Advantest Corporation — a critical supplier of semiconductor test equipment to the global chip supply chain — has begun notifying affected individuals that personally identifiable information was stolen during a ransomware attack earlier this year. This is the now-familiar double-extortion playbook: attackers exfiltrate sensitive data before detonating encryption, so even organizations with pristine backups still face a data breach, regulatory notification obligations, and extortion pressure.
For defenders, the Advantest incident matters for two reasons. First, it reinforces that encryption is the final act of a ransomware intrusion, not the first. By the time files start being renamed, the attackers have typically been inside the environment for days or weeks — harvesting credentials, staging data for exfiltration, and dismantling recovery mechanisms. Second, semiconductor and manufacturing supply-chain firms remain high-value targets precisely because of the downstream pressure a disruption creates. If your organization sits anywhere in that ecosystem, this is your incident to learn from.
This post breaks down the attack pattern behind incidents like Advantest's and delivers concrete detection logic — Sigma, KQL, and Velociraptor hunts — focused on the pre-encryption window where you still have time to stop the damage.
Technical Analysis
What happened
Per Advantest's disclosure, unauthorized actors gained access to internal systems, exfiltrated personally identifiable information, and deployed encryption against portions of the environment. The company has notified affected individuals — a strong indicator the stolen data included employee and/or customer PII at sufficient volume to trigger breach notification statutes.
The attack chain (defender's perspective)
Incidents of this type — no CVE has been publicly attributed — almost universally follow this chain rather than exploiting a single novel vulnerability:
- Initial access — compromised VPN/remote access credentials, phishing-delivered loaders, or exploitation of an internet-facing appliance.
- Persistence and privilege escalation — valid account abuse, service creation, and credential dumping from LSASS memory.
- Discovery and staging — enumeration of file shares and databases containing PII; data archived with tools like 7-Zip or WinRAR into staging directories.
- Exfiltration — bulk transfer to attacker-controlled cloud storage (MEGA, Rclone to commercial providers) or direct transfer over HTTPS/SFTP. This is the step that creates breach notification liability.
- Impact preparation — deletion of Volume Shadow Copies, disabling of backup agents and security tooling via
vssadmin,bcdedit,wmic, ornet stop. - Encryption detonation — mass file modification across local drives and network shares, followed by ransom note deployment.
Exploitation status
No CVE identifier appears in the Advantest disclosure, so none will be fabricated here. The actionable intelligence is behavioral: the pre-encryption staging and impact-preparation behaviors (steps 3–5) are consistent across virtually every modern ransomware family and represent the highest-fidelity detection opportunities available to a SOC.
Detection & Response
The detections below target the behaviors that precede and accompany encryption — shadow copy destruction, backup tampering, mass file modification, and staging tooling. These are tuned to fire on genuinely suspicious patterns rather than routine admin work.
---
title: Volume Shadow Copy Deletion via vssadmin or WMIC
id: 8f2c1a94-3b7d-4e51-a6c9-2d4e5f6a7b8c
status: experimental
description: Detects deletion of Volume Shadow Copies, a near-universal precursor to ransomware encryption detonation. Observed in double-extortion intrusions including incidents of the type disclosed by Advantest.
references:
- https://attack.mitre.org/techniques/T1490/
- https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/
author: Security Arsenal
date: 2026/02/12
tags:
- attack.impact
- attack.t1490
logsource:
category: process_creation
product: windows
detection:
selection_vssadmin:
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
selection_wmic:
Image|endswith: '\wmic.exe'
CommandLine|contains: 'shadowcopy delete'
selection_powershell:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'Get-WmiObject Win32_Shadowcopy'
- 'Remove-CimInstance'
- 'Win32_ShadowCopy'
condition: 1 of selection_*
falsepositives:
- Rare legitimate storage reclamation by backup administrators; investigate parent process and user context immediately
level: critical
---
title: Boot Configuration Tampering to Disable Recovery
id: 3e9b2d15-7c4f-4a68-b1d3-5e7f8a9b0c1d
status: experimental
description: Detects bcdedit modifications that disable recovery mode and ignore boot failures — standard ransomware preparation to prevent system restore after encryption.
references:
- https://attack.mitre.org/techniques/T1490/
author: Security Arsenal
date: 2026/02/12
tags:
- attack.impact
- attack.t1490
- attack.defense_evasion
- attack.t1562
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'recoveryenabled no'
- 'bootstatuspolicy ignoreallfailures'
falsepositives:
- Extremely rare in production; any hit warrants immediate triage
level: critical
---
title: Mass Archive Creation with Compression Tooling for Exfiltration Staging
id: 6d4a7e28-1f9c-4b35-92e4-8a1b3c5d7e9f
status: experimental
description: Detects compression utilities archiving files with password protection or recursive flags into non-standard locations, consistent with pre-exfiltration data staging seen in double-extortion ransomware campaigns.
