HabrAugust 26, 2026🇷🇺Translated from Russian

7 Core Rules for Responding to Ransomware and Infrastructure Breaches

In recent months, questions and requests for advice after various incidents have become increasingly common: some organizations find their systems encrypted, others discover that their infrastructure has been damaged or that corporate email accounts and credentials have been stolen.

In mature companies with established information security practices, such situations are already covered by documented incident response procedures, and teams know exactly who does what in the first minutes and hours. However, when an organization encounters an incident for the first time, the situation becomes far more difficult: everything is down, business stakeholders are anxious, information is scarce, and immediate action is required.

At such moments it is easy to act too aggressively—rebooting servers, deleting suspicious files, clearing logs, or starting restoration from backups—and thereby accidentally complicate any subsequent investigation.

1. Isolate affected systems

The first action is to disconnect compromised machines from the network, including LAN, Wi-Fi, and VPN connections. If the boundary of the incident is clear, isolate specific hosts or network segments. When the scope is unknown and the attack may still be spreading, temporarily shutting down the entire network can be preferable to allowing further lateral movement.

Isolation does not mean powering off the server. Systems should be left running whenever possible. The preferred method is to isolate the host externally—through switch ACLs, firewall rules, port shutdowns, or by physically unplugging the network cable. If software controls must be used, both inbound and outbound traffic should be blocked so that a compromised system cannot continue communicating with attacker infrastructure.

2. Do not reboot or power off systems indiscriminately

A common reaction is to reboot an encrypted server or power it off entirely. Rebooting or shutting down erases volatile information that may be critical for forensic analysis: contents of RAM, active connections, running processes, and other traces of activity at the time of discovery. Once the spread has been contained through isolation, leave systems in their current state unless active encryption or destruction is still occurring.

3. Do not delete or clean anything

Another instinctive response is to locate suspicious items and remove them immediately. Avoid running antivirus scans that delete files, clearing the %TEMP% folder, wiping event logs, or terminating processes simply because they appear unusual. Artifacts that seem irrelevant now—malware launch files, logs with timestamps, command-line arguments, or evidence of lateral movement—may later prove essential to reconstructing the attack.

4. Do not begin restoring from backups

When data is encrypted or systems are broken, the immediate impulse is often to restore from backups and resume operations. This step should be postponed until it is confirmed that the backups themselves are intact and that the attacker is no longer present in the environment. Restoring systems into a still-compromised network risks a second round of encryption. Offline backups should also be protected and not connected directly to potentially compromised infrastructure.

5. Close obviously compromised access channels

If the initial entry point is known—whether a specific account, VPN, exposed RDP, SSH, or email credential—that channel must be closed. When dealing with accounts, terminate active sessions and revoke tokens where possible. Perform these actions from the perimeter or a trusted system rather than from a potentially compromised host. Avoid mass password resets or broad infrastructure changes in the first minutes, as such actions create noise and alter the environment that investigators need to examine.

6. Document what happened

During an incident, details are easily forgotten. Spend a few minutes recording the facts: when the problem was first noticed, who observed it and what exactly they saw, which systems are confirmed affected, what was happening immediately before discovery, the exact time and time zone, and what actions administrators have already taken. Screenshots of ransom notes, error messages, and system states should also be captured. These records will be requested by any investigator and help reconstruct the timeline later.

7. Stop and wait for a plan

Once affected systems are isolated, obvious access channels are closed, the current state is documented, and further spread has been halted, further experimentation should cease. Installing multiple antivirus products, deleting files, rebuilding domain controllers, or returning servers to production without a coordinated plan can destroy evidence and complicate recovery. From this point, structured activities—artifact collection, entry-point identification, timeline reconstruction, and scope assessment—should begin according to a deliberate plan.

In summary, the seven rules are: isolate infected systems, avoid unnecessary reboots or shutdowns, do not delete or clean files, do not start backup restoration prematurely, close known compromised access paths, record observed facts and actions, and stop once containment is achieved so that subsequent work follows a structured plan. These steps are not a complete incident response framework, but they provide a solid starting point when an organization faces its first ransomware or infrastructure incident.

