Evolution: From CryptoLocker to RaaS #

CryptoLocker (2013 to 2015) #

2013 marked the turning point: CryptoLocker infected hundreds of thousands of computers and encrypted files using strong asymmetric cryptography. The demand: ransom in Bitcoin. At the time it was a shock. Today CryptoLocker looks primitive.

WannaCry and NotPetya (2017) #

These worms used network exploits (EternalBlue) to propagate themselves. WannaCry alone hit more than 200,000 computers in around 150 countries. The lesson: ransomware no longer requires human interaction. It can self-replicate.

Ransomware-as-a-Service (RaaS): today #

Today’s reality is professionalised. Cybercriminals offer ransomware as a service. Groups like LockBit, BlackCat, and Cl0p have operated like software companies with affiliate programmes. An attacker does not need to be a technician: they pay, get the malware, and launch their attack. The European Union Agency for Cybersecurity (ENISA) consistently ranks ransomware among the top threats in its annual Threat Landscape reports.


Three Main Types of Ransomware #

1. Locker Ransomware (Screen Locker) #

Blocks access to the system without encrypting data. The screen displays a message: pay to unlock. This is often easy to remove and is becoming less common, but still encountered.

2. Crypto Ransomware #

Encrypts files using strong cryptography. This is the current standard. Files are inaccessible until the key is available, and the key is held by the attacker.

3. Double Extortion Ransomware #

The modern, more aggressive approach. The attacker:

  • encrypts the data AND
  • exfiltrates (steals) the data before encrypting it.

You then face two extortion scenarios: pay, or your data stays encrypted” and pay, or we publish your data.” This makes extortion harder to resist: even with working backups, the data may have been leaked.


Why Prevention Alone Is Not Enough #

IT security works in layers. Many organisations focus on prevention:

  • Endpoint protection (E, antivirus)
  • Email filtering
  • Patch management
  • Employee training

This is necessary, but not sufficient. Why?

  1. Prevention is never 100 percent effective. Even the best E solution does not stop all zero-days or social engineering attacks.
  2. Insider threats and misconfigurations exist. A disgruntled administrator or a misconfiguration can bypass the best defences.
  3. Patch gaps always exist. Days or weeks pass between vulnerability disclosure and patching.

This is why recoverability is the key to real protection. An organisation with automated, tested, immutable, air-gapped backups can recover from a ransomware attack within hours to days, regardless of how far the attack progressed.

EU regulation reflects this shift. The NIS2 Directive (Directive (EU) 20222555) requires backup management and crisis management as part of risk management measures. Article 32 requires the ability to restore availability and access to personal data in a timely manner after an incident.


Impact: What the Numbers Show #

  • Roughly seven in ten organisations report being attacked within a year (Veeam Trends 2025).
  • 89 percent of attacks targeted backup repositories; on average, about a third of those repositories were modified or deleted (Veeam 2025).
  • 49 percent of organisations with encrypted data paid the ransom (Sophos State of 2025).
  • Industry reports consistently show that total recovery costs (downtime, restoration, forensics) amount to a multiple of the ransom demand itself.

These figures make one thing clear: ransomware is no longer an IT problem. It is a business risk with board-level relevance, and under NIS2, management bodies carry personal responsibility for approving and overseeing cybersecurity risk measures.


Frequently Asked Questions #

Is backup the only thing that helps against ransomware? Backups are necessary but not sufficient. They must be combined with prevention (E, patch management). The key requirement: backups must be automated, offline or immutable, and regularly tested.

Why do companies pay the ransom even when they have backups? Several reasons: backups are too old (RPO too high), not tested (recovery failed), or destroyed (ransomware also deleted the backups). Or the risk of a data leak (double extortion) is judged too high.

Can I decrypt the data myself? Usually not. If your data is encrypted with modern ransomware, you need the attacker’s private key. Free decryptors exist only for a few older families. A clean backup is the reliable way out, supported by professional incident response.


Further Resources #

Protection: Guide for IT Decision-Makers (/en/blog/ransomware-schutz-leitfaden/) → How Destroys Backups: Technical Analysis (/en/blog/wie-ransomware-backups-zerstoert/) → -as-a-Service: How the Shadow Economy Works (/en/blog/ransomware-as-a-service/) → Silent Brick System: Hardware Backup (/en/produkte/silent-brick-system/) → Request a Demo (/​en/​kontakt/​demo/​)

Disclaimer

This article was written by our editorial team and edited using AI. It provides a general overview and does not constitute legal advice – we recommend seeking professional advice for your specific situation.