The chain, step by step
Each step depends on the one before it. Break any link and the chain stops there.
-
1
Step 1 of 8
A spear-phishing email arrives referencing a real invoice, with a link to a convincing document portal.
-
2
Step 2 of 8
The victim enters their password on the look-alike page, handing over a valid credential.
-
3
Step 3 of 8
The credential is replayed against VPN or webmail that has no MFA, giving the attacker a legitimate foothold.
-
4
Step 4 of 8
Reconnaissance maps the domain: file servers, admin accounts, backup systems and monitoring coverage.
-
5
Step 5 of 8
A loader drops a beacon, which stages tools for privilege escalation and lateral movement.
-
6
Step 6 of 8
Access to backup infrastructure is established first, so recovery paths are removed before anything else.
-
7
Step 7 of 8
The encryptor is deployed simultaneously across every reachable host, with a ransom note left behind.
-
8
Step 8 of 8
Data exfiltrated earlier becomes leverage: pay or the material is published.
Entries behind these steps
The vulnerabilities, techniques and malware that make each stage possible.