Malware Threat Actor Campaigns
Everything this module has covered so far, static and dynamic analysis, unpacking, injection and C2 tradecraft, YARA and Sigma detection, is a response to how real intrusions actually unfold. This chapter grounds that theory in patterns that have been reported, repeatedly and independently, across the security industry. It walks through the loader-to-ransomware pipeline, the reuse of a single commercial red-team framework by wildly different actors, and the operational business model behind modern ransomware, then draws out the tradecraft threads that connect all three.
Why Case Studies Matter After Six Chapters of Technique
Techniques in Isolation vs a Real Intrusion
It's possible to learn every technique in this module in isolation and still misjudge what a real intrusion looks like. Persistence mechanisms, process injection, and C2 beaconing (Chapter 5) each read as discrete, almost academic topics on their own. In practice, they show up bundled together, executed by different people, at different stages of the same intrusion, often with a commercial motive sitting underneath the technical detail. A phishing email doesn't just deliver a payload, it starts a chain of custody where the initial operator's job is to get a foothold and hand it off, not to finish the job themselves.
What a Purely Technical Read Misses
That handoff is the part a purely technical read of malware behavior tends to miss, and it's the part that matters most for a detection engineer trying to prioritize alerting. If the actor who gets initial access is rarely the actor who causes the most damage, then detecting and killing that initial foothold early is disproportionately valuable, because it denies every downstream actor in the chain their entry point at once. This chapter works through the publicly documented patterns that make that argument concrete: how a commodity loader family becomes an access broker's product, how a single legitimate red-team tool ends up in the hands of unrelated criminal and state actors, and how ransomware operators structure their business to scale intrusions across dozens of affiliates rather than running each one themselves.
The Loader-to-Ransomware Ecosystem
From Banking Trojan to Loader Platform
Emotet started life as a banking trojan, designed to steal financial credentials directly. Over time, and as widely reported by CISA and multiple security vendors, it evolved into something more valuable to the broader criminal ecosystem: a loader, a piece of malware whose primary job is not to cause damage itself but to get onto a machine quietly, establish persistence, and then download and execute whatever payload its operators (or their customers) decide to push next. TrickBot followed a similar arc, starting as banking malware and becoming one of the most widely reported loader platforms used to deliver follow-on payloads, including ransomware, onto compromised networks. Both have been named repeatedly in joint CISA advisories and vendor incident reports as infrastructure that other threat actors relied on rather than built themselves.
The Handoff Chain, as Reported
The distribution mechanism for both families has been consistently reported as phishing. What happens after initial execution is where the access broker model becomes visible in public reporting:
Why This Matters for Defenders
This separation between "who got in" and "who caused the damage" is the single most consequential structural fact in this chapter. It means the actor a defender's telemetry first catches is very often not the actor with the most damaging objective, and it means a loader infection that looks contained and low-severity at hour one can be the opening move of a ransomware event by hour forty-eight. Multiple vendor incident reports and CISA advisories describe exactly this pattern: a loader infection detected and, if not remediated quickly and completely, followed within days by ransomware deployment across the same environment.
Commodity C2 Frameworks Repurposed by Multiple, Unrelated Actors
Cobalt Strike: Legitimate Tool, Widely Abused
Cobalt Strike is a legitimate, commercially licensed red-team tool built for adversary simulation. It is also, by a wide margin, the most consistently reported post-exploitation command-and-control framework in cybercriminal and nation-state intrusions alike. CISA and multiple international partner agencies have issued joint advisories specifically addressing the widespread use of cracked, pirated copies of Cobalt Strike by threat actors who have no relationship to the legitimate red-team customers the tool was built for. Chapter 5's coverage of C2 beaconing patterns applies directly here: Cobalt Strike's default and customized beacon behavior has been documented and fingerprinted extensively precisely because so many unrelated actors rely on it.
The Attribution Problem
That widespread reuse creates a genuine analytic problem. If dozens of unrelated actors, ranging from financially motivated ransomware affiliates to state-sponsored operators, all use the same cracked commercial framework for C2, then finding Cobalt Strike beacon traffic or artifacts in an environment tells you almost nothing about who is behind the keyboard. Tooling overlap has repeatedly misled early attribution efforts across the industry, and the tradecraft discipline this chapter wants to reinforce is simple: tools don't equal actors. Shared infrastructure, shared malware families, and shared frameworks are useful indicators when correlated with other evidence, but on their own they are weak signal for attribution, and treating them as strong signal has produced public misattribution before.
The Detection Opportunity
For a detection engineer, the practical takeaway is the inverse of the attribution problem. Because Cobalt Strike is so heavily reused, it's one of the highest-value detection targets in this entire module. Building durable detection against its known process injection behaviors, named pipe patterns, and beacon jitter and sleep characteristics (all covered conceptually in Chapter 5) pays off against a huge share of the threat landscape at once, precisely because so many otherwise unrelated actors are relying on the same underlying tool rather than building custom C2 from scratch.
Ransomware Operational Patterns
Double Extortion
Modern ransomware operations are businesses, and the two structural features that show up across essentially the entire landscape, as reported by CISA and every major incident response vendor, are double extortion and the ransomware-as-a-service affiliate model. Double extortion pairs file encryption with a second threat: before locking files, the operators exfiltrate sensitive data and threaten to publish or sell it if the ransom isn't paid, which gives victims a reason to pay even if backups make recovery from encryption alone unnecessary. This pattern has been so consistently reported across ransomware families and victim organizations that it's now closer to the industry default than an exceptional tactic.
The RaaS Affiliate Model
The ransomware-as-a-service model separates the people who build and maintain the encryptor and negotiation infrastructure from the people who actually break into victim networks. A RaaS operator licenses their malware and support infrastructure to affiliates, who conduct the intrusions (often using exactly the loader-to-access-broker pipeline and Cobalt Strike C2 described earlier in this chapter) and split the ransom proceeds with the operator. This division of labor is well documented and explains why "the ransomware group" behind a given incident is frequently more accurately described as one affiliate operating under a shared brand, with meaningfully different tradecraft from another affiliate using the same encryptor.
The Conti and Babuk Leaks
Two leak events are worth naming specifically because they are genuinely, extensively documented and because they explain a visible trend in ransomware proliferation. Internal chat logs and a builder toolkit belonging to the Conti ransomware operation were leaked publicly, and separately, source code associated with the Babuk ransomware family was leaked as well. Both leaks have been widely reported and analyzed by security researchers. In the time since, multiple new ransomware families have been documented as derivative of, or directly built from, this leaked code and tooling, which is a big part of why the ransomware landscape has fragmented into so many named variants rather than consolidating around a small number of stable groups. Leaked, working ransomware infrastructure lowers the barrier to entry for a new affiliate or splinter group considerably.
| Pattern | Typical initial access | Typical objective | Defining tradecraft signature |
|---|---|---|---|
| Loader-to-ransomware handoff (Emotet, TrickBot) | Phishing document or link, macro-enabled execution | Establish and monetize a foothold, often sold or handed to another operator | Quiet beaconing loader followed, sometimes days later, by unrelated follow-on payload |
| Commodity C2 reuse (Cobalt Strike) | Varies by actor, delivered after initial foothold | Post-exploitation command and control, lateral movement staging | Cracked commercial framework used identically by unrelated actors |
| RaaS affiliate ransomware | Purchased or brokered access, phishing, exposed remote services | Extortion via encryption and data leak threat | Double extortion, encryptor licensed from a separate operator |
Common Threads Across These Campaigns
Laid side by side, a banking-trojan-turned-loader, a legitimate red-team framework gone commodity, and a ransomware business model look like three different problems. The tradecraft underneath them converges on the same handful of patterns often enough that it's worth naming explicitly, because these patterns are what a detection strategy should be built around, rather than any single named family's specific behavior.
Thread One: Access via Phishing or Brokered Foothold
Initial access is almost always phishing or a purchased and brokered foothold, not a novel exploit. Emotet and TrickBot both relied on getting a user to open a malicious document. Ransomware affiliates frequently buy access rather than develop it themselves. None of this depends on discovering a new vulnerability, which means vulnerability management, while necessary, is not the layer that stops the majority of what this chapter describes.
