About

Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Tuesday, May 26, 2026

The Last Line:

The Last Line of Defence: How Ransomware Erases Your Recovery Options Before Encryption

The Last Line of Defence: How Ransomware Erases Your Recovery Options Before Encryption

Modern ransomware attacks do not begin with encryption. They begin with preparation. Long before employees see ransom notes or encrypted files, attackers quietly disable recovery mechanisms, destroy backups, and erase Windows Volume Shadow Copies. By the time encryption starts, the organization has already lost its easiest recovery path.

This article explores how ransomware families abuse tools such as vssadmin, wmic, PowerShell, and direct COM API access to destroy recovery options. We will also explore how defenders can detect these attacks early using threat hunting, SIEM correlation, behavioral analysis, and security monitoring.

What Are Shadow Copies?

Volume Shadow Copy Service, commonly called VSS or Shadow Copies, is a Windows technology that creates point-in-time snapshots of files and storage volumes. Microsoft introduced this feature to help users recover previous versions of files, restore systems after failures, and support backup applications.

When a user right-clicks a file in Windows and selects “Previous Versions,” the operating system may retrieve the file using VSS snapshots. These snapshots silently exist in the background and are incredibly valuable during ransomware incidents.

For many organizations, shadow copies become the fastest recovery mechanism after accidental deletion or corruption. Security teams often discover during ransomware response that shadow copies represent the difference between quick recovery and catastrophic downtime.

“Ransomware operators understand one critical principle: destroying backups increases the probability of payment.”

Because of this, ransomware operators aggressively target:

  • Volume Shadow Copies
  • Backup servers
  • Database snapshots
  • Cloud backup agents
  • Recovery catalogs
  • Disaster recovery infrastructure

Why Shadow Copies Matter During Ransomware Attacks

Many organizations mistakenly assume ransomware attacks begin with encryption. In reality, modern ransomware campaigns are highly organized operations involving:

  • Initial access
  • Credential theft
  • Lateral movement
  • Privilege escalation
  • Data exfiltration
  • Recovery destruction
  • Encryption deployment

Destroying shadow copies gives attackers enormous leverage. Without recovery options, organizations face:

  • Longer downtime
  • Business disruption
  • Higher recovery costs
  • Operational paralysis
  • Increased pressure to pay ransom

Ransomware Statistics

  • More than 90% of modern ransomware attacks attempt backup destruction.
  • Average ransomware recovery costs continue rising yearly.
  • Downtime often lasts weeks after enterprise ransomware incidents.
  • Double extortion attacks now combine encryption and data theft.

Attackers no longer depend only on encryption. They depend on psychological pressure.

If victims can restore systems easily, ransom payments decrease significantly. Therefore, deleting shadow copies is often prioritized before encryption even begins.

The Modern Ransomware Kill Chain

Modern ransomware groups operate like professional businesses. Many ransomware gangs use a Ransomware-as-a-Service model where affiliates perform attacks using shared malware platforms.

Stage 1: Initial Access

Attackers enter organizations through:

  • Phishing emails
  • Compromised VPN accounts
  • Exposed RDP servers
  • Software vulnerabilities
  • Third-party supply chain compromises

Stage 2: Privilege Escalation

Attackers attempt to obtain administrator or SYSTEM privileges. Without elevated permissions, many destructive operations cannot succeed.

Stage 3: Internal Reconnaissance

Threat actors map the environment carefully:

  • Domain controllers
  • File servers
  • Database servers
  • Backup systems
  • Security software

Stage 4: Data Exfiltration

Modern ransomware operations frequently steal sensitive files before encryption. This allows attackers to threaten public leaks if victims refuse payment.

Stage 5: Shadow Copy Destruction

This stage is critically important.

Attackers disable:

  • Windows recovery features
  • Backup agents
  • VSS snapshots
  • System restore points

Stage 6: Encryption

Only after preparation is complete does encryption begin.

By then, attackers often already control the environment completely.

How Attackers Use vssadmin

One of the most abused Windows utilities in ransomware operations is:

vssadmin.exe

This built-in Windows tool manages Volume Shadow Copy Service snapshots.

