Skip to content
BreachPathAttack Path LibraryStart
AdvancedRansomware

Vulnerable web application to ransomware

A flaw in an internet-facing application provides a server foothold, which is used to move onto the internal network, escalate privilege and deploy ransomware against reachable systems.

Technologies
Custom web applications, On-premises Active Directory
Entry points
Vulnerable application
Sectors
Retail, Manufacturing, Healthcare
Stages
3
01

The internet-facing application is used to gain a server foothold

The attacker finds unvalidated input or an insecure component in the public application and uses it to gain execution or command in the server's context, establishing a foothold behind the perimeter.

Attacker objective

Turn an application weakness into the ability to run in the server's context.

Controls that should stop this
  • Secure development lifecycle and dependency management
  • Web application firewall and virtual patching
  • Isolated, minimally-privileged application hosting with egress control
What defenders should see
  • WAF and application logs showing anomalous requests
  • Unexpected process or command activity on the app server
  • Outbound connections from the application tier
What a pentest validates
  • Application penetration test of the exposed service
  • Review of hosting isolation and egress restrictions
  • Validate WAF and patching processes
Business impact

The attacker has a foothold inside the network perimeter.

02

The attacker moves inward and escalates

From the foothold, the attacker harvests credentials, enumerates the internal network and moves laterally, seeking privileged accounts and systems that broaden their reach.

Attacker objective

Move from the compromised server toward broader internal control.

Controls that should stop this
  • Network segmentation isolating the application tier
  • Least privilege and credential-theft protections
  • Endpoint detection tuned for lateral movement
What defenders should see
  • Internal connections originating from the app server
  • Credential-access and enumeration alerts
  • Use of service or admin credentials from unexpected hosts
What a pentest validates
  • Assumed-breach test from the application tier inward
  • Validate segmentation between the DMZ and internal systems
  • Test detection of credential theft and lateral movement
Business impact

The attacker expands from a single server toward privileged internal access.

03

Ransomware is deployed to reachable systems

With sufficient reach and privilege, the attacker impairs recovery where they can and deploys encryption across the systems accessible from their position.

Attacker objective

Encrypt as many reachable systems as possible to maximise disruption.

Controls that should stop this
  • Immutable, offline backups tested for restore
  • Application control limiting unauthorised executables
  • Alerting on mass file change and shadow-copy deletion
What defenders should see
  • Mass file-modification and encryption behaviour
  • Backup tampering or deletion events
  • Rapid spread of activity across many hosts
What a pentest validates
  • Validate segmentation limits how far an app-tier breach spreads
  • Confirm backups survive a privileged compromise
  • Test detection of mass file change and recovery inhibition
Business impact

Reachable systems are encrypted — operational disruption and costly recovery follow.

ATT&CK techniques in this chain

If this chain completes

An application weakness on the edge becomes an internal ransomware event — encrypting reachable systems, disrupting operations and forcing a costly recovery.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.