Ground.News Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft
Article Content
- •Attackers exploit VSS to delete recovery options and steal credentials.
- •Common tools used include vssadmin.exe and diskshadow.exe.
- •MITRE ATT&CK tracks VSS abuse under Inhibit System Recovery.
Cybercriminals are increasingly abusing Microsoft’s Volume Shadow Copy Service (VSS) to facilitate ransomware attacks and steal credentials. They achieve this by deleting recovery options before deploying ransomware and extracting sensitive data from protected files, including the Active Directory database. Tools such as vssadmin.exe and diskshadow.exe are commonly used in these attacks, which fall under the MITRE ATT&CK tactic of Inhibit System Recovery. The misuse of VSS has prompted security experts to recommend that organizations treat VSS telemetry as critical behavior requiring context rather than routine maintenance. This shift in understanding is essential for effective detection and response strategies. The threat landscape includes various ransomware families known to exploit VSS, such as LockBit and Conti. Current security measures must evolve to address these sophisticated tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Akira in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Ransomware Attacks Target Multiple Companies in September 2026 In September 2026, multiple ransomware groups, including Booba Project and Panzer, launched attacks on various organizations. Atlas Ocean Voyages suffered a breach where 37 GB of sensitive data was stolen, while Cerámicas Kantu S.A.C. was threatened with data release unless negotiations occurred. The attacks highlight…