History of ransomware
Even though a version of malware that encrypts data has been around since the late 1980s, the current explosion in ransomware coincides with the development of cryptocurrency. This is the ability to anonymously send and receive digital currency that has allowed ransomware threat actors to execute attacks and extract payment from their victims while remaining anonymous. Over the past decade, this type of attack has gone through an evolution in terms of sophistication but has largely remained consistent with some core TTPs, such as an initial infection followed by propagating the ransomware and encrypting a user’s files with the intent to extract payment for the decryption key. We will briefly discuss some of the key variants in this evolution, as seen in the following diagram:
Figure 14.1 – A brief history of ransomware
CryptoLocker
The first ransomware attacks took place between September 2013 and May 2014 and utilized...