Back to Intelligence

Q3 2026 Ransomware Surge: 2,627 Claimed Attacks Set New Record — Detection and Hardening Playbook

SA
Security Arsenal Team
October 9, 2026
11 min read

Comparitech's latest tracking data shows 2,627 claimed ransomware attacks in Q3 2026 — the highest quarterly figure on record. Critical sectors bore the brunt: finance, technology, education, and healthcare all saw significant increases in claimed incidents. These are claimed attacks — incidents where threat actors publicly named a victim on a leak site or the victim disclosed — meaning the true number, including unreported and quietly-paid cases, is almost certainly higher.

If you're defending an organization in one of these verticals, the takeaway is blunt: ransomware crews are operating at industrial scale, and the dwell time between initial access and encryption continues to compress. The days of catching operators during a leisurely recon phase are gone. Your detection content has to fire on the behaviors that immediately precede detonation — and your containment has to be measured in minutes, not hours.

This post gives you the detection rules, hunt queries, and hardening steps we deploy at client sites to catch ransomware operators in the pre-encryption window.

Technical Analysis: The Pre-Encryption Kill Chain

No single CVE or product drives this quarter's numbers — this is a technique-level problem. Across the ransomware engagements we've responded to in 2025–2026, the operational pattern is remarkably consistent regardless of the affiliate or RaaS brand involved:

  1. Initial access — compromised credentials (often via infostealer logs), exploited edge devices (VPN concentrators, firewalls, remote access gateways), or phishing with callback/loader payloads.
  2. Privilege escalation and lateral movement — PsExec-style service execution, SMB admin shares, RDP, and legitimate admin tools (PsExec, AnyDesk, ScreenConnect) repurposed for spread.
  3. Defense evasion — disabling EDR via vulnerable drivers (BYOVD), tampering with security services, clearing event logs.
  4. Pre-encryption staging — this is the critical detection window:
    • Deletion of Volume Shadow Copies via vssadmin, wmic, bcdedit, or PowerShell (Get-WmiObject Win32_Shadowcopy | Remove-WmiObject)
    • Disabling boot recovery (bcdedit /set {default} recoveryenabled no, bootstatuspolicy ignoreallfailures)
    • Stopping backup, database, and AV services (net stop, sc stop, taskkill loops)
    • Mass file modification with high-entropy writes and ransom note drops (README, HOW_TO_DECRYPT, RECOVER_FILES style filenames in every directory)
  5. Extortion — data exfiltration to cloud storage or attacker infrastructure often precedes or accompanies encryption (double extortion is now the default, not the exception).

Exploitation status: Actively exploited at record scale — 2,627 claimed attacks in a single quarter per Comparitech. This is not theoretical. Every defender should treat pre-encryption behaviors as a paging-level alert.

The defensive lesson from this record quarter: organizations that survive ransomware events without catastrophic impact are the ones that detect at stages 3–4 and isolate automatically. If your first alert fires when users report encrypted files, you've already lost the containment window.

Detection & Response

The detection content below targets the pre-encryption behaviors that are common across virtually all modern ransomware families. These are high-fidelity signals with low false-positive rates in most environments.

