Using Threat Intelligence to Stop Ransomware Attacks

Using Threat Intelligence to Stop Ransomware Attacks
The article explains that ransomware defense is most effective before encryption, when defenders can detect exposed credentials, malicious infrastructure, and attacker behavior earlier in the attack lifecycle. It also shows how Recorded Future uses threat intelligence, the Intelligence Graph, and workflow integrations to help organizations prioritize relevant ransomware threats and disrupt them sooner. #RecordedFuture #IntelligenceGraph #RaaS

Keypoints

  • Ransomware attacks often begin long before encryption, with compromised credentials, lateral movement, and C2 communication already in place.
  • Threat intelligence helps defenders identify ransomware activity earlier by tracking actors, infrastructure, access methods, and exposed assets.
  • IOCs are useful for detection, but TTPs provide longer-lasting context because attacker behavior changes less often than indicators like IP addresses or hashes.
  • Initial access brokers, exposed RDP access, and credentials for sale are important early warning signs that can be investigated before use.
  • C2 infrastructure is a key disruption point because defenders can block or investigate connections before payload execution or further spread.
  • Recorded Future connects ransomware intelligence with organizational exposure, victimology, and existing security workflows through APIs and integrations.
  • AI-driven correlation in the Intelligence Graph and Risk Profile helps teams focus on the ransomware actors and threats most relevant to their organization.

MITRE Techniques

  • [T1078 ] Valid Accounts – Attackers may already have legitimate credentials before encryption, allowing access to the network (‘obtained valid credentials’).
  • [T1021 ] Remote Services – The article mentions exposed Remote Desktop Protocol access used as an early access path (‘exposed Remote Desktop Protocol (RDP) access’).
  • [T1087 ] Account Discovery – Criminals may identify or use compromised organizational accounts as part of initial access and follow-on activity (‘credentials associated with their organization are exposed’).
  • [T1105 ] Ingress Tool Transfer – Threat intelligence and malware analysis are used to observe and add newly observed indicators and behaviors (‘Malware analysis and controlled sandbox testing can add newly observed indicators’).
  • [T1219 ] Remote Access Software – Compromised systems may be managed through attacker-controlled access channels before ransomware is deployed (‘entered the network, moved between systems and established a command-and-control (C2) channel’).
  • [T1021.002 ] SMB/Windows Admin Shares – Lateral movement between systems is explicitly referenced as part of attacker progression (‘moved between systems’).
  • [T1071 ] Application Layer Protocol – Command-and-control communication is highlighted as a key stage to detect and disrupt (‘command-and-control (C2) channel’).
  • [T1090 ] Proxy – The article notes attacker infrastructure and communication paths that defenders can block or detect (‘connections are blocked or detected earlier’).
  • [T1588 ] Obtain Capabilities – Initial access brokers obtain access and sell it to other criminals (‘Initial access brokers (IABs) obtain access to compromised organizations and advertise it’).
  • [T1595 ] Active Scanning – The article discusses tracking exposed infrastructure and vulnerabilities as part of external intelligence gathering (‘monitoring … infrastructure connected to known threat actors’).

Indicators of Compromise

  • [IP address ] Malicious infrastructure associated with ransomware actors and C2 – example: malicious IP addresses, example: known C2 infrastructure
  • [Domain ] Infrastructure used by threat actors for command-and-control or related operations – example: domains associated with their operations, example: malicious infrastructure domain
  • [File hash ] Known malware or payload identification – example: file hashes, example: malware hashes
  • [Credential / account ] Exposed access that may be sold or abused before an attack – example: compromised credentials, example: exposed corporate credentials
  • [Remote access endpoint ] Early access path exposed to attackers – example: exposed RDP access, example: Remote Desktop Protocol access
  • [Vulnerability / exploited weakness ] Flaws linked to active exploitation activity – example: vulnerabilities, example: a weakness associated with an active threat


Read more: https://www.recordedfuture.com/blog/ransomware-threat-intelligence