Types of Ransomware by Encryption and Targeting Method
Understanding how attackers choose encryption methods and targets separately.

Ransomware is malware that blocks access to your files or your systems, then demands payment (almost always crypto) to give that access back. That's the textbook version. In 2025, the textbook version is missing half the story, because modern ransomware is defined by two separate decisions an attacker makes: how they're going to lock you out, and who they picked to lock out in the first place.
Those two decisions move independently. A gang can use dead-simple encryption and still wreck a hospital, or use state-of-the-art cryptography against someone who couldn't tell a ransom note from a chain email. Treat encryption method and targeting logic as one blended idea, and you'll misjudge both the danger and the fix. Treat them as two separate axes, and the threat landscape actually starts to make sense.
The scale of the problem defenders are navigating in 2025
2025 set records nobody wanted to set. Double-extortion leak sites listed more victims than any prior year, and Q3 alone saw a record number of ransomware groups operating at the same time. Dozens of groups, all competing for the same pool of victims.
Money followed the same curve. Global losses now run into the tens of billions annually, and median ransom payments jumped sharply between 2024 and 2025. Healthcare stayed the most expensive sector per breach of anywhere, and that fact alone tells you something important: the cost is primarily about who got hit, not encryption quality. A hospital pays more than a hardware store because downtime in a hospital kills people; the sophistication of the malware is irrelevant.
That's really the whole argument for this piece. When you've got this many specialized groups running around, each one optimizing a different combination of technique and target, lumping them all under "ransomware" is like calling every vehicle on the road a car. Technically true, and wholly useless if you're trying to plan for one.
Crypto ransomware: the encryption-first baseline that everything else is measured against
This is the OG. Crypto ransomware encrypts your files, usually specific file types, and without the attacker's key, that's the ballgame. CryptoLocker made this style famous, spreading through email attachments and a botnet, picking off small and midsize businesses by the thousands. It ran indiscriminate, high-volume campaigns by design.
Newer versions have stretched past local drives into shared drives, networked storage, even cloud folders. Same encryption idea, just a bigger net. And here's the detail that matters for the taxonomy: crypto ransomware is defined by what it does. The targeting logic gets bolted on separately depending on who's running the operation that week.
One more thing worth saying plainly: payment leaves file recovery uncertain. Sometimes the decryption tool is broken, and sometimes the attacker just never sends it. That's a real conversation organizations need to have before they wire money to a stranger hoping for the best.
Locker ransomware: device access as the lever instead of file encryption
Locker ransomware skips encryption entirely. It just takes over your device, locks your input, and slaps a ransom demand on the screen. Your files are untouched, technically fine, just unreachable because you can't get past the lock screen to use them.
The technical bar to build one is lower, which sounds like good news for defenders until you remember LockBit ran a huge share of all attacks in 2024, including the mess it made of the UK's Royal Mail in 2023. Simpler doesn't mean smaller here; it just means the lever is different.
Locker's targeting logic tends to follow its own limits, though. It works best on individuals, small businesses without real IT support, and regions where cybersecurity maturity is still catching up, places where the shock of a locked screen produces a faster payment than a technical fight would. WinLock, an early locker variant, asked for a small payment via SMS code. Low ransom, high volume: that's the tell of an attacker going after individuals, not enterprises.
Scareware: coercion through psychology rather than technical encryption
Scareware doesn't need to encrypt anything. It just needs to scare you. Fake virus alerts, made-up scan results claiming your system is crawling with malware, or a screen dressed up like a law enforcement notice. Sometimes it locks the screen for effect, but fear is the actual threat, with the lock serving only as scenery.
Reveton is the textbook case here: it impersonated the FBI, INTERPOL, or local police, telling victims they'd committed a crime and needed to pay an "immediate fine." No judge, no court date, just a scary logo and a countdown clock. People paid because they believed, for a minute, that the cops were about to show up; the data was never touched.
