
When I look at how modern ransomware operates, I often notice a fundamental misunderstanding: most people assume the attack is entirely about the encryption. In reality, a ransom demand only holds weight if the victim genuinely believes they are completely out of options.
Long before you ever see an encryptor run or a ransom note appear on a screen, an attacker is usually already quietly navigating your network with a highly methodical checklist. They are specifically identifying which backups to disable, which security tools to dismantle, which logs to erase, and which systems to compromise next.
The true objective isn't merely to lock your data, but to systematically eliminate your recovery alternatives. That encryption phase isn't the whole attack; it is simply the final, highly visible stage of a malicious operation that began much earlier.
Encryption Is Visible; Preparation Is Not
Ask most people to describe a ransomware attack, and they will describe the ransom note: files renamed with an unfamiliar extension, a text file demanding payment, or a countdown timer.
That is the part designed to be seen.
By the time it appears, the attacker may already have spent hours, days, or weeks weakening the victim’s ability to detect, contain, and recover from the attack.
The earlier work, the part that determines whether an organization can recover on its own, tends to happen quietly. Individually, these actions can resemble legitimate administration: a service stopping, a scheduled task running, or a log file being cleared.
The warning often lies in their context, sequence, and timing.
The Recovery Stack Is Now Part Of The Attack Surface
It was once reasonable to treat security and backup as two separate disciplines. One team kept attackers out, while another maintained copies of critical data in case an attacker got in anyway.
Ransomware operators do not respect that boundary. Organizations that continue to treat recovery infrastructure as separate from the security perimeter risk being left with fewer options when an attack occurs.
A modern ransomware attack may attempt to close off several recovery routes at once:
| Exit Route | How Attackers Close It Off |
|---|---|
| Restore from a snapshot | Delete Volume Shadow Copies and local restore points. |
| Recover from enterprise backup | Stop backup services and jobs, disable agents, and target repositories or catalogs. |
| Rebuild the environment | Reach hypervisors, virtualization management layers, and infrastructure configurations. |
| Contain the attack | Disable security tools and spread further using existing credentials. |
| Investigate what happened | Clear event logs, delete forensic artifacts, and disguise malicious activity as legitimate processes. |
Many of these actions can be carried out through administrative utilities, existing credentials, and interfaces that are already trusted inside the environment.
That is exactly why they can be difficult to detect.
Trusted Tools, Weaponized
Attackers do not always need custom malware to prepare an environment for encryption. In many cases, they use tools that administrators already rely on every day.
This makes pre-encryption activity difficult to identify because the tools themselves may be legitimate. What matters is how, when, and why they are being used.
PowerShell, WMI, and PsExec, for example, are standard administrative tools. They can also be abused to execute commands remotely and move laterally across a domain.
Similarly, a malicious payload renamed after a familiar system process may attract less scrutiny or bypass controls that rely too heavily on file names, locations, or assumed trust. Renaming alone, however, does not defeat content-based scanning, hashing, or behavioral detection.
An organization looking only for known malicious files can miss critical stages of an attack carried out through trusted utilities.
Detecting this type of activity requires monitoring behavior rather than waiting to recognize a specific malicious file. Warning signs may include a backup service stopping outside a maintenance window or a process suddenly deleting logs it has no legitimate reason to access.
Different ransomware, the same underlying strategy
This is not a theory based on a single attack. The same strategic pattern appears, with local variations, across ransomware families that otherwise have little in common.
Microsoft’s May 2026 analysis of The Gentlemen ransomware, a Go-based, self-propagating encryptor associated with the threat actor Storm-2697, documented a pre-encryption sequence that disabled Microsoft Defender, deleted Volume Shadow Copies, cleared event logs, and removed forensic artifacts.
The ransomware also terminated backup, database, security, and virtualization-related processes and services. These actions helped release locked files for encryption while weakening detection and recovery.
A joint CISA, FBI, and MS-ISAC advisory on LockBit 3.0 documented a similar pattern. LockBit 3.0 deletes shadow copies and log files, weakening recovery and forensic visibility. It also replaces the desktop wallpaper and drops ransom instructions to signal that encryption has occurred.
The same strategy appeared again in a June 2026 attack involving a newly identified ransomware strain called Spirals. Before deploying the encryptor, the attackers disabled Windows Defender and force-stopped services associated with more than 20 backup, database, and virtualization products. The attack reportedly reached the wider network within a single day.
Three separate ransomware operations used different tooling but followed the same strategic pattern: Weaken defenses, restrict recovery, spread, and then encrypt.
Backups are necessary but alone are not ransomware protection
None of this is an argument against maintaining backups. It is quite the opposite.
CISA’s #StopRansomware guidance recommends offline, encrypted, and regularly tested backups precisely because backups that are reachable from the network may also be reachable by an attacker.
But backups provide a recovery path. They do not, on their own, terminate an encryption process while it is running, identify the process responsible, isolate an affected endpoint, or explain how the incident spread.
That is a different job, and it has to happen while the attack is still active.
Detecting The Attack While Options Still Exist
This is the gap Ransomware Protection Plus is designed to address: not just the recovery step after damage has occurred but the window in which the attack is still active, and recovery remains a viable option.
Ransomware Protection Plus complements offline and immutable enterprise backups rather than replacing them. Its role is to detect and stop ransomware activity at the endpoint, contain affected devices, preserve protected local recovery points, and help security teams understand how the attack unfolded.
1. Behavioral and ML-based detection
Rather than relying only on signatures associated with known ransomware families, Ransomware Protection Plus monitors endpoints for anomalous behavior, including irregular encryption activity.
This helps identify ransomware based on what it does, even when the specific payload or family has not been encountered before.
2. Automatic process termination and ransomware kill switch
When Kill mode is enabled, Ransomware Protection Plus can automatically terminate suspicious processes and interrupt active encryption without waiting for manual intervention.
Stopping the responsible process early can reduce the number of files affected and limit the attacker’s opportunity to continue the operation.
3. Real-time device isolation
Affected endpoints can be isolated from the network to help contain the threat and reduce the risk of lateral movement to other critical assets.
4. Attack chain discovery
Ransomware Protection Plus breaks down the incident life cycle, from the initial affected device to process-level activity.
This helps security teams identify the likely point of origin, understand how the attack progressed, and determine which processes and endpoints were involved.
5. Single-click file recovery
Affected files can be restored using protected VSS snapshots created every three hours.
Ransomware Protection Plus uses patented tamper protection to safeguard these local recovery points against ransomware-driven deletion and modification attempts. Depending on when the file was affected, the latest available recovery point may be up to three hours old.
Final Thoughts
I consistently emphasize to teams that we can no longer afford to treat security and backup as two entirely separate disciplines. The practical reality is that your recovery infrastructure must be defended just as aggressively as your primary production infrastructure.
By the time a ransom note actually becomes visible, your most valuable window for containing the threat has likely already closed. The true fight against these threat actors happens much earlier, and much more quietly, while your organization's path back to safety is still standing.
If we only prepare for the final encryption stage, we give attackers exactly the time they need to destroy our way out.

By Nivedhitha D
Product Specialist, ManageEngine






