7 Main Functional Types of Ransomware in 2026

The seven functional types of ransomware are crypto, locker, double extortion, doxware, triple extortion, RaaS, and wiper. How each works and what stops it.
Published on
Monday, September 21, 2026
Updated on
September 18, 2026

The seven main functional types of ransomware in 2026 are crypto, locker, double extortion, doxware, triple extortion, Ransomware-as-a-Service, and wiper-based models. Each is defined by a distinct coercion method: cryptographic file locking, system-level denial, combined encryption and data exposure, threatened publication alone, multi-layer pressure, affiliate-based deployment, or irreversible destruction.

Classification here follows mechanism rather than brand name, because the same family shifts tactics between campaigns. CloudSEK’s technical dissection of the Gunra ransomware locker illustrates why: across Akira, Qilin, Royal, and DoNex, researchers found ChaCha20 paired with RSA-4096 as the prevailing hybrid scheme, with Rust-based Qilin builds using AES-256-CTR instead. Strain names change faster than the mechanics underneath them.

A single incident routinely combines two or three of these functional types at once, which is why defenders classify by how coercion works rather than by which group claimed the attack.

What Are the Main Functional Types of Ransomware?

There are seven functional types of ransomware active today, based on encryption behavior, extortion architecture, infrastructure control, and monetization structure.

ransomware categorized

1. Crypto Ransomware

Crypto ransomware encrypts files using hybrid cryptography, pairing a fast symmetric cipher with asymmetric key exchange so that only the attacker holds the private key. Textbook descriptions cite AES with RSA, and current families lean toward ChaCha20 with RSA-4096, which performs better on systems without hardware AES acceleration. Decryption keys are generated per victim and transmitted to attacker-controlled command-and-control infrastructure, the mechanism examined in detail under crypto ransomware.

File availability is restricted while system processes keep running. Victims see their files and cannot open them, and monetization depends entirely on the attacker retaining exclusive key control. LockBit remains the reference case, having relaunched with version 5.0 in September 2025 and resumed extortion across Windows, Linux, and ESXi environments within weeks of the law enforcement seizure that was meant to end it.

2. Locker Ransomware

Locker ransomware restricts access at the operating system level, blocking login interfaces, keyboard input, or the desktop environment. Payload execution modifies system processes or boot configuration to prevent interaction rather than touching file contents.

Data survives intact on the storage media in most cases, which changes the recovery calculation entirely. Coercion depends on device-level denial rather than cryptographic control, so a clean reimage restores the system without any decryption key. TorrentLocker is a documented variant, spreading through spam campaigns and blocking device access rather than encrypting individual files.

3. Double Extortion Ransomware

Double extortion exfiltrates data before encryption, transferring sensitive information to attacker infrastructure, where it is cataloged and staged for publication on a leak portal. Confidentiality loss becomes a second pressure mechanism alongside availability disruption, so a victim who restores cleanly from backup still faces publication, regulatory penalties, and contractual breach claims. Data theft before encryption is now standard practice across established operations rather than a differentiator, which is why ransomware threat intelligence tracks leak-site activity as closely as it tracks payloads.

Qilin ran a representative campaign in September 2025, compromising one managed service provider and using that access against 28 downstream organizations, 24 of them in South Korea’s financial sector, exfiltrating more than 2TB before encrypting anything. CloudSEK’s analysis of the Qilin ransomware operation covers the group’s tooling and targeting in depth, and the MSP route makes this simultaneously a third-party data breach for every downstream victim.

4. Doxware (Leakware)

Doxware, or leakware, uses threatened publication of stolen data as the primary coercion lever rather than as a supplement to encryption. Double extortion encrypts first and threatens exposure second. Doxware inverts that priority, and pure leakware campaigns skip encryption altogether.

Dropping the encryption stage removes both work and noise. There is no locker to build, no per-victim key management to run, and no mass file-write activity for endpoint tooling to flag, which shortens the window between intrusion and exfiltration. Cl0p ran its 2023 MOVEit campaign this way, extorting more than 2,700 organizations on the strength of stolen data alone without encrypting a single environment.

No amount of backup quality protects against this model. Restoration returns the systems and does nothing about the copy the attacker holds, so leverage survives a clean recovery intact. Organizations holding personal, medical, financial, or legal records face the most pressure, because the regulatory consequence of publication routinely exceeds the ransom, and every client whose records were caught in the same theft becomes an affected party in their own right.

5. Triple Extortion Ransomware

Triple extortion adds a third coercive layer beyond encryption and leak threats. Operators launch distributed denial-of-service attacks against victim infrastructure, or contact customers, partners, regulators, and journalists directly to escalate pressure from outside the negotiation.

Availability, confidentiality, and service continuity come under attack at the same time. Operational design integrates encryption payloads, leak infrastructure, and external disruption into one coordinated sequence, raising both technical recovery cost and reputational cost. REvil pioneered the DDoS layer, and direct victim-contact campaigns have since appeared across multiple groups including Cl0p and BlackCat.

6. Ransomware-as-a-Service (RaaS)

A structured affiliate ecosystem sits behind every RaaS operation. Developers maintain the malware, payment portals, negotiation panels, and decryption management dashboards, while affiliates gain ready-made payloads and distribution tooling in exchange for a revenue share. CloudSEK researchers documented the recruitment side directly when Gunra opened an affiliate program on a dark web forum in January 2026, having operated without one since May 2025.

Advertised affiliate shares cluster in the 70% to 90% range, with the highest splits used as recruitment leverage when a rival operation collapses and its affiliates go looking for a new platform. Infrastructure centralization allows rapid payload updates, campaign tracking, and automated negotiation, separating whoever wrote the malware from whoever deploys it. Payload type varies by affiliate, so a Ransomware-as-a-Service incident can present as crypto, double extortion, or a hybrid depending on who ran it.

7. Wiper-Based (Destructive) Ransomware

Wiper-based ransomware embeds destructive payloads that overwrite or corrupt data beyond recovery. Encryption routines, where present, are superficial and serve as a facade for irreversible damage, and ransom notes sometimes appear even though no decryption capability exists.

Where other models sell recovery, this one removes the possibility of it. NotPetya remains the clearest example, disguised as crypto-ransomware while functioning as a wiper, spreading from Ukraine into corporate systems worldwide and destroying data with no working decryption path. Attack objectives here align with sabotage or strategic disruption rather than ransom collection.

Ransomware Type Comparison

Coercion method, data impact, and recovery path separate the seven models more reliably than any strain name does.

Type Coercion Method Data Impact Recovery Path Example
Crypto Encryption via ChaCha20 or AES with RSA Files inaccessible, not exposed Decryption key or backup restore LockBit
Locker OS or device-level lockout Data intact in most cases Reimage or unlock TorrentLocker
Double Extortion Encryption plus data theft Files inaccessible and exposed Backup restore, leak risk remains Qilin
Doxware / Leakware Threatened publication of stolen data Data exposed, systems left intact No restore path for exposure, notification required Cl0p (MOVEit)
Triple Extortion Encryption, leak, plus DDoS or direct contact Files, data, and service availability all hit Backup restore, leak, and disruption risk remain REvil, Cl0p
RaaS Affiliate-deployed payload of any type above Depends on deployed payload Depends on deployed payload Gunra, Akira
Wiper Destructive overwrite Data permanently destroyed No decryption path, backup restore only NotPetya

How Common Is Each Ransomware Type in 2026?

Double extortion dominates current activity, to the point where encryption-only incidents have become the exception among established operations. Nearly every group running a leak site exfiltrates before encrypting, because stolen data preserves leverage after a victim restores from backup. A growing share go further and skip encryption entirely, running pure leakware campaigns that trade the noise of mass file writes for a quieter theft.

Fragmentation underneath that pattern comes from the RaaS model itself. Affiliate programs let one codebase serve dozens of unrelated operators, so the number of distinct brands posting victims keeps climbing while the number of underlying lockers stays comparatively small. Compromised remote-access credentials remain the leading entry route, which makes monitoring for leaked credentials more consequential than payload detection for most organizations.

Methods of getting the payload onto a machine shifted alongside the business model. CloudSEK’s TRIAD team documented an Epsilon Red campaign using fake ClickFix verification pages impersonating Discord, Twitch, and OnlyFans to trigger malicious HTA files through ActiveX, downloading the payload without a conventional attachment. Locker and wiper models remain comparatively rare, the first because reimaging defeats it and the second because destruction earns nothing.

Which Defense Matches Which Ransomware Type?

Defensive priority shifts with the functional type in play. Matching the control to the mechanism closes gaps that a single generic checklist leaves open.

  • Crypto ransomware. Immutable, offline backups tested on a fixed schedule. Restoration defeats the core mechanism, the withheld key, without payment.
  • Locker ransomware. Endpoint imaging and device management policies that support a fast, clean operating system reinstall.
  • Double extortion. Data loss prevention and outbound traffic monitoring that catch exfiltration during the window before encryption starts.
  • Doxware and leakware. Data classification and exfiltration detection, because backups protect nothing once files have left. Encryption at rest reduces what stolen data is worth.
  • Triple extortion. DDoS mitigation capacity alongside the double extortion controls, since one control layer cannot stop a multi-vector campaign.
  • RaaS-deployed attacks. Multi-factor authentication on every external-facing service, because affiliates enter through compromised credentials far more than through custom exploits.
  • Wiper-based attacks. Air-gapped backups, because destruction leaves no negotiation or decryption path to recover through.

