Log in Sign up
Back to Discover
💻

Ransomware

technology Maturity 11-13 war conflict
This article covers sensitive topics: war_conflict. Parents can manage visibility in Parental Controls.

Bad programs can lock your files.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg
They hide your work. They ask for money to give it back. This is a mean trick. It can happen on computers. Do you use a computer? Be very careful with what you open.

41 words

Bad programs can lock your files.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg
They hide your work. They ask for money to give it back. This is a mean trick. It can happen on computers.

Sometimes people trick you. They send an email with a bad file. If you open it, the program starts. It can lock your computer or your files.

It might show a fake warning. It might say you did something wrong. This is just a way to scare you.

These bad programs want money. They use digital money that is hard to track. This makes it hard to catch them.

Be very careful with what you open. Always check your files first.

110 words

Ransomware is a type of bad software. We call this malware. It locks your files so you cannot use them. The person who sent it asks for money to unlock them. This money is called a ransom.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg

Attackers often use a Trojan to get into a computer. A Trojan is a bad program that hides inside a normal file. You might click it in an email. Once it starts, it uses encryption. Encryption is a way to scramble data so only one key can read it. The malware uses a special key to lock your files. It then asks for payment in digital money like Bitcoin. This kind of money is hard for police to trace.

Some ransomware is just a trick to scare you. It might show a fake warning from the police. It may claim you did something illegal. This is called scareware. Other types are more serious. They truly lock your system. In 2021, there were about 623 million ransomware attacks worldwide. In 2023, ransom payments reached a record $1.25 billion.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg

Caption: A fake warning used to scare people into paying money.

187 words

Ransomware is a type of bad software known as malware. It works by locking a person's files so they cannot be used. The person who sends the malware asks for a ransom to unlock them.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg
This money is often sent using digital currencies like Bitcoin. These currencies are hard for police to trace. Because they are hard to follow, it is difficult to catch the people responsible. Some ransomware is just a trick called scareware. It might show a fake warning from the police to scare you.

Most ransomware attacks happen in a specific way. An attacker often uses a Trojan to get into a computer. A Trojan is a bad program that hides inside a normal file. You might be tricked into opening it as an email attachment. Once inside, the malware uses encryption to scramble your data. Encryption is a way to lock information so only one key can read it. The malware uses a special key to lock your files. It then shows a message asking for payment.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg

The idea of using encryption for this was first studied in 1996. Researchers Adam L. Young and Moti Yung at Columbia University presented this idea. They called it cryptoviral extortion. They were actually inspired by a creature called a facehugger from the movie Alien. This new method was much stronger than older versions. Earlier versions, like the AIDS Trojan from 1989, had big mistakes. In that case, the key could be found easily. This meant people did not actually have to pay the ransom to get their files back.

Since then, these attacks have grown very large. In the first six months of 2018, there were 181.5 million attacks worldwide. That was 229% more than in the same time in 2017. Some specific programs have been very successful at taking money. For example, CryptoLocker took in an estimated US$3 million. Another program called CryptoWall took over US$18 million by June 2015. In 2023, ransom payments reached a record high of $1.25 billion.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg

Today, ransomware affects many different parts of our world. In 2022, Costa Rica had many attacks on its government and hospitals. This was so serious that the President declared a state of emergency. Some attackers even sell this bad software to others like a subscription service. This makes it easier for more people to use it. Even though it is a big problem, law enforcement works hard to stop it. In 2024, ransom payments dropped to $813 million because of these actions.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg

419 words

Ransomware is a dangerous form of malware designed to extort money from victims. It works by locking a person's digital data or computer systems. The attacker demands a ransom payment to restore access to the files.

Metropolitan Police ransomware scam.jpg
Metropolitan Police ransomware scam.jpg
To make the money hard to track, attackers often use cryptocurrencies like Bitcoin. They may also use services like paysafecard or wire transfers. Because these digital currencies are difficult to trace, prosecuting the criminals is a major challenge for law enforcement. While some ransomware simply locks a screen to scare users, the most sophisticated versions use complex math to scramble data.

