The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires
The history of ransomware stretches from a peculiar 1989 postal campaign to today's sophisticated criminal ecosystem featuring affiliate programs, access brokers, leak sites, technical support, and professional negotiators. In 1989, victims were instructed to mail $189 to a Panamanian post office box. By 2021, REvil demanded $70 million for a universal decryptor after compromising Kaseya VSA. By 2026, ransomware had evolved from odd mailings into a structured criminal market.
1989: Floppy disks, a biologist, and the first ransom
In autumn 1989, thousands of scientists and medical workers received floppy disks labeled “AIDS Information Introductory Diskette v2.0.” The mailing targeted participants of the 1988 International AIDS Conference in Stockholm and subscribers to journals such as PC Business World. Estimates range from 20,000 to 26,000 disks distributed. After 90 system reboots, the program hid directories and renamed files on drive C:, rendering documents inaccessible while leaving data intact. A message demanded $189 sent to PC Cyborg Corporation in Panama. The author, Harvard-educated evolutionary biologist Joseph Popp, was arrested but never stood trial after psychiatric evaluation found him unfit. The underlying idea survived its creator.
2000s: Cryptography moves to criminals
The concept remained largely theoretical until the internet became widespread and cryptographic libraries accessible. Early GPCode variants around 2004–2005 used weak symmetric encryption that researchers could break. By 2008, GPCode.ak employed 1024-bit RSA, making brute-force impractical. Archiveus in 2006 introduced full asymmetric encryption by archiving files and demanding purchases from a specific online pharmacy; operators were quickly identified and the password leaked.
2012–2014: Psychology, Bitcoin, and the first industrial model
Reveton (2012) blocked the screen and impersonated law enforcement, displaying localized warnings from the FBI, German BKA, or UK Police Central e-Crime Unit. CryptoLocker (September 2013) combined RSA-2048 encryption, the Gameover Zeus botnet, and Bitcoin payments at scale.
2016–2017: National-scale impact
Petya (2016) overwrote the MBR and encrypted the MFT, preventing system boot. WannaCry (May 2017) used the leaked EternalBlue exploit (MS17-010) to spread autonomously, affecting over 200,000 systems in 150 countries and forcing the UK NHS to cancel operations. Researcher Marcus Hutchins halted it by registering a kill-switch domain. NotPetya (June 2017) masqueraded as ransomware but functioned as a wiper, causing an estimated $10 billion in damage including $300 million to Maersk and $870 million to Merck; it originated via a compromised M.E.Doc update and combined EternalBlue with Mimikatz.
2018–2020: Professionalization
Groups such as Ryuk used Trickbot and Emotet for initial access, spent weeks mapping networks, destroyed backups, then deployed encryptors. Maze popularized double extortion in 2019 by exfiltrating data before encryption and threatening leaks. The Ransomware-as-a-Service model emerged, with developers taking 20–30% of ransoms and affiliates handling attacks. Access brokers began selling corporate entry points.
2021: Peak big-game hunting
DarkSide hit Colonial Pipeline, causing six-day fuel shortages; the company paid $4.4 million. REvil targeted JBS Foods for $11 million and later compromised Kaseya VSA, demanding $70 million. The FBI obtained a decryptor key without payment.
2022–2024: Major operations and brand resilience
LockBit conducted over 2,000 attacks since 2020, earning at least $120 million. Operation Cronos seized its infrastructure in 2024, yet the brand re-emerged. ALPHV/BlackCat infrastructure was disrupted in late 2023; the group was later linked to the Change Healthcare incident. Cl0p exploited MOVEit Transfer in 2023. Newer actors include Akira, Qilin, and Lynx.
2025–2026: Market fragmentation and new targets
The FBI IC3 report for 2025 recorded 3,600+ ransomware complaints and $32 million+ in stated losses, plus 63 new variants. Frequent names include Akira, Qilin, INC/Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SafePay, and Medusa. Medusa uses timers on leak sites and sells publication delays. Akira now targets virtual disks on Nutanix AHV, VMware ESXi, and Hyper-V. ENISA and Europol reports note continued use of known vulnerabilities, affiliate collaboration, privacy coins, and AI-assisted reconnaissance and phishing.
Why the model remains resilient
RaaS, access brokers, and role specialization lower attack costs. Double and triple extortion combine encryption, data leaks, customer notifications, regulatory pressure, and DDoS. Bitcoin and privacy coins facilitate payments, though blockchain analytics increasingly enable seizures. Victims in healthcare, manufacturing, and critical infrastructure often pay to avoid downtime.
