Skip to content
Cyber Defense Technologies

Threat Intelligence

Ransomware Playbooks: How Modern Attacks Unfold, Stage by Stage

Ransomware is rarely a single event. It is the final stage of an intrusion that may have lasted days or weeks. How modern ransomware operations work, where defenders can interrupt them, and how to prepare for the worst.

By Cyber Defense Technologies February 3, 2026 4 min read

The word "ransomware" suggests a piece of malware that encrypts files. That is only the last step. In most serious incidents today, ransomware is deployed by operators who have already spent days or weeks inside the victim's network: stealing credentials, mapping systems, disabling defenses and taking data.

Understanding that sequence is the key to stopping it, because every stage before encryption is a chance to detect and evict the attackers.

How a modern ransomware attack unfolds

  1. 1

    Initial access

    Phishing, stolen credentials, exposed remote access or an unpatched edge device.

  2. 2

    Establish foothold

    Remote access tools, new accounts or scheduled tasks for persistence.

  3. 3

    Escalate and discover

    Harvest credentials, map the network, find backups and valuable data.

  4. 4

    Spread and steal

    Move laterally with legitimate tools, then exfiltrate data for leverage.

  5. 5

    Disable defenses

    Turn off security tools and delete or encrypt backups.

  6. 6

    Encrypt and extort

    Encrypt systems, then demand payment for decryption and to prevent a data leak.

The ransomware business

Many ransomware operations work as businesses. Some groups develop the ransomware and run leak sites, while affiliates carry out intrusions in exchange for a share of the proceeds. Others specialize in gaining initial access and selling it. This specialization means organizations face skilled operators even from groups they have never heard of.

Joint government advisories, published under CISA's #StopRansomware campaign, describe the tactics of many specific groups. Their details vary, but the pattern is consistent.

Stage by stage

1. Initial access

Common entry points include:

  • phishing that delivers malware or captures credentials
  • stolen or purchased credentials for VPNs and remote desktop
  • exploitation of unpatched internet-facing systems, especially VPNs, firewalls and file transfer applications
  • abuse of trusted relationships, such as managed service providers

Defensive opportunity: patch internet-facing systems urgently, require phishing-resistant multifactor authentication for remote access, and monitor for unusual logons.

2. Establishing a foothold

Attackers install remote access tools, create accounts or schedule tasks to ensure they can return. Many use legitimate remote management software, which blends in.

Defensive opportunity: alert on new remote access tools, new accounts and new scheduled tasks or services, especially on servers.

3. Privilege escalation and discovery

Attackers harvest credentials, often targeting domain administrator accounts, and map the network to find domain controllers, file servers, databases and, critically, backups.

Defensive opportunity: detect credential dumping, unusual Active Directory queries and use of network scanning tools; protect privileged accounts with tiered administration.

4. Lateral movement and data theft

Using stolen credentials and built-in tools, attackers move across the network and collect valuable data, then exfiltrate it to cloud storage or attacker infrastructure. Stolen data becomes leverage: pay, or it will be published.

Defensive opportunity: monitor for unusual administrative connections between systems and large outbound data transfers.

5. Disabling defenses and backups

Before encryption, attackers commonly disable security tools, delete shadow copies and target backup systems so recovery is harder.

Defensive opportunity: alert on security tools being stopped, protect backup infrastructure with separate credentials, and keep backups that cannot be modified or deleted from the production network.

6. Encryption and extortion

Finally, ransomware is deployed across as many systems as possible, often at night or over a weekend when response is slower. A ransom note directs the victim to negotiate.

Preparing for the worst

Even with good defenses, organizations should prepare for a successful attack:

  • Backups that survive. Offline or immutable copies, protected by separate credentials, and tested regularly through actual restoration.
  • An incident response plan with ransomware-specific steps, including decision authority, legal counsel, law enforcement contact and communication.
  • A recovery plan that sets priorities: which systems come back first, and in what order.
  • Asset and network documentation available offline, because internal systems may be unavailable.
  • Exercises. A ransomware tabletop exercise reveals gaps in decisions and coordination.

Frequently asked questions

If we have good backups, are we safe? Backups address encryption, not data theft. Most groups now steal data first and threaten to publish it. Backups remain essential for recovery, but prevention and detection matter just as much.

Should we pay? It is a complex business, legal and ethical decision. Payment does not guarantee recovery or deletion of stolen data, and paying certain groups may carry legal risk. Consult counsel and law enforcement. Preparation reduces the chance of facing the decision.

How quickly do attackers move? Timelines vary widely, from days to weeks. Some intrusions move from initial access to encryption very quickly, which is why detection at early stages is so valuable.

What to do this week

  • Confirm at least one backup copy is offline or immutable, and protected by separate credentials.
  • Restore a real system from backup to prove it works.
  • Check that alerts fire when security tools are stopped or shadow copies are deleted.
  • Review remote access: is every path protected by MFA and logged?
  • Print, or store offline, the contact list and key steps of your response plan.

How CDT can help

CDT's incident response and digital forensics team contains ransomware attacks and restores operations, and our cyber hunt service looks for attackers before they reach the encryption stage. Penetration testing and red team exercises show how far an attacker could get in your environment. If you are under attack now, go to our Under Attack page.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.