An Endpoint Detection and Response (EDR) agent alerts security personnel that files across a shared network drive are rapidly being encrypted and appended with a custom `.locked` file extension. In addition, a text file demanding payment in exchange for a decryption key has been placed in each affected directory. Which of the following malware types is most likely responsible for this activity?
- RansomwareAnswer
- BWorm
- CTrojan
- DRootkit
Answer
Ransomware is the malware type responsible for encrypting files and placing ransom notes.
The correct answer is Ransomware because the defining characteristics of ransomware include unauthorized encryption of user or system files followed by extortion demands (such as ransom text files) detailing payment instructions to retrieve decryption capabilities.
Step-by-Step Solution
Key Concept
Ransomware Indicators of Compromise