Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.
What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker.
So, what can organizations do to protect themselves from these new threats? In this report from the KnowBe4 Threat Labs team, you will be able to:
- Identify the infrastructure patterns defining 2025-2026 ransomware campaigns.
- Map the critical stages that separate the initial email from the final encryption event.
- Understand the mechanics of the "ClickFix" technique and why modern threats are designed specifically to evade your current security controls.
How Has Ransomware Delivery Evolved?: A Timeline
Every shift in delivery method was a direct response to whatever controls had just become effective against the previous approach. In 2019 an internationally coordinated effort took down the Necurs botnet, a criminal infrastructure responsible for 90% of email-based malware. This disruption of the world’s largest botnet, with the loss of 9 million infected nodes, is the clearest inflection point: until then, volume was the strategy. Once that infrastructure was disrupted and security products had matured to catch direct attachment delivery, the economics changed. Operators moved to precision targeting and multi-stage chains where the email carries nothing dangerous itself.
|
PERIOD |
ACTOR / CAMPAIGN |
WHAT CHANGED |
|
Early 2000s |
GPCode ransomware |
Spear phishing with trojans disguised as job applications. First documented use of phishing as a ransomware delivery vector. |
|
2007 onwards |
Evil Corp / Dridex |
Cridex banking trojan via phishing, evolved into modular Dridex. Introduced the rentable malware model: operators and affiliates begin to separate. |
|
Mid-2010s |
Locky / Necurs botnet |
Up to 23 million phishing emails per 24-hour period across ~120,000 IPs in 139 country-code TLDs. Industrialised phishing at botnet scale. |
|
2019 |
Necurs takedown |
Microsoft and 35 law enforcement agencies dismantle Necurs. Forces transition away from high-volume direct-payload delivery. |
|
2025-2026 |
Multiple groups incl. access brokers |
Multi-hop redirect chains, fileless droppers, RMM tools for persistence, DNS-based staging. Phishing operators and ransomware operators are now separate commercial parties. |
What Ransomware Infrastructure Patterns Arose Between 2025-2026?
Threat Labs monitoring across this period revealed six consistent infrastructure patterns across diverse campaigns, regardless of varying lures or payloads. Each pattern maps directly to a control that had become effective against the previous approach.
Trusted First Hops: Attackers route through Google Drive, Dropbox, Slack and GitHub as first-hop redirect points. Links to these platforms appear trustworthy to the user and receive low-risk treatment from security products.
Seasoned Domain Redirects: The redirect chain leverages compromised or parked domains that have maintained clean reputation for a longer period of time, which affects blocklisting. This provides the attacker with a clear delivery window. Multistage redirect chains also exhaust the analysis timeframes of automated sandbox analysis.
Traceless Payloads: Droppers prioritize evasion through layered obfuscation and polymorphic signatures. Some campaigns use built-in Windows utilities like Certutil to stage payloads directly in process memory, bypassing the filesystem entirely. This means no detectable files remain for malware scanners.
Purchased Access: Ransomware operators treat access as a commodity rather than building it themselves. They procure established, valid credentials and pre-compromised infrastructures from underground markets, allowing them to bypass initial intrusion phases and pivot directly to malware deployment.
RMM for Persistence: Persistence is achieved using legitimate, signed commercial remote management tools. These blend into routine network traffic and IT environments, making unauthorized installations difficult to identify without specific environment baselines.
Separated Operators: Phishing and ransomware operations are often distinct commercial entities. One actor specializes in securing the initial foothold, which is then traded to a different ransomware operator. This ensures that the final payload deployment is decoupled from the original email by a discrete financial transaction between parties.
How The Ransomware Chains Actually Run
The common infrastructure patterns of the last year share a common thread: the inbox as an entry point. The phishing email carries a call-to-action or attachment whose only function is the first redirect. There is no payload in it. From that redirect, the victim moves through cloud platforms and then through domains with degraded or no reputation signal before reaching infrastructure the attacker controls.
