Global security desk · updated coverage of threats, exploits & breaches

Threat Intelligence Report: Ransomware Gangs Adopt New Encryption Tactics

Ransomware operations are changing their use of encryption as defenders improve backup hygiene, deploy endpoint detection, and learn to recognise familiar extortion playbooks. Current campaigns increasingly treat encryption as one component in a wider disruption strategy, combining selective file locking, credential theft, virtual machine targeting, and pressure against cloud-connected systems.

The shift matters to Australian organisations operating across distributed offices, managed service providers, and critical infrastructure environments. A hospital network in Melbourne, a council in regional New South Wales, or a logistics company in Brisbane may face the same criminal ecosystem, yet have very different recovery dependencies. Threat intelligence teams therefore need to examine how encryption is deployed, not simply whether ransomware is present.

Selective Encryption Creates Faster Disruption

Older ransomware families commonly attempted to encrypt large numbers of user files, a process that could take hours and generate obvious disk activity. Newer affiliates frequently use intermittent or partial encryption. A file may have only a portion of its content transformed, while the remainder stays intact. This can make the operation significantly faster and complicate simple file-based detection.

The technique also reduces the time attackers spend inside a compromised environment. If a gang can render essential documents unusable after a short encryption run, it has less exposure to security analysts and incident responders. Some variants prioritise file headers, database structures, virtual machine disks, or high-value extensions rather than processing every file equally.

Selective encryption creates a difficult distinction between availability and integrity. A document can appear present in a directory while failing to open correctly, and a database may start before corrupted tables cause later errors. Recovery teams in Australian businesses should validate application behaviour and data integrity rather than relying on file counts or storage utilisation as proof that restoration has succeeded.

Encryption Keys Are Becoming More Difficult To Analyse

Ransomware developers continue to refine key generation, key storage, and the exchange of encryption material. Some families use separate keys for individual devices, directories, or victims, limiting the value of a single recovered artefact. Others encrypt local keys with an embedded public key, making it difficult for defenders to reconstruct the decryption process from a memory sample.

Attackers may also delay key creation until a final execution stage. This limits the usefulness of sandbox detonation and reduces the chance that a security team can capture an operational key before widespread damage occurs. In several intrusions, threat actors have used legitimate system tools to stop security software, delete shadow copies, and interfere with backup agents before launching encryption.

These changes raise the value of behavioural telemetry. Analysts should correlate suspicious service stops, recovery-object deletion, remote administration, and mass file modification within a short time window. The presence of a ransomware executable is useful evidence, but a sequence of preparatory actions may provide an earlier and more reliable warning.

Double Extortion Remains A Core Pressure Mechanism

Encryption is now frequently paired with data theft. Before disrupting systems, intruders may search file shares, collaboration platforms, email repositories, and cloud storage for information that can be used to threaten publication. This creates leverage even when an organisation can restore from clean backups.

Some gangs have adjusted their tactics when encryption is likely to fail. If protected endpoints, immutable snapshots, or segmented networks prevent broad file locking, attackers may focus on exfiltration and public disclosure. Others target a smaller number of systems that support revenue, manufacturing, clinical operations, or customer services, creating an outage without encrypting the entire estate.

Australian organisations must account for regulatory and contractual consequences alongside operational recovery. A breach involving health information, financial data, or government-related records may require rapid assessment under Australian privacy obligations and sector rules. Public companies and suppliers can also face notification, procurement, and reputational pressures when stolen material is posted on a leak site.

Virtual Infrastructure Is A High-Value Target

Hypervisors, backup servers, and management consoles give attackers a way to affect many workloads from a small number of systems. Ransomware crews increasingly investigate VMware, Hyper-V, storage arrays, and orchestration tools before choosing where to deploy their payload. Encrypting virtual machine disks or shutting down guest systems can produce a major outage without touching every individual workstation.

The same principle applies to cloud management planes. Stolen administrator credentials, compromised API keys, and weakly protected service accounts can allow an intruder to delete snapshots, alter retention policies, or disable logging. Hybrid environments are especially exposed when on-premises identity services remain trusted by cloud applications.

Security teams should treat backup infrastructure as a separate security boundary rather than an ordinary server group. Administrative credentials need dedicated protection, access should be tightly restricted, and restoration procedures must be tested against realistic loss of identity services. Workspace organisation can assist investigations when analysts must separate endpoint, identity, cloud, and network evidence; practical guidance on managing multiple workspaces illustrates how separated work areas can support focused operational tasks.

