🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
The seven main functional types of ransomware in 2026 are crypto, locker, double extortion, doxware, triple extortion, Ransomware-as-a-Service, and wiper-based models. Each is defined by a distinct coercion method: cryptographic file locking, system-level denial, combined encryption and data exposure, threatened publication alone, multi-layer pressure, affiliate-based deployment, or irreversible destruction.
Classification here follows mechanism rather than brand name, because the same family shifts tactics between campaigns. CloudSEK’s technical dissection of the Gunra ransomware locker illustrates why: across Akira, Qilin, Royal, and DoNex, researchers found ChaCha20 paired with RSA-4096 as the prevailing hybrid scheme, with Rust-based Qilin builds using AES-256-CTR instead. Strain names change faster than the mechanics underneath them.
A single incident routinely combines two or three of these functional types at once, which is why defenders classify by how coercion works rather than by which group claimed the attack.
There are seven functional types of ransomware active today, based on encryption behavior, extortion architecture, infrastructure control, and monetization structure.

Crypto ransomware encrypts files using hybrid cryptography, pairing a fast symmetric cipher with asymmetric key exchange so that only the attacker holds the private key. Textbook descriptions cite AES with RSA, and current families lean toward ChaCha20 with RSA-4096, which performs better on systems without hardware AES acceleration. Decryption keys are generated per victim and transmitted to attacker-controlled command-and-control infrastructure, the mechanism examined in detail under crypto ransomware.
File availability is restricted while system processes keep running. Victims see their files and cannot open them, and monetization depends entirely on the attacker retaining exclusive key control. LockBit remains the reference case, having relaunched with version 5.0 in September 2025 and resumed extortion across Windows, Linux, and ESXi environments within weeks of the law enforcement seizure that was meant to end it.
Locker ransomware restricts access at the operating system level, blocking login interfaces, keyboard input, or the desktop environment. Payload execution modifies system processes or boot configuration to prevent interaction rather than touching file contents.
Data survives intact on the storage media in most cases, which changes the recovery calculation entirely. Coercion depends on device-level denial rather than cryptographic control, so a clean reimage restores the system without any decryption key. TorrentLocker is a documented variant, spreading through spam campaigns and blocking device access rather than encrypting individual files.
Double extortion exfiltrates data before encryption, transferring sensitive information to attacker infrastructure, where it is cataloged and staged for publication on a leak portal. Confidentiality loss becomes a second pressure mechanism alongside availability disruption, so a victim who restores cleanly from backup still faces publication, regulatory penalties, and contractual breach claims. Data theft before encryption is now standard practice across established operations rather than a differentiator, which is why ransomware threat intelligence tracks leak-site activity as closely as it tracks payloads.
Qilin ran a representative campaign in September 2025, compromising one managed service provider and using that access against 28 downstream organizations, 24 of them in South Korea’s financial sector, exfiltrating more than 2TB before encrypting anything. CloudSEK’s analysis of the Qilin ransomware operation covers the group’s tooling and targeting in depth, and the MSP route makes this simultaneously a third-party data breach for every downstream victim.
Doxware, or leakware, uses threatened publication of stolen data as the primary coercion lever rather than as a supplement to encryption. Double extortion encrypts first and threatens exposure second. Doxware inverts that priority, and pure leakware campaigns skip encryption altogether.
Dropping the encryption stage removes both work and noise. There is no locker to build, no per-victim key management to run, and no mass file-write activity for endpoint tooling to flag, which shortens the window between intrusion and exfiltration. Cl0p ran its 2023 MOVEit campaign this way, extorting more than 2,700 organizations on the strength of stolen data alone without encrypting a single environment.
No amount of backup quality protects against this model. Restoration returns the systems and does nothing about the copy the attacker holds, so leverage survives a clean recovery intact. Organizations holding personal, medical, financial, or legal records face the most pressure, because the regulatory consequence of publication routinely exceeds the ransom, and every client whose records were caught in the same theft becomes an affected party in their own right.
Triple extortion adds a third coercive layer beyond encryption and leak threats. Operators launch distributed denial-of-service attacks against victim infrastructure, or contact customers, partners, regulators, and journalists directly to escalate pressure from outside the negotiation.
Availability, confidentiality, and service continuity come under attack at the same time. Operational design integrates encryption payloads, leak infrastructure, and external disruption into one coordinated sequence, raising both technical recovery cost and reputational cost. REvil pioneered the DDoS layer, and direct victim-contact campaigns have since appeared across multiple groups including Cl0p and BlackCat.
A structured affiliate ecosystem sits behind every RaaS operation. Developers maintain the malware, payment portals, negotiation panels, and decryption management dashboards, while affiliates gain ready-made payloads and distribution tooling in exchange for a revenue share. CloudSEK researchers documented the recruitment side directly when Gunra opened an affiliate program on a dark web forum in January 2026, having operated without one since May 2025.
