How Modern Ransomware Actually Works

Ransomware is rarely a single event. Understanding the stages before encryption is where the defensive opportunity lives.

Encryption is the last step, not the attack

The moment files become unreadable is the end of the attack, not the beginning. By then an intruder has typically been present for days or weeks. That dwell time is the defensive opportunity: every stage before encryption is a chance to detect and interrupt.

The typical sequence

  • Initial access through phishing, exposed remote access, unpatched internet-facing services, or credentials bought from a broker
  • Persistence, so access survives reboots and password changes
  • Privilege escalation toward administrative accounts
  • Lateral movement to map the environment and locate valuable systems
  • Targeting backups, because recoverable backups remove the leverage
  • Data theft before encryption, enabling extortion even if you can restore
  • Encryption, usually timed for evenings, weekends, or public holidays

Why extortion changed the calculation

Reliable backups used to be a fairly complete answer. Attackers adapted by stealing data first, then threatening publication. Restoring from backup solves availability but does nothing about a threatened leak of customer records. Under POPIA and similar regimes, that leak is also a reportable breach with regulatory consequences.

Some groups add further pressure by contacting customers, partners, or regulators directly.

What genuinely reduces risk

  • Offline or immutable backups an intruder with administrator rights cannot delete
  • Multi-factor authentication on all remote access, which closes a large share of initial access
  • Prompt patching of internet-facing systems, prioritised by known active exploitation
  • Network segmentation, so one compromised machine does not expose the whole estate
  • A tested recovery plan, because untested backups fail at the worst possible moment
  • Detection tuned for the middle stages, particularly unusual privilege use and mass file access

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist