Ransomware in 2026: Encryption Is the Last Step. Detect the Four That Come Before It
The encryptor is the terminal event, not the attack. Detection didn't vanish when breakout hit 29 minutes. It relocated to the pre-encryption phases.
Most ransomware detection programs are built to catch the encryptor. Alert on mass file renames, on vssadmin delete shadows, on the ransom note dropping into every directory. It feels like the right target because it is the moment the damage becomes undeniable. It is also the moment you have already lost, because by the time the encryptor runs, the operator has been inside for days, has read your data, has copied the parts worth extorting you over, and has disabled the recovery path you were counting on. Encryption is not the attack. It is the operator cashing out.
Two things in the 2025-26 data make this concrete. First, extortion decoupled from encryption: Unit 42 found encryption present in only about 78% of extortion cases in 2025, down from the 90%-plus norm of prior years, and Sophos measured encryption in under half, 49%, of the enterprise attacks it surveyed, the lowest in five years [1][2]. A growing share of victims never see a single file encrypted; the leverage is the stolen data, full stop. Second, even when encryption does happen, it is the last event in a sequence, fired only after the intruder has already won.
So the encryptor is the wrong detection target, and this is the good news, not the bad. The detection window did not close when CrowdStrike clocked eCrime breakout time at 29 minutes [3]. It relocated backward, into the pre-encryption phases, where the telemetry is loud, scriptable, and shaped exactly like the commodity tooling affiliates actually use. This post maps those windows. In Living Off the Land in 2026 I covered the ESXi mass-encryption chain and the LOLBins that carry it: the encryptor’s own delivery. This one is about the four steps before the encryptor ever runs.
The Encryptor Is the Wrong Target
Walk the sequence a ransomware operation actually executes and the encryptor lands at the very end: initial access, then discovery, then credential access and lateral movement, then collection and exfiltration, and only then, if at all, recovery inhibition and encryption. Every dollar of leverage the attacker will use against you is already banked before the first file changes. The stolen data is staged off-site. The backups are gone. The encryptor is a receipt.
This is why “detect the encryption” is a category error. You are instrumenting the one phase where nothing about your response can still change the outcome. The data already left. The shadow copies are already deleted. Paging an analyst on the ransom note is paging them to witness, not to intervene.
And increasingly there is no encryption phase to catch at all. Symantec’s telemetry counted 6,182 extortion attacks in 2025, a 23% year-over-year rise, while encryption-based ransomware stayed essentially flat at +0.8% [4]. The growth is entirely in steal-and-extort. If your ransomware program is a set of encryptor tripwires, it is structurally blind to the fastest-growing half of the threat, and late on the other half.
The reframe is simple. Stop treating encryption as the event to detect and start treating it as the deadline. Everything upstream of it is your detection surface, and the further upstream you catch it, the more of the outcome you can still change.
Speed Is the Steelman: Name It Before You Map the Windows
There is a serious argument that this whole exercise is a waste of time, and it comes straight from the same reports I just cited. CrowdStrike’s average eCrime breakout time fell to 29 minutes, with a fastest-ever observation of 27 seconds and one intrusion where exfiltration began within four minutes of initial access [3]. Mandiant found the handoff from initial-access broker to the operator who does the damage has collapsed to about 22 seconds [5]. The prevention-only camp reads those numbers and concludes: human-speed detection is a fantasy. Stop writing Sigma. Buy immutable backups, phishing-resistant MFA, and an IR retainer, and accept that if they get in, they win the race.
Take that seriously, because half of it is correct. Prevention is the highest-leverage spend here, and I will land on it at the end. Immutable, offline backups defeat the encryptor outright. They turn “recover or pay” into “restore and move on.” Phishing-resistant MFA kills the cheapest initial-access path. If you do nothing else, do those.
But the speed argument smuggles in a bad inference. Breakout time and the 22-second handoff measure lateral velocity (how fast an operator moves from one host to the next), not the duration of the whole operation. Those two are not the same number, and the gap between them is your detection window. Mandiant’s own frontline data puts the median dwell time for ransomware intrusions at 6 days, with 56.5% resolved within a week [6]. Unit 42 puts the median time-to-exfiltration at 2 days [1]. An operator can pivot between machines in seconds and still spend days inside your environment doing the loud, mechanical work of finding the data, staging it, and killing your backups. The velocity is high. The runway is long. Both are true.
