Ransomware Protection
How Ransomware Attacks Work: Anatomy of a Modern Attack
Modern ransomware attacks follow a multi-stage kill chain: initial access via phishing or exploited vulnerabilities, persistence through backdoors and credential theft, lateral movement across the network, data exfiltration for double extortion, and finally simultaneous encryption of all accessible systems with a ransom demand.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
The Modern Ransomware Kill Chain
Today's ransomware attacks bear little resemblance to the simple encryption malware of a decade ago. Modern attacks are multi-stage, human-operated campaigns that unfold over days or weeks before the encryption payload deploys. Understanding each stage reveals where defenses can interrupt the attack.
Stage 1: Initial Access (Day 0)
Attackers must first gain a foothold in your environment. The most common methods:
- Phishing emails remain the #1 initial access vector. Attackers send targeted emails with malicious attachments (weaponized Office documents, PDFs) or links to credential-harvesting sites. Spear phishing — targeting specific individuals with personalised lures — can succeed even in security-aware organisations.
- Exploited vulnerabilities in internet-facing systems are the second most common vector. VPN appliances (Fortinet, Pulse Secure, Citrix), remote desktop services, email servers (Exchange), and web applications with known unpatched vulnerabilities are prime targets. Attackers scan the internet continuously for vulnerable systems and often exploit new CVEs within hours of disclosure.
- Compromised credentials purchased from initial access brokers on dark web marketplaces. These brokers specialise in breaching organisations and selling access. Credentials from previous data breaches, password spraying, and brute-force attacks also provide entry.
- Supply chain attacks compromise trusted software or service providers to gain access to their customers. The SolarWinds and Kaseya attacks demonstrated how a single supply chain compromise can affect thousands of organizations simultaneously.
Stage 2: Establishing Persistence (Days 1-3)
After gaining initial access, attackers establish multiple persistence mechanisms to ensure they maintain access even if the initial entry point is discovered:
- Creating new user accounts or modifying existing ones
- Installing web shells on internet-facing servers
- Deploying legitimate remote access tools (AnyDesk, TeamViewer) for backup access
- Creating scheduled tasks or modifying startup scripts
- Deploying command-and-control (C2) implants like Cobalt Strike beacons
Simultaneously, attackers begin credential harvesting — dumping credentials from memory (Mimikatz), extracting from the Windows credential store, or performing Kerberoasting attacks against Active Directory.
Stage 3: Lateral Movement (Days 3-14)
Armed with stolen credentials, attackers move across the network:
- Active Directory compromise. The primary target. Gaining domain administrator credentials gives attackers access to virtually every system in the network. Tools like BloodHound map AD relationships to find the fastest path to domain admin.
- Internal reconnaissance. Attackers map the network — identifying file servers, databases, backup systems, and security tools. They prioritize systems containing valuable data and identify backup infrastructure to target.
- Privilege escalation. Moving from standard user to local admin to domain admin, exploiting misconfigured permissions, unpatched local vulnerabilities, and weak service account passwords.
- Security tool evasion. Sophisticated attackers may disable or tamper with endpoint protection, delete security logs, and modify monitoring configurations to avoid detection.
Stage 4: Data Exfiltration (Days 7-21)
Before encrypting, modern ransomware groups steal data for double extortion:
- Customer databases, financial records, employee data, intellectual property
- Data is compressed and transferred to attacker-controlled infrastructure
- Exfiltration methods include cloud storage (Mega, OneDrive), FTP, and custom tools
- Data volumes can reach hundreds of gigabytes or terabytes
- Attackers use the stolen data as leverage: "Pay the ransom, or we publish your data"
Stage 5: Encryption and Ransom (Day 14-21)
The final, visible stage:
- Ransomware payload deploys simultaneously across all accessible systems
- Shadow copies (VSS) and system restore points are deleted
- Backup systems that are accessible from the network are targeted and encrypted
- Files are encrypted with strong cryptographic algorithms (AES-256 + RSA)
- Ransom notes are dropped on every encrypted system
- A negotiation portal (usually Tor-based) provides payment instructions
- - Ransom demands vary widely depending on the target
Breaking the Kill Chain
Every stage of the kill chain presents an opportunity to detect and stop the attack:
- Stage 1: Email filtering, vulnerability patching, MFA, credential monitoring
- Stage 2: EDR detection of persistence mechanisms, behavioral analysis
- Stage 3: Network segmentation, privileged access management, lateral movement detection
- Stage 4: Egress monitoring, DLP controls, anomalous data transfer alerts
- Stage 5: If you're here without detection, rely on immutable backups for recovery
The earlier you detect, the less damage.
How SeqOps fits
Ransomware usually starts with a known weakness: an unpatched server, an exposed service or a misconfigured cloud account. SeqOps finds these across your cloud and servers and ranks them so you can close the most dangerous ones first. It doesn't detect or stop an attack in progress.