
Randeep Gill at Exabeam describes how to use weaknesses in ransomware’s kill chain against it
Given the rate and impact of recent ransomware attacks, many organisations are understandably wary about their ability to resist and recover should they be targeted. Compounding the problem is a common defensive blindspot, where organisations are unaware of the presence of ransomware that performs reconnaissance on their systems before fully activating.
Leveraging this knowledge, however, can offer vital insight into the likelihood of an attack and allow organisations to take effective preventative action.
Looking at the development of the cyber-crime ecosystem, it’s fascinating to see how ransomware has become a go-to tactic and highly lucrative form of extortion. With the first attack identified back in 1989, it’s only comparatively recently that incident volumes have snowballed, as have the size of payments demanded by attackers.
When the CryptoLocker variant was first used in 2013 it was accompanied by a demand for what now seems a tiny $300 to decrypt the files. Today, both the volume of attacks and ransom demands are on an entirely different level, with PC manufacturer Acer reportedly asked for $50 million by its attackers last year.
Ransomware-as-a service (RaaS) is also prevalent. Offering opportunists pre-built kits to launch attacks with minimal technical knowledge. These inexpensive kits are sold on the dark web and even offer a subscription model with 24-7 support, forum advice and discounted offers for future purchases.
Using this methodology often results in making it difficult to track and identify these specific ransomware developers since they are not the only ones launching int attacks.
In addressing these risks, it’s important to recognise the fundamental difference between typical malware and typical ransomware. On the one hand, malware is designed to be silent, hidden and linger, whereas the purpose of ransomware is to strike as rapidly as possible.
In fact, most phases in the attack last only minutes, but are part of a more complex, integrated process: Initially, attackers often employ a distribution campaign, using techniques like social engineering and weaponised websites to trick or force users to download a dropper - or Trojan - to initiate the infection process. This Trojan then downloads an executable file that installs the ransomware, enabling it to embed itself onto the target system.
The ransomware then scans the infected machine and wider accessible network resources for content to encrypt. It’s after that point when the ransom demand is presented, along with instructions on how to pay. Some cyber-criminals have now become so organised that they offer a form of ‘customer support’ where they help victims navigate the unfamiliar crypto-currency payment process.
Despite the growing effectiveness of this attack process, there are some key points where organisations can disrupt active ransomware, but always with the caveat that time is of the essence.
In the early phases of a ransomware incident, for instance, detecting the attack requires the identification of pieces of forensic data, or ‘Indicators of Compromise’ (IOC). The problem is that these IOCs usually only exist after attacks have been effective and reported back to CISO Role.
Making the problem even worse is the fact that many ransomware attacks now use new or ‘zero-day’ exploits to circumvent defensive technologies, such as antivirus or sandboxing. As a result, the gap between the publication of a new vulnerability and its use in a ransomware attack can be very short.
The “Encrypt” phase, however, gives endpoint CISO Role the chance to efficiently disrupt the attack, but only for known variants where deterministic signatures have been developed. Disrupting zero-day ransomware, in contrast, would typically require endpoint CISO Role to also disrupt regular users from their normal operations, such as preventing any suspicious process to open, save and/or delete any file.
The window of opportunity for ransomware defence, therefore, is when it is out in the open and operating on the network during its ‘scan’ phase. At that time it’s accessing the network for files and locations to encrypt, verifying the endpoint’s capabilities to encrypt the files and to delete the cleartext versions of these files, as well as checking for the endpoint’s ability to communicate to a command-and-control centre.
This behaviour cannot be detected using simple correlation rules because, not only does it require too many rules, but it would generate too many false positives. It is important to employ cross-layered detection mechanisms that anticipate ransomware activities, techniques and movement before the threat actually culminates.
User and entity behavioural analytics (or UEBA) can help identify key behaviour patterns throughout an environment and thus create a holistic picture of an emerging threat and possible attack scenario.
An example could be to quickly identify a compromised user, never seen before file executions or abnormal activity, while mapping these seamlessly into a timeline of events. By using advanced analytics’ behavioural modelling to understand what is normal versus abnormal, UEBA tools can provide the insight needed to identify these changes and subsequently defeat the attack.
This is achieved by analysing the ransomware executable and the way it interacts with the host and the network to detect any behavioural deviation that indicates malicious activity without the need for signatures.
Separate security tools like firewalls/IDS or endpoint security helpful in preventing the initial infection. However, once these defences are penetrated, security teams are often left to scramble managing disparate products in the midst of an attack. Precious time is lost while the ransomware makes its way further down the attack chain.
Planning for such events is imperative, as is implementing key playbooks for threat triage and attack prevention. For example, orchestrating specific actions such as isolating a host, blocking an IP address or other indicators that will help to limit the scope of the attack.
With hundreds - and perhaps thousands - of ransomware attacks successfully taking place every month, there is a renewed sense of urgency among organisations who accept that it’s no longer ‘if’, but ‘when’ they will be targeted.
By understanding the kill chain and being prepared to act on the brief opportunities to respond, it becomes possible to significantly improve the likelihood that ransomware can be defeated before it’s too late.
Randeep Gill is Principal Security Engineer at Exabeam
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543