惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
爱范儿
爱范儿
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
阮一峰的网络日志
阮一峰的网络日志
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
博客园 - 聂微东
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
博客园 - 叶小钗
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
博客园 - 司徒正美
博客园 - 【当耐特】
IT之家
IT之家

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat?
From Inbox to Encryption: How Ransomware Delivery Has Evo...
KnowBe4 Threat Lab · 2026-07-23 · via Human Risk Management Blog

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.

What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker.

So, what can organizations do to protect themselves from these new threats? In this report from the KnowBe4 Threat Labs team, you will be able to:

  • Identify the infrastructure patterns defining 2025-2026 ransomware campaigns.
  • Map the critical stages that separate the initial email from the final encryption event.
  • Understand the mechanics of the "ClickFix" technique and why modern threats are designed specifically to evade your current security controls.

Every shift in delivery method was a direct response to whatever controls had just become effective against the previous approach. In 2019 an internationally coordinated effort took down the Necurs botnet, a criminal infrastructure responsible for 90% of email-based malware. This disruption of the world’s largest botnet, with the loss of 9 million infected nodes, is the clearest inflection point: until then, volume was the strategy. Once that infrastructure was disrupted and security products had matured to catch direct attachment delivery, the economics changed. Operators moved to precision targeting and multi-stage chains where the email carries nothing dangerous itself.

PERIOD

ACTOR / CAMPAIGN

WHAT CHANGED

Early 2000s

GPCode ransomware

Spear phishing with trojans disguised as job applications. First documented use of phishing as a ransomware delivery vector.

2007 onwards

Evil Corp / Dridex

Cridex banking trojan via phishing, evolved into modular Dridex. Introduced the rentable malware model: operators and affiliates begin to separate.

Mid-2010s

Locky / Necurs botnet

Up to 23 million phishing emails per 24-hour period across ~120,000 IPs in 139 country-code TLDs. Industrialised phishing at botnet scale.

2019

Necurs takedown

Microsoft and 35 law enforcement agencies dismantle Necurs. Forces transition away from high-volume direct-payload delivery.

2025-2026

Multiple groups incl. access brokers

Multi-hop redirect chains, fileless droppers, RMM tools for persistence, DNS-based staging. Phishing operators and ransomware operators are now separate commercial parties.

What Ransomware Infrastructure Patterns Arose Between 2025-2026?

Threat Labs monitoring across this period revealed six consistent infrastructure patterns across diverse campaigns, regardless of varying lures or payloads. Each pattern maps directly to a control that had become effective against the previous approach.

Trusted First Hops: Attackers route through Google Drive, Dropbox, Slack and GitHub as first-hop redirect points. Links to these platforms appear trustworthy to the user and receive low-risk treatment from security products.

Seasoned Domain Redirects: The redirect chain leverages compromised or parked domains that have maintained clean reputation for a longer period of time, which affects blocklisting. This provides the attacker with a clear delivery window. Multistage redirect chains also exhaust the analysis timeframes of automated sandbox analysis.

Traceless Payloads: Droppers prioritize evasion through layered obfuscation and polymorphic signatures. Some campaigns use built-in Windows utilities like Certutil to stage payloads directly in process memory, bypassing the filesystem entirely. This means no detectable files remain for malware scanners.

Purchased Access: Ransomware operators treat access as a commodity rather than building it themselves. They procure established, valid credentials and pre-compromised infrastructures from underground markets, allowing them to bypass initial intrusion phases and pivot directly to malware deployment.

RMM for Persistence: Persistence is achieved using legitimate, signed commercial remote management tools. These blend into routine network traffic and IT environments, making unauthorized installations difficult to identify without specific environment baselines.

Separated Operators: Phishing and ransomware operations are often distinct commercial entities. One actor specializes in securing the initial foothold, which is then traded to a different ransomware operator. This ensures that the final payload deployment is decoupled from the original email by a discrete financial transaction between parties.

How The Ransomware Chains Actually Run

The common infrastructure patterns of the last year share a common thread: the inbox as an entry point. The phishing email carries a call-to-action or attachment whose only function is the first redirect. There is no payload in it. From that redirect, the victim moves through cloud platforms and then through domains with degraded or no reputation signal before reaching infrastructure the attacker controls.

