Ransomware
Introduction
Section titled “Introduction”Ransomware encrypts victim’s files and demands payment (typically cryptocurrency) for decryption. Modern variants use double extortion — exfiltrate data first, then threaten public release if ransom isn’t paid. Ransomware-as-a-Service (RaaS) has lowered the skill barrier, enabling affiliates to launch attacks using developer-provided tools.
History
Section titled “History”| Milestone | Year | Details |
|---|---|---|
| AIDS Trojan | 1989 | First ransomware; floppy disk; $189 to Panama |
| GPCode | 2004 | Early crypto-ransomware; RSA-1024 |
| CryptoLocker | 2013 | Game-changer; RSA-2048; C2; $3M+ |
| WannaCry | 2017 | Worm + ransomware; EternalBlue; global |
| NotPetya | 2017 | Wiper disguised as ransomware; $10B+ |
| Ryuk | 2018 | Targeted enterprises; Ryuk/Conti lineage |
| LockBit | 2019+ | RaaS; fast encryption; affiliates |
| Cl0p | 2019+ | Double extortion; MOVEit 2023 |
How It Works
Section titled “How It Works”1. INITIAL ACCESS └─ Phishing, RDP brute-force, exploit, IAB
2. RECONNAISSANCE & LATERAL MOVEMENT └─ AD enumeration, credential theft, AD compromise
4. DATA EXFILTRATION (Double Extortion) └─ Steal sensitive data → threat to publish
5. ENCRYPTION └─ AES-256 + RSA; delete shadows, kill processes
5. RANSOM NOTE └─ Payment instructions; Tor site; countdown timer
6. PAYMENT & DECRYPTION (maybe) └─ BTC/XMR payment → decryptor (no guarantee)Notable Families
Section titled “Notable Families”| Family | Year | Model | Notable |
|---|---|---|---|
| CryptoLocker | 2013 | Single | RSA-2048, $3M |
| WannaCry | 2017 | Worm | EternalBlue, global |
| NotPetya | 2017 | Wiper | $10B damage |
| Ryuk/Conti | 2018+ | Targeted | Hospitals, municipalities |
| LockBit | 2019+ | RaaS | Fastest encryptor |
| BlackCat/ALPHV | 2021+ | RaaS | Rust, Rust |
| Cl0p | 2019+ | Double ext | MOVEit 2023 |
| Akira | 2023+ | RaaS | ESXi targeting |
Prevention
Section titled “Prevention”- ✅ Offline, tested backups (3-2-1 rule)
- ✅ Patch RDP / VPN / internet-facing services
- ✅ MFA everywhere — especially VPN/RDP
- ✅ Network segmentation — limit lateral movement
- ✅ Application whitelisting / EDR
- ✅ Phishing-resistant MFA (FIDO2)
- ✅ Incident response plan + tabletop exercises
- ✅ Do not pay — no guarantee; funds crime
MITRE ATT&CK
Section titled “MITRE ATT&CK”| Technique | ID | Description |
|---|---|---|
| Data Encrypted for Impact | T1486 | File encryption |
| Inhibit System Recovery | T1490 | Delete shadow copies |
| Exfiltration Over C2 | T1041 | Data theft for double extortion |
Related
Section titled “Related”- Wiper Malware — Destruction without ransom
- Botnet — Delivery vector
- Supply-Chain — Software supply chain