Kevin Surace
2 minute read
Ransomware does not start with ransomware. It starts with access. An attacker who can log in as a legitimate user can move quietly through the network, escalate their privileges and deploy a payload before anyone notices. Most ransomware defences focus on the payload stage. The attackers win before that stage is even reached.
The ransomware kill chain is a framework for understanding how attacks progress from first contact to full compromise. Breaking it requires understanding where in the chain authentication failures occur and what it would take to close them.
The kill chain describes the sequence an attacker follows from initial access to payload deployment. Stages vary by attack type, but the pattern is consistent. An attacker gets in, establishes a foothold, moves laterally to reach high-value systems, escalates their privileges and then deploys the ransomware.
Every stage depends on the previous one. That means the chain can be broken at any point. Breaking it at the earliest stage, initial access, stops every stage that follows.
Most ransomware attacks begin with a phishing email. The attacker sends a convincing message that directs the victim to a login page that looks legitimate. The victim enters their credentials. The attacker captures them in real time via a relay proxy and forwards them to the real service, completing the authentication and bypassing the MFA challenge.
The attacker now has an authenticated session. They are inside.
Once inside, the attacker’s priority is to spread. An authenticated session on one account gives access to shared drives, internal applications and other resources that account can reach. From there, attackers look for credential stores, Active Directory configurations and service accounts.
Stolen credentials are reused wherever they will work. Because many organisations share password conventions or reuse credentials across systems, a single stolen account frequently opens others. Legacy MFA provides no resistance at this stage. The credentials are already valid.
With a foothold across multiple accounts, the attacker targets administrative credentials.
One method is MFA fatigue: flooding a user with push authentication requests until they approve one out of frustration or mistake. The attacker gains administrative access without ever breaking the authentication system.
Social engineering is the other route. Attackers call help desks, impersonate employees and request credential resets. Once they hold administrative credentials, they control the environment.
Administrative access is the final step before deployment. The attacker identifies backup systems and disables them. They map the most valuable data. Then they deploy the ransomware across the network and trigger it simultaneously on as many systems as possible to maximise disruption and ransom pressure.
Every stage from initial access through payload deployment depends on authentication that can be tricked, relayed or socially engineered. Phishing-resistant MFA removes that dependency.
TokenCore devices require a live biometric match and cryptographically bind each credential to the exact domain it was created for. There are no codes to relay and no prompts to approve. A spoofed login page cannot complete a Token authentication because the domain does not match. A stolen credential cannot be reused because the private key never leaves the device. MFA fatigue cannot succeed because there are no push approvals.
The kill chain breaks at stage one. Every subsequent stage never happens.
Ready to protect your workforce right now?
Order TokenCore™ Portable or TokenCore™ Wearable today and start using them this week.
In today’s digital landscape, identity security is not just a concern—it’s a critical defense against the growing threats of phishing and ransomware. While multifactor authentication (MFA) has been promoted as a solution, the reality is that not all MFA is equally effective in securing user identities.
When ransomware hits, most organizations face the same question immediately. Pay the ransom and try to recover quickly, or refuse and rebuild from backups. The answer is rarely obvious in the moment. Attackers count on that. This page covers what the payment data actually looks like, what paying costs beyond the ransom itself and what the research says about organizations that pay versus those that do not.
In an era where cyber threats are becoming increasingly sophisticated, Token’s biometric identity assurance stands out as a beacon of innovation. Recently, this groundbreaking device earned a prestigious spot in the Science and Technology category of Fast Company's 2024 World Changing Ideas Awards. With over 1,300 global entries vying for recognition, Token's achievement is a testament to its transformative impact on cybersecurity.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.