HeadlinesBriefing favicon HeadlinesBriefing.com

Ransomware Evolution: New Tactics Emerge

Hacker News •
×

Ransomware attacks continue to rise globally, with 698 incidents reported in May 2026, a 48% increase from the previous year. The landscape is shifting from dominant groups to a more fragmented ecosystem of specialized actors, including initial access brokers and affiliates. This evolution leads to more diverse and unpredictable tactics, techniques, and procedures (TTPs), with attackers increasingly using native tools and legitimate penetration testing frameworks like Sliver to evade detection. Anomaly-based and behavioral detection are becoming critical for identifying pre-ransomware activity.

In early 2026, Darktrace detected a multi-stage ransomware intrusion that began with compromised VPN credentials. The attack involved rapid internal reconnaissance and lateral movement using legitimate tools, bypassing traditional signature-based detection. The intrusion utilized Sliver, an open-source framework favored for its stealth. The attack unfolded over three days, presenting multiple opportunities for early intervention before encryption.

During the initial stages, anomalous scanning behavior and widespread network enumeration were detected, indicative of tools like Nmap. Privilege escalation was observed through Active Directory replication abuse, similar to 'DCSync' attacks. The later stages involved extensive lateral movement using living-off-the-land techniques (PSExec, WMI, RDP) and command-and-control communications consistent with Sliver, alongside potential data exfiltration. While Darktrace's Autonomous Response was not fully configured, it highlighted the potential for early disruption.