And the work they do on that runway is not subtle. NetScan appeared in 19% of Symantec’s investigated attacks; Rclone in 10% [4]. A network scanner and a cloud-copy utility, both driven from the command line, both leaving textbook process and command-line telemetry. This is the same point I made about identity-first attacks relocating to a sensor you don’t own: the phases don’t vanish, they move. Here they move earlier in the same environment you already instrument, which is the best possible place for them to go. The window moved. It didn’t close.
The Four Windows: Earlier Is More Time to Act
Here is the part the “exfil is the widest window” crowd gets slightly wrong, and it’s the crux of how you should weight your effort. Yes, exfiltration is the loudest, most detectable phase. But it is also late. It sits right next to the attacker’s final objective. Detecting at exfil means detecting with the least reaction time and the highest stakes. The right way to read the kill chain is as a gradient: the earlier you catch the operator, the more time you have to act, and the cheaper the intervention. The same “break it early” economics I applied to the identity kill chain apply here: treat these four windows as widening reaction time as you move backward, not just as a trends list.
Window 1: Initial access handoff (earliest, most reaction time, quietest signal). This is where a broker sells a foothold and the operator logs in. Mandiant now attributes 30% of ransomware initial access to prior compromise, access that was already sitting there, up from 15% [5], which means the clock often started days before the operator showed up. That is enormous reaction time if you can see it. The problem is the signal is thin: it looks like a valid login, the same problem the identity post is entirely about. So this window offers the most time and the least obvious telemetry. It is worth instrumenting, but it is not where a Sigma rule earns its keep fastest.
Window 2: Discovery and recon (early, high reaction time, loud signal). This is the sweet spot, and it is underweighted by almost everyone. Before an operator can steal or encrypt, they have to find things: enumerate Active Directory, scan the network, map the file shares. That is what NetScan’s 19% prevalence represents [4]. Discovery is mechanical, scriptable, and, critically, happens before the attacker has what they need, so catching it here still lets you evict them before any data moves. A workstation that suddenly runs a full-subnet port scan, or a service account enumerating every domain admin, is loud and early. This is the highest-ROI window: lots of reaction time, plenty of signal, and the attacker hasn’t accomplished anything yet.
Window 3: Credential access and lateral movement (mid, shrinking reaction time). This is where breakout time lives, the 29-minute number. The operator is dumping credentials, spraying them across hosts, moving toward the data and the backup infrastructure. The signal is strong (Kerberoasting, lsass access, anomalous remote execution) but your reaction time is now measured against that fast lateral velocity. Still catchable, still upstream of impact, but you’re racing.
Window 4: Collection and exfiltration (latest before impact, widest signal, least time). This is the loudest window and the one everybody points to: bulk reads followed by Rclone or MEGAcmd pushing gigabytes to mega:, s3:, or a Backblaze bucket. Unit 42’s median time-to-exfil is 2 days, but the fastest quartile hit it in 72 minutes and roughly 22% of incidents exfiltrated within the first hour [1]. So yes, detect it, but understand you are detecting at the attacker’s goal line. By the time bytes are leaving, your window to prevent the extortion is nearly gone even if you can still prevent the encryption. Exfil is the widest net, and the one you must have, but it is the consolation prize, not the target.
Then, terminal: recovery inhibition and encryption. vssadmin delete shadows /all /quiet, wbadmin delete catalog, bcdedit recovery tampering. The CISA #StopRansomware advisory on Akira lists exactly these as the pre-encryption recovery-kill steps to monitor [7]. Loud, unambiguous, and far too late to matter for anything but forensics.
Read top to bottom, the gradient is the whole thesis: exfil is where most programs finally notice, and it’s the worst place to first notice. Push your detection center of mass into Windows 2 and 3.
Why the Toolkit Is Commodity, and Why That’s Good News
You might expect this variety of speed and sophistication to come with bespoke, hard-to-detect tooling. The opposite is true, and the reason is economic. Ransomware-as-a-service fragmented after the LockBit and ALPHV takedowns; the affiliate pool widened and the skill floor dropped. A lower skill floor means affiliates reach for the same off-the-shelf kit: NetScan for discovery, Rclone or MEGAcmd for exfil, vssadmin for recovery destruction. The DBIR reflects the resulting blast radius: ransomware present in 44% of breaches (up from 32%) and in 88% of breaches at small and midsize businesses [8]. That reach is built on commodity TTPs.
