SecuritylabAugust 31, 2026🇷🇺Translated from Russian

The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires

The history of ransomware stretches from a peculiar 1989 postal campaign to today's sophisticated criminal ecosystem featuring affiliate programs, access brokers, leak sites, technical support, and professional negotiators. In 1989, victims were instructed to mail $189 to a Panamanian post office box. By 2021, REvil demanded $70 million for a universal decryptor after compromising Kaseya VSA. By 2026, ransomware had evolved from odd mailings into a structured criminal market.

1989: Floppy disks, a biologist, and the first ransom

In autumn 1989, thousands of scientists and medical workers received floppy disks labeled “AIDS Information Introductory Diskette v2.0.” The mailing targeted participants of the 1988 International AIDS Conference in Stockholm and subscribers to journals such as PC Business World. Estimates range from 20,000 to 26,000 disks distributed. After 90 system reboots, the program hid directories and renamed files on drive C:, rendering documents inaccessible while leaving data intact. A message demanded $189 sent to PC Cyborg Corporation in Panama. The author, Harvard-educated evolutionary biologist Joseph Popp, was arrested but never stood trial after psychiatric evaluation found him unfit. The underlying idea survived its creator.

2000s: Cryptography moves to criminals

The concept remained largely theoretical until the internet became widespread and cryptographic libraries accessible. Early GPCode variants around 2004–2005 used weak symmetric encryption that researchers could break. By 2008, GPCode.ak employed 1024-bit RSA, making brute-force impractical. Archiveus in 2006 introduced full asymmetric encryption by archiving files and demanding purchases from a specific online pharmacy; operators were quickly identified and the password leaked.

2012–2014: Psychology, Bitcoin, and the first industrial model

Reveton (2012) blocked the screen and impersonated law enforcement, displaying localized warnings from the FBI, German BKA, or UK Police Central e-Crime Unit. CryptoLocker (September 2013) combined RSA-2048 encryption, the Gameover Zeus botnet, and Bitcoin payments at scale.

2016–2017: National-scale impact

Petya (2016) overwrote the MBR and encrypted the MFT, preventing system boot. WannaCry (May 2017) used the leaked EternalBlue exploit (MS17-010) to spread autonomously, affecting over 200,000 systems in 150 countries and forcing the UK NHS to cancel operations. Researcher Marcus Hutchins halted it by registering a kill-switch domain. NotPetya (June 2017) masqueraded as ransomware but functioned as a wiper, causing an estimated $10 billion in damage including $300 million to Maersk and $870 million to Merck; it originated via a compromised M.E.Doc update and combined EternalBlue with Mimikatz.

2018–2020: Professionalization

Groups such as Ryuk used Trickbot and Emotet for initial access, spent weeks mapping networks, destroyed backups, then deployed encryptors. Maze popularized double extortion in 2019 by exfiltrating data before encryption and threatening leaks. The Ransomware-as-a-Service model emerged, with developers taking 20–30% of ransoms and affiliates handling attacks. Access brokers began selling corporate entry points.

2021: Peak big-game hunting

DarkSide hit Colonial Pipeline, causing six-day fuel shortages; the company paid $4.4 million. REvil targeted JBS Foods for $11 million and later compromised Kaseya VSA, demanding $70 million. The FBI obtained a decryptor key without payment.

2022–2024: Major operations and brand resilience

LockBit conducted over 2,000 attacks since 2020, earning at least $120 million. Operation Cronos seized its infrastructure in 2024, yet the brand re-emerged. ALPHV/BlackCat infrastructure was disrupted in late 2023; the group was later linked to the Change Healthcare incident. Cl0p exploited MOVEit Transfer in 2023. Newer actors include Akira, Qilin, and Lynx.

2025–2026: Market fragmentation and new targets

The FBI IC3 report for 2025 recorded 3,600+ ransomware complaints and $32 million+ in stated losses, plus 63 new variants. Frequent names include Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay, and Medusa. Medusa uses timers on leak sites and sells publication delays. Akira now targets virtual disks on Nutanix AHV, VMware ESXi, and Hyper-V. ENISA and Europol reports note continued use of known vulnerabilities, affiliate collaboration, privacy coins, and AI-assisted reconnaissance and phishing.

