All chapters

Chapter 3

From stolen credential to ransomware

The journey from one stolen login to a full-scale ransomware incident can take as little as 24 to 72 hours. That is the window where external intelligence matters.

1

Credential stolen

Malware on a device exfiltrates logins, session tokens, and VPN configs.

2

Sold underground

Data is packaged and listed on forums, markets, and channels within hours.

3

Purchased by actors

Gangs and brokers select victims by domain, access level, and sector.

4

Silent infiltration

Attackers authenticate with real credentials — no brute force, often no malware signature on the login event.

5

Ransomware deployed

Lateral movement, exfiltration, and encryption — downtime and recovery costs mount fast.

Groups such as LockBit, BlackCat/ALPHV, Cl0p, and Scattered Spider have been documented using infostealer-derived credentials as a primary initial access vector. Buying logins costs a fraction of a zero-day yet can deliver equivalent access — that economics commoditised ransomware at scale.