Malware

Ransomware

Ransomware is malware that encrypts your files, or steals them and threatens to publish, then demands payment. Backups you cannot reach or trust are what turn it from an incident into a crisis.

How it is measured

Signs: many files renamed with a new extension, a ransom note in each folder, spikes in disk writes and CPU, shadow copies deleted, and security tools disabled. Count affected hosts and shares, and find the earliest encrypted file's modification time.

Establish scope before you act: which machines, which accounts, which backups were reachable from the infected host. Modern crews often copy data out first, so check outbound transfer volume in the days before encryption.

Worked example

A dental office server shows .locked files on the shared patient-scans drive at 06:50 Monday. README_RESTORE.txt demands 0.8 bitcoin. The backup NAS is mapped as a drive letter on the same server, and its last nine nightly backups are also .locked.

The offsite cloud copy, written by a separate account with versioning on, still holds Friday's clean state. The office restores from it onto rebuilt machines. A firewall log shows 14 GB left to an unknown host on Saturday night, which means a breach notification as well as a restore.

How it differs

Malware is any hostile software. Ransomware is the kind whose business model is extortion: your files, or the secrecy of your data, for payment. A trojan that steals passwords is malware that asks you for nothing; ransomware announces itself.

Common errors

Paying before checking whether a clean backup exists. Keeping backups on a mounted share the infected host can write to. Restoring onto machines that still hold the attacker's access. Skipping the question of stolen data. Wiping evidence before finding the entry point, often an exposed remote desktop or a stolen VPN login.

In practice

This week, test a full restore from a backup the production network cannot modify, such as immutable or offline storage. Close or protect remote access, require MFA on admin and VPN accounts, and write down who you call first. For a web host, keep database dumps off the server.

See also

Malware, Payload

Sources

Count this on a real site.

Watch my website