foyl Concepts / Ransomware Lifecycle
Attack Technique

Ransomware Lifecycle

Ransomware operators may dwell for days, but IRON CHIMNEY shows that a complete attack can also unfold in minutes. Six native-tool events connect one lure, one replayed session, cloud persistence, lateral movement, data theft, and encryption into a single investigation.

T1486 Data Encrypted for Impact T1550.004 Web Session Cookie T1041 Exfiltration over C2 6-event canonical timeline
IRON CHIMNEY - six separate events correlated into one attack: ALT-7272, ALT-7274, ALT-7276, ALT-7278, ALT-7287, ALT-7291
Click any phase to expand details
1
Initial Access
06:47 UTC
2
Session Replay
06:52 UTC
3
Cloud Persistence
06:55 UTC
4
Lateral Movement
07:09 UTC
5
C2 / Exfiltration
07:12-07:18
6
Impact
07:24 UTC
Event 1 of 6
Double extortion: why data theft happens before encryption
Modern ransomware is not just about encryption anymore

Ransomware groups discovered that backups break the leverage of encryption alone. If a victim has tested, isolated backups they can restore from, there is no incentive to pay. So the model evolved.

Double extortion means the attacker steals data before triggering encryption. If the victim restores from backups and refuses to pay, the attacker threatens to publish the data. Financial records, customer PII, intellectual property, and internal communications are all high-leverage targets. The threat of regulatory fines (GDPR, HIPAA) and reputational damage often makes victims pay even when their backups are fine.

This is why exfiltration precedes encryption in IRON CHIMNEY. Defenders who interrupt the outbound transfer can reduce exposure even when the endpoint compromise is already established.

Common myth
"We have backups, so we are not vulnerable to ransomware." Backups protect against data loss from encryption. They do not protect against data exposure if the attacker has already exfiltrated the data. In a double-extortion attack, paying or not paying is a separate decision from whether you can restore operations.
The defender's window: when can this be stopped?
Every phase offers detection and interruption opportunities - the earlier, the better
PhaseBest detection opportunityTool
Initial AccessMalicious lure plus chrome.exe DNS resolution for invoices-secintel.ioMailGuard EDR
Session ReplayPreviously satisfied MFA reused from 185.220.101.42 on an unmanaged browserIdentity
Cloud PersistenceHidden Finance-Archive rule forwarding invoice and payment mail externallyIdentity MailGuard
Credential Access / Lateral MovementLSASS access followed by remote service creation through SI-DC-01 to RESEARCH-STATION-01EDR Identity
C2 / Exfiltration60-second beacon followed by 47 restricted files and 547 MB sent to the campaign C2 channelCASB NGFW EDR
Impactsvc32.exe renamed 847 files before EDR terminated the process and isolated the hostEDR
The key principle
If you detect initial access and respond before lateral movement, you limit the blast radius to one host. If you detect lateral movement before exfiltration, you prevent double extortion leverage. By the time you detect encryption, you are already in incident response. Every phase caught earlier dramatically reduces recovery cost and data exposure.
See it in foyl Learn
Where to lookWhat you will find
IRON CHIMNEY scenarioSix canonical events mapped to their native evidence and SIEM alerts ALT-7272 through ALT-7291
CASBDLP-001 / CAB-ALT-001: 47 restricted files totaling 547 MB from RESEARCH-STATION-01
SOAR / PB-001AiTM response playbook; the IRON CHIMNEY run was partial and endpoint isolation occurred after impact began
IR LabGuided exercise: triage, contain, and document a multi-phase attack using the full tool suite
Related concepts