CHAPTER 07 35 MIN READ ADVANCED

Malware Threat Actor Campaigns

Everything this module has covered so far, static and dynamic analysis, unpacking, injection and C2 tradecraft, YARA and Sigma detection, is a response to how real intrusions actually unfold. This chapter grounds that theory in patterns that have been reported, repeatedly and independently, across the security industry. It walks through the loader-to-ransomware pipeline, the reuse of a single commercial red-team framework by wildly different actors, and the operational business model behind modern ransomware, then draws out the tradecraft threads that connect all three.

loader ecosystems ransomware case studies

Why Case Studies Matter After Six Chapters of Technique

Techniques in Isolation vs a Real Intrusion

It's possible to learn every technique in this module in isolation and still misjudge what a real intrusion looks like. Persistence mechanisms, process injection, and C2 beaconing (Chapter 5) each read as discrete, almost academic topics on their own. In practice, they show up bundled together, executed by different people, at different stages of the same intrusion, often with a commercial motive sitting underneath the technical detail. A phishing email doesn't just deliver a payload, it starts a chain of custody where the initial operator's job is to get a foothold and hand it off, not to finish the job themselves.

What a Purely Technical Read Misses

That handoff is the part a purely technical read of malware behavior tends to miss, and it's the part that matters most for a detection engineer trying to prioritize alerting. If the actor who gets initial access is rarely the actor who causes the most damage, then detecting and killing that initial foothold early is disproportionately valuable, because it denies every downstream actor in the chain their entry point at once. This chapter works through the publicly documented patterns that make that argument concrete: how a commodity loader family becomes an access broker's product, how a single legitimate red-team tool ends up in the hands of unrelated criminal and state actors, and how ransomware operators structure their business to scale intrusions across dozens of affiliates rather than running each one themselves.

Note: Every named example in this chapter, Emotet, TrickBot, Cobalt Strike, the Conti and Babuk leaks, is chosen specifically because it is widely and repeatedly documented across independent vendor reporting and government advisories, not because it is the most dramatic or recent incident available. Where this chapter describes a pattern rather than a single event, that's deliberate: the pattern is the well-established part, and inventing specific dates or dollar figures around it would add false precision rather than useful detail.

The Loader-to-Ransomware Ecosystem

From Banking Trojan to Loader Platform

Emotet started life as a banking trojan, designed to steal financial credentials directly. Over time, and as widely reported by CISA and multiple security vendors, it evolved into something more valuable to the broader criminal ecosystem: a loader, a piece of malware whose primary job is not to cause damage itself but to get onto a machine quietly, establish persistence, and then download and execute whatever payload its operators (or their customers) decide to push next. TrickBot followed a similar arc, starting as banking malware and becoming one of the most widely reported loader platforms used to deliver follow-on payloads, including ransomware, onto compromised networks. Both have been named repeatedly in joint CISA advisories and vendor incident reports as infrastructure that other threat actors relied on rather than built themselves.

The Handoff Chain, as Reported

The distribution mechanism for both families has been consistently reported as phishing. What happens after initial execution is where the access broker model becomes visible in public reporting:

1
Phishing Delivery
A malicious document or link, often disguised as an invoice, shipping notice, or reply to an existing email thread, gets a user to enable macros or run an attachment.
→
2
Loader Executes and Beacons
The loader's job is done in the narrow sense: it has a beacon calling home and sits quietly gathering information about the compromised host and network.
→
3
Access Sold or Handed Off
The operators running the loader, or a separate group that purchases access from them, sell or hand off the established foothold to a different actor entirely.
→
4
Ransomware Deployment
Typically the receiving actor runs ransomware, often within days of the original loader infection.

Why This Matters for Defenders

This separation between "who got in" and "who caused the damage" is the single most consequential structural fact in this chapter. It means the actor a defender's telemetry first catches is very often not the actor with the most damaging objective, and it means a loader infection that looks contained and low-severity at hour one can be the opening move of a ransomware event by hour forty-eight. Multiple vendor incident reports and CISA advisories describe exactly this pattern: a loader infection detected and, if not remediated quickly and completely, followed within days by ransomware deployment across the same environment.

