However, after detailed analysis, it is apparent in many cases that the ransomware functionality is just a ruse, and in reality, the malware is a wiper. There could be a couple of reasons to do this: As seen previously with Ordinypt, a sample can follow the ransomware business model without the intention to recover files.