
04.07.2026 recovery denialwiper malwareincident responsecloud forensik
For years, DFIR practitioners have known the ransomware playbook: encrypt, extort, threaten to leak. That playbook is changing fast, and with it the evidentiary starting point of every incident response engagement. Two parallel developments from recent months show where this is heading. First, attackers are increasingly targeting the ability to recover itself, not just the data. Second, the window defenders have to act has collapsed dramatically.
Mandiant’s M-Trends 2026, drawing on more than 500,000 hours of 2025 incident response work, documents a systemic shift: while encryption and data theft remain central, attackers are increasingly focused on undermining an organization’s ability to recover, systematically targeting backup infrastructure, identity services, and virtualization management planes. By compromising or destroying recovery capabilities, attackers increase the likelihood that victims will pay, even when backups exist.
A particularly stark illustration is the Iran-linked Handala group’s attack on medical device maker Stryker in March 2026. Rather than deploying malicious code, the attackers followed a “Living-off-the-Cloud” approach, using Stryker’s own administrative capabilities against it — by compromising the identity layer, they carried out large-scale deletion and wipe actions using the same native controls designed for management. Reporting indicates the group leveraged RDP for lateral movement along with Group Policy logon scripts to deploy wiper malware, complemented by legitimate disk encryption utilities like VeraCrypt to complicate recovery efforts.
Similar cases keep surfacing: attackers deleted virtual machines directly through a transit authority’s own virtualization console, and in another incident, backup files were manually erased before core systems were destroyed. Unit 42 now explicitly advises organizations to isolate and air-gap backups, since cloud-connected backups are highly susceptible to the same destruction once the cloud tenant itself is compromised.
At the same time, the operational tempo of attacks has changed radically. M-Trends 2026 shows a growing share of incidents following a division-of-labor model, where an access broker hands off environment access to a second group, often a ransomware crew. This pattern appeared in 9% of 2025 investigations, up from 4% in 2022. What matters most is the speed of that handoff: the median time between initial compromise and hand-off was more than eight hours in 2022, but that window collapsed to just 22 seconds in 2025.
Paradoxically, global median dwell time has risen at the same time. Global median dwell time was 14 days in 2025, up from 11 days in 2024, driven largely by long-term espionage intrusions and North Korean IT worker operations, both of which had a median dwell time of 122 days. More incidents went undiscovered for intermediate periods of one week to six months, a shift attributed to groups that limit their tooling to what’s already present in the environment, mimic legitimate administrative behavior, and remove forensic artifacts. For DFIR teams this means two opposing threat models must be handled simultaneously: lightning-fast automated handoffs on one side, and patient, low-noise long-term presence on the other.
These developments carry concrete implications. First, backup and recovery infrastructure needs to be treated as its own critical line of defense, logically separated from production and identity environments. Second, identity and cloud telemetry — SSO logs, IAM events, OAuth token flows — must become a primary evidence source, since that is precisely where attackers now operate. Third, the 22-second reality forces a rethink of alert triage: what looked like a low-priority malware hit yesterday may already be the opening move of a full compromise today. M-Trends 2026 captures this with a maturity model that maps security posture across prevention friction and recovery path reliability, with the target state of “Active Resilience” combining hardened identity with a recovery environment severed from the attack surface.
For forensic examiners, the takeaway is unambiguous: evidence preservation can no longer start once an alert fires. Teams that only mobilize after detection risk mobilizing too late to find anything useful at all.
← Back to overview