The most advanced method is called cryptoviral extortion. This process uses a specific three-round protocol between the attacker and the victim. First, the attacker creates a key pair. They place a public key inside the malware and release it. Next, the malware infects the victim's computer. It generates a random symmetric key to encrypt the victim's data. To secure this, the malware uses the public key to encrypt the symmetric key. This method is known as hybrid encryption. It creates a small piece of asymmetric ciphertext and a large amount of symmetric ciphertext. The malware then deletes the original files and the symmetric key to prevent recovery. Finally, the victim sees a message with the ciphertext and instructions on how to pay. Once the attacker receives the payment, they use their private key to decipher the ciphertext. They then send the symmetric key back to the victim to unlock the data.

There are different ways that ransomware can behave once it enters a system. Some programs act as a Trojan. A Trojan is a malicious file disguised as something legitimate. Users might accidentally download it through an email attachment or a malicious link. Once active, the program runs a payload. Some payloads are just "scareware." These programs do not actually lock files but show fake warnings. They might claim a user committed a crime to trick them into paying a fine. Other payloads are much more intrusive. They might change the Windows Shell to restrict the system. They can even modify the master boot record to stop the operating system from booting entirely. The most dangerous payloads use strong encryption to ensure only the attacker holds the decryption key.

The history of these attacks shows how the technology has evolved. The first documented case was the "AIDS Trojan" in 1989. It was written by Joseph Popp and was also known as the PC Cyborg Trojan. This early version had a major design flaw. It only encrypted file names and hid files on the hard drive. Because of this mistake, the decryption key could be extracted from the code. This meant victims did not actually have to pay to get their files back. In 1996, researchers Adam L. Young and Moti Yung introduced the concept of using public key cryptography for data kidnapping. They presented their idea of cryptoviral extortion at a security conference. Interestingly, their concept was inspired by the "facehugger" creature from the movie Alien.

Since those early experiments, the scale of ransomware has grown massively. In the first half of 2018, there were 181.5 million attacks worldwide. This was a 229% increase from the same period in 2017. Certain programs have been incredibly successful at collecting money. CryptoLocker was a major example that collected an estimated US$3 million. Another program, CryptoWall, was estimated by the FBI to have earned over US$18 million by June 2015. Ransom payments reached a record high of $1.25 billion in 2023. However, payments dropped to $813 million in 2024. This drop is attributed to victims refusing to pay and increased action by law enforcement.

Modern ransomware attacks can have devastating real-world impacts. In 2022, the country of Costa Rica suffered widespread attacks from the Conti ransomware. These attacks hit government offices, healthcare systems, and various industries. The situation was so severe that President Rodrigo Chaves declared a state of emergency. He stated that the country was "at war" with the hackers. This shows that ransomware is no longer just a problem for individuals. It is a threat to entire nations and their essential services. The cost to fix an attack is also very high. In 2020, the global average cost to remediate a single attack was $761,106. This includes the cost of downtime, lost opportunities, and device repairs.

Today, the ransomware ecosystem has become highly organized. Some criminals now offer ransomware as a service. This works like a subscription model, similar to how people subscribe to Office 365. This allows even less skilled people to launch attacks. Attackers also use various methods to hide their tracks. Some use proxies tied to Tor hidden services to connect to their command and control servers. This makes it much harder for police to find the actual location of the criminals. Despite these growing threats, security experts and law enforcement continue to develop new ways to defend against these digital extortionists.

822 words
🖼️ Images & Media (1)
File:Metropolitan_Police_ransomware_scam.jpg
Metropolitan_Police_ransomware_scam.jpg
Up Next
💻
Malware
Technology
More to explore

🔬 Go deeper

More advanced topics to explore

🪜 Step back

Simpler topics to build understanding

What is Nepedia?

A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.