Attackers commonly execute:

vssadmin delete shadows /all /quiet

This command silently deletes all shadow copies without requiring user confirmation.

The command is devastatingly effective because:

  • It uses legitimate Microsoft software
  • It exists on almost every Windows system
  • Many security tools historically trusted it
  • It requires minimal attacker effort

This technique belongs to a broader category known as:

Living Off The Land (LotL)

Living Off The Land techniques use legitimate operating system tools for malicious purposes. This helps attackers evade antivirus products and reduce suspicious malware artifacts.

Why vssadmin Detection Is Difficult

System administrators legitimately use vssadmin for:

  • Storage management
  • Backup maintenance
  • Troubleshooting
  • System recovery operations

Therefore, security teams cannot simply alert on every vssadmin execution. Effective detection requires context.

How Attackers Use WMIC

As defenders improved monitoring for vssadmin abuse, ransomware operators adapted quickly.

They increasingly shifted toward:

wmic shadowcopy delete

WMIC, or Windows Management Instrumentation Command-line utility, provides another method for manipulating system management functions.

Attackers realized many detection systems only monitored vssadmin command lines. Switching to WMIC helped bypass simplistic detection logic.

Why WMIC Is Dangerous

WMIC allows:

  • Remote administration
  • System inventory collection
  • Shadow copy manipulation
  • Process execution
  • Persistence techniques

Attackers increasingly combine WMIC with:

  • PowerShell
  • Encoded commands
  • Scheduled tasks
  • Remote execution frameworks

This makes forensic analysis significantly more complicated.

PowerShell and Advanced Evasion

Modern ransomware groups rarely rely on a single technique.

As defenders improve visibility into command-line tools, attackers migrate toward:

  • PowerShell automation
  • Direct API calls
  • COM interface abuse
  • Custom binaries

Encoded PowerShell Commands

Attackers frequently Base64 encode PowerShell commands to hide suspicious strings from security tools.

Example techniques include:

  • Encoded WMI commands
  • Memory-only execution
  • Fileless malware behavior
  • Reflection-based execution

COM API Abuse

Some advanced ransomware families bypass vssadmin and WMIC entirely.

Instead, they directly call Windows COM interfaces associated with VSS management.

This significantly reduces forensic evidence because:

  • No suspicious command lines appear
  • No child processes spawn
  • Traditional EDR signatures may fail
  • Behavior resembles legitimate system activity
“The future of ransomware detection depends on behavioral analysis, not simple signature matching.”

Real Ransomware Families and Techniques

Different ransomware groups use different methods for destroying recovery infrastructure.

Ransomware Family Technique
LockBit WMIC and PowerShell-based deletion
Conti vssadmin shadow deletion
BlackCat / ALPHV Rust-based payloads and API abuse
Hive Shadow storage resizing and deletion
REvil Combined backup and VSS destruction
BlackMatter Direct COM API invocation

LockBit

LockBit became one of the most widespread ransomware families globally. Its operators aggressively evolved techniques to evade detection.

Security researchers observed LockBit variants rotating between:

  • vssadmin
  • WMIC
  • PowerShell
  • Encoded commands

This flexibility made static detection rules unreliable.

BlackCat / ALPHV

BlackCat attracted attention because it used the Rust programming language.

Rust offers:

  • Cross-platform capability
  • Memory safety advantages
  • Complex analysis challenges
  • Efficient execution

BlackCat operators focused heavily on stealth and minimized suspicious process creation.

Threat Hunting and Detection Strategies

Effective ransomware defense requires layered visibility.

Organizations should monitor:

  • Process creation events
  • Command-line arguments
  • PowerShell execution
  • WMI activity
  • Privilege escalation
  • Mass file modification behavior

Behavior-Based Detection

Security teams should focus on intent rather than only syntax.

For example:

  • Unknown process spawning vssadmin at 2 AM
  • Backup deletion combined with credential dumping
  • Bulk process termination before encryption
  • Simultaneous security tool tampering

These patterns strongly indicate malicious activity.