Commodity TTPs are exactly what you can write detections for. You are not chasing a novel implant; you are chasing rclone with a bandwidth flag and a remote spec, which looks the same whether the affiliate is competent or not. The fragmentation that made ransomware more prevalent also made it more uniform, and uniform is detectable. This is the detection-funnel coverage argument pointed at a soft target: you don’t need coverage of every technique, you need real coverage of the handful of loud, mechanical steps that nearly every affiliate performs in Windows 2 through 4.
One Rule: Exfil by Behavior, Not by Binary Name
Here is a detection for Window 4. I’m putting the Sigma rule at the latest actionable window on purpose, to make a point about how to write it, then I’ll say what the earlier-window companion looks like.
Naming the binary is a trap. Affiliates rename rclone.exe to svchost.exe, to w.exe, to anything. The rename-resistant signal is the command-line grammar of a bulk cloud transfer: an rclone/mega verb (copy, sync, move), a concurrency or bandwidth flag (--transfers, --multi-thread-streams), an explicit remote spec (remote:, mega:, s3:, b2:), a --config pointing at a dropped config, and the tell-tale --no-check-certificate / --ignore-existing speed flags. That grammar survives a rename because the operator still has to pass the flags. It gets sharper when the process has an implausible parent (a browser, an Office app, PowerShell) or runs under a user or host that has never legitimately touched a cloud-copy tool.
# Detection rationale: ransomware exfiltration is performed with legitimate cloud-copy
# tools (Rclone, MEGAcmd) that operators rename to evade name-based rules. What they
# cannot rename is the COMMAND LINE: a bulk-transfer verb + a concurrency/bandwidth
# flag + an explicit remote backend spec + a --config redirect. This keys on that
# grammar, not the image name, so it survives rclone.exe -> svchost.exe renames.
# It is deliberately a Window-4 (late, but widest-signal) detection; pair it with the
# correlation note below to reach the pre-encryption chain. ATT&CK T1567.002.
title: Bulk Cloud Exfiltration via Rclone/MEGAcmd Command-Line Grammar
status: experimental
logsource:
category: process_creation
product: windows # Sysmon Event ID 1 or Windows 4688 with cmdline auditing
detection:
transfer_verb:
CommandLine|contains:
- ' copy '
- ' copyto '
- ' sync '
- ' move '
- ' moveto '
speed_flag:
CommandLine|contains:
- '--transfers'
- '--multi-thread-streams'
- '--bwlimit'
- '--ignore-existing'
- '--no-check-certificate'
remote_backend:
CommandLine|contains:
- 'mega:'
- 's3:'
- 'b2:'
- 'gcs:'
- 'dropbox:'
- ':crypt'
- '--config'
# Sharpen with novel context. In deployment, exclude your known backup service
# accounts/hosts here and alert hardest on unusual parents or first-time users.
suspicious_parent:
ParentImage|endswith:
- '\powershell.exe'
- '\cmd.exe'
- '\winword.exe'
- '\excel.exe'
- '\chrome.exe'
- '\msedge.exe'
condition: transfer_verb and speed_flag and remote_backend
# Optional escalation to a pre-encryption CHAIN (deploy as a Sigma correlation rule):
# this exfil match, then within 6h on the same host a T1490 recovery-kill event
# ("vssadmin delete shadows", "wbadmin delete catalog", "bcdedit ... recoveryenabled no")
# = high-confidence steal-then-encrypt sequence. Page immediately.
falsepositives:
- Legitimate IT/DevOps/MSP backup and sync jobs. Rclone to Backblaze B2 or S3 is a
mainstream, sanctioned backup pattern, and MEGAcmd/personal MEGA sync is common on
developer and admin machines. Baseline the service accounts and hosts that run these
jobs on a schedule and exclude them; alert on NOVEL context instead.
- Data-migration or cloud-onboarding projects that legitimately move bulk data once.
Confirm against a change ticket and a known operator, then time-box an exception.