Warning: Treating a detected loader infection as a fully resolved incident once the initial payload is removed is a common and costly mistake. If a loader has been present long enough to beacon out and potentially hand off access, remediation needs to assume that credentials, network maps, or persistence mechanisms may already be in a broker's or a ransomware affiliate's hands, not just that one malicious file has been deleted.

Commodity C2 Frameworks Repurposed by Multiple, Unrelated Actors

Cobalt Strike: Legitimate Tool, Widely Abused

Cobalt Strike is a legitimate, commercially licensed red-team tool built for adversary simulation. It is also, by a wide margin, the most consistently reported post-exploitation command-and-control framework in cybercriminal and nation-state intrusions alike. CISA and multiple international partner agencies have issued joint advisories specifically addressing the widespread use of cracked, pirated copies of Cobalt Strike by threat actors who have no relationship to the legitimate red-team customers the tool was built for. Chapter 5's coverage of C2 beaconing patterns applies directly here: Cobalt Strike's default and customized beacon behavior has been documented and fingerprinted extensively precisely because so many unrelated actors rely on it.

The Attribution Problem

That widespread reuse creates a genuine analytic problem. If dozens of unrelated actors, ranging from financially motivated ransomware affiliates to state-sponsored operators, all use the same cracked commercial framework for C2, then finding Cobalt Strike beacon traffic or artifacts in an environment tells you almost nothing about who is behind the keyboard. Tooling overlap has repeatedly misled early attribution efforts across the industry, and the tradecraft discipline this chapter wants to reinforce is simple: tools don't equal actors. Shared infrastructure, shared malware families, and shared frameworks are useful indicators when correlated with other evidence, but on their own they are weak signal for attribution, and treating them as strong signal has produced public misattribution before.

The Detection Opportunity

For a detection engineer, the practical takeaway is the inverse of the attribution problem. Because Cobalt Strike is so heavily reused, it's one of the highest-value detection targets in this entire module. Building durable detection against its known process injection behaviors, named pipe patterns, and beacon jitter and sleep characteristics (all covered conceptually in Chapter 5) pays off against a huge share of the threat landscape at once, precisely because so many otherwise unrelated actors are relying on the same underlying tool rather than building custom C2 from scratch.

Tip: When a Sigma or YARA rule (Chapter 6) targets Cobalt Strike behavior rather than a specific actor's custom malware, it's implicitly getting coverage against every group using cracked or leaked copies of the framework, which is a large and constantly shifting population. That's a strong argument for prioritizing detection against widely reused commodity tooling over chasing bespoke signatures for a single named actor.

Ransomware Operational Patterns

Double Extortion

Modern ransomware operations are businesses, and the two structural features that show up across essentially the entire landscape, as reported by CISA and every major incident response vendor, are double extortion and the ransomware-as-a-service affiliate model. Double extortion pairs file encryption with a second threat: before locking files, the operators exfiltrate sensitive data and threaten to publish or sell it if the ransom isn't paid, which gives victims a reason to pay even if backups make recovery from encryption alone unnecessary. This pattern has been so consistently reported across ransomware families and victim organizations that it's now closer to the industry default than an exceptional tactic.

The RaaS Affiliate Model

The ransomware-as-a-service model separates the people who build and maintain the encryptor and negotiation infrastructure from the people who actually break into victim networks. A RaaS operator licenses their malware and support infrastructure to affiliates, who conduct the intrusions (often using exactly the loader-to-access-broker pipeline and Cobalt Strike C2 described earlier in this chapter) and split the ransom proceeds with the operator. This division of labor is well documented and explains why "the ransomware group" behind a given incident is frequently more accurately described as one affiliate operating under a shared brand, with meaningfully different tradecraft from another affiliate using the same encryptor.