Here are the five stages of a typical ransomware attack chain:
|
|
STAGE 1 -- PHISHING EMAIL The mail arrives as a subtle, time-sensitive lure. There’s no payload here, just a link to a trusted cloud service that slides past security filters unnoticed. It’s a lure designed to look completely harmless. |
|
|
STAGE 2 -- REDIRECT CHAIN A click initiates multi-hop routing through trusted cloud platforms and seasoned domains to evade suspicion. This exhausts sandbox analysis time before the malicious destination is reached. |
|
|
STAGE 3 -- DROPPER DELIVERY Now the trap snaps shut. A small, shape-shifting dropper sneaks into the machine’s memory entirely to avoid file scanners. It performs a silent check to ensure it is not being monitored, then confirms the target before communicating with the attacker. |
|
|
STAGE 4 -- RECONNAISSANCE Now inside, the ransomware operator scouts for high-value data and critical systems. They quietly map the network, positioning the ransomware to prepare for a single, synchronized strike. |
|
|
STAGE 5 -- RANSOMWARE DEPLOYMENT As long as a few weeks after the initial email, the final act plays out. A different operator takes the keys they’ve bought and deploys the ransomware. The environment is already mapped and defenses are already compromised, and the encryption begins. |
Where Standard Controls Do Not Reach
Each stage in this chain occupies a gap that controls designed for the previous generation of attacks were never built to address. The older approach was stopped by SEGs running detonation environments, endpoint products accumulating dropper signatures and hash-based / reputation-based blocking. Each of those controls is deliberately bypassed by a specific design decision in the modern chain.
|
STAGE |
WHY STANDARD CONTROLS MISS IT |
|
Phishing Email |
No payload to scan. Link points to a trusted cloud service — low-risk treatment by default. |
|
Redirect Chain |
Domains are freshly registered, recently compromised or carry no threat intel history. Sandbox windows exhausted before the final stage resolves. |
|
Dropper |
Obfuscated and polymorphic, bypasses static analysis thresholds. Memory-only execution leaves no file artifacts for endpoint scanners. |
|
Persistence |
Signed commercial software or native OS tooling. No detection mandate for legitimate RMM (Remote Monitoring and Management) installs. |
ClickFix: A Case Study in Evasion by Design
The ClickFix technique, observed across multiple campaigns tracked in 2025 and 2026, illustrates how effectively attackers are designing their methods to bypass security controls.
A lure page presents the victim with a fake verification prompt and writes a PowerShell command to the clipboard with no visible indication. The victim is instructed to open the Windows Run dialog, paste and press Enter. The victim is lead to believe they are resolving a display issue or completing an access check. The next command stage was encoded inside a DNS TXT record response and executed directly from memory.
|
NO FILE DROPPED — The payload existed only in a DNS TXT record response, executed in memory. No file written, no web request logged and no attachment delivered. |
|
NO HTTP REQUEST — The technique made zero outbound HTTP requests to retrieve a subsequent stage. Standard proxy and network logging had nothing to capture. |
|
ENGINEERED AROUND DETECTION REALITY — This worked not because of technical sophistication but because it was constructed around how detection actually operates — not how defenders assume it operates. |
Where KnowBe4 Can Help
No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, the ransomware deployment, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.
KnowBe4 Defend: Real-Time Behavioral AI
Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.
Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.
Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.
PhishER Plus: Automated Global Eradication
When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Labs.
Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.
Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.
The Threat Lives in the Sequence
Ransomware campaigns today do not surface as obviously dangerous at any individual stage. The email is unremarkable. The first redirect goes somewhere familiar. The dropper writes nothing to disk. The persistence mechanism is the software thatIT teams use themselves. Weeks later, from a different operator, after the environment has been mapped and the access positioned, the ransomware runs.
Each stage depends entirely on the previous one completing. The email has to reach the inbox, and the recipient has to act on it. Everything that follows traces back to that first delivery.
With KnowBe4’s PhishER Plus and Defend running, that first email is scrutinized as soon as it arrives. Defend helps to reveal it for what it is. PhishER Plus keeps other emails just like it from making it through. The bad actors never had a chance.
