0PricingLogin
Cyber Security Academy · Lesson

How Ransomware Works

Encryption, extortion and double-extortion.

What Ransomware Is

Ransomware is malware that denies access to data or systems, typically by encrypting files, then demands payment for restoration. Modern campaigns are run by organized criminal enterprises with affiliates, support desks, and negotiation playbooks.

Understanding the mechanics defensively, not to build it, lets you break the attack chain at multiple points.

The Attack Lifecycle

Ransomware rarely encrypts the instant it lands. It follows a chain you can interrupt:

  • Initial access — phishing, exposed RDP, vulnerable VPN
  • Foothold and persistence — backdoor, scheduled task
  • Privilege escalation and lateral movement — spreading to more hosts
  • Discovery and exfiltration — finding and stealing data
  • Impact — mass encryption and ransom note

Detection during the early dwell time is far cheaper than recovery after encryption.

All lessons in this course

  1. How Ransomware Works
  2. Prevention and Hardening
  3. Detection and Early Indicators
  4. Incident Response and Recovery
← Back to Cyber Security Academy