Index Engines announced new findings from its proprietary CyberSense Research Lab, highlighting a shift in ransomware tactics. The research indicates that an increasing number of ransomware variants are using data-corruption techniques designed to bypass conventional indicators of obfuscation, making threats more difficult to detect and recover from.
“Bad actors know what scanning tools look for, and the variants we detonated this year are built to hide it,” said Jim McGann, CMO of Index Engines. “Encoder is the clearest example. It destroyed files while leaving their names, sizes, timestamps, and entropy unchanged. A surface scan would report that data as clean. CyberSense caught it by analyzing the content and structure of each file. The Research Lab exists to find techniques like this early and build them into the model our customers rely on for recovery.”
- Ransomware is moving beyond full encryption:Â Directory-entry destruction was the most common behavior identified by the Lab, appearing in 47.8% of strains analyzed.
- Traditional signs of corruption are disappearing:Â Variants suppressed traditional signs of corruption including changed extensions, entropy spikes, altered timestamps and rapid file changes.
- The window to respond is shrinking:Â Lab detonations showed a median attack velocity of approximately 97,321 files corrupted per hour, reaching 10,000 files in about six minutes.
- AI is not present at the point of impact:Â None of the 1,064 strains showed AI making choices about data at the destructive payload stage. Industry research from Palo Alto Networks and ReliaQuest places AI’s current footprint earlier in the attack lifecycle, where it is compressing reconnaissance and lateral movement.
- The findings change the recovery equation: As ransomware moves beyond encryption and suppresses traditional signs of corruption, data that appears unaffected may not actually be clean. Organizations need to validate the integrity of their data before trusting it for recovery.
“In our detonations, ransomware reached 10,000 files in about six minutes, which is faster than most Incident Response escalation paths,” McGann added. “By the time a team moves to recovery, the question is which copy of the data can be trusted. CyberSense answers it with a forensic account of what was affected and pinpoints clean data to restore from.”