Affiliates Exploit Gaps In Identity Security

Many ransomware incidents begin with access obtained through stolen credentials, exposed remote services, phishing, or an unpatched edge device. Initial access brokers sell footholds to criminal affiliates, which means the group performing encryption may not be the same actor that entered the environment. This division of labour makes attribution harder and accelerates the path from compromise to extortion.

Identity systems are particularly important because attackers can use legitimate authentication to avoid triggering malware-focused controls. They may register new multifactor authentication methods, create privileged accounts, add remote access tools, or use existing administrative utilities. Ransomware can then be deployed through software distribution, domain policies, remote management, or scripts rather than a conspicuous dropper.

Australian enterprises should monitor unusual authentication geography, impossible travel, privilege changes, and access to sensitive shares. A login from an unfamiliar country is not always malicious, especially for a multinational business, but it deserves correlation with new device enrolment, mailbox rules, VPN activity, and bulk downloads. The Australian Signals Directorate’s Essential Eight remains a useful baseline for reducing common attack paths, particularly patching, multifactor authentication, application control, and restricted administrative privileges.

Threat Intelligence Needs Technical And Human Context

Threat feeds can identify file hashes, ransom notes, domains, and known malware families, yet those indicators often expire quickly. Affiliates alter payloads, infrastructure, and encryption parameters between campaigns. Effective intelligence therefore combines malware analysis with observations about access methods, target selection, operational timing, and the business functions attackers prioritise.

Research into adjacent criminal tooling is also valuable. Browser-password stealers and crypto-wallet malware may appear unrelated to ransomware, but credential theft can provide the access that enables a later extortion event. Reports on browser password theft help defenders connect endpoint compromise, infostealer activity, and account takeover within the same threat picture.

Organisations should share meaningful findings with trusted industry groups and relevant authorities. In Australia, the ACSC, sector-specific coordination bodies, insurers, and incident response providers can help place an intrusion within a broader campaign. Reports should preserve timestamps, authentication records, ransom notes, encryption samples, and exfiltration evidence so that intelligence remains useful beyond the immediate crisis.

Operational Indicators Worth Tracking

Recovery Must Be Designed Around Business Dependencies

A backup that exists but cannot be restored under pressure is an untested assumption. Recovery planning should identify which systems must return first, how identity will be rebuilt, and which manual processes can keep essential services operating. A regional manufacturer may prioritise production scheduling, while a Sydney professional services firm may depend on document management and email.

Encryption tactics also affect recovery order. If attackers have corrupted portions of large databases or virtual disks, restoring files alone may not return an application to a usable state. Teams need clean infrastructure, known-good software, verified credentials, and procedures for checking data consistency. Recovery exercises should include the loss of central authentication, remote access, and management platforms.

Controls That Reduce Recovery Pressure

Australian Exposure Reflects A Connected Market

Australia’s concentrated economy creates attractive targets for ransomware operators. Large banks, health providers, universities, logistics networks, mining firms, councils, and professional services companies often rely on shared suppliers and managed technology platforms. A compromise at an IT provider can therefore create effects across multiple customers, including organisations with strong internal controls.

Geography adds operational complexity. A business with offices in Perth, Adelaide, and Sydney may have different connectivity, staffing, and recovery windows at each location. Regional hospitals and utilities can face limited specialist capacity, while seasonal disruptions, public holidays, and long travel distances can slow the movement of replacement equipment or response personnel.

The local market also contains many small and medium-sized businesses that support larger enterprises. These suppliers may hold privileged access without having a dedicated security operations centre. Threat intelligence assessments should include vendor identity, remote support pathways, software update channels, and data-sharing arrangements rather than focusing only on the primary organisation.

Tracking Criminal Behaviour Beyond The Payload

Ransomware groups often reveal themselves through behaviour before encryption begins. Their language, negotiation style, leak-site design, preferred victims, and use of particular access brokers can connect an incident to a wider campaign. Monitoring hacking activity provides broader context for credential theft, exploitation, underground services, and intrusion methods that may precede a ransomware deployment.

The intelligence picture should also account for failed attacks. A blocked attempt to disable backups, an unusual search for financial records, or a burst of authentication failures may show that an adversary is testing the environment. Recording these events can expose repeat targeting and help distinguish opportunistic scanning from a deliberate intrusion.

For Australian defenders, the practical priority is speed of detection combined with resilient recovery. Partial encryption, key isolation, virtual infrastructure attacks, and data theft all reduce the warning period available to security teams. Organisations that connect identity monitoring, endpoint telemetry, network controls, backup protection, and clear executive decisions are better positioned to contain the intrusion before criminal operators can convert access into a prolonged business outage.