Threat Intelligence Briefing
Remote Encryption Ransomware on Unmanaged Devices
One unmanaged device. Full network encryption. Zero code on the file server.
- of successful ransomware attacks use remote encryption Microsoft, 2024
- 70%
- of those originate from an unmanaged device Microsoft, 2024
- 92%
- rise in remote encryption attacks from 2024 to 2025 Sophos, 2025
- +55%
Bottom Line
Remote encryption means running the ransomware payload on an unmanaged device and reaching across the network to encrypt files on protected servers. Microsoft's 2024 Digital Defense Report found it in 70% of successful ransomware attacks, with 92% originating from unmanaged devices on the network, up from 60% and 80% a year earlier.[1][2] Sophos telemetry shows remote encryption attacks rose 50% from 2023 to 2024 and another 55% from 2024 to 2025.[1]
Attackers run the encryptor from a webcam, printer, IoT sensor, or unpatched laptop and encrypt shared files over SMB. The malicious process runs only on that device, and most endpoint security tools aren't built to watch for this.[3][6]
How the Attack Works
-
Reconnaissance
The attacker scans the network for unmanaged IP devices (cameras, printers, IoT sensors, unpatched servers) with weak or default credentials and out-of-date firmware.
-
Initial access
The attacker exploits the device directly and gains a remote shell. With no EDR agent on the device, no alert fires.
-
Staging
The compromised device becomes an operating platform, often running a Linux-based encryptor built for lightweight IoT operating systems.
-
Credential and share discovery
From that foothold, the attacker enumerates network shares and harvests or reuses credentials with write access to file servers.
-
Remote encryption
The encryptor runs on the unmanaged device and rewrites files on the protected servers’ shares over SMB. The ransomware binary never executes on the protected machine.
-
Escalation
The same remote access is often used to delete backups and push the encryptor to additional shares, and may be paired with prior data exfiltration for double extortion.
Where the Attack Gets Stopped
The encryptor runs on the unmanaged device, but it still has to write the encrypted files to the server. RansomSnare blocks those writes.
With EDR alone
Unmanaged device
Encryptor runs here
Encrypted writes over SMB
File server
Files encrypted
EDR looks for a ransomware process on the server. None ever runs there, so nothing alerts.
With RansomSnare on the server
Unmanaged device
Encryptor runs here
Encrypted writes over SMB
File server
Write blocked
RansomSnare inspects the files being written. They are encrypted, and the machine sending them has no RansomSnare to confirm the process is trusted, so the write is blocked.
Why Unmanaged Devices Are the Vector
EDR and antivirus tools were built for conventional operating systems: an installable agent, regular patch cycles, and enough compute to run one. IP cameras, printers, IoT sensors, and older OT/SCADA equipment often meet none of those conditions. They run proprietary or lightweight Linux firmware, are rarely patched, and frequently keep factory-default credentials.[5]
These devices also typically sit outside Active Directory and any centralized identity or patch management, so they are invisible to the tools that would otherwise flag anomalous behavior. That combination of network connectivity and zero agent coverage makes them an ideal beachhead: an attacker who can't get a foothold on a hardened server can usually find one unmanaged device that will let them in.
Scale and Impact
Remote encryption dates back to at least 2013 (CryptoLocker) and is now used by multiple major ransomware operations.[3] Select one to see how it has used the technique.
Case study · Reported by S-RM, March 2025
Akira’s IP webcam attack
After EDR blocked Akira’s Windows encryptor, the group scanned the network and found an unsecured IP webcam running outdated firmware with no EDR support. They gained remote shell access to it and deployed a Linux-based encryptor from the camera. Files across the network were encrypted over SMB, completely bypassing the EDR that had stopped the first attempt.[4][5]
Documented by Unit 42, October 2023
A hidden virtual machine as the launch point
BlackCat’s Munchkin utility arrives as an ISO of a customised Alpine Linux, loaded into a freshly installed VirtualBox instance on a compromised host. From inside that virtual machine, which the host’s antivirus has no view into, operators run BlackCat against remote machines or encrypt remote SMB and CIFS shares, using victim credentials stored in its configuration.[7]
Reported by CrowdStrike, July 2025
Unmanaged systems as standard practice
CrowdStrike reports that WANDERING SPIDER, the group behind Black Basta, has been observed accessing unmanaged systems to remotely encrypt files over SMB shares. It describes access to unmanaged systems as central to big game hunting ransomware operations throughout 2024.[6][13]
Documented by CISA, FBI and NSA, October 2021
Every share encrypted from one host
Using embedded, previously compromised credentials, BlackMatter queries Active Directory over LDAP and SMB to discover every host, then enumerates each one for accessible shares. It remotely encrypts the contents of all the shares it finds over SMB from the original compromised host. Backup stores are wiped or reformatted instead of being encrypted.[8]
Case study · The DFIR Report, February 2025
Two hours from Confluence exploit to encryption
After exploiting a Confluence server, the attackers reached ransomware in just over two hours. They pushed LockBit to hosts over SMB with PDQ Deploy, then ran a batch script from the Exchange server that mounted remote systems’ C$ shares. That enabled a second encryption wave across the network for any machine the first pass had missed.[9]
Documented by Group-IB, April 2025
Remote encryption over SMB and SFTP
RansomHub’s locker runs on Windows, Linux, FreeBSD and ESXi and can encrypt remote file systems as well as local ones. With its network-share options enabled it encrypts SMB shares across the network, and an SFTP mode lets the operator name a remote host and path to encrypt without placing the locker on that machine.[11]
Documented by VMware, March 2023
Pointing the encryptor at a server
Royal’s encryptor takes a network path on the command line, so an operator can encrypt a server’s drive remotely using only its IP address. Later versions added a network-only mode that scans for shares and targets them. VMware investigated a Royal attack that relied on file encryption over SMB.[10]
Case study · Sophos, January 2026
No malware on the victim at all
WantToCry operators log in to internet-exposed SMB services with weak or compromised credentials, pull files out over the authenticated session, encrypt them on their own infrastructure, and write the encrypted copies back to the original locations. Nothing executes on the victim, so there is no suspicious process or malicious file to find.[12]
Why Endpoint Agents Miss It
Traditional EDR looks for a process to kill on the protected machine. Remote encryption over SMB leaves none, because the encryptor's process tree lives entirely on the unmanaged device. File-level read/write operations don't trigger process-execution alerts, and attackers often use valid, stolen credentials, so the activity looks like normal file access.[3][6]
Where RansomSnare Fits
RansomSnare runs on the file server and inspects every file written to it, whichever machine sends the write.
If the files being written are encrypted, and the machine writing them doesn't have RansomSnare installed to confirm the process is trusted, RansomSnare blocks the write. This works even when the encryptor is running on a camera or printer with no security software on it.