惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tor Project blog
T
The Blog of Author Tim Ferriss
WordPress大学
WordPress大学
H
Help Net Security
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
博客园 - 司徒正美
Jina AI
Jina AI
雷峰网
雷峰网
博客园_首页
博客园 - 三生石上(FineUI控件)
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
The Cloudflare Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Forbes - Security
Forbes - Security
T
Threatpost
V
Visual Studio Blog
A
Arctic Wolf
Microsoft Azure Blog
Microsoft Azure Blog
Security Latest
Security Latest
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy & Cybersecurity Law Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Spread Privacy
Spread Privacy
N
News and Events Feed by Topic
Vercel News
Vercel News
爱范儿
爱范儿
The GitHub Blog
The GitHub Blog
NISL@THU
NISL@THU
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
PCI Perspectives
PCI Perspectives
博客园 - 【当耐特】
IT之家
IT之家
S
Secure Thoughts
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志
Cisco Talos Blog
Cisco Talos Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
月光博客
月光博客
Latest news
Latest news
小众软件
小众软件
Attack and Defense Labs
Attack and Defense Labs
I
Intezer
Y
Y Combinator Blog
The Last Watchdog
The Last Watchdog
大猫的无限游戏
大猫的无限游戏

Human Risk Management Blog

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
From Inbox to Encryption: How Ransomware Delivery Has Evolved
KnowBe4 Threat Lab · 2026-07-23 · via Human Risk Management Blog

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.

What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker.

So, what can organizations do to protect themselves from these new threats? In this report from the KnowBe4 Threat Labs team, you will be able to:

  • Identify the infrastructure patterns defining 2025-2026 ransomware campaigns.
  • Map the critical stages that separate the initial email from the final encryption event.
  • Understand the mechanics of the "ClickFix" technique and why modern threats are designed specifically to evade your current security controls.

Every shift in delivery method was a direct response to whatever controls had just become effective against the previous approach. In 2019 an internationally coordinated effort took down the Necurs botnet, a criminal infrastructure responsible for 90% of email-based malware. This disruption of the world’s largest botnet, with the loss of 9 million infected nodes, is the clearest inflection point: until then, volume was the strategy. Once that infrastructure was disrupted and security products had matured to catch direct attachment delivery, the economics changed. Operators moved to precision targeting and multi-stage chains where the email carries nothing dangerous itself.

PERIOD

ACTOR / CAMPAIGN

WHAT CHANGED

Early 2000s

GPCode ransomware

Spear phishing with trojans disguised as job applications. First documented use of phishing as a ransomware delivery vector.

2007 onwards

Evil Corp / Dridex

Cridex banking trojan via phishing, evolved into modular Dridex. Introduced the rentable malware model: operators and affiliates begin to separate.

Mid-2010s

Locky / Necurs botnet

Up to 23 million phishing emails per 24-hour period across ~120,000 IPs in 139 country-code TLDs. Industrialised phishing at botnet scale.

2019

Necurs takedown

Microsoft and 35 law enforcement agencies dismantle Necurs. Forces transition away from high-volume direct-payload delivery.

2025-2026

Multiple groups incl. access brokers

Multi-hop redirect chains, fileless droppers, RMM tools for persistence, DNS-based staging. Phishing operators and ransomware operators are now separate commercial parties.

What Ransomware Infrastructure Patterns Arose Between 2025-2026?

Threat Labs monitoring across this period revealed six consistent infrastructure patterns across diverse campaigns, regardless of varying lures or payloads. Each pattern maps directly to a control that had become effective against the previous approach.

Trusted First Hops: Attackers route through Google Drive, Dropbox, Slack and GitHub as first-hop redirect points. Links to these platforms appear trustworthy to the user and receive low-risk treatment from security products.

Seasoned Domain Redirects: The redirect chain leverages compromised or parked domains that have maintained clean reputation for a longer period of time, which affects blocklisting. This provides the attacker with a clear delivery window. Multistage redirect chains also exhaust the analysis timeframes of automated sandbox analysis.

Traceless Payloads: Droppers prioritize evasion through layered obfuscation and polymorphic signatures. Some campaigns use built-in Windows utilities like Certutil to stage payloads directly in process memory, bypassing the filesystem entirely. This means no detectable files remain for malware scanners.

Purchased Access: Ransomware operators treat access as a commodity rather than building it themselves. They procure established, valid credentials and pre-compromised infrastructures from underground markets, allowing them to bypass initial intrusion phases and pivot directly to malware deployment.

RMM for Persistence: Persistence is achieved using legitimate, signed commercial remote management tools. These blend into routine network traffic and IT environments, making unauthorized installations difficult to identify without specific environment baselines.

Separated Operators: Phishing and ransomware operations are often distinct commercial entities. One actor specializes in securing the initial foothold, which is then traded to a different ransomware operator. This ensures that the final payload deployment is decoupled from the original email by a discrete financial transaction between parties.

How The Ransomware Chains Actually Run

The common infrastructure patterns of the last year share a common thread: the inbox as an entry point. The phishing email carries a call-to-action or attachment whose only function is the first redirect. There is no payload in it. From that redirect, the victim moves through cloud platforms and then through domains with degraded or no reputation signal before reaching infrastructure the attacker controls.

Here are the five stages of a typical ransomware attack chain:

STAGE 1 -- PHISHING EMAIL

The mail arrives as a subtle, time-sensitive lure. There’s no payload here, just a link to a trusted cloud service that slides past security filters unnoticed. It’s a lure designed to look completely harmless.

STAGE 2 -- REDIRECT CHAIN

A click initiates multi-hop routing through trusted cloud platforms and seasoned domains to evade suspicion. This exhausts sandbox analysis time before the malicious destination is reached.

STAGE 3 -- DROPPER DELIVERY

Now the trap snaps shut. A small, shape-shifting dropper sneaks into the machine’s memory entirely to avoid file scanners. It performs a silent check to ensure it is not being monitored, then confirms the target before communicating with the attacker.

STAGE 4 -- RECONNAISSANCE

Now inside, the ransomware operator scouts for high-value data and critical systems. They quietly map the network, positioning the ransomware to prepare for a single, synchronized strike.

STAGE 5 -- RANSOMWARE DEPLOYMENT

As long as a few weeks after the initial email, the final act plays out. A different operator takes the keys they’ve bought and deploys the ransomware. The environment is already mapped and defenses are already compromised, and the encryption begins.

Where Standard Controls Do Not Reach

Each stage in this chain occupies a gap that controls designed for the previous generation of attacks were never built to address. The older approach was stopped by SEGs running detonation environments, endpoint products accumulating dropper signatures and hash-based / reputation-based blocking. Each of those controls is deliberately bypassed by a specific design decision in the modern chain.

STAGE

WHY STANDARD CONTROLS MISS IT

Phishing Email

No payload to scan. Link points to a trusted cloud service — low-risk treatment by default.

Redirect Chain

Domains are freshly registered, recently compromised or carry no threat intel history. Sandbox windows exhausted before the final stage resolves.

Dropper

Obfuscated and polymorphic, bypasses static analysis thresholds. Memory-only execution leaves no file artifacts for endpoint scanners.

Persistence

Signed commercial software or native OS tooling. No detection mandate for legitimate RMM (Remote Monitoring and Management) installs.

ClickFix: A Case Study in Evasion by Design

The ClickFix technique, observed across multiple campaigns tracked in 2025 and 2026, illustrates how effectively attackers are designing their methods to bypass security controls.

A lure page presents the victim with a fake verification prompt and writes a PowerShell command to the clipboard with no visible indication. The victim is instructed to open the Windows Run dialog, paste and press Enter. The victim is lead to believe they are resolving a display issue or completing an access check. The next command stage was encoded inside a DNS TXT record response and executed directly from memory.

NO FILE DROPPED — The payload existed only in a DNS TXT record response, executed in memory. No file written, no web request logged and no attachment delivered.

NO HTTP REQUEST — The technique made zero outbound HTTP requests to retrieve a subsequent stage. Standard proxy and network logging had nothing to capture.

ENGINEERED AROUND DETECTION REALITY — This worked not because of technical sophistication but because it was constructed around how detection actually operates — not how defenders assume it operates.

Where KnowBe4 Can Help

No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, the ransomware deployment, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.

KnowBe4 Defend: Real-Time Behavioral AI

Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.

Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.

Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.

PhishER Plus: Automated Global Eradication

When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Labs.

Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.

Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.

The Threat Lives in the Sequence

Ransomware campaigns today do not surface as obviously dangerous at any individual stage. The email is unremarkable. The first redirect goes somewhere familiar. The dropper writes nothing to disk. The persistence mechanism is the software thatIT teams use themselves. Weeks later, from a different operator, after the environment has been mapped and the access positioned, the ransomware runs.

Each stage depends entirely on the previous one completing. The email has to reach the inbox, and the recipient has to act on it. Everything that follows traces back to that first delivery.

With KnowBe4’s PhishER Plus and Defend running, that first email is scrutinized as soon as it arrives. Defend helps to reveal it for what it is. PhishER Plus keeps other emails just like it from making it through. The bad actors never had a chance.