Ransomware Attack - What is it and How Does it Work? - Check Point Software

What is Ransomware?

In 2025, ransomware has evolved significantly past simple file encryption. While denying access to your data by encrypting it and demanding a ransom payment for the decryption key remains a core tactic, today’s ransomware does much more. Cyber– attackers now frequently incorporate additional functionalities like data theft. This means they don’t just lock up your files; they also steal sensitive information. This dual threat creates even greater pressure for victims to pay the ransom, as they face not only data loss but also the potential for public exposure of stolen data or its sale on the dark web.

Ransomware has quickly become the most prominent and visible type of malware. Recent ransomware attacks have impacted hospitals’ ability to provide crucial services, crippled public services in cities, and caused significant damage to various organizations.

Why Are Ransomware Attacks Emerging?

Ransomware reached record levels in 2025, with 7,960 victims listed on double‑extortion leak sites—a 53% increase year‑over‑year. Activity peaked in both Q1 and again in Q4, driven largely by mass‑exploitation campaigns, including Cl0p’s zero‑day attacks that compromised hundreds of organizations early in the year. The collapse of several major RaaS groups reshaped the ecosystem, enabling Qilin to surge ahead as the most active operator, publishing over 1,000 victims and tripling its monthly volume.

The United States accounted for roughly 52% of all disclosed victims, far exceeding other regions. Attacks remained centered on commercial sectors, particularly business services, consumer goods & services, and industrial manufacturing.

How Ransomware Works

In order to be successful, ransomware needs to gain access to a target system, encrypt the files there, and demand a ransom from the victim.

While the implementation details vary from one ransomware variant to another, all share the same core three stages

Ransomware, like any malware, can gain access to an organization’s systems in a number of different ways. However, ransomware operators tend to prefer a few specific infection vectors.

One of these is phishing emails. A malicious email may contain a link to a website hosting a malicious download or an attachment that has downloader functionality built in. If the email recipient falls for the phish, then the ransomware is downloaded and executed on their computer.

Another popular ransomware infection vector takes advantage of services such as the Remote Desktop Protocol (RDP). With RDP, an attacker who has stolen or guessed an employee’s login credentials can use them to authenticate to and remotely access a computer within the enterprise network. With this access, the attacker can directly download the malware and execute it on the machine under their control.

Others may attempt to infect systems directly, like how WannaCry exploited the EternalBlue vulnerability. Most ransomware variants have multiple infection vectors.

In 2025, ransomware attacks frequently leverage vulnerabilities within an organization’s third-party suppliers, recognizing them as a weaker entry point.

After ransomware has gained access to a system, it can begin encrypting its files. Since encryption functionality is built into an operating system, this simply involves accessing files, encrypting them with an attacker-controlled key, and replacing the originals with the encrypted versions.

Once file encryption is complete, the ransomware is prepared to make a ransom demand. Different ransomware variants implement this in numerous ways, but it is not uncommon to have a display background changed to a ransom note or text files placed in each encrypted directory containing the ransom note.

Types of Ransomware Attacks

Ransomware has evolved significantly over the past few years. Some important types of ransomware and related threats include:

Popular Ransomware Variants

1. Ransomhub

RansomHub, a Ransomware-as-a-Service (RaaS) group that emerged in February 2024, quickly rose to prominence. RansomHub’s ransomware is known for its fast encryption. However, on April 1, 2025, RansomHub’s operations ceased.

2. Akira

Akira, a ransomware variant first identified in Q1 2023, targets both Windows and Linux systems using ChaCha2008 encryption.

3. Play

The Play Ransomware Group, also known as Play or Playcrypt, has emerged since 2022, successfully compromising over 300 organizations globally.

4. Clop

Cl0p is a ransomware that primarily targets industries handling sensitive data, such as healthcare and finance.

5. Qilin

Qilin operates as a prominent Ransomware-as-a-Service (RaaS), utilizing a highly customizable Rust-based ransomware.

6. Ryuk

Ryuk is delivered via spear phishing emails or by using compromised user credentials.

7. Maze

Maze is famous for being the first ransomware variant to combine file encryption and data theft.

8. REvil (Sodinokibi)

REvil targets large organizations and is known to have demanded high ransom payments.

9. Lockbit

LockBit is a data encryption malware developed to encrypt large organizations rapidly since September 2019.

10. DearCry

DearCry encrypts certain types of files and shows a ransom message to users.

11. Lapsus$

Lapsus$ is known for extortion, threatening the release of sensitive information if demands are not met.

How Does Ransomware Affect Businesses?

A successful ransomware attack can have various impacts on a business. Some of the most common risks include:

Common Ransomware Target Industries

The top five ransomware target industries in 2023 include:

How to Protect Against Ransomware

How to Remove Ransomware?

How to Mitigate an Active Ransomware Infection

  1. Quarantine the Machine
  2. Leave the Computer On
  3. Create a Backup
  4. Check for Decryptors
  5. Ask For Help
  6. Wipe and Restore

How Can Check Point Help

Check Point’s Anti-Ransomware technology uses a purpose-built engine that defends against sophisticated, evasive zero-day variants of ransomware and safely recovers encrypted data, ensuring business continuity and productivity.