Ransomware comes in many forms, but its consequences are always serious. An infection can block access to a computer or encrypt company data. Criminals then demand a ransom, sometimes threatening to publish stolen files. Paying does not guarantee recovery and may finance another attack.
How does ransomware spread?
Scareware
Scareware displays fake error messages and pretends to be technical support or security software. It claims that the device is infected and pressures the user to buy a program that will supposedly restore it.
Lockers
A locker blocks access to the computer or operating system. A full-screen message may impersonate the police and claim that illegal activity was detected, demanding payment to unlock the device.
Crypto-malware
Crypto-malware encrypts files and demands money in exchange for a decryption key. Even if the victim pays, the files may not be returned. Standard security software cannot decrypt data that has been encrypted by an attacker.
Doxware
Doxware copies confidential files to the criminal’s server and threatens to publish them unless the victim pays. This creates both a ransomware incident and a data-breach risk.
Phishing and malicious email
Many ransomware attacks begin with an email containing a link or infected attachment. Once the victim opens it, the malware can encrypt local and network files and display payment instructions, often requesting cryptocurrency.
Remote Desktop Protocol
Criminals exploit vulnerabilities in RDP software or use stolen credentials to gain remote access and deploy ransomware.
Managed service providers and RMM software
Managed service providers remotely administer their clients’ infrastructure. If an attacker compromises an MSP or its remote monitoring and management software, the infection can spread to multiple customers.
Malvertising
Malvertising distributes malware through online advertisements. Criminals may place ads on reputable websites so that the campaign appears trustworthy. A click redirects the victim to a malicious site.
P2P networks
Illegal copies of software, films and music distributed through peer-to-peer networks may contain ransomware. The infection begins when the victim downloads and opens the file.
Browsers and Wi-Fi
Attackers can exploit browser vulnerabilities, network services and specially prepared websites. Some ransomware can spread across systems connected to the same wireless network.
Examples of ransomware attacks
PC Cyborg
Also known as AIDS, this Trojan is considered one of the earliest ransomware examples. It was distributed on floppy disks containing a survey program and displayed a ransom demand after infecting the system.
CryptoLocker
CryptoLocker spread mainly through email, encrypted files and displayed a ransom demand. FBI estimates put the losses suffered by large organizations at around USD 100 million.
WannaCry
WannaCry infected more than 300,000 devices in almost 100 countries by exploiting a vulnerability in a system protocol. It encrypted files and demanded Bitcoin.
Petya
Petya was initially delivered as an email attachment presented as a job applicant’s CV. It overwrote the master boot record and encrypted the main file tables instead of simply encrypting individual files.
NotPetya
NotPetya used the same exploit as WannaCry, spread across local networks and behaved more like a wiper than ordinary ransomware. Even paying the ransom could not restore the disk. Global losses were estimated at USD 10 billion.
ISS World
In 2020, a ransomware incident disrupted the IT infrastructure of ISS World. Hundreds of thousands of employees lost access to the intranet and email, and the company estimated losses of up to USD 112 million.
BlackCat
BlackCat is a ransomware-as-a-service model based on affiliates. Third parties deploy the malware, which makes attribution and detection more difficult.
How to protect yourself against ransomware attacks
Start with continuous employee education and realistic phishing simulations. Maintain reliable backups, test that they can be restored and keep at least one copy isolated from the production network. Combine this with timely patching, multi-factor authentication, least-privilege access and an incident-response plan. Preparation is what makes it possible to restore operations without relying on the criminal’s promise.

