Home  ›  Glossary  ›  Crypto Ransomware

What is crypto ransomware?

Crypto ransomware is ransomware that encrypts the contents of files, virtual disks or databases and then demands payment for the decryption key. Servers keep running and most file names stay recognizable, yet the data inside them can no longer be read.

Per-file keys sealed with the attacker's public key

The malware does not invent its own cryptography. It generates a fresh symmetric key for each file or batch of files, encrypts the contents with a fast standard cipher, then seals each of those keys with a public key embedded in the malware. Only the matching private key, which stays on the attacker's side, can unseal them. A captured sample of the malware therefore holds nothing that reverses the damage, and guessing a modern key by brute force is not a realistic option.

Cleaning the infection brings nothing back either. Once the original bytes have been overwritten, removing the malware or reinstalling the server leaves the encrypted files exactly as they were. Readable data returns by one of three routes: the attacker's private key, a coding flaw in that particular variant that lets researchers publish a free decryptor, or a copy of the data the malware never touched. Free decryptors cover only a minority of variants, so for most victims the third route means the backup.

Ransomware encryption speed and partial encryption

Ransomware encryption, the stage of an attack in which data is actually scrambled, usually comes last and runs fast. Many variants encrypt only part of each file, such as the header or one block in every ten, because damaging the structure is enough to make a database, virtual disk or archive unusable. The time saved is large. At a sustained 1 GB/s, fully encrypting 10 TB takes 10,000 seconds, about 2 hours 47 minutes. Encrypting one block in ten cuts that to roughly 17 minutes, and touching only file headers to under 2 minutes.

Speed also decides where the damage lands first. Encrypting the virtual disk files on a hypervisor datastore stops every VM on that host in one pass, a virtualized backup server among them, along with its configuration and catalog. The backup data may survive while the means of reading it does not, and rebuilding that server comes before the first restore can start.

Backup files on SMB shares and NAS repositories

To the malware, a backup file is one more file with an extension it recognizes. A repository on a Windows file share, a NAS mounted over SMB or a local volume on the backup server is reachable by the same process, with the same rights, that is encrypting the file servers. Encryption the backup software applies for confidentiality offers no defense, since an already encrypted file can be encrypted a second time, after which the owner's key no longer opens it.

Gradual encryption damages restore points more quietly. When files are encrypted over several days, nightly incrementals capture the scrambled versions as ordinary changed data, so the newest restore points hold damaged files and the last clean point sits further back than anyone expects. The number of restore points retention keeps decides whether that clean point still exists.

Object storage changes the mechanics. An S3 bucket is not a drive letter that malware can browse from an infected server; it is reached through API requests signed with access keys. If those keys are stolen, writing an encrypted copy over an object in a versioned bucket creates a new version and leaves the previous one in place.

ARTESCA and crypto ransomware

Backup software writes to ARTESCA over the S3 API, so a crypto ransomware process running on a file server finds no share or drive letter on it to encrypt. An attacker who has taken the backup application's keys can still send encrypted copies, and versioning turns each of those writes into a new version stored beside the old one. When the earlier versions carry a compliance-mode S3 Object Lock retention date, they stay readable in their original form until that date passes, whichever account sent the overwrite.

ARTESCA does not stop production servers being encrypted and does not decrypt anything. What it preserves is the pre-attack backup data a restore is built from.