Overview
Ransomware is a business model more than a single technique. Operators gain access, spend time moving through the network, take data, then encrypt systems and demand payment. Many also threaten to publish stolen data, so restoring from backup answers only part of the problem.
Because the stages are consistent, each stage is also a place to stop the attack.
Key concepts
- 01
Initial access
Common routes are stolen or reused credentials, phishing, exposed remote access services and unpatched internet-facing systems.
- 02
Privilege and movement
Attackers look for privileged and service accounts, then move toward directories, file stores and backups.
- 03
Exfiltration
Data is copied out before encryption, which is what makes extortion possible even when systems can be restored.
- 04
Encryption and extortion
The visible event comes last. By then most of the intrusion has already happened.
What good looks like
- Reduce what is reachable from the internet, and patch internet-facing systems first.
- Require multi-factor authentication on remote access and privileged accounts.
- Limit standing privilege and review service accounts.
- Segment networks, protect backups with separate credentials, and test restoring them.
- Rehearse the incident response plan, including who decides and who is called.
Common pitfalls
- Assuming backups alone resolve an extortion attempt.
- Leaving old and unmanaged accounts active.
- Discovering that the incident plan has never been exercised.
How Neonix helps
Cybrmonk surfaces exposed services, leaked credentials and ransomware intelligence that point to likely entry points.
CybrIdentity addresses privileged and dormant accounts that attackers rely on, and CybrRonin tests whether a path can be used on targets you have proven you own.
If an incident is under way, use the incident report page.
This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.