Content
Symmetric encryption uses a single key for both locking and unlocking data. It is computationally fast and efficient, making it ideal for encrypting large volumes of files . Think of it as a lockbox with one key—you make copies and share them with trusted parties. The challenge is key distribution: both parties need the same secret key, and securely sharing it over a network can be difficult .
Asymmetric encryption solves this distribution problem using a mathematically linked key pair: a public key and a private key . Data encrypted with the public key can only be decrypted with the corresponding private key. The public key can be freely shared—like a bank's deposit dropbox that anyone can drop deposits into, but only the bank can open . This is slower than symmetric encryption but eliminates the need to share secrets .
How Ransomware Weaponizes Cryptography
Ransomware operators don't choose between these encryption types—they abuse both in a hybrid scheme designed for maximum efficiency and control.
When ransomware executes, it first generates a unique symmetric key on the victim's machine. This key rapidly encrypts files using algorithms like AES-128, which is fast enough to process thousands of documents in seconds . The encrypted files receive new extensions—such as .locked, .encrypted, or variant-specific suffixes—marking them as inaccessible .
The critical step comes next: the ransomware encrypts that symmetric key using the attacker's RSA public key . This asymmetric layer ensures that only the attacker, who holds the corresponding private key on their command-and-control server, can recover the original symmetric key. Without that private key, decryption is computationally infeasible—the victim's files remain locked regardless of their computing resources .
Finally, the ransomware creates a ransom note with payment instructions, often demanding cryptocurrency. Even if payment is made, there is no guarantee the attacker will provide a working decryption key .
Seeing Encryption in Action: A Safe Demonstration
To understand this process without risking real data, security professionals use controlled simulations with harmless sample files . The principle is straightforward: create a dedicated test directory containing dummy text files, apply encryption to mimic ransomware behavior, then recover the files using the saved key .
A typical simulation uses Python's cryptography library with Fernet—a symmetric encryption implementation built on AES-128 in CBC mode with HMAC authentication . The script traverses the test directory, encrypts each file, and renames it with a .locked extension. Crucially, the encryption key is saved separately for recovery.
The recovery phase demonstrates the other side of encryption: running a decryption script with the correct key restores the original files with intact content . This educational exercise reinforces a critical truth: without the key, recovery is impossible. Real ransomware victims do not have this key—it exists only on the attacker's server.
Defenses That Actually Work
Understanding ransomware's cryptographic mechanism reveals why two defenses are non-negotiable.
Offline, immutable backups directly counter the encryption trap. If you have a recent backup that neither the attacker nor malware can modify or delete, you can restore operations without paying . Microsoft's guidance emphasizes storing backups in immutable storage or fully offline/off-site locations, with out-of-band authentication required before any modifications . The most effective backup is one the attacker cannot touch.
Least-privilege permissions limit the blast radius. Ransomware can only encrypt what the compromised account can access. If users operate with minimal necessary permissions, malware cannot spread laterally through shared drives or encrypted network resources . Microsoft recommends implementing Just-In-Time and Just-Enough-Access models, ensuring administrative privileges are time-limited and approval-based . Combined with robust identity protections like multifactor authentication, this makes it significantly harder for attackers to reach critical systems