Skip to main content

Ransomware Shifts to Directory Destruction, Bypassing 47.8% of Scans

Image
Ransomware Shifts to Directory Destruction, Bypassing 47.8% of Scans

Holmdel, N.J. – September 30, 2026 -- Index Engines' CyberSense Research Lab found that 47.8% of 1,064 ransomware strains detonated in the first half of 2026 relied on directory-entry destruction, more than double the 18.3% that used full encryption, marking a shift away from techniques that trigger standard security scans.

Attackers now suppress the telltale signs security tools rely on

The lab documented new ransomware built to preserve file extensions and timestamps, maintain low entropy, and encrypt only selected sections of files slowly enough to avoid detection thresholds. One variant, Encoder, destroyed file content while leaving names, sizes, timestamps, and entropy readings unchanged, according to Jim McGann, CMO of Index Engines. A surface scan would report that data as clean, McGann said, while CyberSense identified the corruption by analyzing file content and structure directly.

Attack velocity outpaces typical incident-response timelines

Detonations in the controlled lab environment showed a median attack velocity of approximately 97,321 files corrupted per hour, with ransomware reaching 10,000 corrupted files in roughly six minutes. McGann noted this speed exceeds most incident-response escalation paths, leaving recovery teams to determine which data copy remains trustworthy once containment begins.

Polymorphism appeared in nearly two-thirds of samples analyzed

The Lab found polymorphic behavior in 64.7% of analyzed strains, where functional code stayed intact while file signatures regenerated between builds. Each new infection produced a fingerprint that signature-based detection tools had not previously encountered, undermining a core assumption behind traditional antivirus and endpoint scanning.

AI has not yet reached the destructive payload stage, lab finds

None of the 1,064 strains showed AI making decisions at the point of data destruction. Citing separate industry research from Palo Alto Networks and ReliaQuest, Index Engines placed AI's current footprint earlier in the attack lifecycle, where it compresses reconnaissance and lateral-movement phases rather than the corruption itself.

Findings push organizations toward data validation before recovery

As ransomware moves beyond encryption and suppresses corruption signals such as entropy spikes and altered timestamps, data that appears unaffected may not be clean, the report concluded. Index Engines said organizations need to validate data integrity before trusting it for recovery, a capability the CyberSense Research Lab feeds into its AI/ML models trained on real-world attack patterns, backed by a claimed 99.99% ESG-validated accuracy rate.

Published by
fairsonline_team
Products
News Type