Ranion is a low-barrier Ransomware-as-a-Service (RaaS) group targeting small businesses.
Analyst brief
Ranion is a ransomware-as-a-service (RaaS) threat actor active since April 2017, operating a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments. It primarily targets small businesses and individual users with weaker defenses, offering attack packages ranging from $150 to $1,900. Key TTPs include a standard ransomware attack chain involving initial access via common vectors (like phishing or RDP), lateral movement, data encryption, and C2 communication using readily available tools. Defenders should prioritize strengthening access controls, ensuring regular offline backups, and monitoring for phishing campaigns and exposed RDP services used for initial entry.
ranion
crime
Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments, with packages ranging from $150 to $1,900, making it a popular entry point for less experienced attackers.