AI assistance and minimum defenses
Generative AI aids reconnaissance, phishing text, and document analysis but does not autonomously execute full attacks. Recommended protections include isolated, immutable, tested backups following the 3-2-1 rule; MFA on all remote access; timely patching; network segmentation; EDR/XDR monitoring; and pre-established incident response plans.
Related articles
Ukrainian Developer of LockerGoga, MegaCortex and Nefilim Ransomware Sentenced to 12 Years and Nine Months
A 52-year-old Ukrainian national has been sentenced by the Zurich District Court to 12 years and nine months in prison for his role as the lead developer of the LockerGoga, MegaCortex and Nefilim ransomware strains. The court determined that the malware he created was deployed against companies across dozens of countries, causing approximately 100 million Swiss francs in damages in the cases examined. Notable victims included train manufacturer Stadler Rail, which suffered the theft of around 500 GB of confidential data and a $6 million ransom demand in 2020, as well as climate equipment supplier Meier Tobler and banking software developer Crealogix. The defendant claimed he was performing ordinary cybersecurity consulting and was unaware of the intended use of his code, but investigators found ransom demand templates alongside the source code, undermining his defense. He has been in custody since October 2021 as part of a wider international investigation into attacks affecting more than 1,800 individuals and organizations in 71 countries. Upon release he will be banned from entering Switzerland for ten years, although the verdict remains subject to appeal.
Android Ransomware Mantax Otax Encrypts Files and Streams Victim Screen in Real Time
Researchers at Zimperium have identified a new Android ransomware strain called Mantax Otax that combines file encryption with live screen recording and surveillance capabilities. The malware is distributed through sideloaded APK files delivered via messaging apps and phishing messages rather than official app stores. Once installed, it uses AES encryption to lock files with the .enc extension and conducts ransom negotiations directly on the infected device through an on-screen chat interface. In addition to encryption, Mantax Otax continuously captures the screen, saves footage as MP4 video, and streams it to operators while also photographing the surroundings with the device camera. The malware abuses accessibility services to read on-screen content, intercepts SMS messages to steal two-factor authentication codes, and exfiltrates contacts, call logs, browser history, and credentials from WhatsApp and Telegram. It also displays a fake lock screen to capture the device PIN. Impact is reduced on Android 10 and later due to Scoped Storage restrictions, though surveillance functions remain active. Evidence points to a targeted campaign against users in Indonesia.
IT Elements 2026 Conference: Ransomware Accounts for 69% of Incidents as Businesses Struggle with Backup Protection and AI Workloads
The fourth IT Elements conference opened in Moscow on September 9, focusing on business continuity after cyberattacks, infrastructure failures, and ransomware incidents. Jet CSIRT data showed that ransomware was responsible for 69% of confirmed incidents in the first half of 2026, with the majority occurring in the second quarter. Experts discussed the challenges of protecting backup copies from compromise, the frequent gap between stated RTO targets and real-world recovery times, and decision-making processes during major outages. The event also covered corporate AI agents, stressing the need for strong Data Governance, Data Quality, and DataOps practices to avoid unreliable model outputs. Research from Jet Infosystems and AC IKS revealed that over 30% of companies have already allocated dedicated network segments for AI workloads, with power demands reaching 80-200 kW per rack. On the networking track, testing of Eltex and EcoRouter devices showed adequate performance in standard scenarios but highlighted the lack of a universal domestic solution. The conference concluded with discussions on workforce changes, noting that AI is altering career paths for junior specialists and increasing demand for professionals who understand business context and can critically evaluate model results.
Ransomware Operators Linked to The Gentlemen Deploy TukTuk C2 Framework for Espionage and Credential Theft
Operators associated with the ransomware group The Gentlemen have adopted a new command-and-control framework called TukTuk to steal credentials, monitor compromised systems, and prepare environments for ransomware deployment. The framework was discovered on a server that also hosted tools for disabling EDR solutions, research on vulnerable drivers, and data apparently stolen from two large organizations. TukTuk includes agents for both Windows and Linux, along with its own backend and management panel that allows remote command execution, file transfers, screen capture, and device tracking through a single interface. One notable feature displays a fake Windows Security window on the victim's machine to capture entered credentials and send them directly to the attackers' panel. Researchers identified a DLL sideloading technique that abuses the legitimate Greenshot.exe executable to load a malicious log4net.dll library and launch the TukTuk agent. The server also contained EDRKiller, WarsawKiller, and UnknownKiller tools, plus materials on BYOVD attacks that leverage vulnerable legitimate drivers to gain kernel access and interfere with security products.