Overview
Modern ransomware is a full intrusion, not a single file: the operator moves laterally, escalates, exfiltrates data, then deploys the encryptor across every reachable host simultaneously.\nDouble extortion publishes the data if the ransom is not paid, and affiliates split the proceeds with the developer.\nOffline, immutable backups and EDR coverage are what actually end the incident.
Indicators of Compromise
Signals that suggest this is present on a system.
- Ransom note files appearing in bulk
- vssadmin deleting shadow copies
- Large outbound transfers before encryption begins
Controls that stop it
-
Keep Tested, Offline Backups
Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.