Sigma Rules

YAML
---
title: Ransomware Shadow Copy Deletion Attempt
id: 8f2c4a91-3d6e-4b7a-9c15-2e8f6a1b4d90
status: experimental
description: Detects deletion or resizing of Volume Shadow Copies via vssadmin, wmic, bcdedit, or PowerShell — a near-universal pre-encryption ransomware behavior.
references:
  - https://attack.mitre.org/techniques/T1490/
  - https://www.infosecurity-magazine.com/news/q3-new-record-ransomware/
author: Security Arsenal
date: 2026/11/14
tags:
  - attack.impact
  - attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection_vssadmin:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
  selection_wmic:
    Image|endswith: '\wmic.exe'
    CommandLine|contains:
      - 'shadowcopy delete'
      - 'shadowcopy where'
  selection_ps:
    CommandLine|contains:
      - 'Win32_Shadowcopy'
      - 'Get-WmiObject Win32_Shadowcopy'
      - 'Remove-WmiObject'
  filter_ps_only:
    CommandLine|contains: 'Win32_Shadowcopy'
  condition: selection_vssadmin or selection_wmic or (selection_ps and filter_ps_only)
falsepositives:
  - Backup software performing legitimate shadow copy management (Veeam, Commvault agents)
  - Storage administrators resizing shadowstorage during maintenance windows
level: high
---
title: Ransomware Boot Recovery Configuration Tampering
id: 4b1e7c28-9a5f-4d32-8e61-7c3b9f2a6e15
status: experimental
description: Detects bcdedit modifications disabling boot recovery — commonly executed immediately before mass encryption to prevent victim self-recovery.
references:
  - https://attack.mitre.org/techniques/T1490/
  - https://www.infosecurity-magazine.com/news/q3-new-record-ransomware/
author: Security Arsenal
date: 2026/11/14
tags:
  - attack.impact
  - attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\bcdedit.exe'
    CommandLine|contains:
      - 'recoveryenabled no'
      - 'bootstatuspolicy ignoreallfailures'
      - 'recoveryenabled 0'
falsepositives:
  - Rare. Some imaging and provisioning tools modify boot configuration, but disabling recovery is highly suspicious outside of scripted OS deployment.
level: critical
---
title: Mass Ransom Note File Creation
id: 6d3a9f47-2c81-4e56-b794-1a8d5c3e7f02
status: experimental
description: Detects creation of files with common ransom note naming patterns on endpoints and servers — indicates active or completed encryption.
references:
  - https://attack.mitre.org/techniques/T1486/
  - https://www.infosecurity-magazine.com/news/q3-new-record-ransomware/
author: Security Arsenal
date: 2026/11/14
tags:
  - attack.impact
  - attack.t1486
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|contains:
      - 'DECRYPT_INSTRUCTION'
      - 'HOW_TO_DECRYPT'
      - 'HOW_TO_RECOVER'
      - 'RECOVER_FILES'
      - 'RESTORE_FILES_INFO'
      - 'README_FOR_DECRYPT'
      - 'FILES_ENCRYPTED'
      - 'RETURN_DATA'
      - 'UNLOCK_FILES'
      - 'RANSOM_NOTE'
    TargetFilename|endswith:
      - '.hta'
      - '.txt'
      - '.html'
  condition: selection
falsepositives:
  - Deception/honeypot files deliberately placed by defenders (these are intentional detections)
  - Security awareness phishing simulation files using similar naming
level: critical

KQL — Microsoft Sentinel / Defender Hunt Queries

Hunt for pre-encryption staging behaviors across your fleet. This query correlates shadow copy deletion, recovery tampering, and suspicious service stops within a tight time window — the signature of an operator preparing to detonate.

KQL — Microsoft Sentinel / Defender
// Hunt: Ransomware pre-encryption staging behaviors (last 7 days)
let stagingCommands = dynamic([
    "vssadmin", "delete shadows", "shadowcopy delete",
    "bcdedit", "recoveryenabled no", "ignoreallfailures",
    "Win32_Shadowcopy"
]);
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where ProcessCommandLine has_any (stagingCommands)
| extend Behavior = case(
    ProcessCommandLine has "vssadmin" or ProcessCommandLine has "shadowcopy", "ShadowCopyDeletion",
    ProcessCommandLine has "bcdedit", "BootRecoveryTampering",
    ProcessCommandLine has "Win32_Shadowcopy", "ShadowCopyDeletion",
    "Other")
| summarize FirstSeen = min(TimeGenerated),
            LastSeen = max(TimeGenerated),
            Commands = make_set(ProcessCommandLine),
            Accounts = make_set(AccountName)
  by DeviceName, Behavior, InitiatingProcessFileName
| order by LastSeen desc;

// Hunt: Mass file rename/modification indicative of active encryption
// Tune the threshold (200) to your environment baseline
DeviceFileEvents
| where TimeGenerated > ago(1d)
| where ActionType in ("FileCreated", "FileRenamed", "FileModified")
| where FileName has_any ("DECRYPT", "RECOVER_FILES", "HOW_TO_DECRYPT", "RANSOM", "RESTORE_FILES")
   or (FolderPath has "\\Users\\" and FileName endswith_any (".locked", ".encrypted", ".enc"))
| summarize FileCount = count(), SampleFiles = make_set(FileName, 20), Actions = make_set(ActionType)
  by DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName
| where FileCount > 5
| order by FileCount desc;

