| attack-chain |
Ransomware Attack Chain |
The chokepoint sequence every ransomware operator must follow. |
2026-04-12 |
/attack-chains/ransomware/ |
true |
ransomware_ttp_overlap |
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
chokepoint_links |
| initial_access |
Initial Access |
detected |
Phishing / exposed VPN / RMM abuse |
Endpoint · Email GW · VPN |
| Browser download of renamed/masqueraded binary (missing or mismatched signature) |
| RDP/VPN login from new geo-location or ASN |
| Email attachment execution from user Downloads folder |
| Legitimate RMM tool (AnyDesk, ConnectWise, TeamViewer) installed outside of IT workflow |
|
| label |
slug |
| Renamed RMM Tools |
renamed-rmm-tools |
|
| label |
slug |
| ClickFix Techniques |
clickfix-techniques |
|
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| credential_access |
Credential Access |
detected |
LSASS dump / credential harvest |
DC · Endpoint |
| LSASS process access by non-system process (Sysmon EID 10) |
| SAM/SECURITY registry hive read outside of system tools |
| rundll32.exe loading comsvcs.dll with MiniDump export |
| esentutl.exe copying browser credential databases |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
chokepoint_links |
| lateral_movement |
Lateral Movement |
exploited |
PsExec / RDP / WMI |
Domain · Servers |
| Network logon Type 3 + service creation across multiple hosts in short window |
| IPC$ share access followed by ADMIN$ write |
| Unusual admin account authenticating to 5+ hosts within 30 minutes |
| PsExec service installation (PSEXESVC) on remote host |
|
| label |
slug |
| Remote Execution Tools |
remote-execution-tools |
|
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
chokepoint_links |
| defense_evasion |
Defense Evasion |
detected |
Kill AV/EDR · Safe-mode boot · Stop backups |
All hosts |
| Multiple security/backup services stopped in rapid succession |
| EDR kill tool execution (Backstab, PowerTool, GMER, Terminator) |
| bcdedit.exe with safeboot argument |
| PowerShell Set-MpPreference DisableRealtimeMonitoring / DisableAntiSpyware |
| Veeam, VSS, or SQL service termination |
|
| label |
slug |
| Ransomware Service Manipulation |
ransomware-service-manipulation |
|
|
|
| id |
label |
mitre_tactic |
mitre_techniques |
detection_status |
attacker_action |
systems |
detection_signals |
| impact |
Impact |
TA0040 |
| id |
name |
| T1486 |
Data Encrypted for Impact |
|
| id |
name |
| T1490 |
Inhibit System Recovery |
|
| id |
name |
| T1567.002 |
Exfiltration to Cloud Storage |
|
|
exploited |
Exfil data · VSS delete · File encrypt |
All file servers · Cloud storage |
| vssadmin delete shadows / wmic shadowcopy delete / PowerShell Get-WmiObject Win32_Shadowcopy | Remove-WmiObject |
| Mass file modifications with high-entropy output (bulk file rename) |
| Ransom note .txt/.html creation across multiple directories |
| WinSCP / RClone / FileZilla outbound to cloud storage (Mega, attacker infrastructure) |
|
|
|
| name |
status |
initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| BlackBasta |
Inactive |
QakBot phishing / Teams social engineering / exploit acquisition (zero-days purchased within days of disclosure) |
Mimikatz LSASS dump + ZeroLogon / NoPac / PrintNightmare CVE exploitation |
PsExec + Cobalt Strike beacon (custom 'Coba PROXY' C2 infrastructure) |
Backstab EDR kill + PowerShell Defender disable (DisableAntiSpyware) + bcdedit safeboot |
vssadmin delete shadows + ChaCha20/RSA-4096 file encrypt (.basta extension) |
|
| name |
status |
initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| LockBit 3.0 |
Disrupted |
Stolen RDP creds / exposed RMM / valid accounts |
LSASS dump + SAM hive export |
PsExec + Cobalt Strike + GPO mass-deploy |
Comprehensive service kill list (50+ services) + registry modification |
WMI shadow copy delete + fastest-in-class encrypt (LockBit 3.0 / Black) |
|
| name |
status |
initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| Akira |
Active |
VPN compromise (no MFA) / SonicWall exploitation / Veeam CVE-2024-40711 |
Mimikatz + LaZagne + esentutl browser credential theft + comsvcs.dll LSASS MiniDump |
RDP + SSH + AnyDesk / RustDesk / MobaXterm |
PowerTool + Terminator BYOVD + Zemana AntiMalware driver EDR kill |
PowerShell WMI shadow delete + Akira / Akira_v2 (Rust) / Megazord encrypt |
|
| name |
status |
initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| Alphv/BlackCat |
Defunct |
Stolen creds / Eamfo infostealer (Veeam credential theft) / exposed web services |
Eamfo Veeam credential theft + LSASS dump |
PsExec + RDP + WMI |
Multi-vendor EDR termination + reg.exe registry modification + bcdedit safeboot |
vssadmin delete shadows + vim-cmd snapshot.removeall (ESXi) + cross-platform Rust encrypt |
|
| name |
status |
initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| Play |
Active |
N-day exploits (FortiOS, Exchange ProxyNotShell/OWASSRF) |
Mimikatz LSASS dump |
PsExec + WMI + Grixba custom infostealer |
GMER + IOBit + Process Hacker + PowerTool |
Custom .NET VSS Copying Tool + PlayCrypt selective file encrypt |
|
|
| initial_access |
credential_access |
lateral_movement |
defense_evasion |
impact |
| User executes payload OR exposed service is network-reachable |
Elevated process reads memory/registry containing credential material |
Valid admin credentials + network path open (445 / 3389 / 135) |
SYSTEM-level process with service stop/delete permission |
File system write access + encryption library loaded |
|