Ransomware: how to react and mitigate the impact of this cyberthreat

Image depicting a ransomware attack

By now it is very likely that the vast majority of readers have already heard about or even suffered a ransomware attack , which, as we explained in a previous article, is just another type of malware.

What is ransomware and how does it work?

The ransomware mainly focuses on encrypting the victim’s files - photos, videos, documents, databases - and then displays a ransom note on screen or in a text file for the victim to read.

It shows instructions that the victim must follow to pay the “ransom” (usually in cryptocurrencies), in exchange for the data decryption key that would allow the recovery of the hijacked information.

The process is almost always automatic: the malware generates a unique encryption key for each computer, sends it to a Command and Control*(C&C*) server controlled by the attackers, and then deletes any local copies of that key to force payment.

In October 2021, VirusTotal published its first ransomware activity report after analyzing 80 million samples.

The report showed that by that time, there were already up to 130 different families uploaded to its platform from 140 countries around the world.

An interesting fact is that most of the families were aimed at infecting Windows-based computers, while only 2 % targeted Android devices.

The hardest hit sectors are healthcare, public administration, education and manufacturing, leading the statistics since 2023.

Common infection vectors

  1. Phishing mail: malicious attachments or links that download ransomware.
  2. Poorly protected RDP access: weak or leaked credentials on the Internet.
  3. Downloading pirated software from the Internet.
  4. Supply chain: compromises a software vendor to infect its update with malicious code in legitimate updates*(e.g.* MoveIT 2023).

As if it were another market product, it is curious to see how platforms proliferate on the Dark Web where RaaS (Ransomware as a Service) service kits are sold or rented , in exchange for which the operator takes a commission from each ransomware.

This model explains why so many new “families” appear every year and why professionalization is so high; “clients” have a C&C control panel from which to manage everything, view statistics and even 24/7 support, just like any commercial software.

With such a well-organized service and making it so easy for cybercriminals, it is no wonder that ransomware is one of the main methods of financing cybercriminal gangs.

To make matters worse, cybercriminals do not only encrypt the files, but also threaten to make the stolen information public if the blackmail is not complied with within a specific time frame, usually very short, in order to create urgency and limit a strategy on the part of the client that could include the FCSE.

This blackmail is extremely sensitive, especially when it involves, for example, patients’ medical data, personal data of ministers and authorities, etc.

It is such a difficult problem to contain that, in 2021, the IST (Institute for Security and Technology) created and published the Ransomware Task Force Framework (RTF)an organization composed of more than 60 experts from international agencies, law enforcement, industry, government and civil society.

Its goal is to promote a unified, public-private, comprehensive and aggressive anti-ransomware campaign to combat this scourge.

The framework outlines 48 recommendations that form a comprehensive strategy for addressing ransomware, including deterrence, disruption of the ransomware business model, attack preparedness and effective response.

The most important thing to keep in mind, before making a decision, is that no matter what the scenario is: even if the ransom is paid, there is no guarantee that access to data or systems will be regained.

It is true that, in the vast majority of cases, attackers do return access (otherwise, their business model would collapse due to lack of credibility), but it is also true that paying opens the door for them to come back for the same victim in the future, as they know that they are the type to pay and fall easily.

The fees they request are usually based on the victim’s purchasing power and are almost always demanded in cryptocurrencies such as Bitcoin.

What to do if we are witnessing file encryption as it happens?

Let’s first look at how to recognize ransomware infection:

  • Sudden appearance of strange file extensions*(e.g.* .lockbit, .blackcat).
  • Rescue note on the desktop or in each folder.
  • Abnormal spike in CPU and disk usage, followed by performance drop.
  • Unforeseen deactivation of the antivirus.

Therefore, should we witness the malware executing while it is encrypting our files, we should react quickly by performing the following actions:

