From Inbox to Encryption: How Ransomware Delivery Has Evolved

KnowBe4 Threat Lab | Jul 23, 2026

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours.

What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker.

So, what can organizations do to protect themselves from these new threats? In this report from the KnowBe4 Threat Labs team, you will be able to:

  • Identify the infrastructure patterns defining 2025-2026 ransomware campaigns.
  • Map the critical stages that separate the initial email from the final encryption event.
  • Understand the mechanics of the "ClickFix" technique and why modern threats are designed specifically to evade your current security controls.

How Has Ransomware Delivery Evolved?: A Timeline

Every shift in delivery method was a direct response to whatever controls had just become effective against the previous approach. In 2019 an internationally coordinated effort took down the Necurs botnet, a criminal infrastructure responsible for 90% of email-based malware. This disruption of the world’s largest botnet, with the loss of 9 million infected nodes, is the clearest inflection point: until then, volume was the strategy. Once that infrastructure was disrupted and security products had matured to catch direct attachment delivery, the economics changed. Operators moved to precision targeting and multi-stage chains where the email carries nothing dangerous itself.

PERIOD

ACTOR / CAMPAIGN

WHAT CHANGED

Early 2000s

GPCode ransomware

Spear phishing with trojans disguised as job applications. First documented use of phishing as a ransomware delivery vector.

2007 onwards

Evil Corp / Dridex

Cridex banking trojan via phishing, evolved into modular Dridex. Introduced the rentable malware model: operators and affiliates begin to separate.

Mid-2010s

Locky / Necurs botnet

Up to 23 million phishing emails per 24-hour period across ~120,000 IPs in 139 country-code TLDs. Industrialised phishing at botnet scale.

2019

Necurs takedown

Microsoft and 35 law enforcement agencies dismantle Necurs. Forces transition away from high-volume direct-payload delivery.

2025-2026

Multiple groups incl. access brokers

Multi-hop redirect chains, fileless droppers, RMM tools for persistence, DNS-based staging. Phishing operators and ransomware operators are now separate commercial parties.

What Ransomware Infrastructure Patterns Arose Between 2025-2026?

Threat Labs monitoring across this period revealed six consistent infrastructure patterns across diverse campaigns, regardless of varying lures or payloads. Each pattern maps directly to a control that had become effective against the previous approach.

Trusted First Hops: Attackers route through Google Drive, Dropbox, Slack and GitHub as first-hop redirect points. Links to these platforms appear trustworthy to the user and receive low-risk treatment from security products.

Seasoned Domain Redirects: The redirect chain leverages compromised or parked domains that have maintained clean reputation for a longer period of time, which affects blocklisting. This provides the attacker with a clear delivery window. Multistage redirect chains also exhaust the analysis timeframes of automated sandbox analysis.

Traceless Payloads: Droppers prioritize evasion through layered obfuscation and polymorphic signatures. Some campaigns use built-in Windows utilities like Certutil to stage payloads directly in process memory, bypassing the filesystem entirely. This means no detectable files remain for malware scanners.

Purchased Access: Ransomware operators treat access as a commodity rather than building it themselves. They procure established, valid credentials and pre-compromised infrastructures from underground markets, allowing them to bypass initial intrusion phases and pivot directly to malware deployment.

RMM for Persistence: Persistence is achieved using legitimate, signed commercial remote management tools. These blend into routine network traffic and IT environments, making unauthorized installations difficult to identify without specific environment baselines.

Separated Operators: Phishing and ransomware operations are often distinct commercial entities. One actor specializes in securing the initial foothold, which is then traded to a different ransomware operator. This ensures that the final payload deployment is decoupled from the original email by a discrete financial transaction between parties.

How The Ransomware Chains Actually Run

The common infrastructure patterns of the last year share a common thread: the inbox as an entry point. The phishing email carries a call-to-action or attachment whose only function is the first redirect. There is no payload in it. From that redirect, the victim moves through cloud platforms and then through domains with degraded or no reputation signal before reaching infrastructure the attacker controls.

Here are the five stages of a typical ransomware attack chain:

 

STAGE 1 -- PHISHING EMAIL

The mail arrives as a subtle, time-sensitive lure. There’s no payload here, just a link to a trusted cloud service that slides past security filters unnoticed. It’s a lure designed to look completely harmless.

 

STAGE 2 -- REDIRECT CHAIN

A click initiates multi-hop routing through trusted cloud platforms and seasoned domains to evade suspicion. This exhausts sandbox analysis time before the malicious destination is reached.

 

STAGE 3 -- DROPPER DELIVERY

Now the trap snaps shut. A small, shape-shifting dropper sneaks into the machine’s memory entirely to avoid file scanners. It performs a silent check to ensure it is not being monitored, then confirms the target before communicating with the attacker.

