• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Ransomware

Also known as: File-Encrypting Malware, Crypto-Ransomware, Screen Locker, Locker Malware, Extortion Malware

COMPROMISE

Malware that encrypts victim's files or locks their device, demanding payment (typically cryptocurrency) to restore access. Consumer infections usually arrive via phishing emails, malicious downloads, or malvertising.

Common attack flows

How it fits in a scam

This technique shows up duringCOMPROMISE

Before

  • Phishing EmailDELIVERY
  • SmishingDELIVERY
  • MalvertisingDELIVERY
  • Poisoned SoftwareDELIVERY
  • +3 more

After

  • ExtortionMONETIZATION

Defense

How to defend against this

How to spot it

  • Ransom message or lock screen suddenly appears demanding payment
  • Files renamed with unfamiliar extensions like .encrypted or .locked or .crypted
  • Unable to open documents photos or other personal files
  • System running unusually slow before lockout
  • Antivirus disabled or uninstalled without your action
  • Text files appearing in folders with ransom instructions like README.txt or DECRYPT_INSTRUCTIONS

Tools you can use

  • Software UpdatesCost low · Effect high
  • Data BackupCost low · Effect high
  • Antivirus SoftwareCost low · Effect medium

Further reading

  • Malwarebytes

    Comprehensive ransomware guide for consumers

  • CISA StopRansomware

    Federal ransomware resources and reporting

Related techniques

Variants

  • Malware

Same stage

  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Malicious App Installation
  • +8 more

Similar defense

  • Remote Access Tool
  • Tech Support Scam
  • Malvertising
  • Poisoned Software
  • Crypto Wallet Drain
  • +3 more