The Conti and Babuk Leaks

Two leak events are worth naming specifically because they are genuinely, extensively documented and because they explain a visible trend in ransomware proliferation. Internal chat logs and a builder toolkit belonging to the Conti ransomware operation were leaked publicly, and separately, source code associated with the Babuk ransomware family was leaked as well. Both leaks have been widely reported and analyzed by security researchers. In the time since, multiple new ransomware families have been documented as derivative of, or directly built from, this leaked code and tooling, which is a big part of why the ransomware landscape has fragmented into so many named variants rather than consolidating around a small number of stable groups. Leaked, working ransomware infrastructure lowers the barrier to entry for a new affiliate or splinter group considerably.

PatternTypical initial accessTypical objectiveDefining tradecraft signature
Loader-to-ransomware handoff (Emotet, TrickBot)Phishing document or link, macro-enabled executionEstablish and monetize a foothold, often sold or handed to another operatorQuiet beaconing loader followed, sometimes days later, by unrelated follow-on payload
Commodity C2 reuse (Cobalt Strike)Varies by actor, delivered after initial footholdPost-exploitation command and control, lateral movement stagingCracked commercial framework used identically by unrelated actors
RaaS affiliate ransomwarePurchased or brokered access, phishing, exposed remote servicesExtortion via encryption and data leak threatDouble extortion, encryptor licensed from a separate operator
Note: Avoid treating a ransomware family name as a stable proxy for a single group with consistent behavior. Between the affiliate model, which puts different people behind the same encryptor, and leaked builder code, which lets unrelated actors stand up derivative families, the name on the ransom note is often the least reliable part of the incident for attribution purposes.

Common Threads Across These Campaigns

Laid side by side, a banking-trojan-turned-loader, a legitimate red-team framework gone commodity, and a ransomware business model look like three different problems. The tradecraft underneath them converges on the same handful of patterns often enough that it's worth naming explicitly, because these patterns are what a detection strategy should be built around, rather than any single named family's specific behavior.

Thread One: Access via Phishing or Brokered Foothold

Initial access is almost always phishing or a purchased and brokered foothold, not a novel exploit. Emotet and TrickBot both relied on getting a user to open a malicious document. Ransomware affiliates frequently buy access rather than develop it themselves. None of this depends on discovering a new vulnerability, which means vulnerability management, while necessary, is not the layer that stops the majority of what this chapter describes.

Thread Two: Commodity Tooling Over Custom Malware

There is a strong preference for widely available commodity tooling over fully custom malware. Cobalt Strike's reuse across unrelated actors is the clearest example, but the same logic applies to the living-off-the-land binaries covered in this site's LOLBAS module: using tools that are already present, trusted, or cheaply available is faster to deploy, easier to maintain, and blends into legitimate administrative activity far better than a bespoke tool an analyst has never seen before.

Thread Three: Specialization of Roles

The criminal ecosystem behind these campaigns is increasingly organized around distinct roles rather than one group doing everything end to end: access brokers who specialize in getting and selling footholds, loader operators who specialize in distribution and persistence, ransomware affiliates who specialize in the intrusion and deployment, and negotiators who specialize in extracting payment once extortion leverage exists. That specialization is exactly why the loader-to-ransomware handoff described earlier in this chapter is so consistently reported: it's not an accident of a single group's workflow, it's the natural result of a market where each role is more efficient when a specialist handles it.

Tip: All three threads point toward the same conclusion: detection investment aimed at the handoff points, the loader's initial beacon, the commodity C2 framework's known behaviors, and the earliest signs of encryptor staging, catches a disproportionate share of this activity precisely because so many otherwise unrelated actors rely on the same small set of chokepoints to move from access to impact.

Mapping These Patterns to ATT&CK

Turning the campaign patterns above into concrete detection coverage is the same discipline this site's Threat Intelligence module teaches with the ATT&CK Navigator coverage mapping exercise, applied here to malware campaign reporting instead of a single actor's profile. Each pattern in this chapter maps cleanly onto a broad technique category, and naming those categories, rather than guessing at specific technique IDs, is the safer and more durable way to do this mapping.

