A BOT

Encryption trojans: how an attack unfolds – and where you can stop it

IT Security5 min read

Security dashboard on a monitor

Monday morning, staff switch on their computers – and instead of their files they only see strange file extensions and a text file with payment instructions. This is how many companies experience an encryption trojan (also known as ransomware). What is often overlooked: encryption is the final step. Before that, the attackers had usually been inside the network for days or weeks.

Knowing how an attack unfolds helps you spot warning signs earlier and know where to stop it.

Phase 1: Getting in

Attackers need initial access. Typical routes:

  • a phishing email with an infected attachment or link – see spotting phishing,
  • stolen credentials for VPN, remote access or email,
  • an unpatched vulnerability in a firewall, VPN appliance or server.

Where to stop it: multi-factor authentication, prompt updates and a mail filter close most doors.

Phase 2: Establishing a foothold

After getting in, attackers install inconspicuous tools so they can come back at any time – often disguised as legitimate remote support or admin programs.

Where to stop it: only allow approved software and monitor new services or autostart entries.

Phase 3: Exploring and spreading

Now the attackers explore the network: which servers exist, where is the data, who has administrator rights? Using captured passwords, they hop from device to device until they own an administrator account.

Where to stop it: separate networks, unique local admin passwords (Windows LAPS) and least privilege. More in our article on GPO hardening.

Phase 4: Stealing data

Before encrypting, many groups copy confidential data out of the company. That lets them extort twice: “Pay, or we publish your customer data.”

Where to stop it: unusually large outbound data transfers stand out when network traffic is monitored.

Phase 5: Disabling backups

Attackers know that a working backup destroys their business model. So they specifically look for backups to delete or encrypt them too.

Where to stop it: immutable copies that not even an administrator can delete, plus an off-site copy – following the 3-2-1 rule.

Phase 6: Encrypting and extorting

Only now does encryption start – often at night or at weekends when nobody is watching. Within a short time servers and workstations are unusable, and the ransom demand arrives.

Early warning signs

Take these signs seriously and report them to your IT immediately:

  • logins at unusual times or from abroad,
  • new user or administrator accounts nobody created,
  • antivirus disabled on individual devices,
  • programs nobody installed,
  • noticeably slow servers or network for no apparent reason,
  • backup software warnings about failed or deleted backups.

A central monitoring system (SIEM) such as Wazuh collects these signals automatically and raises the alarm – often long before encryption begins.

The emergency card for the office

Post these four points somewhere visible:

  1. Disconnect the device from the network – unplug the cable, turn off Wi-Fi. Don’t shut it down.
  2. Call IT immediately – not by email if the mail system might be affected.
  3. Don’t delete anything, don’t pay, don’t contact the extortionists.
  4. Write down what you noticed – time, messages, affected devices.

What to do next – reporting to the Federal Office for Cybersecurity, filing a police report, restoring – is covered in our article on ransomware in SMEs.

Conclusion

An encryption trojan is not a bolt from the blue but the end of a chain. Every phase offers a chance to stop it. Securing access, limiting rights, monitoring the network and keeping an immutable backup make life hard for attackers. We are happy to check where your chain still has gaps – as part of our IT security service.

Frequently asked questions

What is the difference between an encryption trojan and ransomware?

None. Both terms describe malware that encrypts data and demands a ransom for its release.

Is antivirus alone enough against encryption trojans?

No. Good antivirus matters, but attackers often use legitimate tools and deliberately disable protection. What counts is the combination of secured access, monitoring and immutable backups.

How long are attackers in the network before encrypting?

It varies widely – from a few hours to several weeks. That window is exactly the chance to detect the attack early through monitoring.

Can encrypted data be recovered without paying?

The safest way is restoring from a clean backup. Free decryption tools from authorities and security firms exist for some older malware, but you cannot rely on them.

More articles

Questions?

We are happy to review your environment and tell you honestly where action is needed.