Usually, private individuals are not the target of ransomware attacks by organized criminals. Companies often have to pay a lot more money to get their data back. The Petya ransomware is a good example of this.
Nevertheless, when you are on any machine as an intruder and have normal user rights, you can still actively search the machine and network for admin accounts and steal sessions. The ultimate goal is to gain Domain Admin rights.
Besides that, it is not necessary to have admin rights to delete and encrypt data or to run and hide software.
There are also many ways, besides stealing sessions, to gain admin rights, such as through unpatched software, inappropriate user rights, zero-day exploits, and social engineering.
A common way to get users to install malware or ransomware is to bundle it with useful software that the user wants to install.
Nevertheless, when you are on any machine as an intruder and have normal user rights, you can still actively search the machine and network for admin accounts and steal sessions. The ultimate goal is to gain Domain Admin rights.
Besides that, it is not necessary to have admin rights to delete and encrypt data or to run and hide software.
There are also many ways, besides stealing sessions, to gain admin rights, such as through unpatched software, inappropriate user rights, zero-day exploits, and social engineering.
A common way to get users to install malware or ransomware is to bundle it with useful software that the user wants to install.