Advertised affiliate shares cluster in the 70% to 90% range, with the highest splits used as recruitment leverage when a rival operation collapses and its affiliates go looking for a new platform. Infrastructure centralization allows rapid payload updates, campaign tracking, and automated negotiation, separating whoever wrote the malware from whoever deploys it. Payload type varies by affiliate, so a Ransomware-as-a-Service incident can present as crypto, double extortion, or a hybrid depending on who ran it.
Wiper-based ransomware embeds destructive payloads that overwrite or corrupt data beyond recovery. Encryption routines, where present, are superficial and serve as a facade for irreversible damage, and ransom notes sometimes appear even though no decryption capability exists.
Where other models sell recovery, this one removes the possibility of it. NotPetya remains the clearest example, disguised as crypto-ransomware while functioning as a wiper, spreading from Ukraine into corporate systems worldwide and destroying data with no working decryption path. Attack objectives here align with sabotage or strategic disruption rather than ransom collection.
Coercion method, data impact, and recovery path separate the seven models more reliably than any strain name does.
Double extortion dominates current activity, to the point where encryption-only incidents have become the exception among established operations. Nearly every group running a leak site exfiltrates before encrypting, because stolen data preserves leverage after a victim restores from backup. A growing share go further and skip encryption entirely, running pure leakware campaigns that trade the noise of mass file writes for a quieter theft.
Fragmentation underneath that pattern comes from the RaaS model itself. Affiliate programs let one codebase serve dozens of unrelated operators, so the number of distinct brands posting victims keeps climbing while the number of underlying lockers stays comparatively small. Compromised remote-access credentials remain the leading entry route, which makes monitoring for leaked credentials more consequential than payload detection for most organizations.
Methods of getting the payload onto a machine shifted alongside the business model. CloudSEK’s TRIAD team documented an Epsilon Red campaign using fake ClickFix verification pages impersonating Discord, Twitch, and OnlyFans to trigger malicious HTA files through ActiveX, downloading the payload without a conventional attachment. Locker and wiper models remain comparatively rare, the first because reimaging defeats it and the second because destruction earns nothing.
Defensive priority shifts with the functional type in play. Matching the control to the mechanism closes gaps that a single generic checklist leaves open.
Segmentation and verification apply regardless of which model lands. Network segmentation limits how far any payload travels after initial access, and zero trust verification at internal boundaries removes the implicit trust that makes lateral movement cheap. Awareness training against social engineering addresses the delivery stage that precedes every model on this list.
Separating one model from another comes down to coercion method, the security property attacked, infrastructure design, and monetization route.
Recognizing which model is in play changes the response within the first hour. Encryption-only incidents turn on backup integrity, exfiltration-backed incidents turn on notification obligations and leak monitoring, and destructive incidents turn on rebuild capacity. A structured security threat assessment establishes which of these an environment is most exposed to before an incident forces the question.
Classification is useful only when it reflects what groups are doing now, and that changes faster than published taxonomies. CloudSEK Threat Intelligence tracks ransomware operators, their affiliates, exploited CVEs, leak site activity, and tooling across the surface, deep, and dark web, including affiliate recruitment posts on the forums where new programs launch.
Specificity in that tracking comes from original investigation rather than aggregated feeds. The Gunra dissection came from analyzing an affiliate recruitment post and the locker binary behind it, which produced encryption-scheme detail that generic feeds do not carry. Sector-tailored intelligence matters more than raw volume here, since knowing which operators target an industry shapes which defenses get funded first.
Detection, backup strategy, and incident response stay with the existing stack. External intelligence contributes the adversary context those controls cannot generate internally, alongside supply chain attack prevention for the MSP and vendor routes that turn one compromise into dozens.
Ransomware brands rebrand, disband, and reappear faster than any taxonomy tracks. Conti became Black Basta, Royal became BlackSuit, and affiliates move between platforms whenever a better revenue share appears, carrying their tradecraft with them. Classification by mechanism survives all of that, because encryption control, system denial, data exposure, and destruction describe what an attack does rather than who signed it, and that is what malware defenses actually respond to.
Practical value shows up during an incident. Identifying the functional type in the first hour determines whether the response centers on backup integrity, breach notification, DDoS capacity, or rebuild planning. Teams that classify by brand wait for attribution that never arrives; teams that classify by mechanism start acting immediately.
Triple extortion. It combines encryption, data exposure, and DDoS or direct stakeholder contact, hitting availability, confidentiality, and business continuity simultaneously.
Yes. RaaS is a deployment and monetization model. Crypto ransomware is an encryption-based coercion mechanism. RaaS platforms distribute crypto, double extortion, or hybrid payloads.
Rarely. Locker variants restrict system access without encrypting files, so data integrity survives unless a destructive payload is bundled alongside.
It adds exfiltration and leak threats to encryption. Confidentiality loss creates regulatory and reputational exposure that persists after a successful backup restore.
Indefinitely in practice. Deletion cannot be verified, and groups have re-extorted victims months later using data they claimed to have destroyed.
Frequently. Leaked builders and shared libraries mean unrelated brands ship near-identical lockers, which is why mechanism-based classification outlasts group names.
No. Decryptors are routinely incomplete or slow, and wiper-based attacks have no recovery path at all regardless of payment.
