Ransomware (analysis and defense)
Ransomware is the malware type with the greatest economic impact of the last decade: it encrypts the victim’s data and demands a ransom (usually in cryptocurrency) to decrypt it, often combined with leak extortion (stealing the data before encrypting and threatening to publish it). Understanding how it works, how a sample is analyzed, and —above all— how to prevent and respond to it is critical for any organization. This card approaches it from analysis and defense.
How it operates (the chain of a ransomware attack)
Section titled “How it operates (the chain of a ransomware attack)”1. Initial access phishing, exposed RDP/VPN, leaked credentials, exploit (see recon/ad)2. Reconnaissance enumerate the network, AD, backups, valuable data3. Escalation & lateral reach Domain Admin, move across the network (see Windows & AD)4. Exfiltration steal data BEFORE encrypting (double extortion)5. Deployment mass encryption, often via GPO/PsExec for the whole network at once6. Extortion ransom note + threat to publish the stolen dataEncryption is the last step; before it there’s a whole intrusion (days or weeks) offering multiple opportunities for detection and response.
Analyzing a ransomware sample
Section titled “Analyzing a ransomware sample”# static (see mal-static): identify the family and the encryption scheme- crypto imports (CryptEncrypt, BCrypt, or custom crypto) -> AES? RSA? ChaCha?- the ransom note (strings), extension it appends, victim/campaign ID- anti-recovery logic: Shadow Copy deletion (vssadmin delete shadows), disabling recovery, stopping services/databases before encrypting# dynamic (see mal-dynamic): IN AN ISOLATED LAB with decoy files- observe the mass encryption (many fast writes/renames) -> a good behavioral IOC- the key: hybrid scheme? (per-file AES + RSA for the key) -> almost always irreversible without the private keyThe encryption scheme (why it’s usually unrecoverable)
Section titled “The encryption scheme (why it’s usually unrecoverable)”# modern ransomware uses hybrid encryption:- generates a symmetric key (AES/ChaCha) per file or per victim -> encrypts the data (fast)- encrypts that key with the attacker's RSA PUBLIC key -> only they can decrypt it# => without the attacker's private key, decryption is impossible# EXCEPTION: families with implementation flaws (predictable keys, weak crypto)# -> free decryptors sometimes exist (see below)To pay? and recovery
Section titled “To pay? and recovery”# general recommendation: DON'T pay (funds crime, no guarantee of recovery)# first check for free decryptors:No More Ransom (nomoreransom.org) -> per-family decryptors if the crypto was weakID Ransomware -> identify the family by the note/extension# real recovery comes from BACKUPS (if they exist and are intact)Defense: prevention (the most important)
Section titled “Defense: prevention (the most important)”# close the initial-access vectors:- MFA on VPN/RDP/email; don't expose RDP to the Internet; patch (VPN appliances, see net-vpn)- anti-phishing training; email filtering; disable macros# limit the impact:- least privilege and segmentation (so one host can't encrypt the whole network)- harden AD (mass deployments use DA + GPO/PsExec -> see Windows & AD)Defense: backups (the safety net)
Section titled “Defense: backups (the safety net)”# the 3-2-1 rule: 3 copies, 2 different media, 1 offline/immutable- OFFLINE or IMMUTABLE backups (that ransomware can't encrypt or delete)- test restores periodically (an unverified backup isn't a backup)- protect the backups themselves (separate credentials; the attacker looks for them first)Defense: detection and response
Section titled “Defense: detection and response”# early detection (before encryption):- recon/lateral/escalation activity in AD (see Windows & AD, dfir)- Shadow Copy deletion (vssadmin), mass service stopping -> high-priority alert- mass encryption (many renames/writes) -> EDR with rollback/canary files# response (see dfir):- immediately isolate the affected hosts (contain propagation)- identify the scope, the initial vector, and the family- restore from clean backups; rotate ALL credentials (assume full compromise)- investigate exfiltration (double extortion) -> legal/notification implicationsFor the defense (summary)
Section titled “For the defense (summary)”- Prevention: MFA, patching, don’t expose RDP, anti-phishing, least privilege, segmentation.
- Tested offline/immutable 3-2-1 backups — the most important defense.
- Early detection of the intrusion (not just the encryption): recon/lateral/escalation in AD.
- Rehearsed incident-response plan (see dfir); EDR with behavior detection.
- Map to MITRE ATT&CK (TA0040 Impact: T1486 Data Encrypted for Impact).
Testing checklist (analysis/defense)
Section titled “Testing checklist (analysis/defense)”- Analysis: family, crypto scheme, note, extension (static)
- Anti-recovery logic (Shadow Copy deletion, service stop)
- Mass-encryption behavior in an isolated lab (dynamic)
- Identify the family (ID Ransomware) and look for a decryptor (No More Ransom)
- Prevention: MFA/patching/RDP/anti-phishing/segmentation
- 3-2-1 offline/immutable backups and tested restore
- Early detection of the intrusion (recon/lateral/escalation)
- Response plan: isolate, scope, restore, rotate credentials, exfiltration