Open cardosec

Case 470E77 · Malware & intel · L2 Practitioner

Ransomware attack lifecycle

Practise as: Explain it · Interview · Deep dive

Interview questionWalk me through a modern human-operated ransomware attack from initial access to the ransom note.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Initial access: phishing, exposed RDP/VPN without MFA, or exploited edge devices; often bought from initial access brokers
  2. Discovery and privilege escalation: AD recon (BloodHound, AdFind), credential dumping from LSASS, aim for Domain Admin
  3. Lateral movement via RDP, PsExec, WMI or SMB; staging tools with legit RMM software like AnyDesk
  4. Double extortion: exfil with rclone/MEGAsync before encrypting, then leak-site pressure if no payment
  5. Impact: delete shadow copies (vssadmin), kill backups/AV, mass-encrypt via GPO or PsExec, drop ransom note

If the interviewer pushes back

  • Why do operators increasingly skip encryption and do pure data-theft extortion?
  • Which single control breaks the most stages of this chain, and why?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.