TechKnowSurge
VideoSecurityFree

Ransomware

Ransomware is malicious software that encrypts a victim's data and demands payment in exchange for the decryption key needed to restore access. It is one of the most common and damaging categories of malware in use today.

Complete this video to capture a CTF flag worth 1 point.

About this video

Ransomware is a category of malicious software that encrypts files or data on a compromised system, making them completely inaccessible to the victim. The term draws directly from the concept of a ransom — a payment demanded in exchange for the return of something of value, whether a person or property. In a ransomware attack, data takes the place of that valueable asset, and encryption serves as the mechanism of control. Without the correct decryption key, the victim has no way to recover their files through the encrypted system alone. The attacker retains the decryption key and uses it as leverage, releasing it only after the victim submits payment. This model has proven extraordinarily effective across both individual and organizational targets, which is why ransomware has evolved into its own distinct and well-documented category of cyber threat. Understanding how ransomware operates at a fundamental level — encryption, key control, and extortion — is essential groundwork for anyone working in IT security, incident response, or risk management.

What you'll learn

What's covered

Ransomware

Key terms

Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Decryption Key
A cryptographic key used to convert encrypted, unreadable data back into its original readable format.

Topics

Ransomware Malware Encryption Cybersecurity Data Protection Threat Analysis

Transcript

Ransomware has become very effective and very prevalent nowadays. It's become a whole category in itself because it is so prevalent.

Ransomware gets its name from the word ransom. Ransom is the demand of payment for the release of a kidnapped person or stolen property. Sometimes people will kidnap somebody else and then demand that they won't release this person unless they get payment to release that person. Or maybe it's a piece of property. Maybe they steal a piece of property from somebody else that's very valuable, or has some sort of sentimental value or something to that effect, and then they demand that other person pay them before they release that property back to them.

In the case of ransomware, it is software that will hold for ransom some sort of data. Here we've got some files, some data, and then we hold that data for ransom. What it does is it encrypts this data, and you can't access the data because it's encrypted. The only way to access that data then is that you have to have some sort of key to do that. Well, where are you going to get the key? It's from whoever the attacker is, whoever is carrying out this attack. They will give you the key if you pay them for that key.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →