In section Releases

Ransomware Shifts Tactics to Silent Directory Destruction

Nearly half of the 1,064 ransomware strains analyzed by the CyberSense Research Lab in early 2026 bypassed traditional detection by destroying directory entries rather than relying on full file encryption. This shift signals a move toward stealthier methods designed to evade security tools that monitor for standard corruption markers.

Ransomware Shifts Tactics to Silent Directory Destruction

The lab's research indicates that 47.8% of detonated variants utilized directory-entry destruction, a figure more than double the 18.3% that employed full encryption. By preserving original file extensions, timestamps, and maintaining low entropy, these newer threats successfully mask their presence from surface-level scans. Jim McGann, CMO at Index Engines, highlighted the 'Encoder' strain as a prime example of this evolution, noting that it destroys files while leaving their names and sizes unchanged, rendering typical detection methods ineffective.

Beyond directory destruction, the study identified that 64.7% of samples exhibited polymorphism, allowing them to regenerate file signatures and bypass traditional signature-based security. The speed of these attacks remains a critical concern, with a median velocity of 97,321 files corrupted per hour. Because these variants move faster than most incident response teams can mobilize, the findings suggest that organizations must move beyond simple detection and adopt forensic validation to determine which data backups remain truly clean before initiating recovery.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!