Top Highlights
- Modern ransomware groups employ legitimate tools (e.g., Sliver, native admin tools) and compromised credentials to conduct stealthy, multi-stage intrusions over days, evading traditional signature detection.
- Attacks often start with VPN credential breaches, followed by reconnaissance, privilege escalation, lateral movement, and data exfiltration, culminating in encryption—highlighting missed early detection opportunities.
- Attackers utilize cloud services and legitimate infrastructure (e.g., VPS, Wasabi storage) for command and control, exfiltration, and anonymization, emphasizing the need for anomaly-based detection over signature-based methods.
The Threat, Attack Techniques, and Targets
Ransomware attacks are increasing worldwide. In May 2026, there were 698 incidents, a 48% rise from the previous year. Recently, the ransomware landscape has changed. Major groups like LockBit have been disrupted by law enforcement. Now, the ecosystem is more fragmented and includes smaller specialized groups. These groups often act as access brokers, affiliates, or developers.
Attack techniques are growing more diverse and less predictable. Adversaries are using native tools and legitimate frameworks to avoid detection. For example, attackers leverage tools like Sliver, which is originally used for testing and red teaming. They often gain entry through compromised VPN credentials and perform internal reconnaissance. Once inside, they use legitimate admin tools to move laterally across the network.
Targets include organizations’ internal network systems and data. They often focus on virtual private networks (VPNs), access points, and shared storage infrastructure. Attackers also attempt to exfiltrate data before encrypting it, commonly targeting cloud storage services like Wasabi. The use of legitimate tools and infrastructure makes predicting targets more difficult.
Impact, Security Implications, and Remediation Guidance
The impact of these attacks can be severe. They result in data encryption, business disruption, and potential data exfiltration. Attackers often operate over several days, giving defenders multiple chances to detect early signs.
Behavioral anomalies during reconnaissance, privilege escalation, and lateral movement can be detected early. For example, unusual port scans, high-volume internal connections, and suspicious use of admin tools are indicators of malicious activity. To reduce risks, organizations should monitor for anomalies in network activity and privileged access.
In this incident, the use of legacy protocols like SMBv1 contributed to lateral movement. Blocking or removing such protocols can prevent further spread. External communications to rare or suspicious endpoints, especially those mimicking C2 activity, should also be monitored and blocked.
If defenses detect suspicious activity, immediate actions include disabling compromised credentials and isolating affected devices. In this case, the fully implemented Autonomous Response feature might have disrupted the attack early. Organizations should ensure such automated defenses are fully configured across all systems.
For guidance, organizations should refer to their security vendor or authority. They can provide specific instructions on deploying behavioral detection, containment methods, and automated response tools. These proactive measures are crucial in stopping attacks before they escalate.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
