{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T15:53:18Z","timestamp":1780415598840,"version":"3.54.1"},"reference-count":29,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T00:00:00Z","timestamp":1762300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100019920","name":"Naif Arab University for Security Sciences","doi-asserted-by":"crossref","award":["NAUSS-23-R13"],"award-info":[{"award-number":["NAUSS-23-R13"]}],"id":[{"id":"10.13039\/100019920","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Ransomware attacks pose a serious threat to computer networks, causing widespread disruption to individual, corporate, governmental, and critical national infrastructures. To mitigate their impact, extensive research has been conducted to analyze ransomware operations. However, most prior studies have focused on decryption, post-infection response, or general family-level classification for performance evaluation, with limited attention to linking classification accuracy to each family\u2019s threat level and behavioral patterns. In this study, we propose a classification framework for the most dangerous ransomware families targeting Windows systems, correlating model performance with defined threat levels (high, medium, and low) based on API call patterns. Two independent datasets were used, extracted from VirusTotal and Cuckoo Sandbox, and a cross-source evaluation strategy was applied, alternating training and testing roles between datasets to assess generalization ability and minimize source bias. The results show that the proposed approach, particularly when using XGBoost and LightGBM, achieved accuracy rates ranging from 84 to 100% across datasets. These findings confirm the effectiveness of our method in accurately classifying ransomware families while accounting for their severity and behavioral characteristics.<\/jats:p>","DOI":"10.3390\/jcp5040096","type":"journal-article","created":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T17:06:06Z","timestamp":1762362366000},"page":"96","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Enhancing Ransomware Threat Detection: Risk-Aware Classification via Windows API Call Analysis and Hybrid ML\/DL Models"],"prefix":"10.3390","volume":"5","author":[{"given":"Sarah","family":"Alhuwayshil","sequence":"first","affiliation":[{"name":"Department of Cybersecurity and Digital Forensics, Center for Cybercrime and Economic Crime, Naif Arab University for Security Sciences, Riyadh 14253, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9650-8078","authenticated-orcid":false,"given":"Sundaresan","family":"Ramachandran","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity and Digital Forensics, Center for Cybercrime and Economic Crime, Naif Arab University for Security Sciences, Riyadh 14253, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5675-4253","authenticated-orcid":false,"given":"Kyounggon","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity and Digital Forensics, Center for Cybercrime and Economic Crime, Naif Arab University for Security Sciences, Riyadh 14253, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,5]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100665","DOI":"10.1016\/j.eij.2025.100665","article-title":"Cryptocurrency-driven ransomware syndicates operating on the darknet: A focused examination of the Arab world","volume":"30","author":"Kim","year":"2025","journal-title":"Egypt. Inform. J."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Beerman, J., Berent, D., Falter, Z., and Bhunia, S. (2023, January 1\u20134). A review of colonial pipeline ransomware attack. Proceedings of the 2023 IEEE\/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW), Bangalore, India.","DOI":"10.1109\/CCGridW59191.2023.00017"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1016\/j.compeleceng.2019.07.014","article-title":"Ransomware protection using the moving target defense perspective","volume":"78","author":"Lee","year":"2019","journal-title":"Comput. Electr. Eng."},{"key":"ref_4","unstructured":"Lin, Z., Cui, J., Liao, X., and Wang, X. (2024, January 14\u201316). Malla: Demystifying real-world large language model integrated malicious services. Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24), Philadelphia, PA, USA."},{"key":"ref_5","first-page":"857","article-title":"Securing Cloud-Encrypted Data: Detecting Ransomware-as-a-Service (RaaS) Attacks through Deep Learning Ensemble","volume":"79","author":"Singh","year":"2024","journal-title":"Comput. Mater. Contin."},{"key":"ref_6","first-page":"3401","article-title":"Ransomware Classification Framework Using the Behavioral Performance Visualization of Execution Objects","volume":"72","author":"Kim","year":"2022","journal-title":"Comput. Mater. Contin."},{"key":"ref_7","first-page":"3003","article-title":"An Asset-Based Approach to Mitigate Zero-Day Ransomware Attacks","volume":"73","author":"Azzedin","year":"2022","journal-title":"Comput. Mater. Contin."},{"key":"ref_8","first-page":"300979","article-title":"Evaluation of live forensic techniques in ransomware attack mitigation","volume":"33","author":"Davies","year":"2020","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"102377","DOI":"10.1016\/j.cose.2021.102377","article-title":"Differential area analysis for ransomware attack detection within mixed file datasets","volume":"108","author":"Davies","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Talukder, S. (2020). Tools and techniques for malware detection and analysis. arXiv.","DOI":"10.5121\/ijnsa.2020.12203"},{"key":"ref_11","first-page":"8845833","article-title":"Modified decision tree technique for ransomware detection at runtime through API calls","volume":"2020","author":"Ullah","year":"2020","journal-title":"Sci. Program."