Attack chain 8 steps

Phishing to Ransomware

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    A spear-phishing email arrives referencing a real invoice, with a link to a convincing document portal.

  2. 2

    Step 2 of 8

    The victim enters their password on the look-alike page, handing over a valid credential.

  3. 3

    Step 3 of 8

    The credential is replayed against VPN or webmail that has no MFA, giving the attacker a legitimate foothold.

  4. 4

    Step 4 of 8

    Reconnaissance maps the domain: file servers, admin accounts, backup systems and monitoring coverage.

  5. 5

    Step 5 of 8

    A loader drops a beacon, which stages tools for privilege escalation and lateral movement.

  6. 6

    Step 6 of 8

    Access to backup infrastructure is established first, so recovery paths are removed before anything else.

  7. 7

    Step 7 of 8

    The encryptor is deployed simultaneously across every reachable host, with a ransom note left behind.

  8. 8

    Step 8 of 8

    Data exfiltrated earlier becomes leverage: pay or the material is published.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used