What is Ransomware
Malware that encrypts data for extortion
Ransomware is a type of malicious software that encrypts a victim's files or locks system access, demanding a ransom payment for restoration.
How Ransomware Works
Ransomware infiltrates systems through phishing emails, software vulnerabilities, or infected websites. Once activated, it encrypts data and displays a ransom message, typically demanding cryptocurrency payment.
Types of Ransomware
- Crypto-ransomware — encrypts files on the device
- Locker-ransomware — locks system access
- Double extortion — encrypts and threatens to publish data
- RaaS — Ransomware as a Service
Distribution Methods
- Phishing emails
- Malicious attachments and links
- Exploitation of vulnerabilities
- RDP attacks
- Infected USB drives
Protection Methods
- Regular data backups
- Software updates
- Employee cybersecurity training
- Antivirus protection and EDR
- Network segmentation