Earlier quoted context omitted.
Absolutely this - most ransomware attacks are pretty unsophisticated. You don't need privilege escalation, or an exploit. You can carry out the attack using just basic user permissions. You are exploiting a basic "problem" of most modern OSs (that apps run "as" the user executing them) - the user/group permission model ceases to work in 2021 with non-expert users. Portal-based access to individual files via secure OS…
> most ransomware attacks are pretty unsophisticated As weird as it sounds, this is both correct and incorrect at the same time. It is correct, because ransomware is not particularly sophisticated by today's standards. Couple of decades of R&D has made the building blocks robust and uninteresting. It is also correct in the sense that the attacks used to breach systems are unsophisticated. A vulnerability is published…
If it gets in through an access broker, you're definitely looking at a sophisticated outfit of attackers.
I guess I'm approaching this as the defender - if the malicious code isn't exploiting anything needing patched (other than decades-outdated assumptions of a threat model where any binary has the ability to act inseparably "as" the user), the actual ransomware is harder to prevent for most organisations, as all the friendly hand-holding type advice they receive from police and governments doesn't save them (patching desktop systems won't prevent the file encryptor payload from running on the first host, after a user runs the bogus docx.exe file and ignores warnings through alert fatigue).
It would be interesting if companies were more willing to (or required to) share details of ingress vectors, to understand the extent to which they're being breached through really advanced attacks involving reversing of recent patches, versus someone popping a pulsesecure VPN that's been warned about for years. Or on-prem Exchange that they've continued to ignore all the warnings about as nothing is on fire. Or just a user clicking a link to a shared file mistakenly emailed to them, called CONFIDENTIAL - PAY SCALE 2022, which phishes their SSO credentials for 365...