Scareware goes after less technically experienced users, people who won't stop and Google "is this actually the FBI." Home users, older demographics, and (uncomfortably often) people who visited a piracy site and are already primed to feel guilty about something. On the two-axis map, scareware sits in the corner with almost no encryption and maximum psychological pressure. The target is chosen for psychological vulnerability, for being easy to rattle.
Leakware and doxware: exfiltration as the primary threat instead of encryption
Leakware flips the whole model. The threat is that your stolen data gets published or sold, and that's a very different kind of pain than a locked screen.
The targeting logic follows the exposure risk, not the file count. Executives, healthcare providers, law firms, anyone holding personal data that's regulated get singled out, because their damage is "our client list is now on a leak site and our compliance officer is having a bad week," not a day of lost productivity. Doxware sometimes overlaps with scareware too: piracy site users get threatened with public exposure of what they downloaded, mixing reputational fear with a whiff of legal trouble, even when no crime actually occurred.
Here's the part that trips up defenders who are used to thinking about backups: restoring from backup fixes nothing here. The data is already out the door, sitting on someone else's server, and restoration is irreversible.
How hybrid encryption actually works inside a ransomware payload
Almost all serious ransomware today runs on hybrid encryption, and understanding it explains why decryption without the key is basically impossible. A symmetric algorithm, usually AES-256 or ChaCha20, encrypts your files fast. Then an asymmetric algorithm, RSA or ECC, encrypts that symmetric key. The attacker's private key, the only thing that could undo the lock, never touches your infected machine, and only the public key does.
AES-256 remains the workhorse in advanced attacks. ChaCha20 is picking up ground on systems without AES hardware acceleration, since it's faster without dedicated chips helping it along. On the asymmetric side, RSA protected the session key in older heavyweight families like CryptoLocker, Locky, and Ryuk, while ECC is gaining traction because it hits the same security level with a shorter key, leaving a smaller fingerprint for detection tools to spot.
Occasionally, the criminals mess up their own math. The Rhysida group shipped a flawed random number generator, and researchers used that flaw to crack decryption without ever touching the private key. Worth remembering: cryptography stands or falls on its implementation, and implementation mistakes remain one of the only honest paths to free decryption. For vendors, this matters practically too. The encryption method shapes what you can actually see: file entropy spikes, key exchange traffic, specific API calls. That's your detection surface.
Double, triple, and quadruple extortion: stacking levers to multiply pressure
Start with the number, because it changes how you should think about everything else in this piece: 96% of ransomware attacks now combine encryption with data theft, according to BlackFog's 2025 Q3 Ransomware Report. Double extortion has become the standard; pure crypto ransomware, the kind that just locks your files and asks nicely, is now the exception.
Triple extortion piles on a third pressure point: a DDoS attack against your infrastructure, direct outreach to your customers, or threats to report you to regulators. The attacker is squeezing the company's relationships and legal obligations as well as the company itself.
Quadruple extortion is where it gets genuinely absurd, and Change Healthcare in February 2024 is the case study everyone points to. BlackCat/ALPHV stole records tied to hundreds of millions of people, and a ransom got paid. Then the operators exit-scammed their own affiliates, and a separate group, RansomHub, turned around and tried to extort the same victim a second time using the same stolen data. Total damage: well north of two billion dollars, from what started as a single breach. It plays out like a heist movie with a sequel nobody asked for.
Multi-extortion targets organizations with heavy regulatory exposure or reputational fragility (healthcare, financial services, critical infrastructure) because the exposure threat carries leverage all on its own, separate from whatever's encrypted. That's the operational headache for defenders: backup restoration solves the encryption problem, leaving data already in an attacker's hands entirely exposed.
Ransomware-as-a-Service: how the criminal supply chain shapes who gets targeted and how
RaaS split the ransomware business into two jobs. Core groups build and maintain the malware, while affiliates handle the dirty work: breaking in, picking victims, negotiating the ransom, all in exchange for the bulk of the payout.
That split matters more than it sounds like on paper. An affiliate deploys someone else's tool without writing a line of encryption code, which means the pool of people capable of running a ransomware attack got a whole lot bigger, and a whole lot more opportunistic. Qilin has reportedly offered an above-market revenue share to affiliates, and it's pulled talent away from disbanded operations, including reported use by North Korean threat actors chasing the payout.
