> From what I know, a symmetric key is more suitable to encrypting huge amounts of data.
Symmetric key encryption is more efficient, but the typical approach when using public key encryption with large files is to use symmetric key encryption, then encrypt the symmetric key with the public key, and then transmit that over the wire.
I imagine that the process used in this software is the following:
1. Generate symmetric key
2. Encrypt symmetric key using (known) public key (the private key remains on the malware owner's servers)
3. Delete the unencrypted symmetric key.
If these three steps are done before the user is told that their files have been held hostage, then by the time that they know they are infected, it's too late to do any analysis of the program, sniff memory, etc. (at best they'll be able to recover the public key and the encrypted symmetric key, which is useless without the corresponding private key). As soon as the ransom is paid, the malware owners will decrypt the symmetric key (using their private key), and send that back to the victim[0].
This could, of course, also use a different symmetric key for each file as well, in addition to the above.
[0] In theory, the malware owners don't even need to store anything per-victim, since the encrypted symmetric key can remain "safely" with the users the entire time. All they need to store is the single master private key.