EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy
A company's financial department experiences a widespread attack where critical accounting files are encrypted, and a demand for cryptocurrency is displayed on all affected screens. The IT team confirms no data was exfiltrated, only encrypted. Which malware type is most accurately described by this scenario?
- ASpyware
- BRansomware
- CAdware
- DWorm
Show answer & explanationAnswer & explanation
Correct answer: B. Ransomware
The scenario clearly describes ransomware: encryption of critical files and a demand for payment (ransom) to restore access. The confirmation of no data exfiltration further supports this, distinguishing it from data-stealing malware.
Why the other options are wrong
- A. Spyware is designed to secretly collect information, not encrypt files for ransom.
- C. Adware displays unwanted advertisements, not encrypt files for ransom.
- D. A worm is a self-replicating malware that spreads across networks, but its primary function isn't typically file encryption for ransom.
Ransomware
A type of malicious software that encrypts a victim's files or locks their system, then demands a ransom payment (often in cryptocurrency) in exchange for decryption or access restoration.
- Encrypts files or locks system access.
- Demands payment, usually cryptocurrency.
- Can spread via phishing, compromised websites, or exploits.
Memory trick: Ransomware holds your data 'for ransom', demanding crypto cash.