Chapter 3
From stolen credential to ransomware
The journey from one stolen login to a full-scale ransomware incident can take as little as 24 to 72 hours. That is the window where external intelligence matters.
Credential stolen
Malware on a device exfiltrates logins, session tokens, and VPN configs.
Sold underground
Data is packaged and listed on forums, markets, and channels within hours.
Purchased by actors
Gangs and brokers select victims by domain, access level, and sector.
Silent infiltration
Attackers authenticate with real credentials — no brute force, often no malware signature on the login event.
Ransomware deployed
Lateral movement, exfiltration, and encryption — downtime and recovery costs mount fast.
Groups such as LockBit, BlackCat/ALPHV, Cl0p, and Scattered Spider have been documented using infostealer-derived credentials as a primary initial access vector. Buying logins costs a fraction of a zero-day yet can deliver equivalent access — that economics commoditised ransomware at scale.