Skip to content
ransomware

File:Metropolitan_Police_ransomware_scam.jpg · Wikimedia Commons · See Wikimedia Commons

EntityQ926331· pop 64· linked from 1,652 articles

ransomware

Sign in to save

Also known as ransom software, denial-of-access attack

Ransomware is a type of malware that encrypts the victim's personal data until a ransom is paid. Difficult-to-trace digital currencies such as paysafecard or Bitcoin and other cryptocurrencies are commonly used for the ransoms, making tracing and prosecuting the perpetrators difficult. Sometimes the original files can be retrieved without paying the ransom due to implementation mistakes, leaked cryptographic keys or a complete lack of encryption in the ransomware.

AI overview

Ransomware is malware that locks up your personal data by encrypting it, with criminals demanding payment to restore your access. It matters because attackers use hard-to-trace digital currencies like Bitcoin to collect ransoms, which makes it difficult for law enforcement to catch them, though sometimes victims can recover their files without paying if the criminals make mistakes.

AI-generated from the Wikipedia summary — may contain errors.

~47 min read

Encyclopedic overview

32 sections
Contents
  • Operation
  • History
  • Encrypting ransomware
  • Non-encrypting ransomware
  • Exfiltration (Leakware / Doxware){{Anchor|Leakware (also called Doxware)|Leakware|Doxware|Exfiltration}}
  • Mobile ransomware
  • Progression of attacks
  • Notable attack targets
  • Notable software packages
  • Reveton
  • CryptoLocker
  • CryptoLocker.F and TorrentLocker
  • CryptoWall
  • Fusob
  • WannaCry
  • Petya
  • Bad Rabbit
  • SamSam
  • DarkSide
  • Syskey
  • Ransomware-as-a-service
  • Mitigation
  • Sector-specific regulatory responses
  • File system defenses against ransomware
  • File decryption and recovery
  • Criminal arrests and convictions
  • Zain Qaiser
  • Legal aspects
  • See also
  • References
  • Further reading
  • External links

Ransomware is a type of malware that encrypts the victim's personal data until a ransom is paid. Difficult-to-trace digital currencies such as paysafecard or Bitcoin and other cryptocurrencies are commonly used for the ransoms, making tracing and prosecuting the perpetrators difficult. Sometimes the original files can be retrieved without paying the ransom due to implementation mistakes, leaked cryptographic keys or a complete lack of encryption in the ransomware.

Ransomware attacks are typically carried out using a Trojan disguised as a legitimate file that the user is tricked into downloading or opening when it arrives as an email attachment. However, one high-profile example, the WannaCry worm, traveled automatically between computers without user interaction.

Excerpted from Wikipedia’s “ransomware” article, available under the CC BY-SA 4.0 licence.

Gallery (3)