This website is an independent informational resource and is not affiliated with, endorsed by, or operated by Malwarebytes Inc.
Security

Ransomware Basics

Ransomware is one of the more disruptive categories of malware. Here's a general, plain-language explanation of what it is and how prevention tools typically try to stop it.

What ransomware does

Ransomware generally encrypts a victim's files, then demands payment in exchange for the decryption key needed to recover them.

How it commonly spreads

Common infection paths include malicious email attachments, compromised downloads, and exploiting unpatched software vulnerabilities.

Behavior-based prevention

Some security tools specifically watch for the kind of rapid, bulk file-encryption behavior ransomware exhibits, aiming to stop an attack mid-process rather than only recognizing known ransomware signatures.

Backups are a critical safety net

Regular, offline or disconnected backups are widely considered one of the most effective defenses, since they let you restore files without paying a ransom if prevention fails.

This is general educational information about ransomware, not specific incident-response guidance. If you believe a device is currently infected with ransomware, disconnect it from the network and consult official, current guidance or a security professional rather than relying solely on general background information.