By early 2026, just three groups, Qilin, Akira, and DragonForce, accounted for a large share of monthly incidents, even with a record number of groups technically active. Concentration at the top, chaos everywhere else. Akira alone has racked up substantial confirmed proceeds according to CISA advisories, proof that one well-run RaaS operation can sustain serious financial throughput for a long stretch.
The lesson for security vendors is blunt: the same malware family can hit wildly different victims depending on which affiliate happens to be driving that week. The variant name tells you about the encryption and nothing about the target.
OT and ICS-targeted ransomware: when targeting logic reaches physical operations
Some ransomware targets your power grid, your assembly line, your physical operations rather than data. Ryuk and LockerGoga made names for themselves hitting operational technology, where the damage is a shut-down plant.
Groups like Eldorado and Play have built Linux lockers specifically for VMware ESXi environments, encrypting virtual machine files and killing active VMs fast, often with almost no dwell time before encryption kicks in. BERT, which showed up in April 2025, went a step further and built in the ability to forcibly shut down ESXi VMs before encrypting them, because the goal is ensuring nothing remains running to serve as a fallback.
Utilities, hospitals, and manufacturers get targeted here because downtime is either dangerous or unaffordable, and that urgency is exactly what makes the ransom feel worth paying fast, before a forensic team even finishes its coffee. The encryption method might be identical to what hits a regular office network. What's different is the target system and the stakes of losing access to it. Segmenting IT from OT networks remains the main structural defense, because the encryption is identical; the defensive task is stopping the payload before it reaches the systems that matter most.
Wiper malware disguised as ransomware: when the goal is destruction, not payment
Sometimes the ransom note is a costume. Wiper malware looks like ransomware, locks you out, throws up a demand, but the people behind it intend only destruction, full stop.
NotPetya remains the case everyone studies for this, tied to Russian state-sponsored actors and aimed at Ukrainian energy, transport, and banking infrastructure. The ransom demand was set dressing, and decryption was never actually possible, structurally, by design. KillDisk played the same trick. In both cases, dressing the attack up as ransomware bought the attackers time, since incident response teams spent precious hours negotiating with a threat that was never negotiable.
Wipers go after geopolitical adversaries and critical infrastructure, not people who'll pay up. The attacker is optimising for damage that cannot be reversed. A ransom note alone obscures intent; defenders need to check whether decryption is technically feasible before assuming they're dealing with someone who wants money. Detection built around "does a ransom note exist" will sail right past a wiper campaign, because the tell is evidence of destruction that cannot be undone.
Reading the two-axis map: what encryption method and targeting logic together tell a defender
Put the two axes side by side and the whole threat landscape gets a lot less blurry. The encryption axis (file lock, device lock, exfiltration, outright destruction, or no encryption at all) tells you what you can actually see and what a successful response restores. The targeting axis (broad and indiscriminate, sector-specific, OT and ICS, individual, or geopolitical) tells you how much leverage the attacker has and how much you'll have left in a negotiation.
The scariest combination on the map isn't subtle: high-value targeting like healthcare or critical infrastructure, paired with hybrid encryption, paired with exfiltration. Restoring from backup addresses exactly one of those three problems, leaving two-thirds of the damage live while responders congratulate themselves.
RaaS breaks the clean link between the axes entirely, since the same payload can land on wildly different targets depending on which affiliate is steering it that month. A detection plan focused solely on encryption behavior leaves leakware-only attacks invisible, and a response plan built solely around backups leaves exfiltrated data and wiper-style destruction unaddressed.
That's the actual use of a framework like this. Vendors building behavioral detection for encryption, exfiltration monitoring, OT segmentation, or threat intel on active RaaS affiliates each cover a different combination of these two axes, and the buyers reading this should be asking which combination actually matches the risk sitting in front of them, rather than defaulting to whichever vendor shouts loudest.


