TMCnet News
New Index Engines Research Finds Ransomware Variants Built to Evade Detection and Undermine RecoveryThe CyberSense Research Lab analysis of 1,064 ransomware strains finds directory destruction in more than twice as many variants as full encryption HOLMDEL, N.J., Sept. 30, 2026 /PRNewswire/ -- Index Engines the leader in cyber resilience, today announced its latest findings from its proprietary CyberSense® Research Lab (Patent #12248574) revealing a shift in ransomware behavior, with a growing share of analyzed variants using corruption techniques that avoid the traditional signs of obfuscation. "It destroyed files while leaving their names, sizes, timestamps, and entropy unchanged." Among 1,064 ransomware strains acquired and detonated during the first half of 2026, 47.8% exhibited directory-entry destruction, more than twice the 18.3% that exhibited full encryption. The lab also documented new ransomware designed to suppress familiar signs of corruption by preserving file extensions and timestamps, maintaining low entropy, encrypting slowly, and targeting only selected sections of files. "Bad actors know what scanning tools look for, and the variants we detonated this year are built to hide it," said Jim McGann, CMO of Index Engines. "Encoder is the clearest example. It destroyed files while leaving their names, sizes, timestamps, and entropy unchanged. A surface scan would report that data as clean. CyberSense caught it by analyzing the content and structure of each file. The Research Lab exists to find techniques like this early and build them into the model our customers rely on for recoery." The CyberSense Research Lab automates the ingestion and behavioral analysis of ransomware variants in a controlled environment, enabling continuous training of AI/ML models on real-world attack patterns and, enabling continuous training of AI/ML models on real ransomware behavior. The result is more comprehensive corruption detection that keeps pace with the threat landscape, backed by 99.99% ESG-validated accuracy, and smarter recovery decisions for organizations facing today's cyber criminals. Key findings* from the H1 2026 research include:
The research also found polymorphism at work in 64.7% of analyzed samples. These variants kept their functional code intact while regenerating their file signature between builds, so each new infection presented a fingerprint that signature-based tools have never previously seen. At the data layer, the Lab documented variants that used partial encryption, preserved or faked timestamps and low-entropy corruption to shrink the visible footprint of an attack. These techniques evade detection that depends on entropy spikes or bursts of encryption activity. "In our detonations, ransomware reached 10,000 files in about six minutes, which is faster than most Incident Response escalation paths," McGann added. "By the time a team moves to recovery, the question is which copy of the data can be trusted. CyberSense answers it with a forensic account of what was affected and pinpoints clean data to restore from." Access the full CyberSense Research Lab report at www.indexengines.com * Findings reflect variants acquired and detonated by the CyberSense Research Lab and are not an estimate of how often each technique appears in real-world attacks. Individual samples can exhibit multiple behaviors, so percentages reflect overlapping patterns. About Index Engines At Index Engines, we are experts in Cyber Resiliency, helping organizations build an infrastructure where trusted data is available and reliable. Our leading solution, CyberSense, provides a 99.99% SLA for detecting ransomware corruption. CyberSense empowers organizations to confidently navigate cyber challenges, mitigate risks, and quickly recover to normal business operations in the ever-evolving cyber landscape. For more information, visit www.indexengines.com.
SOURCE Index Engines
|
