
Stay Ahead of Ransomware - July 2026
Source: YouTube · SANS Digital Forensics and Incident Response · published Jul 8, 2026 · 58:20
Threat actors are increasingly shifting away from traditional ransomware encryption, focusing instead on data exfiltration and techniques to bypass security controls like MFA and EDR 4:52-5:01.
Key Takeaways:
• Ransomware encryption has dropped to roughly 50% of cases, partly due to better backup recovery and declining extortion payments (now around 20%), with groups like Beyond Leon exfiltrating data only 8:28-9:04.
• Attackers use AiTM phishing kits (like EvilGinx) to steal session tokens, completely bypassing MFA by injecting stolen cookies to access accounts directly 19:37-22:57.
• "EDR killers" exploit vulnerable signed drivers to gain kernel access, allowing attackers to silently terminate security tools like Defender or CrowdStrike and operate undetected 26:29-31:06.
• The tool rclone is heavily abused for rapid data exfiltration, leaving behind forensic artifacts like config files (with obfuscated but easily decrypted credentials), prefetch files, and SRUM database network logs 34:44-37:01.
• Free Canary tokens (e.g., fake insurance docs, AWS keys, or tracking pixels on login pages) provide excellent, low-overhead deception-based detection for defender teams 46:05-51:09.
As the threat landscape pivots from encryption to stealthier extortion methods, organizations must evolve their defenses beyond basic MFA and backups to include phishing-resistant authentication, kernel-level driver monitoring, and proactive deception techniques.
Sources:
- 4:52-5:01 Shift away from encryption toward other extortion techniques
- 8:28-9:04 Stats on encryption drop and declining payment rates
- 19:37-22:57 AiTM phishing demo bypassing MFA via session cookie theft
- 26:29-31:06 EDR killer demo using vulnerable drivers to kill security processes
- 34:44-37:01 rclone exfiltration demo and associated forensic artifacts
- 46:05-51:09 Using Canary tokens for deception and detection
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
And I believe we are live. Hello and welcome folks. My name is Ryan Chapman and I'm here with my fantastic co-host as usual, Mary Deg Grazia. Mary, how you doing today? >> I'm doing wonderful. How you doing, Ryan? >> I am doing all right. I I kind of get really excited by these monthly live streams that we have together. So, typically I have like a great morning. I'm all like ready to go [clears throat] and then as soon as the show's over, I have like this adrenaline dump. I don't know what it is. But I just start yawning and I jump on work calls. People are like, "What? What's going on?" I'm like, "I don't know. I'm done for the day." [laughter] Unless my boss hears that, then I'm just kidding. Doesn't happen at all. So, uh, hey folks, if you are new to the show, this is our stay ahead of…