Case 470E77 · Malware & intel · L2 Practitioner
Ransomware attack lifecycle
Practise as: Explain it · Interview · Deep dive
Interview questionWalk me through a modern human-operated ransomware attack from initial access to the ransom note.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Initial access: phishing, exposed RDP/VPN without MFA, or exploited edge devices; often bought from initial access brokers
- Discovery and privilege escalation: AD recon (BloodHound, AdFind), credential dumping from LSASS, aim for Domain Admin
- Lateral movement via RDP, PsExec, WMI or SMB; staging tools with legit RMM software like AnyDesk
- Double extortion: exfil with rclone/MEGAsync before encrypting, then leak-site pressure if no payment
- Impact: delete shadow copies (vssadmin), kill backups/AV, mass-encrypt via GPO or PsExec, drop ransom note
If the interviewer pushes back
- Why do operators increasingly skip encryption and do pure data-theft extortion?
- Which single control breaks the most stages of this chain, and why?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.