For most of ransomware's history, the attack model was straightforward: encrypt the victim's files, demand payment for the decryption key. The sophistication evolved over time — double extortion added the threat of data publication, triple extortion added customer notification — but the core leverage remained the same. You have data. We have the key. Pay us.
The model has fundamentally changed. Mandiant's M-Trends 2026 report, based on investigations across hundreds of organizations in 2025, documents a systematic shift in ransomware operator strategy: the primary objective is no longer data theft. It is recovery denial.
Modern ransomware operators are not simply encrypting your files. They are destroying your ability to restore from backup. Compromising your identity infrastructure so you cannot authenticate during recovery. Seizing your virtualization management plane so you cannot restart virtual machines. Locking defenders out of their own emergency accounts during the crisis. The goal is not to take your data. The goal is to make recovery impossible — or so costly, in time and operational disruption, that paying the ransom is the rational business decision.
The Three-Layer Attack
Mandiant's analysis identifies three primary target layers in modern ransomware campaigns, which they collectively term "trusted service infrastructure" — the foundational systems that organizations rely on to operate and recover.
Layer 1: Identity
The path to total control of a network almost always begins with identity. But modern ransomware operators have moved well beyond simple credential theft. In multiple 2025 investigations, Mandiant observed attackers exploiting misconfigured Active Directory Certificate Services templates to issue fraudulent certificates and create or impersonate administrator accounts. These attacker-controlled accounts were excluded from MFA requirements and password rotation policies — giving attackers persistent, privileged access that survived credential resets.
In some investigations, attackers extracted the entire Active Directory database — exposing every password hash in the domain simultaneously. In others, they accessed enterprise credential vaults to extract dozens of high-privilege credentials in a single session, then forced password changes on administrator accounts, locking legitimate defenders out of their own emergency access during the incident response.
Layer 2: Virtualization
Most enterprise workloads now run on virtualized infrastructure. Ransomware operators have recognized that attacking the hypervisor layer — the software that manages virtual machines — is exponentially more effective than attacking individual endpoints. A single action at the virtualization management plane can encrypt or destroy dozens of virtual servers simultaneously.
Mandiant documented one Akira ransomware attack that successfully encrypted most virtualized servers in an environment in a single operation. The attack also destroyed the network telemetry logs that had been stored on those servers — eliminating the forensic record investigators needed to understand the scope of the breach and the data that had been stolen. The loss of telemetry created substantial friction in the organization's ability to even understand what had happened, let alone recover from it.
Layer 3: Backups
The final and often most devastating stage is the destruction of backups. This is not opportunistic. Mandiant's investigations reveal that modern ransomware operators conduct systematic reconnaissance of backup architectures before taking any destructive action — accessing admin consoles and documentation repositories to map storage locations, SQL configurations, and encryption keys.
Once the backup architecture is mapped, the destruction is methodical. In one investigation, attackers used credentials extracted from a backup management server to access storage controllers and cloud accounts, then executed broad-scale deletion commands — wiping millions of backup objects from cloud storage and deleting dozens of local system backups. In another, attackers deleted backup configurations from the backup server, unlinking the virtualization environment from the backup platform. The backup data existed on immutable storage and was technically not destroyed — but it was completely inaccessible through any normal recovery path, requiring months of engagement with the backup vendor to begin restoration.
The Velocity Problem
What makes the recovery-denial strategy particularly effective is the speed at which modern ransomware operators execute it. Mandiant's investigations show that ransomware operators have collapsed the timeline for seizing administrative control — frequently achieving domain-level control within hours of initial access.
The velocity creates a specific crisis dynamic: defenders are often forced to preemptively disconnect their own identity providers to halt the spread, effectively triggering a self-inflicted business outage to prevent total compromise. The choice is between a controlled shutdown and an uncontrolled one. Neither option is good. Both represent the attack achieving its objective — operational disruption that creates pressure to pay.
Why Traditional Recovery Models No Longer Work
The standard ransomware recovery model assumes that backups are intact and accessible, that endpoint restoration is feasible, and that identity infrastructure can be used to authenticate during recovery. The attack pattern Mandiant documents in 2025 systematically invalidates all three assumptions.
Backups are the primary target, not the last resort. Identity infrastructure is compromised before recovery begins. Virtualization management — the layer on which most modern recovery workflows depend — is seized or destroyed.
Mandiant's framing is direct: organizational survivability predicated on EDR or traditional backup restoration at the endpoint layer is no longer a sufficient recovery model. The new model must be built around resilience — specifically, the ability to recover even when the infrastructure that normally enables recovery has been compromised.
What a Resilience-Focused Model Looks Like
The practical implication of this shift is that backup and recovery architecture needs to be designed with the assumption that an attacker has domain-level access and knows exactly where the backups are. Resilient recovery means:
- Immutable, air-gapped backups that cannot be deleted or encrypted by an attacker with domain admin credentials
- Out-of-band identity recovery that can authenticate administrators without relying on the compromised identity provider
- Virtualization management plane segmentation that limits the blast radius of a compromised hypervisor administrator account
- Tested recovery procedures — not just documented ones — that have been validated against scenarios where identity, virtualization, and backup infrastructure are simultaneously unavailable
The ransomware operators who refined these techniques in 2025 are not going to revert to less effective methods. The destruction of recovery infrastructure has become a standard component of enterprise ransomware operations — not an advanced tactic used by elite groups, but a routine step in campaigns conducted by affiliates across multiple RaaS platforms.
The organizations that survive these attacks are not necessarily those with the most security tools. They are the ones that have thought carefully about what they would do if their recovery infrastructure was compromised — and built their resilience strategy around that scenario rather than around the assumption that their backups will be there when they need them.
See what continuous testing finds in your environment.
Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.
Request early access →