliate breaches victims. This franchised structure is why ransomware scaled into a repeatable, industrial operation.
Ransomware gangs are almost always paid in cryptocurrency, most often Bitcoin, because it is fast, cross-border, and not dependent on a bank that could block the transfer. The victim sends payment to an address supplied in the ransom note, and proceeds are then split between the affiliate and the developer and laundered through mixers, bridges, and exchanges.
Yes. Every ransom payment is recorded on a public blockchain, so investigators can trace it from the victim's transaction through each hop, cluster the operator's wallets, and follow the funds to a cash-out point. Mixers and bridges raise the difficulty, but blockchain intelligence can often re-establish the trail and attribute it to a named entity.
Paying a ransom is not automatically illegal, but it can breach sanctions law if the payment reaches an entity designated by bodies such as OFAC or EU and UK authorities, and that liability can apply regardless of intent. Because of this, destinations should be screened against sanctions lists before payment. This is general information, not legal advice.
Blockchain intelligence traces ransom payments, clusters the wallets an affiliate or operator controls, attributes them to known entities, and flags sanctions exposure. It converts an anonymous ransom demand into attributable evidence and links affiliates to the operators behind them, so investigators can target a whole ransomware-as-a-service programme rather than a single attack.
Because no single party sees the whole picture. The payment, the exchange KYC record, the malware infrastructure, and the seizure powers sit with different organisations. Collaboration pools on-chain intelligence with off-chain evidence, which is why the most effective takedowns, seizures, and arrests have been coordinated operations between analytics providers, exchanges, and law enforcement.