Related articles

AntiMalwareRansomware & Extortion

IT Elements 2026 Conference: Ransomware Accounts for 69% of Incidents as Businesses Struggle with Backup Protection and AI Workloads

The fourth IT Elements conference opened in Moscow on September 9, focusing on business continuity after cyberattacks, infrastructure failures, and ransomware incidents. Jet CSIRT data showed that ransomware was responsible for 69% of confirmed incidents in the first half of 2026, with the majority occurring in the second quarter. Experts discussed the challenges of protecting backup copies from compromise, the frequent gap between stated RTO targets and real-world recovery times, and decision-making processes during major outages. The event also covered corporate AI agents, stressing the need for strong Data Governance, Data Quality, and DataOps practices to avoid unreliable model outputs. Research from Jet Infosystems and AC IKS revealed that over 30% of companies have already allocated dedicated network segments for AI workloads, with power demands reaching 80-200 kW per rack. On the networking track, testing of Eltex and EcoRouter devices showed adequate performance in standard scenarios but highlighted the lack of a universal domestic solution. The conference concluded with discussions on workforce changes, noting that AI is altering career paths for junior specialists and increasing demand for professionals who understand business context and can critically evaluate model results.

BoletimSecRansomware & Extortion

Ransomware Operators Linked to The Gentlemen Deploy TukTuk C2 Framework for Espionage and Credential Theft

Operators associated with the ransomware group The Gentlemen have adopted a new command-and-control framework called TukTuk to steal credentials, monitor compromised systems, and prepare environments for ransomware deployment. The framework was discovered on a server that also hosted tools for disabling EDR solutions, research on vulnerable drivers, and data apparently stolen from two large organizations. TukTuk includes agents for both Windows and Linux, along with its own backend and management panel that allows remote command execution, file transfers, screen capture, and device tracking through a single interface. One notable feature displays a fake Windows Security window on the victim's machine to capture entered credentials and send them directly to the attackers' panel. Researchers identified a DLL sideloading technique that abuses the legitimate Greenshot.exe executable to load a malicious log4net.dll library and launch the TukTuk agent. The server also contained EDRKiller, WarsawKiller, and UnknownKiller tools, plus materials on BYOVD attacks that leverage vulnerable legitimate drivers to gain kernel access and interfere with security products.

SecuritylabRansomware & Extortion

The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires

Ransomware has transformed dramatically since its origins in 1989, when evolutionary biologist Joseph Popp mailed AIDS-themed floppy disks demanding $189 via Panamanian mail. Early experiments like GPCode and Archiveus introduced stronger cryptography by the mid-2000s, while Reveton and CryptoLocker in 2012-2013 combined psychological pressure, Gameover Zeus botnets, and Bitcoin payments. Major incidents such as WannaCry, NotPetya, and attacks on Colonial Pipeline and JBS Foods demonstrated global reach and state-level involvement. Modern groups like REvil, LockBit, Maze, and Akira refined double extortion, Ransomware-as-a-Service models, access brokers, and virtualization targeting. Law enforcement operations have disrupted infrastructure repeatedly, yet the market fragments and regenerates with new brands. The core business model remains resilient due to easy initial access, layered extortion tactics, and victims' operational dependencies.

HabrRansomware & Extortion

Ragnarök: F6 Investigates VantaCore Ransomware Attacks and Suspected Thor Rebrand

F6's Digital Forensics Laboratory has identified a new ransomware group called VantaCore that has struck at least seven Russian organizations with multimillion-dollar ransom demands. Researchers assess VantaCore as a rebrand of the previously known pro-Ukrainian Thor group, part of a broader consolidation among such actors in 2025–2026. The group abandoned LockBit 3 Black and Babuk in favor of its own VantaCore ransomware built on similar foundations, while deploying custom tools including VantaCoreLoader, VantaCoreRAT, and the SnowKiller BYOVD utility. VantaCore maintains a Tor-based data leak site launched no later than June 2026 and uses double and triple extortion tactics, selling or publicly releasing stolen data after encryption. Initial access relies on exposed RDP, VPN, public application vulnerabilities, and compromised partner credentials, followed by lateral movement via legitimate accounts and SMB/RDP. The group disables security products, clears logs, and destroys backups using Bootice before deploying its ChaCha20/X25519 ransomware via manual RDP sessions or automated loaders.