// Hunt: Rapid service stops targeting backup/database/security services
DeviceProcessEvents
| where TimeGenerated > ago(3d)
| where FileName in~ ("net.exe", "net1.exe", "sc.exe", "taskkill.exe")
| where ProcessCommandLine has_any ("stop", "/f")
| where ProcessCommandLine has_any ("vss", "sql", "backup", "veeam", "sophos", "defender", "sentinel", "exchange", "mssql")
| summarize StopCount = count(), Targets = make_set(ProcessCommandLine, 15)
  by DeviceName, InitiatingProcessAccountName
| where StopCount > 3
| order by StopCount desc;

Velociraptor VQL Hunt

Deploy this artifact across your estate to surface hosts where pre-encryption staging or mass-encryption artifacts are present.

VQL — Velociraptor
-- Hunt: Ransomware staging — shadow copy tampering, ransom notes, and suspicious processes
LET staging_procs = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(vssadmin.*delete|shadowcopy delete|bcdedit.*recoveryenabled|ignoreallfailures|Win32_Shadowcopy)'

LET ransom_notes = SELECT FullPath, Size, Mtime
FROM glob(globs=[
    'C:/Users/*/Desktop/*DECRYPT*',
    'C:/Users/*/Documents/*DECRYPT*',
    'C:/Users/*/Desktop/*RECOVER_FILES*',
    'C:/Users/*/Desktop/HOW_TO_*',
    'C:/*/README_FOR_DECRYPT*',
    'C:/*/RESTORE_FILES_INFO*'
], accessor='ntfs')

SELECT * FROM {
    SELECT 'StagingProcess' AS FindingType, Name AS Artifact, CommandLine AS Detail, Username AS Context FROM staging_procs
    UNION
    SELECT 'RansomNote' AS FindingType, FullPath AS Artifact, format('%v bytes', Size) AS Detail, timestamp(Mtime) AS Context FROM ransom_notes
}

Hardening Script — Pre-Encryption Mitigations

Run this on endpoints and servers (via GPO/Intune/SCCM at scale) to harden against the most common pre-encryption techniques and verify your exposure.

PowerShell
# Ransomware Pre-Encryption Hardening — Security Arsenal IR Playbook
# Run as SYSTEM/Administrator. Test in a pilot OU before broad deployment.

# 1. Verify shadow copies are enabled and protected on the OS volume
Write-Host "[*] Checking Volume Shadow Copy status..." -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
    Write-Host "[!] No shadow copies found. Enabling VSS protection on C:..." -ForegroundColor Yellow
    vssadmin add shadowstorage /for=C: /on=C: /maxsize=10%
    wmic shadowcopy call create Volume='C:\'
}

# 2. Restrict vssadmin/wmic/bcdedit abuse via AppLocker-style audit (check for unauthorized use)
Write-Host "[*] Auditing recent shadow copy deletion events (Event ID 524)..." -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=524; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Message | Format-List

# 3. Enable Controlled Folder Access (Defender anti-ransomware) — audit mode first on servers
Write-Host "[*] Enabling Controlled Folder Access..." -ForegroundColor Cyan
Set-MpPreference -EnableControlledFolderAccess Enabled
# Add protected folders for file shares on servers:
# Add-MpPreference -ControlledFolderAccessProtectedFolders "D:\Shares"

# 4. Disable administrative shares on workstations (lateral movement choke point)
# CAUTION: Skip on servers where admin shares are required for management tooling
Write-Host "[*] Disabling AutoShareWks (workstation admin shares)..." -ForegroundColor Cyan
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" -Name "AutoShareWks" -Value 0

