Skip to content
Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft

Threat Actors Exploit Windows Shadow Copies for Ransomware and Credential Theft

First seen 15 Sep 2026, 16:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 17:55 UTC
  • Attackers exploit VSS to delete recovery options and steal credentials.
  • Common tools used include vssadmin.exe and diskshadow.exe.
  • MITRE ATT&CK tracks VSS abuse under Inhibit System Recovery.

Cybercriminals are increasingly abusing Microsoft’s Volume Shadow Copy Service (VSS) to facilitate ransomware attacks and steal credentials. They achieve this by deleting recovery options before deploying ransomware and extracting sensitive data from protected files, including the Active Directory database. Tools such as vssadmin.exe and diskshadow.exe are commonly used in these attacks, which fall under the MITRE ATT&CK tactic of Inhibit System Recovery. The misuse of VSS has prompted security experts to recommend that organizations treat VSS telemetry as critical behavior requiring context rather than routine maintenance. This shift in understanding is essential for effective detection and response strategies. The threat landscape includes various ransomware families known to exploit VSS, such as LockBit and Conti. Current security measures must evolve to address these sophisticated tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

Recent
Increased VSS abuse reported
Cybercriminals are using VSS for credential theft and ransomware, necessitating a shift in detection strategies.
cybernoz.com
Recent
Ransomware families identified
Ransomware groups like LockBit and Conti are known to exploit VSS for deleting shadow copies.
cybernoz.com
Recent
Shift in VSS telemetry understanding
Experts recommend treating VSS telemetry as critical behavior requiring context, not routine maintenance.
Huntress

More articles in this cluster (5)

Following this threat?

Track Akira in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed