Information Technology Act, 2000
Ransomware vs Malware: Difference, Attack Lifecycle and the Law
The comparison is genus and species again, but with a twist that matters legally: ransomware is malware whose defining feature is not code but a business model, extortion. Where other malware steals, spies or disrupts, ransomware manufactures leverage, encrypting the victim's own data and selling it back, which is why its charge sheet always carries an offence the rest of the family rarely needs: extortion. Topics 104 and 105 built the family's internal distinctions; this note, as asked, covers its most consequential member.
1. Genus and the Extortion Species
Figure 1: The family and the hostage-taker
- Malware. The genus, defined by malicious purpose: viruses, worms, trojans, spyware, keyloggers, botnets, logic bombs and cryptojackers, each harming in its own way, theft, surveillance, disruption, stolen compute (Topic 104). The statutory home is the s.43 Explanation's computer contaminant, wide enough for the whole family.
- Ransomware. The species defined by method and demand: malware that encrypts files or locks systems and presents a ransom note, payment, in cryptocurrency, for the decryption key or unlocking. Its harm is engineered leverage: the victim's own data and operations held hostage, hospitals, ports, manufacturers and municipalities the classic targets because downtime is unaffordable.
- Every ransomware is malware. The one-way inclusion holds again: ransomware is always malware, but most malware demands nothing, and the demand is precisely what changes the legal analysis, adding an extortion offence to the intrusion offences the whole family shares.
2. The Attack Lifecycle
Figure 2: Five beats of a modern attack
- Entry to detonation. Entry through phishing, stolen credentials, exposed remote access or unpatched flaws, often with worm-style propagation; then preparation, privilege escalation, lateral spread, destruction of backups, and frequently exfiltration of the data before encryption; then detonation, the encryption event and the note.
- Double and triple extortion. Modern operations demand twice: pay for the key, and pay again or the exfiltrated data is leaked, with pressure on the victim's customers as the third turn; ransomware-as-a-service franchises the toolkit, splitting developer and affiliate, which the criminal law answers with conspiracy and abetment doctrine (s.84B, Topic 84)
- To pay or not. Indian law does not expressly criminalise paying a ransom, but payment funds crime, invites repetition and may engage other laws on the facts; CERT-In and enforcement practice discourage payment and require reporting either way, and sanctions exposure can arise where payees are designated entities, points best stated cautiously.
3. The Charge Sheet
- The intrusion core. Introducing the ransomware is s.43(c), the contaminant clause, with s.43(e), (f) and (i) for the disruption, denial and diminution it causes; done dishonestly or fraudulently, as it always is, it is the s.66 offence (Topics 53, 58)
- The extortion limb. The demand is BNS extortion, putting the victim in fear of injury to person, reputation or property to deliver property: the ransom note is the offence's own evidence, and the leak threat of double extortion fits the same frame.
- The escalations. Where essential services or critical information infrastructure are paralysed with the requisite intent, s.66F reaches life imprisonment; a notified protected system struck engages s.70's ten years; and the stolen data may add s.72A and DPDP consequences for the custodian's own defaults (Topics 60, 63, 87)
- The incident response. A ransomware incident is CERT-In reportable within six hours; forensics proceeds on images and hashes for the s.79A examination, and the cryptocurrency trail is chased through exchanges and the cooperation routes (Topics 64, 82, 86)
⚠ Exam trap Define ransomware by its demand, not its code: malware that encrypts or locks and then extorts, so the charge sheet always pairs the intrusion offences, s.43(c) with s.66, with BNS extortion for the note, and escalates through s.66F only where essential services or critical infrastructure are struck with terror-grade intent and consequence. Mention double extortion, exfiltrate first, then leak, because it is why breach and extortion charges now travel together, and remember the six-hour CERT-In clock runs from noticing the incident, unaffected by any ransom negotiation. |
4. Frequently Asked Questions
What distinguishes ransomware from other malware?
Its method and its demand. Malware is the whole family of malicious software, harming by theft, surveillance, disruption or hijacked resources; ransomware is the species that encrypts the victim's files or locks systems and demands payment, typically in cryptocurrency, for restoration, with modern operations exfiltrating data first and threatening its leak as a second lever. Every ransomware attack is malware, but the extortion demand is what sets its legal treatment apart, adding BNS extortion to the intrusion offences.
Which provisions apply to a ransomware attack in India?
Section 43(c) of the IT Act for introducing the contaminant, with Sections 43(e), (f) and (i) for the disruption and damage, Section 66 for the offence, and BNS extortion for the ransom demand. Where supplies or services essential to the life of the community are disrupted or critical information infrastructure is harmed with the requisite intent, Section 66F applies, reaching life imprisonment, and a notified protected system attacked engages Section 70. The incident must be reported to CERT-In within six hours, and the evidence is preserved by imaging and hashing for examination under Section 79A.
5. Related Topics
- Topic 104: Malware vs Virus. The genus this species belongs to.
- Topic 64: Section 70B CERT-In. The six-hour clock and directions.