Let’s talk about the identity gaps every team has to close. Join the convo.
Utility navigation bar redirect icon
Portal LoginSupportBlogContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    Infostealers
    Infostealers
    Living off the Land
    Living off the Land
    Initial Access & RaaS
    Initial Access & RaaS
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Disrupting your business is Big Cybercrime’s business model

    Stop unwanted interruptions before they stop your workflow.



    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    Ebooks
    Ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    The Devil, Eight Million Emails, and a Whole Lot of Milk
    Huntress Cybersecurity
    The Devil, Eight Million Emails, and a Whole Lot of Milk
    Huntress Cybersecurity
    Akira, LimeWire, and the Sour Taste of Data Exfiltration
    Huntress Cybersecurity
    Akira, LimeWire, and the Sour Taste of Data Exfiltration
    Huntress Cybersecurity
    Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit
    Huntress Cybersecurity
    Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Kaseya
    Kaseya
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Blog
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportBlogContact
Search
Close search
Get a Demo
Start for Free
HomeResource GuidesRansomware Guide
The Evolution of Ransomware: How

The Evolution of Ransomware: How Attacks Have Changed and What to Expect Next

Last Updated:
June 15, 2026

Key Takeaways:

  • Ransomware actors now conduct pre-attack reconnaissance and actively hunt for high-value targets, including healthcare organizations, critical infrastructure, and governments.
  • Today's attackers can move from initial access to full network encryption in less than 24 hours, and in some cases within just five hours of first gaining a foothold.
  • The Huntress Managed Security platform delivers proactive hardening and 24/7 managed detection and response across endpoints, identities, and cloud/email environments, helping you catch and contain ransomware campaigns before they wreck havoc on your business.
Try Huntress for Free
Get a Free Demo
Topics
The Evolution of Ransomware: How Attacks Have Changed and What to Expect Next
Down arrow
Topics
  1. What is Ransomware? A Complete Guide to Ransomware in 2026
  2. What are the Types of Ransomware Attacks?
  3. How ransomware affects business: The operational, financial & reputational impact
  4. The Cost of Ransomware Attacks for Business
  5. Ransomware Attack Statistics, Trends & Key Stats for Businesses
  6. Can Antivirus Detect Ransomware?
  7. Breaking Down Ransomware Attacks
  8. How to Prevent Ransomware
  9. Ransomware Detection: Methods & Tools to Stop Attacks
  10. How to Protect Against Ransomware Before It Encrypts Data
  11. How to Remove Ransomware
  12. How to Recover from Ransomware Attack?
  13. Ransomware trends reshaping threats in 2026
  14. Real Ransomware Examples: How Recent Attacks Happened and What We Can Learn
  15. How To Identify Attacks With Ransomware Detection Tools
  16. Securing Active Directory Against Ransomware
  17. How to Prevent Ransomware in Healthcare: Best Practices for Hospitals and Clinics
  18. Ransomware Defense Strategy: How to Build a Modern, Layered Approach in 2026
  19. Ransomware Readiness Checklist: Are You Prepared?
  20. The Evolution of Ransomware: How Attacks Have Changed and What to Expect Next
    • Historical overview of ransomware
    • Key milestones in ransomware evolution
    • Current trends in ransomware attacks
    • Ransomware evolution in cybersecurity
    • Protecting against ransomware threats: What to watch next
    • Stay two steps ahead of the evolution of ransomware
Share
Facebook iconTwitter X iconLinkedin iconDownload icon

The Evolution of Ransomware: How Attacks Have Changed and What to Expect Next

Last Updated:
June 15, 2026

Key Takeaways:

  • Ransomware actors now conduct pre-attack reconnaissance and actively hunt for high-value targets, including healthcare organizations, critical infrastructure, and governments.
  • Today's attackers can move from initial access to full network encryption in less than 24 hours, and in some cases within just five hours of first gaining a foothold.
  • The Huntress Managed Security platform delivers proactive hardening and 24/7 managed detection and response across endpoints, identities, and cloud/email environments, helping you catch and contain ransomware campaigns before they wreck havoc on your business.
Try Huntress for Free
Get a Free Demo

Historical overview of ransomware

If you thought ransomware was invented recently, you're not alone. You're also wrong.

The first ransomware (christened the AIDS Trojan) arrived all the way back in 1989. Physical media containing the malware were mailed on floppy disks to conference goers at a WHO conference on AIDS. The AIDS Trojan encrypted the names of targeted files on the victim's computer, then demanded payment sent via postal mail to a P.O. Box in Panama.

For the next 24 years, ransomware existed but never gained meaningful traction—the technical infrastructure and payment mechanisms simply weren't there yet. CryptoLocker changed that in 2013. It used asymmetric encryption, demanded payment in Bitcoin, and spread through phishing email attachments at scale. Criminal enterprises finally found a sustainable way to cash in.

By 2016, the first true ransomware-as-a-service (RaaS) platforms began to emerge—ecosystems that would evolve into the sprawling RaaS economy we recognize today, with operators acting less like organized crime and more like software companies with affiliate programs, tech support, and revenue splits.

