Cyberlium

Malware › Module 2 › Lesson 2

BeginnerModule 2Lesson 2/5

Ransomware Named

Ransomware is named for defender and IR literacy — encryption impact, extortion, recovery — NO how-to encrypt or build ransomware.

15 min+40 XP3 quiz
Module progress2 of 5

Visual · mal_ransomware_named

Ransomware named — defender view. $MAL_LAB only. Original Cyberlium.

Opening

This lesson is IR and backup literacy — not encryption tutorials or ransomware builders.

Ransomware families encrypt or exfiltrate data then demand payment. Defenders respond with isolation, scope assessment, backup restore, and law enforcement/reporting per policy. IR playbooks name behaviors: mass file rename, shadow copy deletion, double extortion — mapped to detection and containment. Cyberlium explicitly does NOT teach how to encrypt files, build ransomware, or test lockers on unauthorized systems. You learn recognition and response literacy for $MAL_LAB reports. Next: Spyware/APT Named.

1. Ransomware behaviors defenders recognize

Mass file encryption with uniform extensions, ransom notes (README.txt), deletion of volume shadow copies, service stop lists, and C2 for key exchange or data leak sites. EDR and SIEM rules target these sequences — not student-built encryptors.

On $MAL_LAB, you may read public reports or static strings mentioning ransom notes — never deploy encryptors, even 'on your own files' outside controlled fixtures.

Command guide

Try these commands — Ransomware behaviors defenders recognize

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

ATT&CK software — https://attack.mitre.org/software/ (map families to techniques) Hybrid Analysis trends — https://www.hybrid-analysis.com/ (family report literacy)

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

mkdir -p "$HOME/cyberlium-lab/t22-mal/notes"
cat > "$HOME/cyberlium-lab/t22-mal/notes/families.txt" <<'EOF'
ransomware: encrypt + extort — defender focus
trojan: delivery + persistence — static IOCs
worm: self-propagate — network IOCs
EOF

Command — copy this

grep -E 'ransomware|trojan|worm' "$HOME/cyberlium-lab/t22-mal/notes/families.txt"
curl -sS https://attack.mitre.org/software/ | grep -oE 'S[0-9]{4}' | sort -u | head -8

Primary tools to practice this lesson: grep, curl. Reference sites: ATT&CK software (https://attack.mitre.org/software/); Hybrid Analysis trends (https://www.hybrid-analysis.com/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. IR response literacy (named steps)

Isolate affected hosts, preserve evidence, identify scope (lateral movement, backups touched), restore from clean backups, reset credentials, report per org policy. Communication templates warn users not to pay without legal/exec guidance.

Purple teams may simulate ransomware prep indicators in lab SIEM — still $MAL_LAB only with written lab policy, not live encryption of production or classmates.

3. Hard boundary: no encryption how-to

Forbidden: ransomware builders, encryption loop tutorials, 'test on roommate laptop,' or sharing locker source in chat. Allowed: name families from reports, document IOC types, and write defender checklist for IR.

Ship: ransomware defender checklist — five IR/detection items, zero encryption steps. Next: Spyware/APT Named.

4. What you ship: ransomware defender checklist (no encrypt how-to)

Five IR/detection items. Explicit NEVER builders/encryption tutorials. $MAL_LAB report context. chmod 600.

5. What you record before the next lesson

Date. Ransomware defender checklist. NEVER encrypt how-to. File t22-m02-l02-ransomware-named.txt chmod 600.

6. Wrong vs right: live malware on daily driver vs sandbox

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Download ransomware builder 'for analysis.' Write encrypt loop as homework.

  • Right

    Write ransomware defender/IR checklist — no encryption steps. Next: Spyware/APT Named.

Mission: document ransomware defender view

1) List five defender/IR recognition or response items. 2) Write NEVER builders/encryption tutorials line. 3) chmod 600. Never include encrypt implementation steps.

Stuck? Ask Cyberlium AI Mentor

Backups and isolation beat paying — IR literacy saves orgs.

Knowledge Check

1

APPLY: Ransomware Named on Cyberlium teaches:

Multiple choice

Knowledge Check

2

APPLY: True or False: Cyberlium allows ransomware builder tutorials for lab.

True or False

Knowledge Check

3

APPLY: Mass file rename + ransom note + shadow copy deletion suggests:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)