Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Ransomware

How Ransomware Attacks Unfold: A Step-by-Step Guide

Ransomware isn't a single event but a multi-stage attack. Learn the full lifecycle, from initial breach and network mapping to data exfiltration and.

By · Published · 12 min read

A darkened server room with a single red glowing server rack, symbolizing a network under a ransomware attack.

A ransomware attack is not a singular event but a methodical, multi-stage campaign that can unfold over days or weeks. Attackers first gain an initial foothold in a network, then move laterally to map critical systems and escalate privileges before stealing sensitive data. Only then do they deploy the ransomware payload to encrypt files and present their ransom demand.

Understanding this lifecycle—often called the "attack chain"—is crucial for detection and defense. By recognizing the tactics used at each stage, organizations can implement controls to break the chain and prevent the devastating final impact. This is the modern reality of digital extortion, where the encryption of your files is often the last, and loudest, step in a long, covert operation.

Stage 1: Initial Access

Every ransomware attack begins with a security breach. Attackers are opportunistic, leveraging a variety of well-established techniques to get their foot in the door. Their goal is simply to establish a presence on a single machine, which will serve as their beachhead for the rest of the operation.

Common entry vectors include:

  • Phishing Emails: This remains the most common method. A crafted email containing a malicious link or attachment is sent to employees. Clicking the link or opening the document triggers a malware download. These campaigns can be generic mass mailings or highly targeted "spear phishing" attacks aimed at specific individuals. Learning how to spot a phishing email is a foundational skill for any employee.
  • Exploiting Vulnerabilities: Attackers continuously scan the internet for unpatched software vulnerabilities in public-facing systems like VPNs, firewalls, and web servers. When a new flaw, or "zero-day," is discovered, they race to exploit it before organizations can apply the security patch.
  • Stolen Credentials: Passwords and usernames stolen in previous data breaches are often sold on dark web marketplaces. Attackers buy these lists and use automated tools to test them against corporate login portals in a technique called credential stuffing. A valid credential provides direct, legitimate-seeming access.
  • Exposed Remote Services: Poorly secured Remote Desktop Protocol (RDP) or Virtual Private Network (VPN) ports are a prime target. Attackers can brute-force weak passwords or use stolen credentials to log in directly, giving them an interactive session on a corporate workstation or server.

Stage 2: Establishing Persistence

Once inside, an attacker's immediate priority is to ensure they don't lose their access. A simple reboot of the compromised machine could wipe away their initial foothold. To prevent this, they establish persistence—a way to automatically maintain control over the system.

This is typically achieved by installing a small, discreet piece of malware known as a "loader" or "beacon." This tool is configured to communicate with the attacker's command-and-control (C2) server at regular intervals, awaiting further instructions. To remain hidden, it often masquerades as a legitimate system process.

Methods for achieving persistence include: - Creating a scheduled task that runs the malware at startup. - Modifying Windows Registry keys to execute malicious code when the user logs in. - Installing a new service that appears to be a normal part of the operating system.

During this phase, the attacker's activity is minimal and designed to avoid detection by security software. They are playing a long game, content to wait until they are ready to escalate the attack.

Stage 3: Reconnaissance and Privilege Escalation

With a stable foothold secured, the attackers begin to explore the network. They start with the limited permissions of the user account or system they initially compromised. Their next objective is to gain administrative privileges, which will give them the keys to the entire kingdom.

This phase involves two parallel activities:

Privilege Escalation Attackers use specialized tools to exploit local system vulnerabilities or harvest credentials stored on the compromised machine. A famous example is the tool Mimikatz, which can extract plaintext passwords and hashes from a computer's memory. Obtaining the credentials of a local or domain administrator is the primary goal.

Internal Reconnaissance With or without elevated privileges, the attackers begin mapping the internal network. They need to understand the environment to identify high-value targets. They scan for: - **Domain Controllers:** The servers that manage user accounts and security for the entire network. - **File Servers:** Where the organization's most critical documents, intellectual property, and operational data are stored. - **Backup Servers:** A key target to neutralize the victim's ability to recover without paying. - **Databases:** Repositories containing customer information, financial records, and other structured data.

This discovery process can take days. The attackers move slowly and carefully, using legitimate administrative tools like PowerShell to blend in with normal network traffic and avoid raising alarms.

Stage 4: Lateral Movement

After identifying their targets, attackers use their escalated privileges to move from their initial beachhead to other systems on the network. This "lateral movement" is a critical step for expanding their control and reaching the high-value assets they discovered during reconnaissance.

They essentially island-hop from one machine to another, installing their beaconing malware on each new system to bring it under their control. Common tools for lateral movement are often built-in Windows utilities, which makes the activity difficult to distinguish from legitimate administrative tasks. These include Windows Management Instrumentation (WMI), PowerShell Remoting, and PsExec.