Here are the five stages of a typical ransomware attack chain:

STAGE 1 -- PHISHING EMAIL

The mail arrives as a subtle, time-sensitive lure. There’s no payload here, just a link to a trusted cloud service that slides past security filters unnoticed. It’s a lure designed to look completely harmless.

STAGE 2 -- REDIRECT CHAIN

A click initiates multi-hop routing through trusted cloud platforms and seasoned domains to evade suspicion. This exhausts sandbox analysis time before the malicious destination is reached.

STAGE 3 -- DROPPER DELIVERY

Now the trap snaps shut. A small, shape-shifting dropper sneaks into the machine’s memory entirely to avoid file scanners. It performs a silent check to ensure it is not being monitored, then confirms the target before communicating with the attacker.

STAGE 4 -- RECONNAISSANCE

Now inside, the ransomware operator scouts for high-value data and critical systems. They quietly map the network, positioning the ransomware to prepare for a single, synchronized strike.

STAGE 5 -- RANSOMWARE DEPLOYMENT

As long as a few weeks after the initial email, the final act plays out. A different operator takes the keys they’ve bought and deploys the ransomware. The environment is already mapped and defenses are already compromised, and the encryption begins.

Where Standard Controls Do Not Reach

Each stage in this chain occupies a gap that controls designed for the previous generation of attacks were never built to address. The older approach was stopped by SEGs running detonation environments, endpoint products accumulating dropper signatures and hash-based / reputation-based blocking. Each of those controls is deliberately bypassed by a specific design decision in the modern chain.

STAGE

WHY STANDARD CONTROLS MISS IT

Phishing Email

No payload to scan. Link points to a trusted cloud service — low-risk treatment by default.

Redirect Chain

Domains are freshly registered, recently compromised or carry no threat intel history. Sandbox windows exhausted before the final stage resolves.

Dropper

Obfuscated and polymorphic, bypasses static analysis thresholds. Memory-only execution leaves no file artifacts for endpoint scanners.

Persistence

Signed commercial software or native OS tooling. No detection mandate for legitimate RMM (Remote Monitoring and Management) installs.

ClickFix: A Case Study in Evasion by Design

The ClickFix technique, observed across multiple campaigns tracked in 2025 and 2026, illustrates how effectively attackers are designing their methods to bypass security controls.

A lure page presents the victim with a fake verification prompt and writes a PowerShell command to the clipboard with no visible indication. The victim is instructed to open the Windows Run dialog, paste and press Enter. The victim is lead to believe they are resolving a display issue or completing an access check. The next command stage was encoded inside a DNS TXT record response and executed directly from memory.

NO FILE DROPPED — The payload existed only in a DNS TXT record response, executed in memory. No file written, no web request logged and no attachment delivered.

NO HTTP REQUEST — The technique made zero outbound HTTP requests to retrieve a subsequent stage. Standard proxy and network logging had nothing to capture.

ENGINEERED AROUND DETECTION REALITY — This worked not because of technical sophistication but because it was constructed around how detection actually operates — not how defenders assume it operates.

Where KnowBe4 Can Help

No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, the ransomware deployment, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.

KnowBe4 Defend: Real-Time Behavioral AI

Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.

Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.

Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.

PhishER Plus: Automated Global Eradication

When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Labs.

Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.

Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.

The Threat Lives in the Sequence

Ransomware campaigns today do not surface as obviously dangerous at any individual stage. The email is unremarkable. The first redirect goes somewhere familiar. The dropper writes nothing to disk. The persistence mechanism is the software thatIT teams use themselves. Weeks later, from a different operator, after the environment has been mapped and the access positioned, the ransomware runs.

Each stage depends entirely on the previous one completing. The email has to reach the inbox, and the recipient has to act on it. Everything that follows traces back to that first delivery.

With KnowBe4’s PhishER Plus and Defend running, that first email is scrutinized as soon as it arrives. Defend helps to reveal it for what it is. PhishER Plus keeps other emails just like it from making it through. The bad actors never had a chance.