← Back to list

Malware Basics: Ransomware

the fourth article on malware in which we take a quick look at ransomware.

Sam Steers · 2023-03-23 17:20 · 2 claps · 1.9 min read
#ransomware #revil #cybersecurity #hacking #pentest
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Malware Basics: Ransomware

This is the fourth article in our malware basics series, I would recommend you reading our previous articles on Trojans, Worms, and Viruses in addition to this to get a full understanding of malware basics.

Ransomware is malicious software (malware) that restricts access to a victim’s computer until a ransom is received. Ransomware uses a vulnerability in your software to gain access and then encrypts your files.

This type of malware is usually used by the organised crime threat actors as a way of profiting off vulnerabilities within an organisations system. Ransomware attacks can have severe economic and repetitional impacts on victims, as even reluctantly agreeing to the hackers demands can lead to legal penalties further down the line.

A note like below is usually left as a text file when the victim logs (or tries to) the next day. The note will contain details of what has been encrypted and how to get those files back. Usually there is a threat of releasing this sensitive information to the public if the demands are not met.

Hackers tend to want payment in cryptocurrencies like Bitcoin and Monero. Monero is especially popular as the blockchain ledger is completely anonymous. This leads to additional complications as the ransom can sometimes be in the millions for larger organisation who are victims and most crypto exchanges have a cap on how much they’re allowed to lend which leads to even further issues in raising the necessary funds.

Prevention methods:

  • Conduct regular vulnerability scanning
  • Report to law enforcement if you believe you are a victim
  • Make encrypted backups of data on a regular basis
  • Regularly patch and update software and operating systems

A real life example would be the Russian-based cybercrime organisation REvil. This was a private ransomware-as-a-service (RaaS) operation that operated between 2019 and 2021. The group provided a file blocking virus which encrypts files after infection and provided notes to senior people within the target organisation on instructions to pay the hackers in whatever preferred way (usually bitcoin or Monero) to un-encrypt the files, if the victim did not comply their data would be leaked. Notable victims of the RaaS were the Harris Federation and Invenergy, the group also claimed to have used the service on Lady Gaga, Donald Trump in 2020.

Resources:

https://www.cisa.gov/stopransomware#:~:text=Ransomware%20is%20a%20form%20of,ransom%20in%20exchange%20for%20decryption.


메타데이터
post_id
c3ab60f5c052
slug
malware-basics-ransomware-c3ab60f5c052
url
https://medium.com/@samuel.i.steers/malware-basics-ransomware-c3ab60f5c052
canonical_url
https://medium.com/@samuel.i.steers/malware-basics-ransomware-c3ab60f5c052
author_url
https://medium.com/@samuel.i.steers
status
ok
fetched_at
2026-07-25 23:39:52