Ransomware & Incident Response

Ransomware Initial Access

Most ransomware intrusions begin with phishing or exposed remote access services.

What it is

Ransomware groups gain initial access through phishing emails delivering malware loaders, exploitation of public-facing vulnerabilities in VPN appliances and RDP servers, or purchase of access from Initial Access Brokers (IABs) who sell pre-compromised environments. CISA's Known Exploited Vulnerabilities catalog tracks dozens of perimeter device CVEs actively exploited by ransomware groups.

Attack techniques

  • Phishing with malware attachment (T1566.001)
  • Exploit of VPN/RDP vulnerability (T1190)
  • Purchased initial access via IABs
  • Valid account abuse (T1078)
  • Drive-by compromise (T1189)

Business impact

Initial access is the start of a multi-day intrusion that culminates in encryption. The window between initial access and encryption has been shrinking — averaging 2–5 days in recent ransomware campaigns. Detection during this dwell period prevents the ransomware event entirely.