Report: ransomware gangs are using intermittent encryption, where files are partly encrypted, to evade detection tools looking for intense file I/O operations
A growing number of ransomware groups are adopting a new tactic that helps them encrypt their victims' systems faster while reducing …Source:SentinelOne.
Context & Ripple Effects
Ransomware tradecraft has been layering leverage on top of encryption for years: gangs began stealing data before encrypting so that backups alone would not save a victim, a playbook later codified in the double-extortion tactics used by Nefilim. Intermittent encryption is the next layer — this time aimed at the defenders rather than the victim's negotiating position.
The move also connects to speed. A March analysis of ten strains found LockBit and Babuk encrypt fastest, because time-on-system is a ransomware operator's biggest exposure window; encrypting only part of each file shortens that window further while degrading the very file-I/O signal detection tools rely on.
First-order effects
- Detection tools tuned to flag intense file I/O lose their primary tripwire against strains using intermittent encryption, leaving victims with partly encrypted files and fewer early warnings.
- Security vendors like SentinelOne, whose research surfaced the tactic, must now distinguish malicious partial encryption from normal file activity — a harder classification problem than volume-based detection.
Second-order effects
- Vendors will be pushed toward behavioral and pre-encryption telemetry — process lineage, shadow-copy deletion, exfiltration traffic — since the encryption event itself is no longer a reliable signal.
- Slower strains like Conti, Maze, and PYSA, already flagged in the speed analysis, face pressure to adopt the same partial-encryption technique or accept longer, more detectable dwell times.
Third-order effects
- If partial encryption becomes standard, the ransomware arms race shifts decisively from encrypt-fast to detect-evasion-first, and defensive value migrates from storage-layer monitoring to identity, access, and backup-integrity controls.
- Combined with double extortion, victims face a compound threat — stolen data plus degraded, partly encrypted systems — that strengthens the argument for paying even when backups exist, sustaining the payout economics researchers have already mapped.
The trend: Ransomware is evolving from a pure encryption-speed race into a detection-evasion race, with each new tactic — data theft, faster ciphers, now partial encryption — targeting the previous generation of defenses.