PatternATT&CK CategoryWhy
Loader-to-ransomware handoffInitial Access, then PersistencePhishing and user execution of a malicious attachment or link get the foothold; the loader then establishes persistence it can hand off later
Widespread reuse of Cobalt StrikeCommand and ControlApplication-layer C2 through a shared, commercially available framework; a mapping built entirely around Cobalt Strike artifacts covers many actors at once but should never be read as evidence of who any one of them is
Ransomware double extortionImpactCovers both data encrypted for impact and the exfiltration techniques that feed the data-leak side of the extortion threat

The exercise itself is what matters more than memorizing any single mapping. Take a piece of credible reporting, whether it's a CISA advisory on Emotet or TrickBot, a joint advisory on cracked Cobalt Strike usage, or a vendor writeup on a Conti-derived ransomware family, extract the technique categories it describes, and check that against your own environment's detection coverage. Where there's no query, no alert, and no documented visibility gap for a given category, that's the finding worth acting on, and it's a more durable output than trying to track every individually named actor this chapter or any single report happens to mention.

Note: This chapter deliberately avoids citing specific ATT&CK technique IDs. The technique categories named here (phishing-based Initial Access, framework-based Command and Control, encryption and exfiltration-based Impact) are stable and safe to state with confidence. Specific T-numbers change and get revised across ATT&CK versions, and getting one wrong in training material is a worse outcome than describing the category accurately and pointing you to look the current ID up yourself.

Key Takeaways

  • Loader families like Emotet and TrickBot, both extensively documented by CISA and multiple vendors, illustrate the access broker business model: a phishing-delivered foothold gets established, then sold or handed off to a separate operator, often a ransomware affiliate, rather than monetized directly.
  • Cobalt Strike, a legitimate commercial red-team tool, has been widely reported as cracked and reused for post-exploitation C2 by numerous unrelated criminal and nation-state actors, which makes shared tooling a weak basis for attribution on its own even though it's a high-value detection target.
  • Double extortion (encrypting data while also threatening to leak it) and the ransomware-as-a-service affiliate model, where an operator licenses malware and infrastructure to affiliates who run the actual intrusions, are both well-documented structural features of the modern ransomware business.
  • The Conti chat and builder leaks and the Babuk source code leak are extensively documented public events, and both have been followed by derivative ransomware families built on the leaked code, lowering the barrier to entry for new affiliates and splinter groups.
  • Across all of these examples, the common threads are phishing or brokered access rather than novel exploits, a strong preference for commodity tooling over custom malware, and increasing specialization of roles across the criminal ecosystem.
  • Mapping these patterns to ATT&CK's Initial Access, Command and Control, and Impact categories converts campaign reporting into testable detection coverage decisions, the same discipline taught elsewhere in this site's Threat Intelligence module.

Knowledge Check

Click an answer to reveal the explanation.

In the widely reported loader-to-ransomware pattern involving families like Emotet and TrickBot, why does a detected and removed loader infection not necessarily mean the incident is over?

The access broker model separates who gets the initial foothold from who causes the eventual damage. If a loader has been present long enough to beacon out, credentials, network information, or persistence mechanisms may already be in another actor's hands, so remediation needs to assume a broader compromise rather than treating removal of the loader file as a complete resolution.

Cobalt Strike has been widely reported as reused by many unrelated criminal and nation-state actors. What does this widespread reuse mean for attribution?

Tooling overlap has repeatedly misled early attribution efforts across the security industry precisely because a shared framework like Cobalt Strike gets used by financially motivated criminal groups and state-sponsored operators alike. The tradecraft discipline is "tools don't equal actors": shared infrastructure is useful when correlated with other evidence, but weak signal on its own, even though building detection against its known behaviors still pays off broadly.

What is the ransomware-as-a-service (RaaS) affiliate model, and why does it complicate treating a ransomware family name as a stable proxy for a single consistent group?

Under the RaaS model, the people who build and maintain the ransomware and negotiation infrastructure are frequently different from the people who break into victim networks and deploy it. Affiliates split proceeds with the operator, and because different affiliates bring different intrusion tradecraft to the same shared encryptor and brand, the ransomware family name on a ransom note is often the least reliable part of an incident for identifying who is actually behind it.