🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
Anatomy of a ransomware attack: the six stages from first login to ransom note
SCAN
Threat Intelligence

Anatomy of a ransomware attack: the six stages from first login to ransom note

ERD Research TeamJul 15, 20267 min read

Key takeaways

  • Enterprise ransomware is a staged campaign measured in days or weeks, not a single event — and every stage before detonation is a detection opportunity.
  • The cheapest place to stop an attack is initial access; the most common place it's actually caught is lateral movement.
  • Exfiltration now typically precedes encryption, so outbound data monitoring buys warning time that endpoint alerts alone won't.

Stage 1–2: Initial access and foothold

Nearly every enterprise incident starts one of three ways: a valid credential (phished, bought, or reused), an exposed remote service like VPN or RDP, or an unpatched internet-facing device. Whichever door was used, the first hours look mundane — a successful login, a normal-looking session. The attacker's immediate job is persistence: a scheduled task, a rogue account, or increasingly a legitimate remote-management (RMM) tool installed quietly so that losing the first session doesn't mean losing the intrusion.

This is the cheapest stage to win. Phishing-resistant MFA, an accurate inventory of exposed services, and alerting on new RMM installs close the doors most affiliates actually use — no advanced detection required.

Stage 3–4: Escalation and lateral movement

With a foothold, the attacker hunts for privilege — dumping credentials from memory, exploiting misconfigured services, and above all targeting Active Directory, because domain admin turns one compromised laptop into every machine in the fleet. Movement between systems rides ordinary administrative plumbing: RDP, SMB, PowerShell, PsExec. That's deliberate. Tooling that looks like your own IT team generates alerts your analysts are conditioned to ignore.

This stage takes days, and it's where defenders most often catch a live intrusion — an admin login at 3am from a workstation that has never touched that server, a service account suddenly browsing file shares. Segmentation and tiered admin accounts don't just slow the attacker down; they force the noisy behavior that gets caught.

Stage 5: Exfiltration — the quiet theft before the loud one

Before anything is encrypted, data leaves. Attackers stage archives of finance, legal, HR, and customer data and push them out through cloud storage tools like Rclone or MEGA — often throttled to blend into normal traffic. In most modern enterprise incidents this happens before any ransom note exists, because stolen data is the leverage that makes victims pay even when backups are good.

Egress monitoring — large or sustained outbound transfers to unfamiliar destinations, especially from servers that never talk to the internet — is the last reliable tripwire before real damage. It is also the difference between an outage and a reportable data breach.

Stage 6: Detonation, and what the timeline means for you

Detonation is the part everyone pictures: shadow copies deleted, backups targeted first, the encryptor pushed to every reachable host, and a ransom note dropped in each directory. It is loud and fast — often kicked off on a Friday night or before a holiday to maximize the window before anyone responds. By the time the note appears, the attacker has already spent days or weeks inside, and the outcome is largely decided.

That is the real lesson of the lifecycle: the ransom note is the end of the story, not the beginning. Every hour of dwell time before it is an hour you could have detected, contained, or evicted. Map your controls to the six stages and you stop asking 'how do we survive encryption?' and start asking 'where would we have caught this first?' — which is the question that actually changes outcomes.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy