Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Part one of two: How ransomware operators weaponize Active Directory—and what that means for recovery.
There was a time when ransomware meant a single infected workstation and a handful of encrypted files. Those days are long gone. Modern ransomware operators like RansomHub, Akira, Qilin, BlackSuit, Medusa, Fog, and their peers have long understood that the real leverage isn't on the endpoint—it's in the directory that governs every endpoint in a Microsoft-centric environment: Active Directory (AD).
In the vast majority of successful ransomware attacks today, Active Directory is the central pivot point attackers exploit throughout the intrusion. It is compromised, weaponized, and ultimately sabotaged. That's precisely why identity resilience can no longer be an afterthought—it must be a first-order security priority.
Phase 1: Initial access and reconnaissance: The attack rarely starts in Active Directory. The adversary enters through a side door: spear-phishing, exploitation of an exposed VPN or RDP endpoint, credential stuffing against a public-facing portal, or a supply chain compromise through a trusted partner. Once a foothold is established, reconnaissance begins.
Key Tactics, Techniques, and Procedures (TTPs)
ID
Technique
T1078
Valid Accounts - Stolen credentials reused for legitimate access
T1087.002 / T1069.002
Domain Account & Group Discovery - Mapping privilege paths
T1482
Domain Trust Discovery - Identifying inter-domain trust relationships
Tools like BloodHound, SharpHound, and ADRecon can map delegation paths, privileged group memberships, and domain trust relationships within minutes. The attacker quickly identifies high-value targets: Domain Admins, Enterprise Admins, overprivileged service accounts, and objects with misconfigured ACLs.
Active Directory's attack surface isn't just from a single vulnerability or misconfiguration. It's a decade of inherited configurations, forgotten delegations, and permissions granted for convenience.
Phase 2: Privilege escalation and AD takeover: This is where the attack changes in nature. The adversary is no longer moving quietly through the environment—they are moving in for the kill, aiming to own the directory outright.
Key TTPs
T1558.003
Kerberoasting - Offline cracking of service ticket hashes
T1558.001
Golden Ticket - Forging Kerberos tickets after krbtgt hash compromise
T1003.006
DCSync - Impersonating a DC to extract all AD password hashes
T1068
Exploitation for Privilege Escalation - ZeroLogon, noPac, PrintNightmare
Once the krbtgt account is compromised, the attacker can forge Golden Tickets, valid Kerberos tickets for any account, any service, with an arbitrary lifetime. At that point, Active Directory is fully under adversarial control.
Phase 3: Persistence, planting backdoors inside Active Directory: This is the least visible phase and the most dangerous one for incident response teams. Before triggering encryption, sophisticated attackers embed persistence mechanisms directly into the structure of Active Directory itself.
T1207
DCshadow - Rogue DC replicating malicious changes with no audit trail
T1556.001
Skeleton Key - Master password injected into DC LSASS processes
T1178
SID-History Injection - Invisible Domain Admin rights on an innocuous account
T1222.001
AdminSDHolder ACL Modification - Auto-propagation of malicious rights
These backdoors are engineered to survive partial restores and password resets. They ensure that even after the application layer is recovered, the directory remains compromised, and the attacker's access remains intact.
Phase 4: Lateral movement and data exfiltration: Before triggering the payload, modern ransomware operators exfiltrate data, the fuel for double extortion.
T1021.001 / T1021.002
RDP & SMB — Lateral movement using stolen credentials
T1567.002
Exfiltration to Cloud Storage — Data staging via Rclone, Mega
Phase 5: Deployment and encryption: With persistence established and data staged for exfiltration, the signal is given. Group Policy Objects are used to push the ransomware payload across the entire domain simultaneously.
T1486
Data Encrypted for Impact — Mass encryption of files and volumes
T1490
Inhibit System Recovery — Deletion of VSS shadow copies
T1485
Data Destruction — Destruction of network-accessible backups
T1484.001
GPO Modification — Ransomware deployment pushed via Group Policy
Within minutes, file servers and databases are encrypted. The ransom notes appear. The clock starts.
As the attack chain laid out above makes clear, when Active Directory falls, everything falls with it. But the good news is that this doesn't have to be the end of the story. Organizations that understand how these attacks unfold are far better positioned to recover cleanly. With the right preparation, Active Directory can be hardened against the most common attack paths, identity threats can be detected and remediated before they become a crisis, and a clean, automated recovery can be validated rather than assumed. Identity resilience isn't just possible—it's achievable. In part two, we'll get into exactly how.
Interested in testing your own identity security today?
Written By
Julien Mousqueton
Field CISO Europe