skip to content

A ransom note on unreadable files: what actually decides ransomware versus a wiper?

level: juniorimportance: must knowfreq 55%

answer

  1. ask who still holds a key
  2. the note costs the operator nothing
  3. per-victim key escrow versus none kept
  4. identifier random, not derived from a key
  5. overwrite and discarded key look identical

basics

~20 s

Whether anyone still holds a key that can reverse it. Ransomware keeps a per-victim key to sell back; a wiper overwrites data or generates a key and throws it away. The note is decoration and costs the operator nothing.

solid answer

~50 s

The classification turns on key management, not on the note. An extortion payload only works as a business if a per-victim key survives somewhere the operator can reach — that is the product being sold. A destructive payload either overwrites data in place or encrypts it with a key that is never transmitted and never stored, so nobody, including its author, can reverse it. On the first morning the two are indistinguishable: files will not open, a note is on the desktop. What separates them is evidence about the key — is the victim identifier actually derived from key material or is it random bytes, does the payload contact anything before encrypting, does the contact channel answer, has any other victim of this payload recovered. A note is a few hundred bytes of text; treating it as proof that a decryptor exists is the mistake that costs the first day.

go deeper

for a junior

Be ready to say in one sentence that the difference is whether a usable key still exists, and that a note is not evidence of one. Know that a destroyer can encrypt too.

for a middle

Explain the key-escrow architecture an extortion payload needs — per-victim key, wrapped with an embedded public key — and why a destroyer can skip all of it and still produce identical-looking ciphertext.

for a senior

Show that you treat the two possible errors asymmetrically: always preserve a copy of the ciphertext and a sample because it is cheap, never pause a rebuild on the strength of a note because that is what the note is for.

for a principal

Own the framing you give non-technical leadership: the event is classified by key management, not by the note, and the cost of getting it wrong is measured in outage hours rather than in the demanded sum.

## The question behind the question An interviewer asking this is testing one thing: do you classify a destructive event by its **symptom** or by its **economics**? The symptom — files that will not open, plus a note demanding payment — is shared by two payload classes whose consequences could not be more different. The thing that separates them is invisible on the victim's screen: whether a key that can undo the damage still exists anywhere in the world. ## Why extortion needs a key and destruction does not Extortion is a sale. The seller must be able to deliver, at least often enough that future victims believe delivery is possible — a crew that never decrypts stops getting paid within weeks. So an extortion payload is built around key escrow: it typically generates a random symmetric key per victim (often per file), encrypts that key with a public key embedded in the sample, and leaves the wrapped key behind or transmits it. Only the matching private key, held by the operator, can unwrap it. The whole architecture exists so that one party — and only one — can reverse the damage on demand. A destructive payload has no such constraint, because there is no sale. It has two common shapes: - **Overwrite in place.** Write a fixed pattern, or random bytes, over file contents, over filesystem metadata, or over whole devices. There is no key because there is no ciphertext. - **Encrypt and discard.** Generate a key, encrypt, then never store or transmit it — let it die with the process. This is often cheaper to write than a careful overwrite loop, it runs at whatever speed the crypto library manages, and to the victim it produces exactly the same ciphertext-looking rubbish that extortion produces. That second shape is the one that catches people. "The files are encrypted, therefore a decryptor exists" does not follow. Encryption is trivially available to a destroyer; **key retention** is the expensive, deliberate, business-motivated part, and a destroyer skips it. ## Why a destroyer writes a note anyway Because it is free and it buys time. A note redirects the first hours of the response into evaluating payment: reading the note, valuing the demand, finding someone who can move funds, asking counsel, contacting the address. Those are hours not spent rebuilding — and for an actor whose success is measured in downtime rather than revenue, extending the outage *is* the objective, so the note is a second stage of the payload. A note also misdirects attribution toward criminal extortion and away from an actor with a political objective, which shapes how the victim talks about the event publicly. The canonical demonstration is the 2017 destructive outbreak known as NotPetya, which presented a conventional ransom note with a single payment address and a contact mailbox. The victim identifier it displayed was random data rather than anything derived from key material, so no key could be looked up from it; the mailbox was shut down almost immediately. Every property required for a sale was missing, while every property required for a plausible note was present. ## What the classification changes It changes what you do with the next day, not just how you label the event: | If it is extortion | If it is destruction | | --- | --- | | A decryptor is a possible recovery path, with a price and a delay | Rebuilding from clean media is the only path | | Preserving ciphertext preserves an option | Preserving ciphertext preserves a sample, nothing more | | Time spent negotiating may be time well spent | Time spent negotiating is the payload working as designed | The useful posture is that the two errors are not symmetric. Preserving one untouched copy of the ciphertext and one copy of the payload costs almost nothing, so you always do it. Pausing the rebuild in order to evaluate a payment costs the thing that is most scarce, so you do not do it on the strength of a note. ## The honest edge case Intent and effect can diverge. Extortion payloads have shipped with broken key handling — keys never transmitted, identifiers that do not map to anything, contact infrastructure seized or abandoned — leaving victims with data that is unrecoverable even though the crew fully intended to sell it back. So the sharper framing is not "which family is this" but "is there any reachable key". That question has an answer you can pursue; the family name does not.

  • If the operator kept no key, why bother writing a note at all?
    Because it is a few hundred bytes and it buys hours. The note pushes the victim into valuing a demand, finding funds and contacting an address instead of rebuilding, and for an actor whose success is measured in downtime that delay is part of the payload. It also steers the public story toward criminal extortion and away from a political objective.
  • Can a payload be extortion in intent but destruction in effect?
    Yes, and it has happened repeatedly. Keys that are generated but never transmitted, victim identifiers that map to nothing, and contact infrastructure that is seized or abandoned all leave data unrecoverable while the crew fully expected to sell it back. That is why the operative question is whether any key is reachable, not which family the sample belongs to.
  • A hacktivist crew posts screenshots and claims it wiped a utility. How much does the claim change your reading?
    Very little on its own. For an actor optimising for attention the claim is the product, so scope is routinely overstated and unrelated damage is adopted. What the payload did on your own hosts decides the classification; the claim only tells you what the actor wants believed, which is useful for predicting whether more noise follows.

A ransom note proves someone wanted the door locked. It does not prove a key was ever cut. If no key was cut, paying the locksmith changes nothing about the door.

saying these in an interview costs you the question

  • A ransom note means payment can restore the data
  • Encrypted files imply a decryptor exists somewhere
  • Wipers only overwrite; they never use encryption
  • A criminal-looking note proves the motive was money
  • Classification can wait until the rebuild is finished

context