Ransomware
Ransomware locks a company's data and demands payment to release it. The ransom is asked in cryptocurrency because it makes the money harder to follow — which is exactly why attackers use it.
Term
description · examples · notesRansomware locks a company's data and demands payment to release it. The ransom is asked in cryptocurrency because it makes the money harder to follow — which is exactly why attackers use it.
Description
The locking is only part of the problem. Before encrypting the files, the attacker takes copies of the data and threatens to publish them if nothing is paid — double extortion. Some ransomware groups sell their whole operation to affiliates as a package (ransomware as a service), so attacks are now run by people with no particular technical skill. There are many of them, and they are no less dangerous.
What follows is not a technical fault but a standstill that lasts for weeks. Hospitals lose access to records and to their operating schedule and divert patients, factories stop, municipalities cannot serve citizens — it ends the same way everywhere. A ransomware attack can also close a company down, under lawsuits and a ruined reputation.
Examples
- The power distribution company is locked, a ransom demand is posted, everything stops: emergency callouts, contact with customers, routine work, billing.
- Ransomware inside a routine update from a software vendor — the whole supply chain is hit.
- Internal company documents on leak sites, because the ransom went unpaid.
- A production line stands still because the control computers are unusable.
Notes
- A backup sitting on the same server or in the same cloud is not protection. Ransomware locks that too. Restores are tested before the incident, not after.
- Paying the ransom guarantees neither a working key nor that the data stops circulating on the dark web. It guarantees one thing only — funding the attack on the next victim.
Mentioned in the news
- 21. JUL 2026. Obrisan rumunski RGZ →
- 5. JUL 2026. AI izveo ceo ransomver napad sam — a otkup tražio sa bitkoin adresom iz udžbenika →
- 22. JUN 2026. Prinz Eugen ransomver prvo zaključava ono što najviše boli →
- 19. JUN 2026. Ransomver banda Gentlemen svoje saradnike snabdeva sa alatima za gašenje naprednih mehanizama zaštite →
- 16. JUN 2026. Ransomver tržište u fazi rasta, sa novim i starim igračima →
- 22. MAJ 2026. Ransomware WantToCry ne probija zaštitu, loguje se sa ključem — dovoljni su izložen SMB i slaba lozinka →
- 5. MAJ 2026. Dvojica stručnjaka za sajber bezbednost osuđena zbog BlackCat napada →
- 5. MAJ 2026. Bivši ransomware pregovarači osuđeni zbog BlackCat napada →
- 24. APR 2026. Trigona koristi novi alat za krađu podataka u ransomware napadima →
- 24. APR 2026. Kyber ransomware cilja Windows i VMware ESXi sisteme →
- 21. APR 2026. Bivši ransomware pregovarač priznao ulogu u BlackCat napadima →
- 20. APR 2026. Ransom note ne otkriva kako zaista radi ransomware industrija →
- 19. APR 2026. Payouts King koristi QEMU virtuelne mašine da zaobiđe endpoint zaštitu →
- 16. APR 2026. Ransomware pogodio Autovistu i poremetio usluge u Evropi i Australiji →
- 15. APR 2026. Storm-1175 koristi zero-day i N-day propuste za brzu isporuku Medusa ransomware-a →
- 15. APR 2026. Nemačka policija identifikovala vođe REvil i GandCrab ransomware grupa →
- 4. APR 2026. Nemačka stranka Die Linke potvrdila krađu podataka u Qilin ransomware napadu →
- 29. MAR 2026. Bearlyfy pogađa ruske firme sopstvenim GenieLocker ransomwareom →
- 28. MAR 2026. Pay2Key ransomware za Linux cilja servere i hostove za virtuelizaciju →
- 23. MAR 2026. Otpornost na ransomware je pitanje opstanka biznisa →
- 23. MAR 2026. LockBit 5.0 zahvata celu infrastrukturu →
- 21. MAR 2026. Otvoren server Beast ransomware grupe otkrio njihove alate i fokus na uništavanje bekapa →
- 13. MAR 2026. INC ransomver koristi PowerShell i PsExec za krađu podataka prije enkripcije →
- 5. MAR 2026. Ruski operater ransomvera priznao krivicu pred sudom u SAD →
- 5. MAR 2026. Šta je ransomver i kako se zaštititi od njega →
- 4. MAR 2026. Ransomver grupe sve više koriste krađu identiteta i AI alate →
- 27. FEB 2026. Marquis tuži SonicWall zbog kompromitovanog backup sistema i ransomver napada →
- 24. FEB 2026. Lazarus grupa koristi Medusa ransomver u novoj kampanji →
- 21. FEB 2026. Advantest pogođen ransomver napadom →
- 19. FEB 2026. Ukrajinski državljanin osuđen na 5 godina zatvora zbog sajber kriminala →
- 19. FEB 2026. Univerzitetski medicinski centar u Misisipiju zatvorio klinike nakon ransomver napada →
- 18. FEB 2026. Poljska uhapsila osumnjičenog povezanog sa Phobos ransomver operacijom →
- 18. FEB 2026. Zašto ransomver i dalje ostaje dominantna pretnja →
- 18. FEB 2026. Ranjivi firewall uređaji korišćeni kao ulazna tačka za ransomver napade →
- 13. FEB 2026. Zlonamerna virtuelna mašina cilja VMware vSphere okruženja →
- 12. FEB 2026. Reynolds ransomver koristi BYOVD tehniku za zaobilaženje zaštite →
- 12. FEB 2026. Cephalus ransomver cilja javno izložene RDP servise →
- 7. FEB 2026. Proizvodni sektor pod rastućim pritiskom ransomware napada →
- 4. FEB 2026. CISA: ransomver grupe aktivno koriste VMware ESXi sandbox escape ranjivost →
- 23. JAN 2026. Rumunski operater naftovoda pogođen Qilin ransomware napadom →
- 18. JAN 2026. BridgePay potvrdio da iza višednevnog prekida stoji ransomver napad →
- 3. JUL 2026. FortiBleed prelazi sa krađe na monetizaciju →
- 25. JUN 2026. Tata Electronics potvrdio napad, World Leaks objavio navodne podatke iz proizvodnje Apple uređaja →
- 25. JUN 2026. Ransomver vežba nije samo tehnički zadatak →
- 22. JUN 2026. Šta nam 22.000 incidenata govori o našoj spremnosti za sajber napade i eventualna curenja podataka →
- 7. MAJ 2026. Zašto backup često ne preživi ransomware napad →
- 5. MAJ 2026. Skoro polovina firmi u UK pogođena sajber napadima ili curenjem podataka →
- 30. APR 2026. Europol IOCTA 2026: AI, enkripcija i proxy servisi šire sajber kriminal →
- 28. APR 2026. Phishing ponovo glavni način početnog upada, navodi Cisco →
- 22. APR 2026. SystemBC otkrio više od 1.570 žrtava povezanih sa Gentlemen ransomware grupom →
Techniques
carried out with 17Techniques used to carry it out. Select one to open its page.
- Exploitation→
- Data Exfiltration→
- Malware Delivery→
- Lateral Movement→
- Command & Control→
- Impair Defenses→
- Double Extortion→
- Automation & Scripting→
- Encrypted C2 Channels→
- Living off the Land→
- Payload Obfuscation→
- In-Memory Execution→
- Data Destruction→
- Indicator Removal→
- Log Tampering→
- Fast-Flux DNS→
- Domain Fronting→
Defenses
countered by 18How it is defended against. Select one to open its page.