Offline ransomware emerged in early 2015, notably characterized by its ability to encrypt files on a victim's system without requiring an active internet connection or communication with a command-and-control (C&C) server, which is an external server used by attackers to manage their malware. This ransomware variant operates by locally generating encryption keys, eliminating the typical network-based key exchange and allowing it to function effectively in isolated or air-gapped network environments. Its primary motivation is financial extortion, with attackers demanding payment for decryption. A distinguishing feature of this ransomware is its implementation using Pascal-based languages and Delphi for its core encryption routines, alongside a Visual Basic compiled protector for its payload. Symantec has identified specific versions of this ransomware under the alias Ransomcrypt.U.