Attack Techniques ยท 2.5
๐ฐ Ransomware & Extortion
When social engineering is the delivery mechanism, not the end goalโฑ ~2 min
Ransomware and extortion attacks threaten to reveal sensitive information or disrupt systems unless a ransom is paid. While ransomware itself is malware, the initial access nearly always comes through social engineering โ a phishing email with a malicious attachment, a vished call talking someone into installing 'remote support' software, or stolen credentials from a phishing site.
How a Ransomware Attack Typically Starts
- 1.Phishing email with a malicious Office document or link delivers an initial foothold (a 'loader' or remote access trojan)
- 2.Attacker uses that access to move laterally through the network, often over days or weeks, escalating privileges
- 3.Attacker locates and exfiltrates valuable data before deploying ransomware (double extortion)
- 4.Ransomware encrypts files across as many systems as possible, often timed for a weekend or holiday when response is slower
- 5.Ransom note demands payment (usually cryptocurrency) and threatens to leak the stolen data publicly if not paid
โ WarningDouble extortion (encrypt AND threaten to leak data) has become the norm. Even organizations with solid backups โ who can restore systems without paying โ are still extorted with the threat of public data exposure, regulatory fines, and reputational damage.
โ
FactLaw enforcement agencies (FBI, Europol, NCSC) generally advise against paying ransoms: payment funds further criminal activity, doesn't guarantee data recovery or deletion, and marks the organization as a 'payer' likely to be targeted again.
๐ง Quick Checkfirst try = +5 XP
Modern ransomware gangs use 'double extortion,' meaningโฆ
๐ฎ Practice what you learned
โญ 0 XP๐ฅ 0 days