What is crypto ransomware?

Crypto ransomware is a type of malicious software (malware) that encrypts a victim’s files and demands a cryptocurrency ransom—most often Bitcoin—in exchange for the decryption key needed to restore access. It is the dominant and most damaging form of malware-based extortion, and the demand for payment in cryptocurrency is what gives it its name.

The “crypto” in the name refers to two things working together: the cryptography that locks the victim’s data, and the cryptocurrency used to collect the ransom. Once the malicious code executes, it uses strong asymmetric encryption (such as RSA) to scramble files, then displays a ransom note demanding payment to a crypto wallet by a deadline. Crypto ransomware should not be confused with crypto malware like cryptojacking, which secretly mines cryptocurrency rather than extorting a ransom.

Because the ransom is paid in cryptocurrency, crypto ransomware sits at the intersection of cybersecurity and financial crime. Attackers choose crypto for its speed and pseudonymity—but every payment is recorded on a public blockchain, making blockchain analytics one of the most effective tools for tracing ransom funds and identifying the groups behind attacks.

How does crypto ransomware work?

A crypto ransomware attack typically unfolds in four stages:

  1. Infection. The malware reaches a victim through an attack vector such as a phishing email, a malicious attachment, or compromised remote access. Once executed, the malicious code establishes a foothold.
  2. Encryption. Using asymmetric encryption, the ransomware locks files, databases, and sometimes entire systems, producing encrypted files that are unrecoverable without the attacker’s private decryption key.
  3. Ransom demand. A ransom note appears, explaining what happened and demanding a cryptocurrency ransom payment—often with a countdown timer to pressure the victim.
  4. Payment and (possible) decryption. Victims who pay send Bitcoin or another cryptocurrency to a wallet controlled by the attackers. Paying does not guarantee a working decryption key, and it may invite repeat attacks.

Modern operators frequently add double extortion: stealing data before encrypting it and threatening to publish it on a dark web leak site—turning the attack into a data breach—unless paid. This gives attackers leverage even over victims who have offline backups.

How does crypto ransomware spread?

Ransomware reaches victims through several common attack vectors:

  • Phishing emails and social engineering that trick users into opening a malicious attachment or link—the most common entry point.
  • Remote Desktop Protocol (RDP), where attackers exploit weak or stolen credentials, sometimes via a brute force attack.
  • Software vulnerabilities and exploits, such as the EternalBlue exploit used by WannaCry.
  • Drive-by downloads and botnets that deliver malicious software automatically from compromised sites.

What are the types of ransomware?

Ransomware generally falls into a few categories:

  • Crypto (encrypting) ransomware. The most common type, which encrypts files and demands payment for the decryption key. CryptoLocker was an influential early example.
  • Locker ransomware. Locks a victim out of their device or system entirely rather than encrypting individual files.
  • Scareware. Fake security software or alarming pop-ups that pressure victims into paying for a non-existent problem.
  • Doxware (leakware). Threatens to publish stolen data unless paid—the core of double extortion.

What are notable crypto ransomware variants?

Several families have shaped the threat landscape, many operating as crypto ransomware that demands payment in Bitcoin:

  • CryptoLocker — an early, influential encrypting ransomware that popularized crypto ransom demands.
  • WannaCry and Petya / NotPetya — fast-spreading 2017 outbreaks; NotPetya functioned as a destructive wiper.
  • Locky and Ryuk — high-impact families targeting enterprises and healthcare.
  • REvil (Sodinokibi), DarkSide, Conti, Maze, Hive, LockBit, BlackCat, Dharma, Black Basta, and Phobos — prolific operations run by professional threat actors, many offered as ransomware as a service.

What is ransomware as a service (RaaS)?

Ransomware-as-a-service (RaaS) is a cybercrime business model that mirrors legitimate software-as-a-service (SaaS). Instead of building malware themselves, RaaS operators—the ransomware developers—lease ready-made ransomware tools and RaaS kits to affiliates, who carry out the actual ransomware attacks. This division of labor has dramatically lowered the technical barrier to entry and fueled its explosion.

RaaS operations are run like businesses, advertised on the dark web. The RaaS ecosystem includes several revenue models:

  • Affiliate programs and profit-sharing, where affiliates keep a percentage of each ransom and the developers take a cut.
  • Monthly subscription or one-time fee access to the ransomware kits.
  • Leak sites used to pressure victims through double extortion, and access brokers who sell the initial network access that affiliates use.

Major RaaS operations have included LockBit, REvil, DarkSide, Hive, and Conti, and new RaaS groups emerge as older ones are disrupted. Because ransom payments flow in cryptocurrency, blockchain analytics can map the financial relationships between operators and affiliates—turning the RaaS profit-sharing model into a trail investigators can follow.

Why does crypto ransomware use cryptocurrency?

Attackers demand cryptocurrency because it can move quickly across borders without a bank intermediary, and because wallet addresses are pseudonymous rather than tied directly to a name. Bitcoin remains the most common ransom currency.

