Full Report
Nazar Tymoshyk from UnderDefense shares his thoughts on what ransomware attacks look like during the all-important opening hours.
Analysis Summary
# Incident Report: The First 24 Hours of Ransomware
## Executive Summary
This report analyzes the critical first 24 hours of a ransomware engagement, highlighting that encryption is typically the final stage of a multi-week intrusion. Modern threat actors have reduced the "hand-off" time between initial access and specialized ransomware groups to seconds, emphasizing the need for rapid containment and pre-authorized decision-making. The primary impact involves high-speed data exfiltration and the targeted destruction of backup infrastructure to force ransom payments.
## Incident Details
- **Discovery Date:** Varies (Typically detected via operational failure or ransom note)
- **Incident Date:** Median dwell time of 14 days prior to detection
- **Affected Organization:** Generic case studies (Food production, business services, retail)
- **Sector:** Multi-sector
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Approximately 14 days prior to encryption ("Hour 0").
- **Vector:** Often via VPN, external remote access, or phishing.
- **Details:** Access is often gained by an Initial Access Broker (IAB) and handed off to a ransomware affiliate.
### Lateral Movement
- **Progression:** Attackers move from a single workstation to file shares, then to Domain Controllers, and finally the virtualization layer (hypervisors).
- **Timeframe:** The gap between initial access and hand-off to the second threat group has collapsed to a median of 22 seconds in recent years.
### Data Exfiltration/Impact
- **Exfiltration:** Occurs early. CISA reports cases where data theft was completed within 2 hours of initial entry.
- **Encryption:** The final step. Attackers purposefully target and destroy backup infrastructure before locking files.
### Detection & Response
- **Detection:** Rarely triggered by automated rules first; usually reported by staff unable to access production files or finding `README` ransom notes.
- **Response:** Focuses on "blast radius" assessment (Host -> Share -> DC -> Hypervisor) and emergency containment choices (Network isolation vs. pulling cables).
## Attack Methodology
- **Initial Access:** VPN/Remote Access exploitation or IAB hand-off.
- **Persistence:** RMM tools (e.g., ScreenConnect) and rogue agents.
- **Privilege Escalation:** Not specified in detail, but targets Domain Admin to reach hypervisors.
- **Defense Evasion:** Use of legitimate RMM tools and "quiet" dwell time.
- **Credential Access:** Targeting identity providers and cloud permissions.
- **Discovery:** Identifying backup infrastructure and high-value data shares.
- **Lateral Movement:** Moving through the virtualization layer to maximize encryption speed.
- **Collection:** Gathering sensitive data for double extortion.
- **Exfiltration:** High-speed removal of data before encryption starts.
- **Impact:** Encryption of production data and deletion/corruption of backups.
## Impact Assessment
- **Financial:** High (Ransom demands + recovery costs).
- **Data Breach:** High (Exfiltration occurs hours after entry).
- **Operational:** Severe (Total loss of production schedules, finance systems, and virtualization layers).
- **Reputational:** Significant (Public disclosure by ransomware groups if payment is refused).
## Indicators of Compromise
- **Network:** Unexpected traffic to command-and-control (C2) servers; unauthorized VPN logins.
- **File:** Mass file extension changes; presence of `README` or `.txt` ransom instructions on shared drives.
- **Behavioral:** High-volume file modifications by a single process; EDR alerts for credential dumping or lateral movement (often ignored for days).
## Response Actions
- **Containment:** Network-isolating hosts via EDR; disabling VPNs and external remote access.
- **Eradication:** Identifying the "quiet" first-access group to prevent re-entry.
- **Recovery:** Restoring from backups *after* verifying the integrity of the backup infrastructure.
## Lessons Learned
- **Decision Paralysis:** The biggest failure is not technical, but the lack of pre-authorized authority for responders to shut down systems.
- **Dwell Time:** Detection of ransomware is a sign of a two-week-old failure.
- **Backup Vulnerability:** You cannot assume backups are safe; attackers hunt them specifically to remove the "safety net."
## Recommendations
- **Pre-Authorize Containment:** Grant incident responders the authority to disable VPNs or isolate servers without waiting for board approval.
- **Harden Backups:** Ensure backups are immutable and stored on a segmented network that does not share credentials with the primary domain.
- **Monitor RMM:** Actively monitor for unauthorized Remote Monitoring and Management (RMM) tools, which are frequently used for persistence.
- **Focus on Identity:** Implement strict application hygiene and trim unnecessary cloud permissions for AI agents and service accounts.