Ransomware
Quick answer
Ransomware is malicious software that encrypts a victim's files and demands payment for the key, often combined with a threat to publish stolen copies. The outcome is decided less by detection than by whether a separate, unreachable copy of the data exists.
The mechanism is ordinary cryptography used against its owner. The program generates or receives a key, encrypts documents, photographs, databases and backups it can reach, deletes or overwrites the originals, and leaves instructions for payment. Properly implemented, the encryption cannot be reversed without the key — this is not a flaw to be worked around but the same mathematics that protects legitimate data.
Two further elements are now routine. The first is extortion based on copying: data is taken before encryption, so paying for decryption does nothing about publication. The second is deliberate destruction of recovery options — connected backup drives, snapshots and shadow copies are targeted early, because the operators understand that a restorable victim does not pay.
How it typically arrives
- Credential abuse
- Logging in with a working username and password, obtained by phishing, bought from a breach, or guessed where the same password was reused. Remote access services exposed to the internet are a frequent entry point.
- Unpatched software
- Exploitation of a known flaw in software reachable from outside. No user action is involved, which is why update discipline is a security control rather than maintenance.
- Malicious attachments and downloads
- A file opened by a person, often a document that runs a script, which then fetches the actual payload. This is the path on which scanners have the most to contribute.
- Compromise of a supplier
- Access gained through a managed service provider or a software update channel, affecting every downstream customer at once.
What detection contributes, and where it ends
Modern products treat ransomware as a specific behavioural problem, described in behavioural detection. Rapid sequential access to many files, writing high-entropy data over them, deleting shadow copies, and enumerating network shares are all monitored patterns, and some products protect designated folders so that only approved applications may write to them.
These measures work, and they are not sufficient on their own. Detection has to be correct the first time and fast enough to interrupt a process designed to finish quickly. Where the attacker has valid credentials and is operating interactively, much of the activity resembles legitimate administration. Where encryption completes, detection has no further contribution: the files are encrypted and remain so.
The rule that follows from this
Recovery capability is decided before an incident, not during one. A backup that was connected and writable at the moment of the attack should be assumed encrypted. See cloud backup for what makes a copy survivable.
On paying
Payment is a decision with legal, financial and practical dimensions, and this entry does not advise on it. What can be stated factually is that payment does not guarantee a working key, does not undo copying of data, and may raise obligations in Australia — including reporting duties that apply to certain businesses in relation to ransomware payments. Any organisation facing this decision should take legal advice and consult the current guidance published by the Australian Cyber Security Centre at cyber.gov.au, which also sets out what the ACSC can assist with.
Where personal information has been accessed, the Notifiable Data Breaches scheme may require notification to affected individuals and to the Office of the Australian Information Commissioner. The scheme and the assessment process are described at oaic.gov.au.
What reduces exposure
| Stage | Measure | What it addresses |
|---|---|---|
| Entry | Multi-factor authentication on remote access and email | Stolen or reused passwords |
| Entry | Prompt patching of internet-facing software | Exploitation without user action |
| Execution | Behavioural monitoring and protected folders | Payloads that run on the device |
| Spread | Separate administrator accounts, limited shares | Reach across a network |
| Recovery | Offline or immutable backup, tested by restoring | Everything the earlier rows missed |
| Aftermath | Written response steps and contact list | Delay and improvisation under pressure |
The last row is cheaper than any of the others and is the one most often skipped. Knowing in advance who disconnects what, who is called, and where the backup credentials are kept removes hours from a response in which hours matter.
Recognising it early
Encryption in progress is not silent, and the signs are mechanical rather than dramatic. Files acquire an unfamiliar extension or stop opening in the applications that created them. Folders gain a text or HTML file with payment instructions, usually repeated in every directory touched. The device becomes unusually busy for no reason the user initiated, and a network drive becomes slow as it is read and rewritten.
Where the files appear encrypted but no payment demand exists, the cause may be something other than ransomware — a failed drive, a damaged file system, or an encryption tool enabled and then forgotten. The distinction matters, because the responses are completely different and because recovery from a hardware failure becomes less likely the more the drive is used.
For households rather than organisations
Most of the above is framed for networks, because that is where ransomware operators concentrate. A household device faces a reduced version of the same problem: the files at risk are photographs, documents and tax records, and the recovery question is identical. A copy of what cannot be replaced, kept somewhere the device cannot silently overwrite, answers it. An external drive connected only while copying is sufficient; so is a versioned online service.
The second consideration for a household is the account rather than the device. Where photographs and documents live in an online service, an attacker with the password can delete them without any encryption at all, which makes the measures in password managers part of the same problem.
Key terms on this page
- Encryption
- Transforming data so it can only be read with the correct key.
- Double extortion
- Combining encryption with a threat to publish data copied beforehand.
- Shadow copy
- A point-in-time snapshot kept by the operating system, commonly deleted by ransomware.
- Immutable backup
- A stored copy that cannot be altered or deleted for a defined period, even with valid credentials.