For most of ransomware's history, the attack model was straightforward: encrypt the victim's files, demand payment for the decryption key. The sophistication evolved over time — double extortion added the threat of data publication, triple extortion added customer notification — but the core leverage remained the same. You have data. We have the key. Pay us.

The model has fundamentally changed. Mandiant's M-Trends 2026 report, based on investigations across hundreds of organizations in 2025, documents a systematic shift in ransomware operator strategy: the primary objective is no longer data theft. It is recovery denial.

Modern ransomware operators are not simply encrypting your files. They are destroying your ability to restore from backup. Compromising your identity infrastructure so you cannot authenticate during recovery. Seizing your virtualization management plane so you cannot restart virtual machines. Locking defenders out of their own emergency accounts during the crisis. The goal is not to take your data. The goal is to make recovery impossible — or so costly, in time and operational disruption, that paying the ransom is the rational business decision.

The Three-Layer Attack

Mandiant's analysis identifies three primary target layers in modern ransomware campaigns, which they collectively term "trusted service infrastructure" — the foundational systems that organizations rely on to operate and recover.

Layer 1: Identity

The path to total control of a network almost always begins with identity. But modern ransomware operators have moved well beyond simple credential theft. In multiple 2025 investigations, Mandiant observed attackers exploiting misconfigured Active Directory Certificate Services templates to issue fraudulent certificates and create or impersonate administrator accounts. These attacker-controlled accounts were excluded from MFA requirements and password rotation policies — giving attackers persistent, privileged access that survived credential resets.

In some investigations, attackers extracted the entire Active Directory database — exposing every password hash in the domain simultaneously. In others, they accessed enterprise credential vaults to extract dozens of high-privilege credentials in a single session, then forced password changes on administrator accounts, locking legitimate defenders out of their own emergency access during the incident response.

Layer 2: Virtualization

Most enterprise workloads now run on virtualized infrastructure. Ransomware operators have recognized that attacking the hypervisor layer — the software that manages virtual machines — is exponentially more effective than attacking individual endpoints. A single action at the virtualization management plane can encrypt or destroy dozens of virtual servers simultaneously.

Mandiant documented one Akira ransomware attack that successfully encrypted most virtualized servers in an environment in a single operation. The attack also destroyed the network telemetry logs that had been stored on those servers — eliminating the forensic record investigators needed to understand the scope of the breach and the data that had been stolen. The loss of telemetry created substantial friction in the organization's ability to even understand what had happened, let alone recover from it.

The convergence attack: Mandiant documented threat actors weaponizing the default virtualization administrator group used in some Active Directory integrations. By adding a compromised service account to an AD group, attackers automatically inherited administrator privileges on all domain-joined virtualization hosts — allowing them to disable firewalls and mass-deploy ransomware to dozens of hypervisors nearly instantaneously.

Layer 3: Backups

The final and often most devastating stage is the destruction of backups. This is not opportunistic. Mandiant's investigations reveal that modern ransomware operators conduct systematic reconnaissance of backup architectures before taking any destructive action — accessing admin consoles and documentation repositories to map storage locations, SQL configurations, and encryption keys.

Once the backup architecture is mapped, the destruction is methodical. In one investigation, attackers used credentials extracted from a backup management server to access storage controllers and cloud accounts, then executed broad-scale deletion commands — wiping millions of backup objects from cloud storage and deleting dozens of local system backups. In another, attackers deleted backup configurations from the backup server, unlinking the virtualization environment from the backup platform. The backup data existed on immutable storage and was technically not destroyed — but it was completely inaccessible through any normal recovery path, requiring months of engagement with the backup vendor to begin restoration.

9 days
median ransomware dwell time in 2025 — attackers seize admin control within hours of access
44%
of ransomware victims first learned of the breach from the attacker's extortion demand
13%
of all Mandiant 2025 investigations were ransomware-related

The Velocity Problem

What makes the recovery-denial strategy particularly effective is the speed at which modern ransomware operators execute it. Mandiant's investigations show that ransomware operators have collapsed the timeline for seizing administrative control — frequently achieving domain-level control within hours of initial access.

The velocity creates a specific crisis dynamic: defenders are often forced to preemptively disconnect their own identity providers to halt the spread, effectively triggering a self-inflicted business outage to prevent total compromise. The choice is between a controlled shutdown and an uncontrolled one. Neither option is good. Both represent the attack achieving its objective — operational disruption that creates pressure to pay.

Why Traditional Recovery Models No Longer Work

The standard ransomware recovery model assumes that backups are intact and accessible, that endpoint restoration is feasible, and that identity infrastructure can be used to authenticate during recovery. The attack pattern Mandiant documents in 2025 systematically invalidates all three assumptions.

Backups are the primary target, not the last resort. Identity infrastructure is compromised before recovery begins. Virtualization management — the layer on which most modern recovery workflows depend — is seized or destroyed.

Mandiant's framing is direct: organizational survivability predicated on EDR or traditional backup restoration at the endpoint layer is no longer a sufficient recovery model. The new model must be built around resilience — specifically, the ability to recover even when the infrastructure that normally enables recovery has been compromised.

What a Resilience-Focused Model Looks Like

The practical implication of this shift is that backup and recovery architecture needs to be designed with the assumption that an attacker has domain-level access and knows exactly where the backups are. Resilient recovery means:

  • Immutable, air-gapped backups that cannot be deleted or encrypted by an attacker with domain admin credentials
  • Out-of-band identity recovery that can authenticate administrators without relying on the compromised identity provider
  • Virtualization management plane segmentation that limits the blast radius of a compromised hypervisor administrator account
  • Tested recovery procedures — not just documented ones — that have been validated against scenarios where identity, virtualization, and backup infrastructure are simultaneously unavailable
The question every organization should answer before an incident: If an attacker had domain admin credentials right now, and had spent 48 hours mapping your backup architecture and identity infrastructure, could you recover? Not theoretically — could you actually authenticate your recovery team, access your backups, and restore operations? If the honest answer is uncertain, you have a resilience gap that ransomware operators are specifically designed to exploit.

The ransomware operators who refined these techniques in 2025 are not going to revert to less effective methods. The destruction of recovery infrastructure has become a standard component of enterprise ransomware operations — not an advanced tactic used by elite groups, but a routine step in campaigns conducted by affiliates across multiple RaaS platforms.

The organizations that survive these attacks are not necessarily those with the most security tools. They are the ones that have thought carefully about what they would do if their recovery infrastructure was compromised — and built their resilience strategy around that scenario rather than around the assumption that their backups will be there when they need them.

Source: Mandiant M-Trends 2026, Google Threat Intelligence Group (GTIG). Based on analysis of more than 500,000 hours of incident response engagements globally, January 1–December 31, 2025. Published March 2026.

See what continuous testing finds in your environment.

Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.

Request early access →