xcellhostTop

XcellHostCloud | Security | Services

What a real ransomware attack looks like from the inside

People imagine ransomware as a sudden event: a skull on the screen, everything gone. The reality is slower, quieter, and far more preventable — which is exactly why it is worth understanding.

Day minus 21: the way in

An accounts assistant received an invoice attachment from what appeared to be a known supplier. It was a good forgery. Opening it installed a small remote-access tool. Nothing visible happened. No alert fired.

Day minus 20 to minus 3: quiet mapping

The attacker spent three weeks doing nothing dramatic. They mapped the network, found the file server, identified which machines held the accounting data, and — critically — located the backup drive. They harvested credentials from a machine where someone had saved the domain admin password in a text file.

This phase is where attacks are actually won or lost. Three weeks is a long time to be caught. Nothing was watching.

Day minus 2: the backups go first

Before touching production, they deleted the backup job history and encrypted the local backup drive. Standard practice. If you cannot restore, you negotiate.

Day zero, 02:40: encryption begins

Chosen for the hour when nobody is watching. Encryption ran across shares in sequence. By 04:15 the file server was done.

Day zero, 08:30: discovery

Staff arrived to unreadable files and a ransom note. The first hour went to confusion — several people rebooted machines, which in some cases destroyed forensic evidence.

What actually determined the outcome

Not the sophistication of the attack. Three things:

  • Whether an off-site, immutable backup existed that the attacker could not reach
  • Whether anyone was monitoring for the three weeks of reconnaissance
  • Whether credentials were sitting in plain text on a workstation

The unglamorous prevention list

  • Off-site immutable backups, tested by restore drill
  • Multi-factor authentication on every remote access path
  • Endpoint detection that flags unusual internal reconnaissance
  • A password manager, so nobody saves admin credentials in a text file
  • An incident plan that says “do not reboot” in the first line

None of that is exotic. All of it is boring. That is rather the point.

If you want to know how you would fare, our readiness assessment walks the same timeline against your environment.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top