- A developer's personal cloud sync running under an interactive user. The parent will
be a shell or the tool itself, not Office/browser; use the parent filter to separate
scripted backups from injected exfil.
level: high
tags:
- attack.exfiltration
- attack.t1567.002 # Exfiltration to Cloud Storage
The false positives here are real and I want to be honest about them, because pretending Rclone is inherently malicious is how you burn analyst trust. Rclone-to-B2 and Rclone-to-S3 are the standard way a huge number of IT teams and MSPs run backups; MEGAcmd and personal MEGA sync live on plenty of developer laptops. That legitimate usage is exactly why name-based blocking fails and why baselining matters more than the signature. This is the alert-fatigue-as-offensive-technique problem in miniature: a rule that pages on every scheduled B2 backup trains your analysts to close Rclone alerts reflexively, which is a gift to the operator who renames their binary and runs it once at 2 a.m. from a host that has never done a backup. Tune on context (known account, known host, known schedule), and let the novel case be the alert.
One rule, at one window. The higher-value companions live earlier: a discovery-window detection for a workstation running full-subnet scans (NetScan behavior), and the correlation escalation noted in the rule (exfil grammar followed within hours by a T1490 recovery-kill event), which fuses Window 4 and the terminal phase into one high-confidence “steal-then-encrypt” signal. The cloud-side version of this movement, en route to the same objective, is the subject of the cloud lateral movement techniques SOCs miss.
Prevention First, Then Instrument the Earliest Window You Can
Now honor the steelman, because it was mostly right. The single highest-leverage control against ransomware is not a detection. It is immutable, offline backups, which neutralize the encryptor completely and turn a catastrophe into a restore. Add phishing-resistant MFA to close the cheapest initial-access door. The DBIR’s payment data shows the market already tilting this way: 64% of victim organizations refused to pay and the median payment fell to $115,000 [8], which is what happens when more organizations can recover without negotiating. Prevention is the play. I say that as someone who writes a detection blog.
But prevention has a hard ceiling, and it is the reason detection still matters: backups defeat the encryptor; they do nothing about the data that already left. Against pure steal-and-extort, now the majority of extortion activity, there is no encryptor to defeat and no backup to restore. The only thing standing between an operator and your data walking out the door is whether you noticed the discovery, the lateral movement, or the exfil in time. That is Windows 2 through 4, and that is where the richest detectable telemetry sits, precisely because it is loud, commodity, and in-environment.
So do both, in this order. Kill the recoverability problem with immutable backups so the encryptor is impotent. Then instrument the earliest window you realistically can. Put your detection center of mass on discovery and lateral movement, not on the encryptor’s death rattle. And rehearse the tabletop that most teams skip: not “ransomware detonated, do we restore?” but “the data already left. Now what?” If that question makes the room go quiet, your program is still guarding the last step. Move it four steps earlier, where you still have time to act.
Resources
- 2026 Unit 42 Global Incident Response Report. Palo Alto Networks Unit 42 (median time-to-exfiltration ~2 days; fastest quartile 72 minutes; ~22% exfiltrated within the first hour; encryption present in only ~78% of extortion cases in 2025).
- The State of Ransomware 2025. Sophos (encryption in 49% of enterprise attacks, lowest in five years; 28% of encrypted organizations also had data exfiltrated).
- CrowdStrike 2026 Global Threat Report: Evasive Adversary Wields AI. CrowdStrike (average eCrime breakout time 29 minutes; fastest ever 27 seconds; exfiltration within 4 minutes of access in one intrusion; 82% of intrusions malware-free).
- Ransomware: Tactical Evolution Fuels Extortion Epidemic. Symantec / Security.com (6,182 extortion attacks in 2025, +23% YoY; encryption-based ransomware flat at +0.8%; NetScan in 19% of attacks, Rclone in 10%).
- M-Trends 2026: Data, Insights, and Strategies From the Frontlines. Google Cloud / Mandiant (initial-access-to-handoff collapsed to ~22 seconds; prior compromise as ransomware initial vector rose 15%→30%).
- M-Trends 2025: Data, Insights, and Recommendations From the Frontlines. Google Cloud / Mandiant (ransomware median dwell time 6 days; 56.5% of ransomware intrusions resolved within one week).
- #StopRansomware: Akira Ransomware (AA24-109A). CISA (Akira uses
vssadmin delete shadows /all /quiet; monitorvssadmin,bcdedit,fsutil,wbadmin, and WMI shadow-copy deletion as pre-encryption recovery-kill steps). - 2025 Data Breach Investigations Report. Verizon (ransomware present in 44% of breaches, up from 32%; 88% of SMB breaches; median ransom payment $115,000; 64% of victims refused to pay).