 

STAGE 4 -- RECONNAISSANCE

Now inside, the ransomware operator scouts for high-value data and critical systems. They quietly map the network, positioning the ransomware to prepare for a single, synchronized strike.

 

STAGE 5 -- RANSOMWARE DEPLOYMENT

As long as a few weeks after the initial email, the final act plays out. A different operator takes the keys they’ve bought and deploys the ransomware. The environment is already mapped and defenses are already compromised, and the encryption begins.

Where Standard Controls Do Not Reach

Each stage in this chain occupies a gap that controls designed for the previous generation of attacks were never built to address. The older approach was stopped by SEGs running detonation environments, endpoint products accumulating dropper signatures and hash-based / reputation-based blocking. Each of those controls is deliberately bypassed by a specific design decision in the modern chain.

STAGE

WHY STANDARD CONTROLS MISS IT

Phishing Email

No payload to scan. Link points to a trusted cloud service — low-risk treatment by default.

Redirect Chain

Domains are freshly registered, recently compromised or carry no threat intel history. Sandbox windows exhausted before the final stage resolves.

Dropper

Obfuscated and polymorphic, bypasses static analysis thresholds. Memory-only execution leaves no file artifacts for endpoint scanners.

Persistence

Signed commercial software or native OS tooling. No detection mandate for legitimate RMM (Remote Monitoring and Management) installs.

ClickFix: A Case Study in Evasion by Design

The ClickFix technique, observed across multiple campaigns tracked in 2025 and 2026, illustrates how effectively attackers are designing their methods to bypass security controls.

A lure page presents the victim with a fake verification prompt and writes a PowerShell command to the clipboard with no visible indication. The victim is instructed to open the Windows Run dialog, paste and press Enter. The victim is lead to believe they are resolving a display issue or completing an access check. The next command stage was encoded inside a DNS TXT record response and executed directly from memory.

NO FILE DROPPED — The payload existed only in a DNS TXT record response, executed in memory. No file written, no web request logged and no attachment delivered.

NO HTTP REQUEST — The technique made zero outbound HTTP requests to retrieve a subsequent stage. Standard proxy and network logging had nothing to capture.

ENGINEERED AROUND DETECTION REALITY — This worked not because of technical sophistication but because it was constructed around how detection actually operates — not how defenders assume it operates.

Where KnowBe4 Can Help

No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, the ransomware deployment, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.

KnowBe4 Defend: Real-Time Behavioral AI

Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.

Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.

Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.

PhishER Plus: Automated Global Eradication

When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Labs.

Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.

Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.

The Threat Lives in the Sequence

Ransomware campaigns today do not surface as obviously dangerous at any individual stage. The email is unremarkable. The first redirect goes somewhere familiar. The dropper writes nothing to disk. The persistence mechanism is the software thatIT teams use themselves. Weeks later, from a different operator, after the environment has been mapped and the access positioned, the ransomware runs.

Each stage depends entirely on the previous one completing. The email has to reach the inbox, and the recipient has to act on it. Everything that follows traces back to that first delivery.

With KnowBe4’s PhishER Plus and Defend running, that first email is scrutinized as soon as it arrives. Defend helps to reveal it for what it is. PhishER Plus keeps other emails just like it from making it through. The bad actors never had a chance.

FAQs

What makes 2025-2026 ransomware delivery different from earlier attacks?

Earlier ransomware campaigns embedded the payload directly in a phishing email, so encryption followed within hours of the click. Modern campaigns separate the phishing operator from the ransomware operator, routing victims through trusted cloud platforms and seasoned domains before any malicious code appears — often weeks after the initial email.

Why do standard security controls miss these ransomware chains?

Each stage is designed around a specific control's blind spot: the email carries no payload to scan, the dropper runs in memory with no file for endpoint scanners to catch, and persistence relies on legitimate signed RMM tools. Because no single stage looks overtly malicious, signature- and reputation-based defenses have nothing conclusive to flag.

What is the ClickFix technique?

ClickFix is a social engineering method where a fake verification page tricks a user into pasting a malicious PowerShell command into the Windows Run dialog themselves. Because the payload can be staged via a DNS TXT record and executed from memory, it generates no file artifact and no outbound HTTP request for security tools to log.

How long is the gap between the initial phishing email and ransomware deployment?

In campaigns tracked through 2025-2026, the gap can run as long as a few weeks. During that window a different operator — one who purchased the compromised access — maps the network and positions the ransomware before triggering a single synchronized encryption event.

How can organizations defend against multi-stage ransomware delivery?

Because every chain depends on the initial email reaching an inbox and being acted on, stopping it there is the highest-leverage control. Tools like KnowBe4 Defend analyze behavioral and language patterns before a user clicks, while PhishER Plus uses a global threat feed to block matching indicators across all connected environments once one organization reports them.

See KnowBe4 Defend™ in Action

Learn how Defend™ strategically enhances Microsoft 365's native security to catch the threats Secure Email Gateways (SEGs) miss.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.