What is Ransomware and How Does it Affect Your Organization?
Ransomware is malware that encrypts files on an infected system, blocking access to critical information until a fee is paid. Cybercriminals extort money in the form of cryptocurrency, such as Bitcoin, to unlock the data. These attacks can have significant financial and operational impacts for organizations.
Criminals spread ransomware through a variety of channels, including digital marketplaces on the dark web and by recruiting affiliates. They then deploy the malware through a botnet to infect computers and networks. A botnet is a collection of hijacked computers that run malicious code and can evade network security, allowing the attacker to control and manipulate them.
Early ransomware strains opportunistically infect systems and encrypt files. As the attacks gained popularity, cybercriminals developed more sophisticated techniques and tactics. They analyzed the value of each victim’s data and targeted specific sectors that would be most lucrative, such as hospitals and retailers. Using multiple attack vectors, they flooded systems with emails and sound, video, or image downloads containing ransomware payloads.
When victims click on these downloads, they infect their systems with the malware. Once the malware has infected a system, it scans local and network drives for files with a specific extension and encrypts them with an asymmetric key that only the attacker has, or a symmetric key that is unique to the individual file.
Some recent ransomware variants have included “wiper” capabilities, preventing system restores even after paying the demanded sum. Examples include NotPetya, Ryuk, and Fusob, which can disable backup files and system recovery features on infected devices.