Key Takeaways

  • PentestMag’s course uses Go exercises to explain, at a high level, how ransomware combines AES and RSA encryption.
  • The material is intended for controlled, authorized red-team labs rather than real-world ransomware deployment.
  • Security leaders can use the concepts to improve detection engineering, response planning, and cross-platform resilience.

PentestMag has introduced a course that uses Go programming exercises to examine how ransomware can combine AES and RSA encryption. The course places malware-development concepts inside a controlled educational setting, giving authorized red teams and security practitioners a closer look at the mechanics defenders may encounter during an intrusion.

That distinction matters. Encryption code has legitimate uses across business technology, while ransomware operators apply similar cryptographic building blocks to deny access to data and pressure victims. A responsible course can explain the architecture without providing a deployment playbook, particularly when exercises are confined to isolated systems with synthetic files, no external connectivity, and explicit authorization.

At a conceptual level, ransomware commonly uses a hybrid encryption design. Symmetric encryption such as AES can process large volumes of data efficiently. Asymmetric encryption such as RSA can then protect the symmetric key, leaving the victim without the private key needed for recovery. PentestMag’s Go exercises introduce this relationship and the underlying encryption concepts, helping learners recognize why file-encryption behavior can move quickly once a payload executes.

Go is a timely language for that discussion. It supports compilation across operating systems and is increasingly relevant to threats aimed at mixed Windows, Linux, and virtualization estates. Google Cloud Threat Intelligence reported that the number of ransomware families observed running on both Windows and Linux doubled in 2025 compared with 2024. RansomHub payloads have reportedly used Golang and C++, while Mandiant’s 2025 observations included REDBIKE, AGENDA, and INC ransomware.

Understanding an encryption routine is only one slice of ransomware readiness. An intrusion generally begins earlier, through an exploited vulnerability, stolen credentials, exposed remote access, or another foothold. Sophos found that exploited vulnerabilities were the leading reported technical root cause in 32% of ransomware incidents during 2025. Among organizations whose data was encrypted, 49% paid a ransom.

That creates a practical question for security teams: what should they gain from controlled malware-development education? The useful outcome is not a working extortion tool. It is stronger visibility into suspicious file access, rapid encryption patterns, unusual key handling, process execution, privilege escalation, and attempts to impair backups or recovery services.

The threat has also moved beyond encryption alone. Suspected data theft accompanied approximately 77% of ransomware intrusions investigated in 2025, up from 57% in 2024, according to Google Cloud Threat Intelligence. A lab focused only on file modification could therefore miss much of the modern attack sequence, including discovery, credential access, lateral movement, staging, and exfiltration.

ENISA analyzed 4,875 cybersecurity incidents from July 2024 through June 2025. Its findings highlighted the continued industrialization of ransomware-as-a-service, including affiliate operations and leaked builder tools. ENISA also reported that ransomware deployment represented 40% of financially motivated cyber events analyzed for 2025. LockBit remains a prominent example of the ransomware-as-a-service model.

Training governance is therefore part of the story. PentestMag course exercises should be conducted with written authorization, tightly restricted lab accounts, disposable virtual machines, test-only data, network isolation, and clear teardown procedures. Organizations can also review course content before use and log lab activity. These controls reduce the chance that experimental code escapes its intended environment or is repurposed outside an approved assessment.

The broader research environment is changing too. The Cloud Security Alliance has examined how AI-assisted development could accelerate ransomware variant proliferation. That trend raises the value of behavioral detection because defenders may face frequent code changes even when the attacker’s objectives remain familiar.

For business leaders, PentestMag’s course is most useful when connected to measurable defensive work. Teams can map observed behaviors to MITRE ATT&CK, then use NIST Cybersecurity Framework 2.0 to organize governance, protection, detection, response, and recovery activities. The final test is straightforward: does the lab help the organization detect encryption activity sooner, contain affected systems, protect backups, and rehearse recovery? If so, controlled exposure to ransomware mechanics can translate into practical resilience without normalizing offensive deployment.