/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: ransomware gangs are using intermittent encryption, where files are partly encrypted, to evade detection tools looking for intense file I/O operations

A growing number of ransomware groups are adopting a new tactic that helps them encrypt their victims' systems faster while reducing …Source:SentinelOne.

BleepingComputer Bill Toulas

Context & Ripple Effects

Ransomware tradecraft has been layering leverage on top of encryption for years: gangs began stealing data before encrypting so that backups alone would not save a victim, a playbook later codified in the double-extortion tactics used by Nefilim. Intermittent encryption is the next layer — this time aimed at the defenders rather than the victim's negotiating position.

The move also connects to speed. A March analysis of ten strains found LockBit and Babuk encrypt fastest, because time-on-system is a ransomware operator's biggest exposure window; encrypting only part of each file shortens that window further while degrading the very file-I/O signal detection tools rely on.

First-order effects

  • Detection tools tuned to flag intense file I/O lose their primary tripwire against strains using intermittent encryption, leaving victims with partly encrypted files and fewer early warnings.
  • Security vendors like SentinelOne, whose research surfaced the tactic, must now distinguish malicious partial encryption from normal file activity — a harder classification problem than volume-based detection.

Second-order effects

  • Vendors will be pushed toward behavioral and pre-encryption telemetry — process lineage, shadow-copy deletion, exfiltration traffic — since the encryption event itself is no longer a reliable signal.
  • Slower strains like Conti, Maze, and PYSA, already flagged in the speed analysis, face pressure to adopt the same partial-encryption technique or accept longer, more detectable dwell times.

Third-order effects

  • If partial encryption becomes standard, the ransomware arms race shifts decisively from encrypt-fast to detect-evasion-first, and defensive value migrates from storage-layer monitoring to identity, access, and backup-integrity controls.
  • Combined with double extortion, victims face a compound threat — stolen data plus degraded, partly encrypted systems — that strengthens the argument for paying even when backups exist, sustaining the payout economics researchers have already mapped.

The trend: Ransomware is evolving from a pure encryption-speed race into a detection-evasion race, with each new tactic — data theft, faster ciphers, now partial encryption — targeting the previous generation of defenses.