BotNet News

Your source for Online Security News

Ransomware

Ransomware is malware that encrypts files on a device, rendering them unusable. It demands a ransom payment in order to decrypt the data and unlock the system. Ransomware can disrupt operations, cause business disruptions, and create a financial loss for your organization. Ransomware can spread to devices through phishing, social engineering, and deceptive attachments in emails. Once it is installed on a device, it quickly spreads across your network, encrypting more files and evading EDR (endpoint detection and response) tools.

Attackers typically target businesses, since they are likely to pay higher ransom amounts. Often, attacks start with phishing and social engineering emails, using urgency or authority to bypass scrutiny. Once a victim clicks on an attacker-controlled link, the ransomware enters the system and begins to encrypt files. Many attackers also delete backup and shadow copies to make recovery without the decryption key more difficult.

The first ransomware was documented in 1989, and spread via floppy disks. The malware hid file directories and demanded USD 189 to unhide the data. More advanced forms of ransomware followed, encrypting data in a way that could not be reversed. Columbia University’s Moti Yung and Adam Young coined the term “cryptoviral extortion” in 1996. More recently, a popular ransomware known as Ryuk targeted high-value targets and disabled the system’s backup and restoration capabilities. Other more destructive variants include NotPetya, which destroyed entire systems and demanded a ransom to restore systems.