By the end of this stage, the ransomware group has typically gained control over the domain controller, giving them administrative access to nearly every server and workstation in the organization. They can now create, modify, and delete user accounts, disable security tools, and prepare the environment for the final stages of the attack.

Stage 5: Data Exfiltration (Double Extortion)

Before deploying the encryption payload, modern ransomware groups engage in data theft. This tactic, known as "double extortion," fundamentally changes the dynamic of the attack and is one of the key reasons how data breaches happen has become so intertwined with ransomware.

Attackers identify the most sensitive and valuable data—financial reports, customer databases, intellectual property, executive emails—and quietly copy it to their own cloud storage servers. This process can involve compressing terabytes of data into archives and uploading them over hours or days, often throttled to avoid triggering alerts for unusual network traffic.

This stolen data serves as powerful leverage. If the victim organization has reliable backups and can recover its systems, it might be tempted to refuse the ransom demand. However, the attackers can then threaten to publicly leak the exfiltrated data, creating a second crisis involving regulatory fines, reputational damage, and customer lawsuits. Some groups have even evolved to "triple" or "quadruple" extortion, adding DDoS attacks or direct harassment of the victim's customers and partners to the list of threats.

Stage 6: Impact (Encryption)

This is the phase most people associate with ransomware. Once the data has been exfiltrated and the attackers have control over a critical mass of systems, they deploy the encryption payload. This is the final, irreversible step designed to cause maximum disruption.

Using their administrative access, they push the ransomware executable to hundreds or thousands of machines simultaneously. The malware works quickly to encrypt files, targeting common document types, images, videos, and databases. To prevent recovery, it will also actively seek out and delete volume shadow copies (Windows' built-in file versioning) and attempt to wipe or encrypt connected network backups.

Once encryption is complete, the final payload is delivered: the ransom note. This is a text file, often named something like `README.txt` or `DECRYPT-INSTRUCTIONS.html`, dropped into every encrypted directory. It contains: - A declaration that the files are encrypted. - The amount of the ransom demand, usually in a cryptocurrency like Bitcoin or Monero. - A deadline, after which the ransom will double or the decryption key will be deleted. - A unique ID for the victim. - Instructions on how to contact the attackers, typically via a secure chat portal on a Tor hidden service.

In some cases, the attackers will also change the desktop wallpaper on all machines to display the ransom message, ensuring the attack cannot be ignored.

Stage 7: Negotiation and Aftermath

The attack is now visible to the organization. IT systems are down, employees cannot access their files, and operations grind to a halt. The leadership team is faced with a critical decision. They must assess the damage, determine if their backups are viable, and decide whether to engage with the attackers. The question of should you pay a ransomware demand is complex, with legal, ethical, and operational considerations.

If the organization chooses to pay, they typically hire a professional incident response firm that specializes in ransomware negotiation. This firm will make contact with the attackers, verify that they can actually decrypt a sample file, and negotiate the price down. Payment is made via cryptocurrency, and in return, the attackers provide a custom decryption tool and key.

However, recovery is never simple. Decryptors are often slow and buggy, and some files may be corrupted beyond repair. Furthermore, the organization is still left with a compromised network. The entire environment must be methodically cleaned, all attacker backdoors removed, and systems rebuilt before business can resume—a process that can take weeks or months.

Breaking the Attack Chain

Preventing a catastrophic ransomware attack is not about a single silver-bullet solution, but about implementing defenses at every stage of the attack chain. The goal is to make the attacker's job as difficult as possible.

Attack StageDefensive Measures
Initial AccessSecurity awareness training, advanced email filtering, robust patch management, and mandatory multi-factor authentication (MFA) on all external services.
PersistenceEndpoint Detection and Response (EDR) tools to monitor for suspicious processes, scheduled tasks, and registry changes.
Privilege EscalationImplementing the principle of least privilege so user accounts only have the access they absolutely need. Patching internal system vulnerabilities.
Lateral MovementNetwork segmentation to prevent attackers from moving freely between different parts of the network. Monitoring for abnormal use of admin tools.
Data ExfiltrationData Loss Prevention (DLP) tools that can detect and block large, unusual outbound data transfers.
ImpactThe ultimate safety net: immutable, offline backups. Following the 3-2-1 rule (three copies of data, on two different media, with one copy off-site) ensures you can always restore your systems.

By layering these defenses, an organization can significantly increase its resilience. Even if an attacker succeeds at one stage, a well-placed control at the next can stop the campaign dead in its tracks, long before the final, devastating encryption payload is ever delivered.

Read next