# 5. Block Office macro child processes and common LOLBin abuse via ASR rules (audit first, then block)
Write-Host "[*] Setting Defender ASR rules to Block mode..." -ForegroundColor Cyan
$asrRules = @{
    "d4f940ab-401b-4efc-aadc-ad5f3c50688a" = 1  # Block Office apps from creating child processes
    "3b576869-a4ec-4529-8536-b80a7769e899" = 1  # Block Office apps from creating executable content
    "75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84" = 1  # Block Office apps from injecting code
    "92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b" = 1  # Block Win32 API calls from Office macros
    "c1db55ab-c21a-4637-bb3f-a12568109d35" = 1  # Block executable content from email/webmail
    "56a863a9-875e-4185-98a7-b882c64b5ce5" = 1  # Block abuse of exploited vulnerable signed drivers (BYOVD)
    "7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c" = 1  # Block ransomware-like file modification (CFA enforcement)
}
foreach ($rule in $asrRules.GetEnumerator()) {
    Add-MpPreference -AttackSurfaceReductionRules_Ids $rule.Key -AttackSurfaceReductionRules_Actions $rule.Value
}

# 6. Verify RDP is not exposed and NLA is enforced
Write-Host "[*] Checking RDP NLA enforcement..." -ForegroundColor Cyan
$nla = Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name "UserAuthentication" -ErrorAction SilentlyContinue
if ($nla.UserAuthentication -ne 1) {
    Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name "UserAuthentication" -Value 1
    Write-Host "[+] NLA enforced for RDP." -ForegroundColor Green
}

# 7. Confirm tamper protection is enabled (prevents EDR disablement)
Write-Host "[*] Verifying Defender Tamper Protection..." -ForegroundColor Cyan
$tamper = Get-MpComputerStatus | Select-Object -ExpandProperty IsTamperProtected
if (-not $tamper) {
    Write-Host "[!] Tamper Protection is OFF — enable via Intune/MEM or Defender portal." -ForegroundColor Red
}

Write-Host "[*] Hardening complete. Review ASR events (Event ID 1121/1122) before enforcing on servers." -ForegroundColor Green

Remediation and Defensive Priorities

There is no single patch for this threat — the record quarter reflects a mature criminal ecosystem, not one vulnerability. Your remediation program should prioritize the choke points that show up in nearly every ransomware IR engagement:

  1. Immutable, offline, and tested backups. Air-gapped or immutable (object-lock) backups are the difference between an incident and a catastrophe. Test restores quarterly — a backup that has never been restored is a hypothesis, not a control. Protect backup infrastructure credentials separately from domain credentials; Veeam and backup admin compromise is a standard operator move.

  2. Eliminate exposed remote access. Audit internet-facing RDP, VPN concentrators, and remote management tools. Ransomware initial access in 2026 is dominated by compromised credentials against edge devices and remote access gateways. Enforce phishing-resistant MFA (FIDO2) on all remote access and patch edge appliances on an emergency-change cadence.

  3. Deploy the pre-encryption detections above as paging alerts. Shadow copy deletion, bcdedit recovery tampering, and mass ransom-note creation should trigger automated host isolation via your EDR — not a ticket in a queue. Containment in under 15 minutes is the metric that matters.

  4. Credential hygiene against infostealers. The access broker pipeline feeding ransomware crews runs on stolen session tokens and credentials. Enforce conditional access, block legacy auth, and hunt for impossible travel and token theft indicators.

  5. Deception canaries. Plant fake credentials (klist-visible tickets, decoy password files) and honeypot file shares. Canary files with ransom-note-style detection give you early warning with effectively zero false positives.

  6. Incident response readiness. With attack volume at record levels, assume you will face an event. Maintain a tested IR plan, retainer, and offline copies of recovery runbooks. Know your legal counsel and cyber insurance carrier's notification requirements before you need them.

For healthcare and financial sector organizations — the verticals Comparitech flagged as hardest hit — regulatory exposure compounds the operational damage. HIPAA breach notification obligations and financial sector reporting requirements (including SEC disclosure rules for public companies) make rapid scoping and forensics a legal necessity, not just an operational one.

The Q3 2026 record isn't an anomaly; it's the trend line. The organizations that contain ransomware successfully detect at the staging phase and isolate automatically. Build for that window.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.