The notion of using public key cryptography for data kidnapping attacks was introduced in 1996 by Adam L. Young and Yung critiqued the failed AIDS Information Trojan that relied on symmetric cryptography alone, the fatal flaw being that the decryption key could be extracted from the Trojan, and implemented an experimental proof-of-concept cryptovirus on a Macintosh SE/30 that used RSA and the Tiny Encryption Algorithm (TEA) to hybrid encrypt the victim's data.Since public key crypto is used, the cryptovirus only contains the encryption key.

Young and Yung's original experimental cryptovirus had the victim send the asymmetric ciphertext to the attacker who deciphers it and returns the symmetric decryption key it contains to the victim for a fee.

Unlike the previous Gpcode Trojan, Win Lock did not use encryption.

Instead, Win Lock trivially restricted access to the system by displaying pornographic images, and asked users to send a premium-rate SMS (costing around US) to receive a code that could be used to unlock their machines.

They referred to these attacks as being "cryptoviral extortion", an overt attack that is part of a larger class of attacks in a field called cryptovirology, which encompasses both overt and covert attacks. Encrypting ransomware returned to prominence in late 2013 with the propagation of Crypto Locker—using the Bitcoin digital currency platform to collect ransom money.

In December 2013, ZDNet estimated based on Bitcoin transaction information that between 15 October and 18 December, the operators of Crypto Locker had procured about US million from infected users.

Its payload hid the files on the hard drive and encrypted only their names, and displayed a message claiming that the user's license to use a certain piece of software had expired.