references:
- https://attack.mitre.org/techniques/T1560.001/
- https://attack.mitre.org/techniques/T1048/
author: Security Arsenal
date: 2026/02/12
tags:
- attack.collection
- attack.t1560.001
- attack.exfiltration
- attack.t1048
logsource:
category: process_creation
product: windows
detection:
selection_tool:
Image|endswith:
- '\7z.exe'
- '\7za.exe'
- '\rar.exe'
- '\winrar.exe'
selection_flags:
CommandLine|contains:
- ' -p'
- ' -r '
- ' a '
filter_legit:
CommandLine|contains:
- '\Program Files\'
- 'software deployment'
condition: selection_tool and selection_flags and not filter_legit
falsepositives:
- IT administrators packaging software or logs; baseline expected usage and alert on new hosts/users executing this pattern
level: high
// Hunt: Pre-encryption impact preparation and mass file modification
// Microsoft Sentinel / Defender — covers Windows endpoints; Syslog/CommonSecurityLog
// sections cover Linux and network appliance telemetry ingested via CEF.
// 1) Shadow copy deletion and recovery tampering across the fleet
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where (
(FileName =~ "vssadmin.exe" and ProcessCommandLine has_any ("delete shadows", "resize shadowstorage"))
or (FileName =~ "wmic.exe" and ProcessCommandLine has "shadowcopy delete")
or (FileName =~ "bcdedit.exe" and ProcessCommandLine has_any ("recoveryenabled no", "ignoreallfailures"))
)
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessAccountName
| sort by TimeGenerated desc;
// 2) Hosts with abnormally high file-rename/modify rates (encryption behavior)
// Baseline deviation — tune the threshold against your environment's norm.
DeviceFileEvents
| where TimeGenerated > ago(1h)
| where ActionType in ("FileRenamed", "FileModified")
| summarize FileOps = count(), DistinctExtensions = dcount(parse_path(FolderPath).Extension) by DeviceName, bin(TimeGenerated, 5m)
| where FileOps > 500
| sort by FileOps desc;
// 3) Compression/staging tooling executed by interactive users on servers
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName in~ ("7z.exe", "7za.exe", "rar.exe", "winrar.exe")
| where ProcessCommandLine has_any (" -p", " a ", " -r")
| join kind=leftouter (
DeviceLogonEvents
| where TimeGenerated > ago(14d)
| summarize LogonTypes = make_set(LogonType) by DeviceName, AccountName
) on DeviceName, AccountName
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, LogonTypes;
// 4) Linux/Syslog telemetry: mass outbound transfer or archive tooling on servers
Syslog
| where TimeGenerated > ago(7d)
| where ProcessName has_any ("tar", "zip", "7z", "rclone", "curl", "wget")
| where SyslogMessage has_any ("/etc/", "/home/", "/var/lib/", "--transfers", "mega.nz", "s3://")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| sort by TimeGenerated desc;
-- Velociraptor hunt artifact: Ransomware pre-impact indicators
-- Targets shadow copy destruction artifacts, staging archives, and
-- suspicious compression/exfiltration processes across the fleet.
-- Section 1: Live processes matching staging/impact tooling
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(vssadmin.*delete shadows|bcdedit.*recoveryenabled|shadowcopy delete)'
OR Exe =~ '(?i)(7z|7za|rar|rclone)\.exe$'
-- Section 2: Recently created archives in non-standard staging locations
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=['C:/Users/Public/**/*.zip', 'C:/Users/Public/**/*.7z',
'C:/Users/Public/**/*.rar', 'C:/ProgramData/**/*.7z',
'C:/ProgramData/**/*.rar', 'C:/Windows/Temp/**/*.7z',
'C:/Windows/Temp/**/*.rar'])
WHERE Mtime > now() - 86400*7
-- Section 3: Ransom note artifacts dropped across common directories
SELECT FullPath, Size, Mtime
FROM glob(globs=['C:/Users/*/Desktop/**/readme*.txt', 'C:/Users/*/Desktop/**/recover*.txt',
'C:/Users/*/Desktop/**/decrypt*.txt', 'C:/Users/Public/**/readme*.txt'])