Thread Two: Commodity Tooling Over Custom Malware
There is a strong preference for widely available commodity tooling over fully custom malware. Cobalt Strike's reuse across unrelated actors is the clearest example, but the same logic applies to the living-off-the-land binaries covered in this site's LOLBAS module: using tools that are already present, trusted, or cheaply available is faster to deploy, easier to maintain, and blends into legitimate administrative activity far better than a bespoke tool an analyst has never seen before.
Thread Three: Specialization of Roles
The criminal ecosystem behind these campaigns is increasingly organized around distinct roles rather than one group doing everything end to end: access brokers who specialize in getting and selling footholds, loader operators who specialize in distribution and persistence, ransomware affiliates who specialize in the intrusion and deployment, and negotiators who specialize in extracting payment once extortion leverage exists. That specialization is exactly why the loader-to-ransomware handoff described earlier in this chapter is so consistently reported: it's not an accident of a single group's workflow, it's the natural result of a market where each role is more efficient when a specialist handles it.
Mapping These Patterns to ATT&CK
Turning the campaign patterns above into concrete detection coverage is the same discipline this site's Threat Intelligence module teaches with the ATT&CK Navigator coverage mapping exercise, applied here to malware campaign reporting instead of a single actor's profile. Each pattern in this chapter maps cleanly onto a broad technique category, and naming those categories, rather than guessing at specific technique IDs, is the safer and more durable way to do this mapping.
| Pattern | ATT&CK Category | Why |
|---|---|---|
| Loader-to-ransomware handoff | Initial Access, then Persistence | Phishing and user execution of a malicious attachment or link get the foothold; the loader then establishes persistence it can hand off later |
| Widespread reuse of Cobalt Strike | Command and Control | Application-layer C2 through a shared, commercially available framework; a mapping built entirely around Cobalt Strike artifacts covers many actors at once but should never be read as evidence of who any one of them is |
| Ransomware double extortion | Impact | Covers both data encrypted for impact and the exfiltration techniques that feed the data-leak side of the extortion threat |
The exercise itself is what matters more than memorizing any single mapping. Take a piece of credible reporting, whether it's a CISA advisory on Emotet or TrickBot, a joint advisory on cracked Cobalt Strike usage, or a vendor writeup on a Conti-derived ransomware family, extract the technique categories it describes, and check that against your own environment's detection coverage. Where there's no query, no alert, and no documented visibility gap for a given category, that's the finding worth acting on, and it's a more durable output than trying to track every individually named actor this chapter or any single report happens to mention.
Key Takeaways
- Loader families like Emotet and TrickBot, both extensively documented by CISA and multiple vendors, illustrate the access broker business model: a phishing-delivered foothold gets established, then sold or handed off to a separate operator, often a ransomware affiliate, rather than monetized directly.
- Cobalt Strike, a legitimate commercial red-team tool, has been widely reported as cracked and reused for post-exploitation C2 by numerous unrelated criminal and nation-state actors, which makes shared tooling a weak basis for attribution on its own even though it's a high-value detection target.
- Double extortion (encrypting data while also threatening to leak it) and the ransomware-as-a-service affiliate model, where an operator licenses malware and infrastructure to affiliates who run the actual intrusions, are both well-documented structural features of the modern ransomware business.
- The Conti chat and builder leaks and the Babuk source code leak are extensively documented public events, and both have been followed by derivative ransomware families built on the leaked code, lowering the barrier to entry for new affiliates and splinter groups.
- Across all of these examples, the common threads are phishing or brokered access rather than novel exploits, a strong preference for commodity tooling over custom malware, and increasing specialization of roles across the criminal ecosystem.
- Mapping these patterns to ATT&CK's Initial Access, Command and Control, and Impact categories converts campaign reporting into testable detection coverage decisions, the same discipline taught elsewhere in this site's Threat Intelligence module.
Knowledge Check
Click an answer to reveal the explanation.
In the widely reported loader-to-ransomware pattern involving families like Emotet and TrickBot, why does a detected and removed loader infection not necessarily mean the incident is over?
Cobalt Strike has been widely reported as reused by many unrelated criminal and nation-state actors. What does this widespread reuse mean for attribution?
What is the ransomware-as-a-service (RaaS) affiliate model, and why does it complicate treating a ransomware family name as a stable proxy for a single consistent group?