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"5357146","DOI":"10.1155\/2020\/6804290","article-title":"A novel malware classification method based on crucial behavior","volume":"2020","author":"Xiao","year":"2020","journal-title":"Math. Probl. Eng."},{"key":"ref_13","first-page":"138","article-title":"Lightgbm-based ransomware detection using api call sequences","volume":"12","author":"Nguyen","year":"2021","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_14","first-page":"3167","article-title":"Explainable Classification Model for Android Malware Analysis Using API and Permission-Based Features","volume":"76","author":"Aslam","year":"2023","journal-title":"Comput. Mater. Contin."},{"key":"ref_15","first-page":"2301","article-title":"An Effective Memory Analysis for Malware Detection and Classification","volume":"67","author":"Sihwail","year":"2021","journal-title":"Comput. Mater. Contin."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2215","DOI":"10.32604\/csse.2023.036555","article-title":"Augmenting Android Malware Using Conditional Variational Autoencoder for the Malware Family Classification","volume":"46","author":"Ban","year":"2023","journal-title":"Comput. Syst. Sci. Eng."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1424638","DOI":"10.1155\/2022\/1424638","article-title":"Digital forensics as advanced ransomware pre-attack detection algorithm for endpoint data protection","volume":"2022","author":"Du","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Schofield, M., Alicioglu, G., Binaco, R., Turner, P., Thatcher, C., Lam, A., and Sun, B. (2021, January 23\u201324). Convolutional neural network for malware classification based on API call sequence. Proceedings of the 8th International Conference on Artificial Intelligence and Applications (AIAP 2021), Zurich, Switzerland.","DOI":"10.5121\/csit.2021.110106"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Rabadi, D., and Teo, S.G. (2020, January 7\u201311). Advanced windows methods on malware detection and classification. Proceedings of the 36th Annual Computer Security Applications Conference, Virtual.","DOI":"10.1145\/3427228.3427242"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"337","DOI":"10.3233\/JCS-191346","article-title":"Multilayer ransomware detection using grouped registry key operations, file entropy and file signature monitoring","volume":"28","author":"Jethva","year":"2020","journal-title":"J. Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1504\/IJESDF.2023.131961","article-title":"Defence against crypto-ransomware families using dynamic binary instrumentation and DLL injection","volume":"15","author":"Sundaresan","year":"2023","journal-title":"Int. J. Electron. Secur. Digit. Forensics"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"110","DOI":"10.37934\/araset.39.2.110131","article-title":"Early detection of windows cryptographic ransomware based on pre-attack api calls features and machine learning","volume":"39","author":"Zakaria","year":"2024","journal-title":"J. Adv. Res. Appl. Sci. Eng. Technol."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Alhashmi, A.A., Darem, A.A., Alashjaee, A.M., Alanazi, S.M., Alkhaldi, T.M., Ebad, S.A., Ghaleb, F.A., and Almadani, A.M. (2023). Similarity-Based hybrid malware detection model using API calls. Mathematics, 11.","DOI":"10.3390\/math11132944"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Azhar, M.O., Oyshee, F.J., Monir, M.F., Khan, R.H., Ahmed, T., and Alam, K. (2024, January 7\u201310). Comparative Analysis of Machine Learning Models: Ransomware Severity Prediction Using MITRE Cyber Analytics Repository. Proceedings of the 2024 IEEE 100th Vehicular Technology Conference (VTC2024-Fall), Washington, DC, USA.","DOI":"10.1109\/VTC2024-Fall63153.2024.10757523"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Axali, J., Devereaux, L., Spencer, A., and Vasilev, F. (2024). A multicriteria decision-making approach for ransomware detection using mitre att&ck mitigation strategy. Authorea.","DOI":"10.22541\/au.172591117.70081883\/v1"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"103518","DOI":"10.1016\/j.cose.2023.103518","article-title":"CTIMD: Cyber threat intelligence enhanced malware detection using API call sequences with parameters","volume":"136","author":"Chen","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"104061","DOI":"10.1016\/j.cose.2024.104061","article-title":"MDADroid: A novel malware detection method by constructing functionality-API mapping","volume":"146","author":"Yang","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_28","unstructured":"Li, H. (2024, May 18). Ransomware Dataset (ransomwaredataset2016) Analyze. Kaggle. Available online: https:\/\/www.kaggle.com\/code\/stevenli1\/ransomware-dataset-ransomwaredataset2016-analyse\/data."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Lawall, A., and Beenken, P. (2024, January 5\u20136). A threat-led approach to mitigating ransomware attacks: Insights from a comprehensive analysis of the ransomware ecosystem. Proceedings of the 2024 European Interdisciplinary Cybersecurity Conference, New York, NY, USA.","DOI":"10.1145\/3655693.3661321"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/96\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T05:25:07Z","timestamp":1762493107000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/96"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,5]]},"references-count":29,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040096"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040096","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,5]]}}}