Skip to content
BreachPathAttack Path LibraryStart
AdvancedRansomware

Exposed VPN to Active Directory ransomware

Weakly protected remote access is used to reach the internal network, escalate to domain-wide control of Active Directory, neutralise backups and stage ransomware across the estate.

Technologies
On-premises Active Directory
Entry points
Exposed remote access, Stolen credentials
Sectors
Manufacturing, Healthcare, Retailโ€ฆ
Stages
4
01

Remote access is reached without strong authentication

An internet-facing VPN or remote-access portal accepts a single factor or reused credential. Using credentials obtained earlier, the attacker connects and is placed inside the corporate network.

Attacker objective

Get onto the internal network by authenticating to an exposed remote-access service.

Controls that should stop this
  • Phishing-resistant MFA on all remote access, with no exceptions
  • Device-posture checks before granting network access
  • Rapid patching of remote-access appliances and removal of unused ones
What defenders should see
  • VPN authentications from unusual geographies or ASNs
  • Successful logins for accounts that never normally use remote access
  • Concurrent sessions for one identity from different locations
What a pentest validates
  • External assessment of exposed remote-access services and their auth strength
  • Test whether stolen credentials alone grant network access
  • Review appliance patch level and configuration
Business impact

The attacker now has an internal network foothold from which to look for privilege.

02

Active Directory is enumerated for a route to privilege

From the foothold, the attacker enumerates users, groups, machines and trust relationships, looking for misconfigurations, over-privileged accounts and credential material that shortcut the way to domain administration.

Attacker objective

Map the domain and find a path from the current low-privileged account to domain-wide rights.

Controls that should stop this
  • Tiered administration and least privilege; no domain admins on workstations
  • Credential-theft protections and modern authentication hardening
  • Regular AD misconfiguration and attack-path review
What defenders should see
  • Bursts of directory-enumeration activity from a single host
  • Credential-access alerts from endpoint detection
  • Unusual access to domain controllers or replication activity
What a pentest validates
  • Internal AD security review mapping privilege-escalation paths
  • Test tiering enforcement and workstation-to-DC exposure
  • Validate detection of credential dumping and enumeration
Business impact

The attacker finds a viable route to control the identity backbone of the estate.

03

Domain-wide control is achieved

Using the route identified, the attacker obtains domain-administrative privilege, giving them the ability to authenticate to, and push changes to, systems across the estate.

Attacker objective

Gain administrative control over Active Directory so any system can be reached and changed.

Controls that should stop this
  • Protected privileged accounts, PAWs and just-in-time admin access
  • Alerting on Group Policy and privileged-group changes
  • Segmentation limiting how widely one admin identity can reach
What defenders should see
  • Privileged-group membership changes
  • New or modified Group Policy Objects
  • Administrative logons to unusually many hosts in a short window
What a pentest validates
  • Validate whether a single foothold can reach domain dominance
  • Test alerting on privileged changes and mass administrative logon
  • Review segmentation between admin tiers and business units
Business impact

The attacker can now reach essentially every domain-joined system at will.

04

Backups are neutralised and ransomware is staged

Before encrypting, the attacker targets backup systems and recovery capability so restoration is not an easy option, then stages and triggers encryption across the estate โ€” often after quietly exfiltrating data for double-extortion.

Attacker objective

Remove the ability to recover, then encrypt widely to maximise leverage.

Controls that should stop this
  • Immutable, offline and access-segregated backups tested for restore
  • Blocking and alerting on mass file changes and shadow-copy deletion
  • Application controls limiting unauthorised executable deployment
What defenders should see
  • Backup deletion or tampering events
  • Mass file-modification and encryption-behaviour alerts
  • Large data egress preceding encryption
What a pentest validates
  • Verify backups are truly isolated from a domain-admin compromise
  • Test detection of shadow-copy deletion and mass file change
  • Validate that recovery works when the identity plane is compromised
Business impact

The estate is encrypted with recovery crippled โ€” extended outage, recovery cost and extortion pressure.

ATT&CK techniques in this chain

If this chain completes

Estate-wide encryption with backups disabled โ€” the scenario behind most catastrophic ransomware outages, causing extended downtime, recovery cost and potential data-leak extortion.

Should you test this against your environment?

Turn this chain into a scoped red-team brief โ€” objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.