Home  ›  Glossary  ›  Ransomware Kill Chain

What is the ransomware kill chain?

The ransomware kill chain is the ordered set of stages a ransomware attack passes through, from first access to the network to encryption and the ransom demand. The model rests on an observation borrowed from intrusion analysis: the attacker has to complete every stage, so breaking any one link stops the attack short of its goal.

Seven stages and what backup systems record

StageAttacker activityTrace on the backup side
Initial accessUses a stolen password, an unpatched VPN or a phishing emailNothing yet
FootholdInstalls remote access tools to return at willUnfamiliar software inside backed-up servers
Privilege escalationCollects administrator accountsBackup console logins from new places
Discovery and spreadMaps servers, hypervisors, storage and backup systemsQueries against the backup server and repository
Recovery denialDeletes restore points and snapshots, shortens retention, disables jobsRetention changes, missing jobs, deletion requests
ExfiltrationCopies data outUnusual reads from shares or the repository
Encryption and extortionEncrypts systems and leaves the ransom noteBackup sizes jump and data reduction collapses

Real attacks reorder or skip stages, yet recovery denial almost always comes before encryption.

Where the chain breaks decides what is left to deal with. Stopping the initial login or the privilege escalation prevents every later stage. Stopping a late stage leaves the attacker inside, possibly with data already copied out, but with the restore points intact. Recovery denial is the late link the backup team owns outright.

Recovery denial, the last stage the defender controls

Recovery denial sits just before encryption and runs through the backup team's own systems. Using a stolen administrator login, the attacker deletes restore points and snapshots, shortens retention and disables jobs, and each of those actions looks in the console like routine housekeeping. If the backups come through this stage intact, the attack ends in a restore. If they do not, it ends in a discussion about paying.

Controls at this stage fall into two groups. Those that make deletion harder, such as MFA on the console or a second approval, slow a determined attacker down. Those that make deletion impossible for a fixed period break the link outright. Related patterns appear under backup tampering. When the compromised account manages a backup platform shared across MSP tenants, this stage runs against every client on it.

Dwell time against retention length

The early stages take the longest. An attacker can spend days or weeks between initial access and recovery denial, and every backup taken in that period faithfully captures the remote access tools and accounts the attacker planted, sometimes including a new administrator account inside the backup software itself.

That puts retention length and dwell time in direct competition. With daily restore points locked for 7 days and an attacker inside for 14 days before acting, every locked point postdates the intrusion and may bring the foothold back when restored. With 30 days of locked retention, the 16 oldest points predate it.

Points from inside the compromise window still hold intact data. They are commonly restored into a clean room and checked before anything returns to production, while full system images come from a point before the attacker arrived. Compliance-mode S3 Object Lock retention keeps each locked point beyond the reach of every account until its retain-until date, so the open question is how far back the oldest locked point goes.

ARTESCA and ransomware kill chain

ARTESCA sits at the recovery denial stage, where attackers try to delete or overwrite backups. Restore points held under compliance-mode S3 Object Lock refuse those deletions from every account, the root included, until their retain-until date, and its audit logs, forwarded to a SIEM, record each refused request as an early sign that someone is working through the chain.

The earlier stages, from initial access to discovery, play out on systems ARTESCA does not control, and how far back a clean restore point reaches depends on the retention period chosen.