🔄 Topic

Understanding how ransomware attacks work and why encryption is usually the final stage of a longer intrusion.


🎯 Goal

Learn the typical ransomware attack chain and identify where defenders can detect activity before files are encrypted.


🛠 What I Did

Today I studied ransomware attacks.

Ransomware is malware that encrypts files and demands payment for recovery.

Modern ransomware often goes beyond simple encryption.

Many groups now use double extortion:

  • steal data first
  • encrypt systems second
  • threaten to leak the stolen data if the victim refuses to pay

The important mental model is that encryption is usually not the beginning.

It is often the final visible stage.

A simplified ransomware chain:

initial access
    ↓
credential theft
    ↓
privilege escalation
    ↓
lateral movement
    ↓
data discovery
    ↓
data exfiltration
    ↓
encryption
    ↓
ransom demand

If defenders only detect the encryption stage, they are already very late.


🔗 Key Cybersecurity Connections

Ransomware investigations require looking earlier in the timeline.

Common initial access paths include:

  • phishing emails
  • stolen VPN credentials
  • exposed remote desktop
  • exploited public-facing applications
  • malware loaders
  • weak passwords
  • missing MFA

Before encryption, attackers may perform:

  • internal reconnaissance
  • domain discovery
  • privilege escalation
  • lateral movement
  • backup deletion
  • security tool tampering
  • data staging
  • exfiltration

This means ransomware defense is not only about detecting ransomware binaries.

It is about detecting the steps that happen before encryption.


🔍 Investigation Questions

  • How did the attacker get initial access?
  • Was phishing involved?
  • Were VPN or RDP credentials abused?
  • Was MFA enabled?
  • Which account was first compromised?
  • Did the attacker escalate privileges?
  • Did they move laterally?
  • Were backups accessed or deleted?
  • Was data staged before encryption?
  • Was there unusual outbound data transfer?
  • Which systems were encrypted first?
  • What was the earliest suspicious event?

🚨 Detection Opportunities

Possible detection ideas:

  • suspicious VPN login
  • impossible travel login
  • repeated failed logins followed by success
  • RDP access from unusual source
  • mass file rename activity
  • shadow copy deletion
  • backup tampering
  • security service stopped
  • large internal file transfers
  • archive files created in unusual locations
  • unusual outbound data transfer
  • ransomware note creation across many directories

Example suspicious pattern:

process=vssadmin.exe
command_line contains "delete shadows"
user=non_admin_expected_user
host=file_server
risk=high

Deleting shadow copies is a classic ransomware-related behavior.


🧭 MITRE ATT&CK Techniques

  • T1566 — Phishing
  • T1078 — Valid Accounts
  • T1021 — Remote Services
  • T1083 — File and Directory Discovery
  • T1486 — Data Encrypted for Impact
  • T1490 — Inhibit System Recovery
  • T1041 — Exfiltration Over C2 Channel

🗺 Visual Investigation Diagram

Initial access
    ↓
Credential abuse
    ↓
Lateral movement
    ↓
Data theft
    ↓
Backup deletion
    ↓
File encryption
    ↓
Ransom demand

⚠ Challenges

The main challenge is that ransomware is often detected too late.

Encryption is loud, but by that point the attacker may already have:

  • stolen data
  • compromised domain accounts
  • disabled backups
  • moved across the network
  • prepared the environment for maximum damage

Another challenge is that early-stage ransomware activity can look like normal administration.

For example, remote access tools, file transfers, and admin commands may be legitimate.

Context and baseline matter.


📚 What I Learned

I learned that ransomware is not just malware.

It is an intrusion campaign.

The encryption payload is only one piece.

A serious ransomware investigation must reconstruct the timeline from initial access to impact.

The most useful defensive goal is to detect the attacker before encryption starts.


➡ Next Steps

  • Study real ransomware case studies
  • Review common pre-ransomware behaviors
  • Learn detections for shadow copy deletion
  • Practice timeline reconstruction
  • Compare ransomware with destructive malware
  • Study WannaCry and NotPetya as historical incidents

🧠 Reflection

This topic changed how I think about ransomware.

The scary screen and ransom note are not the whole attack.

They are the final announcement.

The real security work is finding the quiet steps that came before.


🧩 Lessons Learned

What worked

Breaking ransomware into stages.

What broke

Thinking encryption is the main event from an investigation perspective.

Why it broke

Encryption is only the impact stage.

The attacker may have been active long before that.

Fix / takeaway

Investigate backwards from encryption to find initial access and earlier detection opportunities.


📈 Skill Progression Context

This supports SOC readiness because ransomware remains one of the most important real-world incident types.

Understanding the full attack chain helps with alert triage, incident response, timeline building, and detection engineering.


😄 TL;DR

Ransomware does not start when files get encrypted.

That is just when the attacker stops being quiet.