logo

Every Ransomware Attack Has a Backstory

ID: 3fe7a1fb-c9ff-547c-b3d0-cca462afe6c3

STIX ID: report--3fe7a1fb-c9ff-547c-b3d0-cca462afe6c3

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-08-19

...
...

**Executive summary:** The report outlines how modern ransomware incidents are typically the end stage of an access-driven supply chain: initial access (e.g., exposed Citrix NetScaler and stolen browser sessions) is often obtained or sold by initial access brokers, followed by living-off-the-land tactics (PowerShell, RMM, remote tools) and ultimately ransomware deployment (examples include DragonForce and several dominant groups responsible for over half of incidents). It emphasizes short average dwell times before encryption (around 20 hours in 2025), rising RMM abuse, identity-based attack prevalence, and the importance of detecting early indicators (suspicious logins, unexpected RMM/RATs, abnormal admin activity) to "break the chain" before extortion occurs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.