WHERE Mtime > now() - 86400*14
# Advantest-style ransomware hardening and verification script
# Run elevated on servers and critical workstations. Read-only by default.
# Pass -Remediate to apply the hardening changes.
param([switch]$Remediate)
Write-Host "=== 1. Verify Volume Shadow Copies exist and are scheduled ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object DeviceObject, InstallDate | Format-Table }
else { Write-Warning "NO shadow copies present — system cannot self-recover from encryption." }
Write-Host "=== 2. Check boot recovery configuration ===" -ForegroundColor Cyan
$bcd = bcdedit /enum | Out-String
if ($bcd -match 'recoveryenabled\s+No') { Write-Warning "Boot recovery is DISABLED — classic ransomware preparation artifact." }
else { Write-Host "Boot recovery enabled." }
Write-Host "=== 3. Audit for staging tooling in unexpected locations ===" -ForegroundColor Cyan
$tools = @('7z.exe','7za.exe','rar.exe','rclone.exe')
foreach ($t in $tools) {
Get-ChildItem -Path 'C:\Users\Public','C:\ProgramData','C:\Windows\Temp' -Recurse -Filter $t -ErrorAction SilentlyContinue |
Select-Object FullName, LastWriteTime
}
Write-Host "=== 4. Verify backup agent health ===" -ForegroundColor Cyan
Get-Service | Where-Object { $_.DisplayName -match 'backup|veeam|vss|commvault|rubrik' } |
Select-Object Name, DisplayName, Status, StartType | Format-Table
if ($Remediate) {
Write-Host "=== Applying hardening ===" -ForegroundColor Yellow
# Enable Controlled Folder Access (Defender ransomware protection)
Set-MpPreference -EnableControlledFolderAccess Enabled
Write-Host "Controlled Folder Access: ENABLED"
# Re-enable boot recovery if it was tampered with
bcdedit /set {current} recoveryenabled yes
bcdedit /set {current} bootstatuspolicy displayallfailures
# Create a fresh restore point as a recovery baseline
Checkpoint-Computer -Description 'Pre-hardening baseline' -RestorePointType MODIFY_SETTINGS
# Block inbound SMBv1 (legacy lateral movement vector)
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force -Confirm:$false
Write-Host "Hardening applied. Reboot recommended and re-verify shadow copies." -ForegroundColor Green
} else {
Write-Host "Audit complete. Re-run with -Remediate to apply hardening." -ForegroundColor Green
}
Remediation
If you suspect an intrusion following this pattern, act in this order — the sequence matters because encryption detonation can be triggered if attackers sense discovery:
Containment (first 60 minutes):
- Isolate, don't power off. Network-isolate affected hosts (EDR isolation or switch ACLs) but preserve memory for forensic capture. Volatile evidence — active sessions, exfiltration connections — dies with the machine.
- Disable compromised credentials globally. Force password resets and revoke sessions for any account observed in attacker telemetry, including service accounts. Assume LSASS was dumped on any host the attacker touched.
- Block staging egress. Temporarily deny outbound traffic to consumer cloud storage (MEGA, Dropbox, Google Drive) and unclassified destinations at the proxy while preserving approved business flows.
Eradication and recovery: 4. Rebuild, don't clean. Ransomware intrusions routinely leave multiple persistence mechanisms. Reimage affected systems from known-good media. 5. Verify backup integrity before restoration. Confirm backups predate the intrusion window — check your earliest evidence of compromise, not just the encryption date. The Advantest notification timeline (attack earlier in the year, notifications following investigation) illustrates how wide that window can be. 6. Assume data was stolen. Scope the breach: which shares, databases, and mailboxes were accessed. Engage counsel on notification obligations in all applicable jurisdictions — GDPR, state breach statutes, and sector-specific regimes (HIPAA, PCI-DSS) each carry different clocks.
Long-term hardening:
7. Enforce phishing-resistant MFA on VPN, remote access, and email — the most common initial access vectors in incidents of this type.
8. Deploy the detections above into your SIEM and test them. Shadow copy deletion and bcdedit tampering should page a human, not queue a ticket.
9. Segment backup infrastructure with immutable/offline copies and dedicated credentials that no domain admin session can reach.
10. Tabletop the double-extortion scenario. Decide now, with legal and executive leadership, what your organization's position is on extortion demands and data-leak response — mid-crisis is the wrong time to draft policy.
Conclusion
The Advantest breach is a reminder that "ransomware" is a misnomer for what these operations actually are: data theft with an encryption encore. Organizations that focus detection solely on the encryption phase have already lost the data. The wins — the ones that turn a breach into a blocked attempt — come from catching the staging, the shadow copy deletion, and the recovery tampering in the days before detonation. Deploy the hunts above, verify your backups against your earliest compromise indicator, and treat every compression utility on a server as a question worth answering.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.