SIEM Correlation

Modern SIEM platforms should correlate:

  • Process telemetry
  • Network connections
  • User authentication
  • Threat intelligence feeds
  • Endpoint behavior

Single alerts are often noisy. Correlated behaviors create higher confidence detection.

Threat Hunting Queries

Threat hunters commonly search for:

vssadmin delete shadows wmic shadowcopy delete powershell Get-WmiObject Win32_ShadowCopy

However, mature hunting teams also investigate:

  • Encoded PowerShell
  • Suspicious parent-child process relationships
  • Rare administrative tool execution
  • Abnormal administrative activity

How Organizations Should Defend Themselves

1. Immutable Backups

Organizations must implement backup systems attackers cannot modify easily.

Immutable backups prevent:

  • Deletion
  • Encryption
  • Tampering
  • Unauthorized modification

2. Privileged Access Management

Restricting administrative privileges reduces attacker capability dramatically.

Many ransomware attacks succeed because:

  • Users possess unnecessary privileges
  • Shared admin accounts exist
  • Password reuse occurs
  • Domain-wide privileges remain excessive

3. EDR and Behavioral Monitoring

Endpoint Detection and Response platforms should monitor:

  • Process execution chains
  • Script behavior
  • Memory anomalies
  • Persistence techniques
  • Recovery destruction attempts

4. Network Segmentation

Segmentation prevents attackers from moving freely across environments.

Critical infrastructure should remain isolated from:

  • User workstations
  • Development systems
  • Internet-facing services

5. Incident Response Preparedness

Organizations should rehearse ransomware response scenarios regularly.

Prepared teams recover faster because:

  • Roles are predefined
  • Recovery procedures exist
  • Communication plans are established
  • Forensic workflows are tested

Future of Ransomware Defense

Ransomware continues evolving rapidly.

Future ransomware operations will likely incorporate:

  • AI-assisted phishing
  • Automated lateral movement
  • Cloud infrastructure targeting
  • EDR evasion frameworks
  • Advanced anti-forensics

Defenders must evolve equally fast.

Future cybersecurity operations will increasingly depend on:

  • Behavioral analytics
  • Machine learning detection
  • Threat intelligence sharing
  • Automation
  • Zero Trust architectures
“The organizations that survive ransomware attacks are not necessarily the ones with the most expensive tools. They are the ones with visibility, preparation, and disciplined operational security.”

Monday, December 9, 2013

Terminology in computer security

The following terms used in engineering secure systems are explained below.
  • Authentication techniques can be used to ensure that communication end-points are who they say they are.
  • Automated theorem proving and other verification tools can enable critical algorithms and code used in secure systems to be mathematically proven to meet their specifications.
  • Capability and access control list techniques can be used to ensure privilege separation and mandatory access control. This section discusses their use.
  • Chain of trust techniques can be used to attempt to ensure that all software loaded has been certified as authentic by the system's designers.
  • Cryptographic techniques can be used to defend data in transit between systems, reducing the probability that data exchanged between systems can be intercepted or modified.
  • Firewalls can provide some protection from online intrusion.

  • A microkernel is a carefully crafted, deliberately small corpus of software that underlies the operating system per se and is used solely to provide very low-level, very precisely defined primitives upon which an operating system can be developed. A simple example with considerable didactic value is the early '90s GEMSOS (Gemini Computers), which provided extremely low-level primitives, such as "segment" management, atop which an operating system could be built. The theory (in the case of "segments") was that—rather than have the operating system itself worry about mandatory access separation by means of military-style labeling—it is safer if a low-level, independently scrutinized module can be charged solely with the management of individually labeled segments, be they memory "segments" or file system "segments" or executable text "segments." If software below the visibility of the operating system is (as in this case) charged with labeling, there is no theoretically viable means for a clever hacker to subvert the labeling scheme, since the operating system per se does not provide mechanisms for interfering with labeling: the operating system is, essentially, a client (an "application," arguably) atop the microkernel and, as such, subject to its restrictions.
  • Endpoint security software helps networks to prevent data theft and virus infection through portable storage devices, such as USB drives.
  • Confidentiality is the nondisclosure of information except to another authorized person.[24]
  • Data integrity is the accuracy and consistency of stored data, indicated by an absence of any alteration in data between two updates of a data record.[25]
Some of the following items may belong to the computer insecurity article:
  • Access authorization restricts access to a computer to group of users through the use of authentication systems. These systems can protect either the whole computer – such as through an interactive login screen – or individual services, such as an FTP server. There are many methods for identifying and authenticating users, such as passwords,identification cards, and, more recently, smart cards and biometric systems.
  • Anti-virus software consists of computer programs that attempt to identify, thwart and eliminate computer viruses and other malicious software (malware).
  • Applications with known security flaws should not be run. Either leave it turned off until it can be patched or otherwise fixed, or delete it and replace it with some other application. Publicly known flaws are the main entry used by worms to automatically break into a system and then spread to other systems connected to it. The security website Secunia provides a search tool for unpatched known flaws in popular products.
  • Backups are a way of securing information; they are another copy of all the important computer files kept in another location. These files are kept on hard disks, CD-Rs, CD-RWs, and tapes. Suggested locations for backups are a fireproof, waterproof, and heat proof safe, or in a separate, offsite location than that in which the original files are contained. Some individuals and companies also keep their backups in safe deposit boxes inside bank vaults. There is also a fourth option, which involves using one of the file hosting services that backs up files over the Internet for both business and individuals.
    • Backups are also important for reasons other than security. Natural disasters, such as earthquakes, hurricanes, or tornadoes, may strike the building where the computer is located. The building can be on fire, or an explosion may occur. There needs to be a recent backup at an alternate secure location, in case of such kind of disaster. Further, it is recommended that the alternate location be placed where the same disaster would not affect both locations. Examples of alternate disaster recovery sites being compromised by the same disaster that affected the primary site include having had a primary site in World Trade Center I and the recovery site in 7 World Trade Center, both of which were destroyed in the 9/11 attack, and having one's primary site and recovery site in the same coastal region, which leads to both being vulnerable to hurricane damage (for example, primary site in New Orleans and recovery site in Jefferson Parish, both of which were hit by Hurricane Katrina in 2005). The backup media should be moved between the geographic sites in a secure manner, in order to prevent them from being stolen.


Cryptographic techniques involve transforming information, scrambling it so it becomes unreadable during transmission. The intended recipient can unscramble the message, but eavesdroppers cannot, ideally.
  • Encryption is used to protect the message from the eyes of others. Cryptographically secure ciphers are designed to make any practical attempt of breaking infeasible. Symmetric-key ciphers are suitable for bulk encryption using shared keys, and public-key encryption using digital certificates can provide a practical solution for the problem of securely communicating when no key is shared in advance.
  • Firewalls are an important method for control and security on the Internet and other networks. A network firewall can be a communications processor, typically a router, or a dedicated server, along with firewall software. A firewall serves as a gatekeeper system that protects a company's intranets and other computer networks from intrusion by providing a filter and safe transfer point for access to and from the Internet and other networks. It screens all network traffic for proper passwords or other security codes and only allows authorized transmission in and out of the network. Firewalls can deter, but not completely prevent, unauthorized access (hacking) into computer networks.
  • Honey pots are computers that are either intentionally or unintentionally left vulnerable to attack by crackers. They can be used to catch crackers or fix vulnerabilities.
  • Intrusion-detection systems can scan a network for people that are on the network but who should not be there or are doing things that they should not be doing, for example trying a lot of passwords to gain access to the network.

  • Pinging The ping application can be used by potential crackers to find if an IP address is reachable. If a cracker finds a computer, they can try a port scan to detect and attack services on that computer.
  • Social engineering awareness keeps employees aware of the dangers of social engineering and/or having a policy in place to prevent social engineering can reduce successful breaches of the network and servers.

Copied from wikipedia.

ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch

ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch Category: Vulnerability Research | Windows Security |...