Ransomware Attack - What is it and How Does it Work? - Check Point Software
What is Ransomware?
In 2025, ransomware has evolved significantly past simple file encryption. While denying access to your data by encrypting it and demanding a ransom payment for the decryption key remains a core tactic, today’s ransomware does much more. Cyber– attackers now frequently incorporate additional functionalities like data theft. This means they don’t just lock up your files; they also steal sensitive information. This dual threat creates even greater pressure for victims to pay the ransom, as they face not only data loss but also the potential for public exposure of stolen data or its sale on the dark web.
Ransomware has quickly become the most prominent and visible type of malware. Recent ransomware attacks have impacted hospitals’ ability to provide crucial services, crippled public services in cities, and caused significant damage to various organizations.
Why Are Ransomware Attacks Emerging?
Ransomware reached record levels in 2025, with 7,960 victims listed on double‑extortion leak sites—a 53% increase year‑over‑year. Activity peaked in both Q1 and again in Q4, driven largely by mass‑exploitation campaigns, including Cl0p’s zero‑day attacks that compromised hundreds of organizations early in the year. The collapse of several major RaaS groups reshaped the ecosystem, enabling Qilin to surge ahead as the most active operator, publishing over 1,000 victims and tripling its monthly volume.
The United States accounted for roughly 52% of all disclosed victims, far exceeding other regions. Attacks remained centered on commercial sectors, particularly business services, consumer goods & services, and industrial manufacturing.
How Ransomware Works
In order to be successful, ransomware needs to gain access to a target system, encrypt the files there, and demand a ransom from the victim.
While the implementation details vary from one ransomware variant to another, all share the same core three stages
- Step 1. Infection and Distribution Vectors
Ransomware, like any malware, can gain access to an organization’s systems in a number of different ways. However, ransomware operators tend to prefer a few specific infection vectors.
One of these is phishing emails. A malicious email may contain a link to a website hosting a malicious download or an attachment that has downloader functionality built in. If the email recipient falls for the phish, then the ransomware is downloaded and executed on their computer.
Another popular ransomware infection vector takes advantage of services such as the Remote Desktop Protocol (RDP). With RDP, an attacker who has stolen or guessed an employee’s login credentials can use them to authenticate to and remotely access a computer within the enterprise network. With this access, the attacker can directly download the malware and execute it on the machine under their control.
Others may attempt to infect systems directly, like how WannaCry exploited the EternalBlue vulnerability. Most ransomware variants have multiple infection vectors.
In 2025, ransomware attacks frequently leverage vulnerabilities within an organization’s third-party suppliers, recognizing them as a weaker entry point.
- Step 2. Data Encryption
After ransomware has gained access to a system, it can begin encrypting its files. Since encryption functionality is built into an operating system, this simply involves accessing files, encrypting them with an attacker-controlled key, and replacing the originals with the encrypted versions.
- Step 3. Ransom Demand
Once file encryption is complete, the ransomware is prepared to make a ransom demand. Different ransomware variants implement this in numerous ways, but it is not uncommon to have a display background changed to a ransom note or text files placed in each encrypted directory containing the ransom note.
Types of Ransomware Attacks
Ransomware has evolved significantly over the past few years. Some important types of ransomware and related threats include:
- Double Extortion: Double-extortion ransomware like Maze combines data encryption with data theft.
- Triple Extortion: Triple extortion ransomware adds a third extortion technique to double extortion.
- Locker Ransomware: Locker ransomware locks the computer — rendering it unusable to the victim — until the ransom has been paid.
- Crypto Ransomware: Ransomware payments are commonly paid in cryptocurrency.
- Wiper: Wipers are a form of malware that is related to but distinct from ransomware.
- Ransomware as a Service (RaaS): RaaS is a malware distribution model in which ransomware gangs provide “affiliates” with access to their malware.
- Data-Stealing Ransomware: Some ransomware variants focus on data theft, abandoning data encryption entirely.
Popular Ransomware Variants
1. Ransomhub
RansomHub, a Ransomware-as-a-Service (RaaS) group that emerged in February 2024, quickly rose to prominence. RansomHub’s ransomware is known for its fast encryption. However, on April 1, 2025, RansomHub’s operations ceased.
2. Akira
Akira, a ransomware variant first identified in Q1 2023, targets both Windows and Linux systems using ChaCha2008 encryption.
3. Play
The Play Ransomware Group, also known as Play or Playcrypt, has emerged since 2022, successfully compromising over 300 organizations globally.
4. Clop
Cl0p is a ransomware that primarily targets industries handling sensitive data, such as healthcare and finance.
5. Qilin
Qilin operates as a prominent Ransomware-as-a-Service (RaaS), utilizing a highly customizable Rust-based ransomware.
6. Ryuk
Ryuk is delivered via spear phishing emails or by using compromised user credentials.
7. Maze
Maze is famous for being the first ransomware variant to combine file encryption and data theft.
8. REvil (Sodinokibi)
REvil targets large organizations and is known to have demanded high ransom payments.
9. Lockbit
LockBit is a data encryption malware developed to encrypt large organizations rapidly since September 2019.
10. DearCry
DearCry encrypts certain types of files and shows a ransom message to users.
11. Lapsus$
Lapsus$ is known for extortion, threatening the release of sensitive information if demands are not met.
How Does Ransomware Affect Businesses?
A successful ransomware attack can have various impacts on a business. Some of the most common risks include:
- Financial Losses: Companies can lose money due to the costs of remediating the infection, lost business, and potential legal fees.
- Data Loss: This can result in data loss, even if the company pays the ransom.
- Data Breach: Ransomware groups are pivoting to double or triple extortion attacks.
- Downtime: Ransomware encrypts critical data and may cause operational downtime.
- Brand Damage: Ransomware attacks can harm an organization’s reputation.
- Legal and Regulatory Penalties: Ransomware attacks may include breach of sensitive data.
Common Ransomware Target Industries
The top five ransomware target industries in 2023 include:
- Education/Research
- Government/Military
- Healthcare
- Communications
- ISP/MSPs
How to Protect Against Ransomware
- Cyber Awareness Training and Education
- Continuous data backups
- Patching
- User Authentication
How to Remove Ransomware?
How to Mitigate an Active Ransomware Infection
- Quarantine the Machine
- Leave the Computer On
- Create a Backup
- Check for Decryptors
- Ask For Help
- Wipe and Restore
How Can Check Point Help
Check Point’s Anti-Ransomware technology uses a purpose-built engine that defends against sophisticated, evasive zero-day variants of ransomware and safely recovers encrypted data, ensuring business continuity and productivity.