An accountant reports that every document on her workstation now has an unfamiliar extension and will not open, and a full-screen message demands payment in cryptocurrency to restore access to the files. Which type of malware best fits this behavior?
Ransomware is malware designed to encrypt files on a device so they become unusable, after which the actors demand a ransom in exchange for decryption, matching the encrypted documents and cryptocurrency demand described.
- AThis guess fixes on data theft, but spyware is software secretly installed to covertly gather information without the user's knowledge, not to encrypt files and openly demand a payment to restore them.
- BThis choice assumes stealthy persistence, yet a rootkit conceals an attacker's activity and maintains privileged access; it does not lock files behind encryption and post a visible ransom demand.
- DThis option focuses on rapid spreading, but a worm is defined by self-propagation across networks; encrypting local files and demanding payment is not what characterizes a worm by itself.