
Ransomware attackers don’t always need to be in a hurry. Some of the most damaging attacks begin with patience. Rather than spreading ransomware as widely as possible and waiting to see who pays, attackers can take their time identifying organisations worth targeting and working out how best to reach them.
An opportunistic ransomware attack might compromise whoever happens to be vulnerable. A patient attacker can spend days, weeks or longer understanding a target, moving through its environment and identifying the systems and data that will give them the greatest leverage. By the time the ransomware is deployed, much of the work is already done.
The attack isn’t simply about encrypting files. It’s about finding the right victim, gaining the right access and maximising the pressure to pay. For organisations defending against ransomware, this creates a problem because the most dangerous part of a ransomware attack may happen long before the payload appears.
Once You’re the Target, Expect Persistence
Today’s attacker is far more determined. Instead of moving on to the next victim if the first attempt fails, they simply try another route. A criminal who has already decided you’re worth pursuing has much more reason to try again. After all, the initial access is only the beginning of a much longer intrusion.
As the APT groups represented in our latest ransomware test show, they are not short on options. Initial access techniques included compromised credentials, phishing and spear phishing, compromised VPN accounts, attacks against public-facing remote desktop services, brute-force attacks and exploitation of legitimate services.
Block one door, and a determined attacker may simply try another.
Getting in is Only the Start
Once they’ve gained access, attackers don’t necessarily rush to deploy ransomware. They often explore. A targeted attacker will spend time working out what you have, what they can reach and where they can do the most damage.
In a broad opportunistic campaign, resistance may be enough to persuade an attacker to move on. But when an organisation has been deliberately selected because it represents a potentially valuable payout, that’s a much less comfortable assumption.
The attacker will keep trying because persistence often pays off.
Encryption Isn’t the Only Payload
Extortion has also become more than simply encrypting files. The ransomware groups we emulated in our evaluation of Palo Alto Networks Cortex XDR included operations associated with data theft, double extortion and other approaches intended to increase pressure on the victim.
With so many attack paths available to an attacker, and no single identifiable payload at the end of an attack, it’s essential for Endpoint Detection and Response (EDR) products that protect against ransomware to act as soon as possible.
And there are numerous opportunities to identify malicious behaviour before the final payload. An organisation could see suspicious credential use, reconnaissance, privilege escalation, attempts to interfere with security controls, unusual remote access or lateral movement. Each represents an opportunity to disrupt the attacker before ransomware is deployed.
Testing Needs to Reflect the Threat
Our testing therefore also needs to examine whether security technology can provide useful visibility as the attack develops over multiple stages. This is why our testers began at the start of the attack chain and progressed through realistic intrusion activity. Some attacks involved moving laterally from the original target to other systems before attempting to deploy ransomware deeper within the network.
It’s worth noting that we turn off protection mode during these tests to evaluate exactly what the product does or doesn’t see. If we hadn’t, then products such as Cortex XDR that received a 100% accuracy rating would have stopped us (as they should do) long before we were able to get deep inside the target system.
Alongside those deep attacks, our recent test also exposed protected systems to 636 ransomware files, combining known ransomware with new variations designed to test whether protection extended beyond those threats that had already been analysed by security researchers.
Together, the two approaches reflect today’s ransomware reality that organisations need to defend against both the ransomware itself and the attacker delivering it.
Assume the Attacker May Keep Trying
There’s another reason why visibility across the whole attack chain is so important. Paying a ransom doesn’t necessarily end an intrusion. If an attacker retains a foothold inside the network via a backdoor, valid credentials or an unpatched access point, encryption was never the whole objective. Some victims have found the same attacker returning weeks or months later, extorting the same organisation twice from an access they never actually lost.
If you’re unfortunate enough not to stop an attack in time detailed detection information may help unravel where the attacker has been, what they’ve had access to, and where they might still be lurking. In targeted attacks, by the time the ransomware appears, it’s likely that the attacker has already been inside your systems for a long time.
For a potentially greater return, an attacker can afford to wait. And that’s what makes the patient attacker so dangerous.
Frequently Asked Questions About Ransomware Attacks
Are ransomware attacks still opportunistic?
Yes, but they’re no longer the whole picture.
Opportunistic, scattergun ransomware still exists. But serious operations now also deliberately target valuable organisations and invest significantly more time and effort into compromising them.
Why do attackers target large organisations specifically?
The payout justifies the persistence.
Large organisations can afford substantial ransoms and stand to lose more from disruption. That gives attackers a much stronger incentive to keep trying after an initial attempt fails, rather than moving on to an easier target.
Can ransomware attacks be detected before files are encrypted?
Yes — there are several earlier warning signs.
Suspicious credential use, reconnaissance, privilege escalation, tampering with security controls, and lateral movement can all occur well before ransomware is deployed. Each is a potential point of detection and intervention.
Does stopping ransomware mean stopping encryption?
No — extortion now goes beyond encryption alone.
Modern ransomware groups increasingly rely on data theft and double extortion alongside, or instead of, encryption. Effective defence means catching the attacker’s earlier behaviour, not just the final payload.
Our latest ransomware security evaluation on Palo Alto Networks Cortex XDR examines how the product performed against both full attack chains and hundreds of ransomware samples and variants. Download the full report to see the attack techniques, methodology and results in detail.