// Ransomware analysis

A must-have sandbox to detect ransomware attacks

Ransomware now uses evasive and modular attack chains that require deep, behavior-based, and recursive analysis to be fully uncovered.

Despite law enforcement disruptions in 2025, the RaaS ecosystem hasproven its resilience. Ransomware attacks reached record levels in December 2025 and continue to accelerate into early 2026.

Attack Chain

Email PDF QR code ClickFix RMM

Malicious chain

Recursive Attack Chain

RMM → Payload

Early indicators are linked before the final ransomware payload appears

Fortune 500 customers
0 +
Government organizations
0 +
Financial institutions
0 +

4 of 5
World’s top tech giants

3 of 4
Big 4 accounting firms
// the Challenges

Ransomware no longer arrives as a single executable

Modern ransomware uses multi-stage delivery chains, legitimate tools, and highly
evasive behavior to avoid detection until the final payload is deployed.

Ransomware chains hide earlier signals

Modern ransomware uses multi-stage delivery chains, living-off-the-land techniques, abused legitimate tools, and evasive malware to avoid detection.

Extortion extends beyond encryption

Attackers increasingly steal data before, alongside, or instead of encryption. Exfiltrated data may then be analyzed with LLMs to intensify blackmail efforts.

SOC teams often get overwhelmed

SOC teams often skip low-severity alerts, even though they may reveal stealthy activities. Distinguishing real threats from benign activity remains difficult.

Incomplete visibility into attack chains

Many tools focus on blocking threats quickly, but fail to expose the full infection chain, missing next-stage malware and associated IOCs.

// Key value

Expose full ransomware chain before the final payload appears

VMRay analyzes alerts recursively, surfaces high-
confidence behavioral context, and extracts IOCs from
ongoing attacks.

Automated analysis of alerts from EDR & SOAR

VMRay analyzes all alerts to detect early signs of attacks that may evolve into ransomware, such as phishing campaigns leading to RMM deployment.

High-confidence verdicts with context

SOC analysts can focus on the alerts that matter by leveraging detailed behavioral insights and high-fidelity IOCs to make fast, informed decisions.

Detection of highly evasive ransomware

Runs static and dynamic analysis in an anti-evasion sandbox to ensure sophisticated malware is fully detonated and observed.

Real-time threat intelligence from attacks

Recursive extraction of high-fidelity IOCs enables rapid detection and blocking of further ransomware activity.

// Key features

Built for ransomware investigation and response

VMRay identifies ransomware TTPs, detonates full attack chains recursively, and delivers clear verdicts and IOCs into existing SOC workflows.

Accurate detection of ransomware TTPs

VMRay identifies early signs of ransomware activity, such as lateral movement, living-off- the-land techniques, RMM deployment, credential theft, privilege escalation, and persistence.

Recursive, full-chain dynamic analysis

By allowing the attack to run in an anti-evasion sandbox, VMRay automatically detonates and analyzes all stages of ransomware, including droppers and abused RMM tools, to identify attacker TTPs.

Integration with SOC tools (SOAR, EDR, TIP)

Analyze alerts recursively so low-severity ransomware indicators are not missed. Clear verdicts reach analysts in existing tools, while IOCs are shared with Threat Intelligence Platforms (TIPs).

Threat Identifiers

VTIs of a LockBit sample

Ransomware
Score Category Operation
5/5 User Data Modification Appends new extensions to many filenames
5/5 User Data Modification Modifies content of user files
5/5 User Data Modification Renames user files
4/5 Defense Evasion Modifies Windows Defender configuration
3/5 System Modification Disables a crucial system service

MITRE ATT&CK

Defense evasion attempt

Mapped

// Next step

From low-severity alert to ransomware-chain visibility

VMRay analyzes alerts recursively, reconstructs multi-stage ransomware behavior, and delivers verdicts and IOCs to SOC and threat intelligence workflows.

Attack chain example
Email, PDF, QR code, Captcha, Clickfix, batch file installing NetSupport (RMM)
  • Malicious

Email

reported

PDF

document

QR code

decoded

CAPTCHA

solved

ClickFix

clipboard

Batch

NetSupport

Step 01

Analyze all alerts.

VMRay analyzes all alerts from EDR and SOAR to detect early signs of attacks that may evolve into ransomware.

Step 02

Detonate recursively.

The attack runs in an anti- evasion sandbox so droppers, abused RMM tools, and next- stage malware can be observed.

Step 03

Identify TTPs.

VMRay identifies lateral movement, living-off-the-land behavior, RMM deployment, credential theft, privilege escalation, & persistence.

Step 04

Operationalize IOCs.

Clear verdicts reach SOC analysts in existing tools, while IOCs from real-time attacks are shared with TIPs.

// Next step

Detect ransomware with behavior-based, recursive analysis.

Use VMRay to uncover evasive ransomware attack chains, identify attacker TTPs, and generate high-fidelity IOCs for response and blocking.