  1. Isolate the computer: disconnect the network (wired and Wi-Fi) and remove all storage drives - USB, hard drives, etc. - to stop the spread.
  2. Decide whether to turn off the equipment: the decision will depend on whether you are a home user or an employee of a company:
  • Home users: shut down the computer as soon as possible to prevent further data encryption. Afterwards, the device should not be turned on as usual, as the malware could persist and continue encryption when it is turned back on. The recommended way to try to recover data that has not yet been encrypted is to disconnect the storage unit and connect it to a different computer to access the data from there. The rest of the data that has already been encrypted can only be recovered if the victim has been making frequentbackups of the data. Making recurring backups (automated or manual) of all the data we care about is one of the main mandatory security measures, as these can save us not only from threats of this type, but also from loss, theft, failure or natural disaster that prevents us from accessing the information.
  • Companies: if you are the employee of a company, especially if it is a large company, it is usually advisable only to disconnect the computer from the network and unplug external drives, but not to turn off the computer. It would be advisable to hand over the powered-on device to the FCSE (State Security Forces) or to computer forensic experts to examine the RAM and try to recover the encryption key, in case it is still there, which is very likely. The reason for keeping the computer on at all times is that, once the computer is turned off, that key disappears from the RAM and, therefore, there is little that can be done to recover the information except pay the ransom or hope that, in the not too distant future, the keys are leaked or a “vaccine” capable of decrypting that ransomware variant appears.

Possible technical recovery solutions

The first thing to try to do is to identify the strain. Next, ย search the internet for information on how to act in the event of a ransomware attack (this article is a good example and includes very interesting links that can help us on how to proceed).

Upload the ransom note or an encrypted file to ID Ransomware(https://id-ransomware.malwarehunterteam.com), see what information it gives us about the type of malware.

Next, search for decryptors. For example, go to the official No More Ransom portal , where you can find more than 180 free tools.

You can also check out a community repository on GitHub that compiles many of the above utilities.

An advanced user would probably use tools such as SysInternals**Process Explorer or the Windows**Task Manager in order to try to perform a memorydump of the malicious process.

This file would be saved in %TMP%, from where it can later be analyzed and even attempt to recover the encryption password.

Another option worth trying would be to stop the execution of the harmful process in RAM and terminate the process tree from Task Manager, although identifying the correct process, if it is camouflaged with a credible name such as “Service Windows host”, may be impossible.

For an average user, once they have followed the initial recommendations - such as shutting down the computer quickly and trying to recover from another device any files that have not yet been encrypted - the next step would be to turn the computer back on, but to boot it into Safe Mode. This is important to prevent the ransomware from running automatically on system startup.

In any case, as I have already indicated, the best solution is to always have recent backups.

To avoid this, the first thing to do is to scan the backup drive and delete the file hosting the malware, so that it does not become active again accidentally.

A very common mistake, both among individuals and companies, is to always keep the backup drive connected to the same device that you want to protect. This is a serious mistake, since one of the first steps that ransomware usually takes is to encrypt precisely those backup copies. Its goal is to prevent the victim from recovering his data without paying the ransom. For this reason, files with names such as backup, backup, or similar, are usually the first to be attacked.

Backups

Companies usually prepare for this type of malware by regularly backing up network folders, where all employees are “supposed*”* to store their documents.

However, those who make the mistake of storing their files directly on the local “C:” drive run the risk of being left out of these backups. In the event of a ransomware attack - or any other incident that compromises the data - that unbacked-up information could be lost for good.

Finally - and although it may seem obvious - it is surprising how many organizations or individuals do not keep their backups in a separate location.

Keeping backup copies at another location, even several kilometers away, is a highly recommended practice even for private individuals, as it not only allows them to recover from an attack, but also from natural disasters, theft or fire.

For example, if you have two homes or can ask your parents to keep your backup disks for you, you are already taking an important step to prevent an incident from affecting all your backups at once. Ideally, there should be a distance of several kilometers between the main location and the offsite copy, especially in case of natural disasters or fire.

And if you want to do things really well, there is a widely recognized rule in the world of backups: the rule 3-2-1.

It consists of having three copies of your data, stored on at least two two different types of media (e.g., hard disks, DVDs, or the cloud), and keeping at least one copy of your one at least one of them in a remote or offsite location.

Another very common mistake, both in companies and individuals, is to never check if the backups are being performed correctly.

The problem arises when, after an incident, the first attempt is made to recover the information and it is discovered that the copies were incomplete, damaged or contained errors that prevent their restoration. Therefore, especially in enterprise environments, periodically verifying the integrity of backups should be a mandatory practice in disaster recovery plans.


In summary, ransomware remains the biggest operational threat to businesses and individuals in 2025.

Its success is based on simple attack vectors, the professionalization of the RaaS model and the willingness of victims to pay.

Effective response combines prevention (patches, MFA, training), early detection and, above all, robust backups.

If infection occurs, isolating the computer, identifying the strain and finding a reliable decryptor should always precede any payment approach. This way we reduce criminal gains and, in the process, strengthen the digital ecosystem for everyone.