Ransomware

Ransomware

Erpressungssoftware

Ransomware is malware that encrypts data or locks systems and demands a ransom for their release. It is among the most consequential threats to companies because it paralyses operations immediately. Modern variants combine the encryption with the theft and the threat of publishing the data.

History & facts. From simple encryption malware, a division-of-labour business model has emerged — up to „ransomware as a service“, in which specialised groups rent out their tools. Double extortion is widespread: data is stolen before encryption, so that even a good backup does not eliminate the publication risk. The actual encryption is usually preceded by a longer, unnoticed phase — initial access, privilege escalation, lateral movement — in which an attack could still be stopped.

Outlook & recommendation. Backups remain indispensable but must be separated from the production network and verifiably restorable in an emergency — otherwise they are encrypted along with everything else. The key is to detect the quiet preliminary phase rather than reacting only to the loud moment of encryption: this is precisely where end-to-end visibility and operated detection (Managed Detection and Response (MDR)/Security Operations Center (SOC)) pay off. Ransom payments are discouraged; a prepared emergency plan and rehearsed recovery are the more robust answer.

Ransomware — Ransomware