What is Ransomware?
Ransomware encrypts your files and demands payment. Learn how it works, how to detect an infection, and how to protect against it.
AI Answer
Ransomware is malware that encrypts a victim's files and demands payment for the decryption key. Protect against it with offline backups, patching, email filtering, and endpoint detection.
Definition
Ransomware is a type of malware that encrypts a victim's data and demands a ransom payment in exchange for the decryption key.
Overview
Ransomware is one of the most financially damaging threats. Attackers encrypt systems and demand payment, often under time pressure.
Common infection vectors
- Phishing emails with malicious attachments or links.
- Remote Desktop Protocol (RDP) exposure with weak credentials.
- Exploited vulnerabilities in internet-facing software.
- Malicious downloads and cracked software.
What happens during an attack
- Initial access is gained.
- Privileges are escalated and lateral movement occurs.
- Data is exfiltrated (double extortion).
- Files are encrypted and a ransom note appears.
Defense
- Maintain offline and immutable backups.
- Patch operating systems and software promptly.
- Enforce strong credentials and MFA on RDP and VPN.
- Use email filtering and endpoint detection & response (EDR).
- Segment networks to limit lateral movement.
If infected
Disconnect affected systems, preserve evidence, do not pay the ransom, and report to authorities.