What is the ransomware kill chain?
The ransomware kill chain is the ordered set of stages a ransomware attack passes through, from first access to the network to encryption and the ransom demand. The model rests on an observation borrowed from intrusion analysis: the attacker has to complete every stage, so breaking any one link stops the attack short of its goal.
Seven stages and what backup systems record
| Stage | Attacker activity | Trace on the backup side |
|---|---|---|
| Initial access | Uses a stolen password, an unpatched VPN or a phishing email | Nothing yet |
| Foothold | Installs remote access tools to return at will | Unfamiliar software inside backed-up servers |
| Privilege escalation | Collects administrator accounts | Backup console logins from new places |
| Discovery and spread | Maps servers, hypervisors, storage and backup systems | Queries against the backup server and repository |
| Recovery denial | Deletes restore points and snapshots, shortens retention, disables jobs | Retention changes, missing jobs, deletion requests |
| Exfiltration | Copies data out | Unusual reads from shares or the repository |
| Encryption and extortion | Encrypts systems and leaves the ransom note | Backup sizes jump and data reduction collapses |
Real attacks reorder or skip stages, yet recovery denial almost always comes before encryption.
Where the chain breaks decides what is left to deal with. Stopping the initial login or the privilege escalation prevents every later stage. Stopping a late stage leaves the attacker inside, possibly with data already copied out, but with the restore points intact. Recovery denial is the late link the backup team owns outright.
Recovery denial, the last stage the defender controls
Recovery denial sits just before encryption and runs through the backup team's own systems. Using a stolen administrator login, the attacker deletes restore points and snapshots, shortens retention and disables jobs, and each of those actions looks in the console like routine housekeeping. If the backups come through this stage intact, the attack ends in a restore. If they do not, it ends in a discussion about paying.
Controls at this stage fall into two groups. Those that make deletion harder, such as MFA on the console or a second approval, slow a determined attacker down. Those that make deletion impossible for a fixed period break the link outright. Related patterns appear under backup tampering. When the compromised account manages a backup platform shared across MSP tenants, this stage runs against every client on it.
Dwell time against retention length
The early stages take the longest. An attacker can spend days or weeks between initial access and recovery denial, and every backup taken in that period faithfully captures the remote access tools and accounts the attacker planted, sometimes including a new administrator account inside the backup software itself.
That puts retention length and dwell time in direct competition. With daily restore points locked for 7 days and an attacker inside for 14 days before acting, every locked point postdates the intrusion and may bring the foothold back when restored. With 30 days of locked retention, the 16 oldest points predate it.
Points from inside the compromise window still hold intact data. They are commonly restored into a clean room and checked before anything returns to production, while full system images come from a point before the attacker arrived. Compliance-mode S3 Object Lock retention keeps each locked point beyond the reach of every account until its retain-until date, so the open question is how far back the oldest locked point goes.
ARTESCA and ransomware kill chain
ARTESCA sits at the recovery denial stage, where attackers try to delete or overwrite backups. Restore points held under compliance-mode S3 Object Lock refuse those deletions from every account, the root included, until their retain-until date, and its audit logs, forwarded to a SIEM, record each refused request as an early sign that someone is working through the chain.
The earlier stages, from initial access to discovery, play out on systems ARTESCA does not control, and how far back a clean restore point reaches depends on the retention period chosen.
Related terms
- Ransomware: an overview of the attacks this model describes.
- Backup tampering: the actions that make up the recovery denial stage.
- Ransomware detection: the signals that reveal each stage while it runs.
- Ransomware as a service (RaaS): who usually works through the chain, and how they are paid.
- Clean room recovery: checking restore points taken during the dwell period.
