Ransomware
Definition
Malware that encrypts a victim's files and demands ransom (typically in crypto) for the decryption key. Organised criminal business model.
Modern playbook: Ransomware-as-a-Service (RaaS) — a core team builds the malware and infrastructure, affiliates deploy it for a cut of the ransom. Brands: LockBit, BlackCat/ALPHV, Cl0p, Akira, Play.
Critical evolution: double extortion (encryption + exfil with public publication on data leak sites if you don't pay), triple extortion (adds DDoS or customer contact), supply-chain (Kaseya, MOVEit) to amplify blast radius.
Entry vectors: phishing with macros, exposed RDP with weak creds, unpatched public vulnerability on perimeter (Fortinet/Ivanti/Citrix), compromised supply chain, initial access broker selling pre-existing access.
Defence: offline backups + tested restore, MFA on everything, fast perimeter patching, behavioural EDR/XDR, network segmentation, documented IR plan.
