Persistence is about surviving change
A foothold is only useful if it survives a reboot, a password change or a rebuild.
Which is why attackers invest in it early and in several places. It also means that removing malware without finding the persistence mechanism guarantees a return. The question during response is not only what was running but what would start it again.
More on Ransomware and malware
- Ransomware is often the last stage, not the firstThe bang is the end of the fuse
- Backups are ransomware targetsThe lifeboat goes first
- Lateral movement turns one foothold into manyAlong the loft, house to house
- Command and control gives malware an operatorSomebody is still holding the controller
- Living off the land reduces new-tool visibilityThey use your tools, not theirs
- Ransomware recovery is an identity problem tooThe data is the easy half