This is also the attackers’ greatest weakness. Public blockchains record every transaction permanently, so once investigators identify a ransom wallet, they can trace the flow of funds—following payments through exchanges, mixers, and the dark web. Far from being untraceable, these ransom payments leave a permanent on-chain trail.

How big is the crypto ransomware problem?

It is among the most financially damaging categories of cybercrime, causing billions in financial losses through ransom payments, downtime, and recovery. According to Chainalysis research, ransomware payments reached a record of roughly $1.1 billion in 2023 before falling by about 35% to approximately $813 million in 2024—a decline researchers attribute to more victims refusing to pay, stronger defenses, and law enforcement disruption of major RaaS groups.

$813M+

Cryptocurrency paid to ransomware attackers in 2024, according to Chainalysis—down from a record of more than $1 billion the prior year as more victims declined to pay.

How can you prevent and respond to ransomware?

A layered defense dramatically reduces the risk:

  • Maintain offline backups that let you restore systems without paying.
  • Harden access with multi-factor authentication (MFA), secured or disabled RDP, VPNs, firewalls, and least-privilege access controls.
  • Patch and segment. Keep systems updated to close vulnerabilities, and use network segmentation to limit lateral spread.
  • Deploy modern defenses. Endpoint protection and endpoint detection and response (EDR/XDR), along with SIEM monitoring, data security controls, and threat intelligence, help detect and block attacks early.
  • Plan ahead. A tested incident response plan—including how to engage law enforcement—shortens recovery when an attack occurs.

Authorities generally discourage paying ransoms, because payment funds further crime, may violate sanctions if the group is designated, and does not guarantee data recovery.

How are crypto ransomware payments traced?

When a ransom is paid, the transaction becomes part of the permanent blockchain record. Investigators use blockchain analytics to trace the payment from the victim to the attackers’ wallets, follow attempts to launder funds through mixers and exchanges, and identify the off-ramps where criminals cash out.

This has produced real results. After the 2021 Colonial Pipeline attack by the DarkSide RaaS group, the U.S. Department of Justice traced and recovered roughly $2.3 million of the Bitcoin ransom—proof that on-chain transparency can turn a ransom payment into an investigative lead. Blockchain tracing also supports sanctions designations against these operators, cutting off their ability to cash out.

How Chainalysis helps fight crypto ransomware

Chainalysis provides the blockchain intelligence that law enforcement, government agencies, and cybersecurity teams use to investigate crypto ransomware and disrupt the groups behind it.

  • Chainalysis Reactor lets investigators trace ransomware payments across blockchains, map the infrastructure of ransomware as a service (RaaS) operations, and build evidence—analysis validated under the Daubert standard in U.S. courts.
  • Chainalysis KYT helps exchanges and financial institutions detect and block ransomware-linked funds in real time by screening transactions for exposure to known ransomware wallets.
  • The Chainalysis Crypto Crime Report tracks ransomware payment trends year over year, giving defenders and policymakers the data to respond.

Together, these tools turn the cryptocurrency that makes this crime possible into the evidence that helps dismantle it.

Frequently asked questions about crypto ransomware

Q: What is crypto ransomware?

A: Crypto ransomware is malware that encrypts a victim’s files and demands a cryptocurrency ransom—usually Bitcoin—in exchange for the decryption key. It is the most common and damaging form of ransomware, named for its use of both cryptographic encryption and cryptocurrency payment.

Q: What is the difference between crypto ransomware and crypto malware?

A: Crypto ransomware encrypts files and extorts a cryptocurrency ransom for their release. Crypto malware more broadly includes threats like cryptojacking, which secretly uses a victim’s device to mine cryptocurrency without demanding a ransom. Both involve crypto, but only ransomware holds data hostage.

Q: What is ransomware as a service (RaaS)?

A: Ransomware-as-a-service (RaaS) is a cybercrime business model in which developers lease ransomware tools to affiliates in exchange for a share of the ransom, much like software-as-a-service. RaaS lowers the barrier to launching attacks and is behind many major operations, including LockBit, REvil, and DarkSide.

Q: Can crypto ransomware payments be traced?

A: Yes. Because ransom payments are made in cryptocurrency recorded on public blockchains, investigators use blockchain analytics to trace funds from the victim to the attackers and the exchanges where they cash out. In the 2021 Colonial Pipeline case, the DOJ recovered about $2.3 million of the ransom this way.

Q: Should you pay a ransomware ransom?

A: Authorities generally advise against paying. Payment does not guarantee a working decryption key, it funds further criminal activity, and it may violate sanctions if the group is designated. Maintaining offline backups is the best way to avoid having to pay.

See how Chainalysis helps investigators trace illicit funds and disrupt crypto crime.

Request a demo.

Chainalysis helps investigators fight crypto ransomware by tracing ransom payments across blockchains, mapping ransomware as a service networks, and screening transactions for exposure to known ransomware wallets in real time.