Critical severity Malware

Ransomware

Files are encrypted and payment is demanded for the key, usually in cryptocurrency.

Overview

Modern ransomware is a full intrusion, not a single file: the operator moves laterally, escalates, exfiltrates data, then deploys the encryptor across every reachable host simultaneously.\nDouble extortion publishes the data if the ransom is not paid, and affiliates split the proceeds with the developer.\nOffline, immutable backups and EDR coverage are what actually end the incident.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Ransom note files appearing in bulk
  • vssadmin deleting shadow copies
  • Large outbound transfers before encryption begins

Controls that stop it

  • Keep Tested, Offline Backups

    Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used