Ransomware Groups Are Increasingly Targeting Identity and Remote Access Systems
Ransomware operations are evolving beyond traditional malware-based attacks. Threat actors increasingly target credentials, identities, cloud accounts and remote access systems to gain an initial foothold inside organizations. This article examines how identity-based attacks work and the security controls organizations can use to reduce their exposure.
RANSOMWARE GROUPS ARE INCREASINGLY TARGETING IDENTITY AND REMOTE ACCESS SYSTEMS
Ransomware remains one of the most significant cybersecurity threats facing modern organizations. However, the techniques used by ransomware operators continue to evolve.
Traditional ransomware attacks were commonly associated with malicious software that encrypted files and demanded payment for their recovery. Modern ransomware operations can involve a much broader attack chain, including credential theft, compromised identities, remote access systems, data theft and extortion.
This shift means organizations need to protect not only their devices and networks, but also the identities that provide access to those systems.
WHY IDENTITY HAS BECOME AN IMPORTANT TARGET
Modern organizations depend heavily on cloud services, email platforms, VPNs, remote administration tools and online collaboration systems.
Each of these services depends on digital identities.
If an attacker obtains legitimate credentials, their activity may initially resemble the activity of a genuine employee. This can make identity-based intrusion particularly important for security teams to detect.
Microsoft's 2025 Digital Defense Report highlights the continuing importance of identity security and reports that password-spray attacks represented a very large proportion of the identity attacks it observed.
The objective for defenders is therefore not simply to identify malicious files. Organizations also need visibility into authentication activity, account privileges and suspicious access behaviour.
HOW ATTACKERS CAN OBTAIN CREDENTIALS
Attackers have several methods available for obtaining access credentials.
Phishing remains an important technique. An attacker may create a convincing email or message directing a victim to a fake authentication page.
Social engineering can also be used to persuade employees to reveal information or approve authentication requests.
Other risks include password reuse, credential-stealing malware and compromised remote-access services.
After obtaining access, attackers may attempt to identify valuable systems, obtain additional privileges, move through the environment and steal sensitive information.
THE ROLE OF REMOTE ACCESS
Remote working has made services such as VPNs and cloud platforms essential to many organizations.
These systems can also become attractive targets because successful compromise may provide an attacker with a pathway into an organization's internal resources.
Security teams should therefore treat remote-access infrastructure as security-critical.
Remote services should be patched, monitored and protected using strong authentication controls. Organizations should also investigate unusual authentication behaviour, particularly unexpected locations, devices or privilege changes.
MULTI-FACTOR AUTHENTICATION
Multi-factor authentication is one of the most important protections against credential-based compromise.
Australia's ASD Australian Cyber Security Centre recommends enabling MFA, particularly for important services such as email and remote access.
MFA means that obtaining a password alone may not be sufficient for an attacker to access an account.
Organizations should particularly protect administrator accounts and other privileged identities because compromise of these accounts may provide significantly greater access.
SECURITY MONITORING
Authentication logs can provide valuable information during both threat detection and incident investigation.
Security teams should monitor for suspicious patterns such as:
• repeated failed authentication attempts • unusual geographic login locations • unexpected administrator activity • abnormal login times • newly created privileged accounts • unexpected changes to MFA settings • suspicious remote-access activity
Combining identity monitoring with endpoint, network and cloud security telemetry provides defenders with a broader view of an attack.
BACKUPS AND INCIDENT RESPONSE
Preventing every cyberattack is unrealistic, which makes resilience extremely important.
Organizations should maintain reliable backups of critical information and test their recovery processes regularly.
Incident response procedures should also define how compromised accounts are disabled, credentials are reset, affected systems are isolated and evidence is preserved.
Testing these procedures before an incident can significantly improve an organization's ability to respond under pressure.
WHAT ORGANIZATIONS SHOULD DO
Organizations can strengthen their defenses by:
1. Enabling multi-factor authentication. 2. Using unique passwords or passphrases. 3. Protecting privileged administrator accounts. 4. Keeping VPNs and remote-access systems patched. 5. Monitoring authentication and identity activity. 6. Training employees to recognize phishing and social engineering. 7. Applying least-privilege access controls. 8. Maintaining tested backups. 9. Developing and testing an incident response plan. 10. Regularly reviewing accounts and removing unnecessary access.
FINAL THOUGHTS
Ransomware is no longer simply a problem involving malicious files and encrypted computers.
Identity, cloud infrastructure and remote access have become important parts of the modern threat landscape.
For defenders, this means cybersecurity strategies should combine endpoint protection with strong identity security, authentication monitoring, vulnerability management, employee awareness and incident response.
Protecting the identity behind the device can be just as important as protecting the device itself.
SOURCES & FURTHER READING
Australian Signals Directorate – Australian Cyber Security Centre Ransomware and ransomware protection guidance
Microsoft Microsoft Digital Defense Report 2025
Microsoft Security Threat Intelligence and Ransomware Research