Segmentation and verification apply regardless of which model lands. Network segmentation limits how far any payload travels after initial access, and zero trust verification at internal boundaries removes the implicit trust that makes lateral movement cheap. Awareness training against social engineering addresses the delivery stage that precedes every model on this list.

What Distinguishes These Functional Ransomware Types?

Separating one model from another comes down to coercion method, the security property attacked, infrastructure design, and monetization route.

  • Encryption control. Crypto ransomware depends on hybrid cryptography and private key retention through command-and-control infrastructure to restrict availability.
  • System denial. Locker ransomware blocks operating system access through interface or boot-level manipulation without necessarily encrypting stored data.
  • Data exposure. Double extortion combines encryption with exfiltration and leak portal publication, attacking confidentiality as well as availability.
  • Publication leverage. Doxware treats exposure as the primary lever rather than a supplement, and pure leakware drops encryption entirely, removing the locker and key management from the operation.
  • Multi-layer pressure. Triple extortion integrates encryption, public leak threats, and external disruption such as DDoS or direct stakeholder contact.
  • Affiliate architecture. RaaS runs on centralized developer infrastructure, affiliate dashboards, and revenue-sharing payment portals rather than a single-actor operation.
  • Destructive payload. Wiper-based ransomware prioritizes irreversible corruption, targeting integrity rather than recoverable monetization.

Recognizing which model is in play changes the response within the first hour. Encryption-only incidents turn on backup integrity, exfiltration-backed incidents turn on notification obligations and leak monitoring, and destructive incidents turn on rebuild capacity. A structured security threat assessment establishes which of these an environment is most exposed to before an incident forces the question.

Tracking Ransomware Operations with CloudSEK Threat Intelligence

Classification is useful only when it reflects what groups are doing now, and that changes faster than published taxonomies. CloudSEK Threat Intelligence tracks ransomware operators, their affiliates, exploited CVEs, leak site activity, and tooling across the surface, deep, and dark web, including affiliate recruitment posts on the forums where new programs launch.

Specificity in that tracking comes from original investigation rather than aggregated feeds. The Gunra dissection came from analyzing an affiliate recruitment post and the locker binary behind it, which produced encryption-scheme detail that generic feeds do not carry. Sector-tailored intelligence matters more than raw volume here, since knowing which operators target an industry shapes which defenses get funded first.

Detection, backup strategy, and incident response stay with the existing stack. External intelligence contributes the adversary context those controls cannot generate internally, alongside supply chain attack prevention for the MSP and vendor routes that turn one compromise into dozens.

Final Takeaway: Classifying Ransomware by Mechanism, Not Brand

Ransomware brands rebrand, disband, and reappear faster than any taxonomy tracks. Conti became Black Basta, Royal became BlackSuit, and affiliates move between platforms whenever a better revenue share appears, carrying their tradecraft with them. Classification by mechanism survives all of that, because encryption control, system denial, data exposure, and destruction describe what an attack does rather than who signed it, and that is what malware defenses actually respond to.

Practical value shows up during an incident. Identifying the functional type in the first hour determines whether the response centers on backup integrity, breach notification, DDoS capacity, or rebuild planning. Teams that classify by brand wait for attribution that never arrives; teams that classify by mechanism start acting immediately.

Frequently Asked Questions

Which ransomware type causes the most operational disruption?

Triple extortion. It combines encryption, data exposure, and DDoS or direct stakeholder contact, hitting availability, confidentiality, and business continuity simultaneously.

Is Ransomware-as-a-Service different from crypto ransomware?

Yes. RaaS is a deployment and monetization model. Crypto ransomware is an encryption-based coercion mechanism. RaaS platforms distribute crypto, double extortion, or hybrid payloads.

Can locker ransomware permanently damage data?

Rarely. Locker variants restrict system access without encrypting files, so data integrity survives unless a destructive payload is bundled alongside.

Why is double extortion considered more severe than encryption-only attacks?

It adds exfiltration and leak threats to encryption. Confidentiality loss creates regulatory and reputational exposure that persists after a successful backup restore.

How long do ransomware groups keep stolen data after payment?

Indefinitely in practice. Deletion cannot be verified, and groups have re-extorted victims months later using data they claimed to have destroyed.

Do ransomware groups reuse the same encryption code?

Frequently. Leaked builders and shared libraries mean unrelated brands ship near-identical lockers, which is why mechanism-based classification outlasts group names.

Does paying a ransom guarantee data recovery?

No. Decryptors are routinely incomplete or slow, and wiper-based attacks have no recovery path at all regardless of payment.

Related Posts
12 Common Cyber Attack Vectors You Should Know
Cyber attack vectors include phishing, compromised credentials, exposed software, API abuse, supply chain threats, and other paths attackers use for initial access.
What is Pastebin? Uses, Risks, and How It Works
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
What is Personally Identifiable Information (PII)?
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.