Attacks
Software that encrypts your files and demands crypto to release them. Ransomware encrypts everything it can reach and leaves a note demanding payment, almost always in crypto, for a decryption key. Crypto is the payment rail rather than the target, but for anyone holding crypto there is a second problem: the same access that encrypted your files can read your wallet files, your browser extension data and any seed phrase you saved on the machine.
What it is
Ransomware encrypts everything it can reach and leaves a note demanding payment, almost always in crypto, for a decryption key. Crypto is the payment rail rather than the target, but for anyone holding crypto there is a second problem: the same access that encrypted your files can read your wallet files, your browser extension data and any seed phrase you saved on the machine.
How it plays out
It gets in through something ordinary
A macro in an attached document, a cracked application, a fake software update, a malicious browser extension, or an unpatched remote desktop service.
It waits
Modern ransomware spends time mapping the network and finding backups before it does anything visible, so the backups go first.
It encrypts and it copies
Most groups now steal the data as well, so paying for decryption does not stop them publishing it.
The note demands crypto
With a countdown, a discount for paying quickly, and a support chat. It is run like a business because it is one.
What gives it away
- Files renamed with an unfamiliar extension, or that will not open.
- A readme or text file appearing in every folder.
- A machine that suddenly slows down while disks work hard.
- Security software disabled without you doing it.
How to not be caught by it
- Keep offline backups. A backup that is always connected is a backup ransomware encrypts too.
- Follow the three two one rule: three copies, two kinds of media, one kept offline or offsite.
- Patch operating systems and browsers promptly, and remove software you do not use.
- Never run cracked software or "activators". That is one of the most common delivery routes.
- Never store a seed phrase as a file, a photo, or a note on any computer or phone.
- Keep meaningful crypto on a hardware wallet, so a compromised computer cannot sign anything.
If it already happened
- Disconnect the machine from the network immediately. Do not delete anything yet.
- Do not pay first. Check whether a free decryptor exists, for example through the No More Ransom project, before considering anything else.
- Assume every credential and every file on that machine is now in somebody else’s hands.
- Move crypto from any wallet whose keys touched that machine, using a different clean device.
- Rebuild the machine from scratch rather than cleaning it, then restore from an offline backup.
- Report it. In the US that is the FBI IC3, and reporting genuinely feeds the decryptor projects.
Common questions
How common is ransomware?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.