Home  ›  Glossary  ›  Ransomware

What is ransomware?

Ransomware is malicious software that makes an organization's data or systems unusable, most often by encrypting them, and then demands payment to restore access. Attacks on businesses are run hands-on by people inside the network, and the encryption is the final step of a longer intrusion.

Human-operated attacks that begin days before the ransom note

A business ransomware attack starts with a login, typically through a stolen password, an unpatched VPN appliance or a phishing email. The operator then gathers administrator accounts, maps the servers, hypervisors and backup systems, removes recovery options and often copies data out before launching the encryptor. Most of that work uses the same admin tools the IT team relies on, so little of it stands out. Initial access and the encryption can be weeks apart, and that gap is where both the damage and the chances to stop it accumulate. The ransomware kill chain breaks the sequence into stages.

Many of the people doing this did not write the malware. Under ransomware as a service, a developer leases the encryptor and payment infrastructure to affiliates who carry out the intrusions, which is why two attacks bearing the same ransomware name can look quite different from one victim to the next.

The note left behind names a price, a deadline and a contact channel, usually a chat portal reached through an anonymizing browser, with payment demanded in cryptocurrency. Paying buys a decryption tool and a promise. The tool still has to process every file, often slowly, and the promise covers neither the attacker's remaining access nor any copy of the data already taken.

Crypto, locker and extortion-only variants

  • Crypto ransomware encrypts the contents of files, disks and databases and sells the key back.
  • Locker ransomware locks the screen or the device and leaves stored data intact, so removing the lock ends the problem.
  • Double extortion pairs encryption with theft of data and a threat to publish it.
  • Extortion-only attacks skip the encryptor and rely on the stolen data alone.

The first and third variants leave the organization needing a large restore. The third and fourth leave a confidentiality problem that no backup solves, however recent.

One domain account across production, hypervisor and repository

Many mid-sized environments share a layout that suits day-to-day running and suits an attacker just as well. The backup server is a Windows machine joined to the production domain. The repository is a file share or NAS on the same network. Every virtual machine, the backup server included, runs on one hypervisor cluster. A single domain administrator account reaches all three, so encrypting the datastores takes production and the backup server down together, and deleting the repository removes the restore points the team planned to use. Hypervisor snapshots and array snapshots kept on the systems they protect disappear in the same pass, so they rarely count as a separate copy afterward.

Two facts then set the outcome: whether at least one clean restore point survived, and how long it takes to bring the business back from it. Encrypted production is the expected loss. Lost backups are what turn an outage into a decision about paying, a decision that lands with leadership, legal counsel and the insurer while IT is still counting what is left.

Separate credentials for the backup storage break that single path.

ARTESCA and ransomware

ARTESCA is an S3 backup target for software such as Veeam, Commvault and Rubrik, and it keeps its own accounts outside the production directory, so a domain password taken from production does not sign in to it. A backup held under compliance-mode S3 Object Lock retention survives every account, root included, until its retain-until date.

The limits are just as specific. ARTESCA does not keep ransomware out of production, does not prevent data theft, and does not protect copies written without a lock or whose retention has already run out.