Like others have said, public/private key crypto can be used to achieve this, and fairly easy: The randomware is distributed with a public key, and after generating the AES key and encrypting the system, it then encrypts the AES key using the public key and removes all other copies of the AES key. Thus, nobody with access to the system can decrypt the system now unless they have the matching private key. If you pay to decrypt your system, the program sends off the encrypted AES key, and then they send back the decrypted AES key which they got by using the matching private key. And then from there you use the AES key to decrypt the rest of the system.
Perhaps the AES key is encrypted with RSA after encryption is complete and kept on the infected machine.
Hiding the key is unnecessary over engineering.
The end result is you see a file encrypted with a symmetric key.
private_key, public_key = keygen_rsa();
send_home(computer_id, private_key);
wipe(private_key);
for file in files {
aes_iv = ivgen_aes()
aes_key = keygen_aes()
encrypted_file = aes_ccm_encrypt(file, aes_iv, aes_key);
encrypted_aes_key = rsa_encrypt(aes_key, public_key);
wipe(aes_key);
filepos(file, 0);
write(file, aes_iv);
write(file, encrypted_aes_key);
write(file, encrypted_file);
} aes_key = keygen_aes()
crypted_aes_key = rsa_encrypt(MALWARE_PUB_KEY, aes_key)
for file in files:
content = read(file)
encrypted = aes_encrypt(content, aes_key)
write(file, encrypted)
wipe(aes_key)
display(RANSOM_NOTE, crypted_aes_key)
I'd assume all the details needed to decrypt the files EXCEPT for a small key would be stored in the encrypted file headers. The AES key could be encrypted to a given public key and then directly displayed to the victim. This means that the software doesn't really need to know how to send infoto the ransomware writers. Instead the victim would be responsible for contacting them.I think this is how PKE is usually done, precisely for the reasons you mention.
I think they encrypt the files with an AES key, which is then encrypted with a public key received from the botnet herder.