CyberSense Research Lab: Ransomware Evolves to Evade Detection

0
Index Engines announced new findings from its proprietary CyberSense Research Lab, highlighting a shift in ransomware tactics. The research indicates that an increasing number of ransomware variants are using data-corruption techniques designed to bypass conventional indicators of obfuscation, making threats more difficult to detect and recover from.
Among 1,064 ransomware strains acquired and detonated during the first half of 2026, 47.8% exhibited directory-entry destruction, more than twice the 18.3% that exhibited full encryption. The CyberSense Research lab also documented new ransomware designed to suppress familiar signs of corruption by preserving file extensions and timestamps, maintaining low entropy, encrypting slowly, and targeting only selected sections of files.

“Bad actors know what scanning tools look for, and the variants we detonated this year are built to hide it,” said Jim McGann, CMO of Index Engines. “Encoder is the clearest example. It destroyed files while leaving their names, sizes, timestamps, and entropy unchanged. A surface scan would report that data as clean. CyberSense caught it by analyzing the content and structure of each file. The Research Lab exists to find techniques like this early and build them into the model our customers rely on for recovery.”

The CyberSense Research Lab automates the ingestion and behavioral analysis of ransomware variants in a controlled environment, enabling continuous training of AI/ML models on real-world attack patterns and, enabling continuous training of AI/ML models on real ransomware behavior. The result is more comprehensive corruption detection that keeps pace with the threat landscape, backed by 99.99% ESG-validated accuracy, and smarter recovery decisions for organizations facing today’s cyber criminals.
Key findings* from the H1 2026 research include:
  • Ransomware is moving beyond full encryption: Directory-entry destruction was the most common behavior identified by the Lab, appearing in 47.8% of strains analyzed.
  • Traditional signs of corruption are disappearing: Variants suppressed traditional signs of corruption including changed extensions, entropy spikes, altered timestamps and rapid file changes.
  • The window to respond is shrinking: Lab detonations showed a median attack velocity of approximately 97,321 files corrupted per hour, reaching 10,000 files in about six minutes.
  • AI is not present at the point of impact: None of the 1,064 strains showed AI making choices about data at the destructive payload stage. Industry research from Palo Alto Networks and ReliaQuest places AI’s current footprint earlier in the attack lifecycle, where it is compressing reconnaissance and lateral movement.
  • The findings change the recovery equation: As ransomware moves beyond encryption and suppresses traditional signs of corruption, data that appears unaffected may not actually be clean. Organizations need to validate the integrity of their data before trusting it for recovery.
The research also found polymorphism at work in 64.7% of analyzed samples. These variants kept their functional code intact while regenerating their file signature between builds, so each new infection presented a fingerprint that signature-based tools have never previously seen.
At the data layer, the Lab documented variants that used partial encryption, preserved or faked timestamps and low-entropy corruption to shrink the visible footprint of an attack. These techniques evade detection that depends on entropy spikes or bursts of encryption activity.

“In our detonations, ransomware reached 10,000 files in about six minutes, which is faster than most Incident Response escalation paths,” McGann added. “By the time a team moves to recovery, the question is which copy of the data can be trusted. CyberSense answers it with a forensic account of what was affected and pinpoints clean data to restore from.”

Related News:
* Findings reflect variants acquired and detonated by the CyberSense Research Lab and are not an estimate of how often each technique appears in real-world attacks. Individual samples can exhibit multiple behaviors, so percentages reflect overlapping patterns.
Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.