The Global Menace: WannaCry
Think of WannaCry as a digital wildfire. In May 2017, it spread to over 230,000 computers across 150 countries in a single day. Unlike many ransomware attacks that rely on tricking a user into clicking a bad link, WannaCry was a worm. It actively hunted
for other vulnerable computers on a network using a leaked exploit called EternalBlue, which targeted a weakness in a Microsoft Windows protocol. Once on a machine, it encrypted files and demanded a $300 Bitcoin ransom. Its spread was indiscriminate and chaotic, famously crippling one-third of the UK's National Health Service hospitals, forcing ambulances to be rerouted and appointments to be canceled. While the attack was eventually halted by a researcher who found a 'kill switch' in its code, its legacy was clear: a single vulnerability could bring critical global infrastructure to its knees.
The Deceiver: NotPetya
Just a month after WannaCry, NotPetya appeared, and it was far more sinister. At first glance, it looked like another ransomware attack, even displaying a ransom note for $300. But this was a disguise. Security experts quickly realized that NotPetya was not designed to make money; it was a state-sponsored "wiper" malware created to destroy data permanently. There was no way to get the files back, even if you paid. The attack was primarily aimed at Ukraine, where it spread through a compromised accounting software update, crippling banks, government agencies, and even the radiation monitoring system at the Chernobyl nuclear power plant. But like WannaCry, it escaped, causing an estimated $10 billion in global damages and hitting multinational corporations like shipping giant Maersk and pharmaceutical company Merck, which reported losses in the hundreds of millions. NotPetya was a geopolitical weapon dressed up as a simple crime.
The Business Franchise: REvil
If WannaCry was chaos and NotPetya was destruction, REvil was pure business. Active from 2019 to early 2022, this group operated on a Ransomware-as-a-Service (RaaS) model. The core REvil developers created and maintained the malicious software, then leased it out to affiliates who carried out the attacks. The profits were then split, allowing the operation to scale massively. REvil's affiliates were known for targeting high-profile companies and pioneering the "double extortion" tactic. Before encrypting a victim's files, they would first steal a copy of the sensitive data. Then they would demand a ransom for the decryption key and a separate ransom to prevent the stolen data from being leaked publicly on their 'Happy Blog' site. This method was used in major attacks on meat supplier JBS and software firm Kaseya, demonstrating a sophisticated, corporate-style approach to cybercrime.
The Evolution: Conti and Double Extortion
The criminal tactics seen with REvil didn't disappear; they evolved with groups like Conti. Conti also operated a RaaS model and perfected the double extortion method. Its affiliates would gain access through common methods like phishing emails or exploiting insecure remote desktop software, steal massive amounts of data, and then encrypt the victim's network. The group became notorious for targeting critical infrastructure, including a devastating attack on Ireland's health system. In these double extortion schemes, victims face an impossible choice: pay to restore operations or pay to prevent a catastrophic data breach. This evolution shows that ransomware isn't just about locking files anymore; it's about weaponizing a company's own sensitive information against it, putting reputation and customer trust on the line.