Why the model remains resilient

RaaS, access brokers, and role specialization lower attack costs. Double and triple extortion combine encryption, data leaks, customer notifications, regulatory pressure, and DDoS. Bitcoin and privacy coins facilitate payments, though blockchain analytics increasingly enable seizures. Victims in healthcare, manufacturing, and critical infrastructure often pay to avoid downtime.

AI assistance and minimum defenses

Generative AI aids reconnaissance, phishing text, and document analysis but does not autonomously execute full attacks. Recommended protections include isolated, immutable, tested backups following the 3-2-1 rule; MFA on all remote access; timely patching; network segmentation; EDR/XDR monitoring; and pre-established incident response plans.

Related articles

HabrRansomware & Extortion

Ragnarök: F6 Investigates VantaCore Ransomware Attacks and Suspected Thor Rebrand

F6's Digital Forensics Laboratory has identified a new ransomware group called VantaCore that has struck at least seven Russian organizations with multimillion-dollar ransom demands. Researchers assess VantaCore as a rebrand of the previously known pro-Ukrainian Thor group, part of a broader consolidation among such actors in 2025–2026. The group abandoned LockBit 3 Black and Babuk in favor of its own VantaCore ransomware built on similar foundations, while deploying custom tools including VantaCoreLoader, VantaCoreRAT, and the SnowKiller BYOVD utility. VantaCore maintains a Tor-based data leak site launched no later than June 2026 and uses double and triple extortion tactics, selling or publicly releasing stolen data after encryption. Initial access relies on exposed RDP, VPN, public application vulnerabilities, and compromised partner credentials, followed by lateral movement via legitimate accounts and SMB/RDP. The group disables security products, clears logs, and destroys backups using Bootice before deploying its ChaCha20/X25519 ransomware via manual RDP sessions or automated loaders.

BoletimSecRansomware & Extortion

Ransomware Group TITAN Deploys Local AI on AMD EPYC Servers to Accelerate Stolen Data Analysis

The TITAN ransomware group has announced the integration of an on-premises artificial intelligence platform designed to process up to 700 GB of exfiltrated data per hour. Operating as a ransomware-as-a-service model since May 2026, TITAN combines file encryption with data theft and has already published 24 victims across 10 countries. Manufacturing and professional services firms account for 29 percent of the targeted organizations. The AI system runs locally on AMD EPYC servers with GPU acceleration and automatically classifies financial documents, legal records, personal data, trade secrets, and intellectual property. It further identifies information with high reputational or regulatory impact, maps corporate and personal relationships, and estimates potential penalties under data-protection laws. The group also claims the platform can generate automated notifications to regulators and media outlets to intensify extortion pressure.

AntiMalwareRansomware & Extortion

VantaCore Ransomware Group Targets Russian Businesses with Custom Toolkit and Triple Extortion

Security researchers at F6 have identified a new ransomware operation called VantaCore that is actively attacking small and medium-sized Russian companies. The group employs a custom set of tools including VantaCoreLoader, VantaCoreRAT, and its own encryption malware to conduct double and triple extortion campaigns. Initial access is gained through poorly secured RDP and VPN services, vulnerable public applications, and compromised partner accounts. Once inside the network, attackers move laterally using SMB and RDP with legitimate credentials, deploy Tactical RMM, and install their backdoor before disabling security products with an AV/EDR killer. Victims face data theft, backup destruction, and encryption, followed by threats to publish or sell stolen information if ransom demands in the millions of dollars are not met. F6 assesses that VantaCore may be a rebranded version of the previously known pro-Ukrainian group Thor, based on similar Tor negotiation chat design and a THOR rune icon on the leak site that appeared no later than June 7, 2026.

安全客Ransomware & Extortion

Boston Scientific Hit by Cyber Attack: Global IT Outage Disrupts Orders and Shipments, Shares Drop

On August 25, Boston Scientific detected a cyber attack that compromised parts of its IT infrastructure, leading to widespread network interruptions across its global operations. The medical device giant, which generates over $16 billion in annual revenue and operates in more than 130 countries, saw customer order processing and product shipments halted in multiple regions. Wall Street Journal and Reuters reported the incident on August 26, after which the company's stock declined. While China operations remained unaffected due to regional system isolation, the company stated that full global recovery timelines remain unknown. The attack's specific methods, including any potential ransomware involvement or data exfiltration, have not been disclosed as third-party investigators continue their work. The event underscores the severe operational and patient-care risks when healthcare supply chains face cyber disruptions.