In 2017, WannaCry and NotPetya taught the world just how destructive ransomware could be. Both used "worm-like" capabilities that automatically spread throughout networks by exploiting unpatched vulnerabilities. WannaCry ultimately infected more than 300,000 systems across roughly 150 countries and caused damage estimated in the hundreds of millions to billions of dollars, including widespread disruption across the UK's National Health Service. NotPetya, which began in Ukraine but quickly spread worldwide, is now widely regarded as one of the most destructive cyberattacks in history, with total losses estimated at over $10 billion).


Key milestones in ransomware evolution

Malware evolution is better understood as several parallel stories—diffuse players adjusting their strategies as the terrain shifts and new vulnerabilities present themselves.

Ransomware-as-a-service goes mainstream

Beyond commoditizing the creation and deployment of ransomware, RaaS groups gave anyone with criminal intent (and a Bitcoin wallet) access to their product without any technical knowledge required to execute an attack. The barrier to entry collapsed.

Double extortion becomes table stakes

Maze pioneered a tactic that essentially rendered backups useless overnight: exfiltrate data before encrypting it, then threaten to publish it publicly if the ransom goes unpaid. Organizations that could previously weather an encryption event now faced a second problem—leaked customer data sitting on a public forum.

The shift from high-volume to high-impact targeting

Ransomware isn't something you throw at everyone and hope something sticks. It's tactical. Targeted. Pre-reconnaissance. Threat actors now take the time to understand which organizations are most likely to pay the biggest ransoms and have the most incentive to pay fast, like healthcare, manufacturers, critical infrastructure, and governments.

Living off the land (LOTL)

Instead of deploying obvious malicious executables, attackers increasingly pivot to tools already installed on your systems to move laterally—think PowerShell, RDP, WMI, and legitimate admin utilities. Detection becomes significantly harder when malicious activity is hidden inside what looks like routine administrative behavior.


Current trends in ransomware attacks

What's unique about ransomware today is the operational sophistication and security that threat groups have developed.

Initial access is often ridiculously easy

Modern phishing lures. Unpatched RDP ports are open on the internet. VPN credentials purchased from initial access brokers. Exposed services. Weak passwords. Attackers rarely need to creatively obtain access to your environment—they just need to find a way in. Think of initial access as low-hanging fruit. The real expertise shows in how attackers move once they're inside.

Attackers are moving faster than ever

For years, ransomware criminals would gain access to a network, remain dormant, and return days or even months later to execute ransomware. As detection technology improved, attackers compressed their timelines to stay ahead of it. Today, many ransomware deployments progress from initial infiltration to full encryption in under 24 hours—and in some cases within just five hours—as median ransomware dwell time continues to fall.

AI is becoming a criminal tool

Just as security teams leverage generative AI to maximize productivity, cybercriminals are too. Attackers use AI to automate attack phases and reduce friction—from AI-generated phishing emails that accelerate credential theft to AI-powered vulnerability scanners that find exploitable gaps faster than your security team can close them.


Ransomware evolution in cybersecurity

Signature-based antivirus. Network monitoring. Whack-a-mole patching. These solutions remain important, but they don't do you much good when an attacker is living off the land, using legitimate admin tools already on your network to attack you. Stop thinking about how to prevent attackers from getting inside your network and start thinking about what you do if they already have.

The arms race on detection and response has driven significant adoption of endpoint detection and response (EDR) and identity threat detection and response (ITDR). You can't prevent every attack, so detect them and stop them fast.


Protecting against ransomware threats: What to watch next

Ransomware attacks aren't declining. In fact, research shows that in more than half of the investigated incidents, ransomware is now deployed within a day of initial access, with a meaningful share executed in just a few hours, and the targets are becoming more deliberate and high-value.

Expect more identity-driven attacks

Your attack surface is no longer just your network and endpoints. It's your identity layer too. Attackers are focusing on passwords and anything protected by username and password. Expect more attacks entering through Active Directory, targeting cloud identities, and exploiting weak passwords and multi-factor authentication (MFA) gaps.

Cross-platform targeting is expanding

The ransomware sweet spots aren't going away. They're just expanding. As enterprise environments virtualize critical infrastructure, Linux and ESXi servers are increasingly becoming primary targets.

Smaller organizations are increasingly in scope

Modern ransomware is lucrative enough that if a large business won't pay, attackers go smaller. More and more small and mid-sized businesses that service larger organizations through the supply chain are becoming viable, attractive targets.


Stay two steps ahead of the evolution of ransomware

The evolution of ransomware shows no signs of slowing, and every new tactic demands a smarter, more proactive response.

The full agentic Huntress platform combines Managed EDR, Managed ITDR, Managed SIEM, and Managed Security awareness training to protect your endpoints, identities, and cloud/email environments, backed by a 24/7 AI-centric SOC. Stop ransomware before it ever starts. Get a demo of the platform and see exactly how we stop attackers before they stop you.


Glitch effectGlitch effect

Protect What Matters

Secure endpoints, email, and employees with the power of our 24/7 SOC. Try Huntress for free and deploy in minutes to start fighting threats.
Try Huntress for Free
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingManaged ISPMManaged ESPMBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 250k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy