Ransomware and Ransomware Extortion Demands
Ransomware is malware that encrypts files, blocking access and demanding a payment to restore them. It is an increasingly popular criminal business model with annual ransomware-induced costs predicted to exceed $265 billion in 2031. New strains and variants continuously emerge, targeting both individuals and large organizations. Techniques are evolving to get around traditional defenses, and cybercriminal gangs compete to lead the market.
Cybersecurity researchers have documented thousands of unique ransomware variants, or “families,” with each displaying its own unique code signature and functions. The ransomware extortion demands are often in hard-to-trace digital currencies, including Bitcoin, making it difficult for law enforcement to track payments and punish attackers.
Once ransomware downloads, it scans local and network storage systems for targeted file extensions to encrypt. Attackers then rename files with new extensions and delete originals to avoid detection by signature-based antivirus tools. Behavioral signatures in modern endpoint detection and response (EDR) platforms recognize these behaviors, alerting responders to suspicious activity.
The most sophisticated ransomware attacks exploit vulnerabilities in widely used software, exposing a wide range of downstream organizations to the same threat. One example, REvil (also known as Sodinokibi), compromised Kaseya’s VSA remote management software in July 2021, encrypting 1,500 downstream businesses and demanding a $70 million ransom.
Ransomware extortion demands are increasing as criminals evolve their tactics. Advanced gangs publish victim-shaming sites with countdown timers, sample stolen data, and press release templates that maximize reputational damage. Others target regulated industries to weaponize regulatory compliance deadlines in ransom negotiations. And the newest double-extortion attacks use stolen data to pressure victims by threatening to publicly expose it online.