{"id":1610,"date":"2026-09-21T10:00:00","date_gmt":"2026-09-21T10:00:00","guid":{"rendered":"https:\/\/blog.scilabs.mx\/en\/?p=1610"},"modified":"2026-09-21T16:52:03","modified_gmt":"2026-09-21T16:52:03","slug":"h1-2026-primary-initial-access-vectors-used-by-threat-actors-in-ransomware-attacks","status":"publish","type":"post","link":"https:\/\/blog.scilabs.mx\/en\/2026\/09\/21\/h1-2026-primary-initial-access-vectors-used-by-threat-actors-in-ransomware-attacks\/","title":{"rendered":"H1 2026: Primary initial access vectors used by threat actors in ransomware attacks"},"content":{"rendered":"\n<p>The purpose of this publication is to provide updated information on the primary initial access methods most commonly used by cybercriminals, based on observed telemetry from ransomware attacks targeting organizations in Latin America during the first half of 2026.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/www.rapid7.com\/fundamentals\/vulnerabilities-exploits-threats\" data-type=\"link\" data-id=\"https:\/\/www.rapid7.com\/fundamentals\/vulnerabilities-exploits-threats\">Exploitation of Vulnerabilities in Perimeter Infrastructure<\/a><\/strong><\/h2>\n\n\n\n<p>Threat actors seek and exploit vulnerabilities in outdated or unpatched software, particularly in applications or infrastructure exposed to the Internet.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work?<\/strong> Attackers conduct reconnaissance of Internet-exposed assets belonging to organizations, identifying and exploiting vulnerabilities present in outdated software, legacy systems, misconfigurations, or <a href=\"https:\/\/www.ibm.com\/mx-es\/think\/topics\/zero-day\">zero-day<\/a> flaws. To accomplish this, they develop their own <a href=\"https:\/\/www.bitdefender.es\/consumer\/support\/answer\/22884\" data-type=\"link\" data-id=\"https:\/\/www.bitdefender.es\/consumer\/support\/answer\/22884\">exploits<\/a> or utilize those generated by other cybersecurity researchers, with the purpose of gaining unauthorized access to systems. Following exploitation, they establish persistence, extract credentials, or deploy tools to expand access within the organization.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen? <\/strong>Many organizations fail to apply security patches in a timely manner, leaving known vulnerabilities exposed. Remote applications and Internet-exposed services\u2014such as <a href=\"https:\/\/www.designveloper.com\/blog\/what-is-the-most-popular-web-server-application\" data-type=\"link\" data-id=\"https:\/\/www.designveloper.com\/blog\/what-is-the-most-popular-web-server-application\">web servers<\/a>, <a href=\"https:\/\/www.openlogic.com\/blog\/web-server-vs-application-server\" data-type=\"link\" data-id=\"https:\/\/www.openlogic.com\/blog\/web-server-vs-application-server\">application services<\/a>, <a href=\"https:\/\/www.znetlive.com\/blog\/server-virtualization-software-comparison-microsoft-hyper-v-vs-vmware-vsphere-vs-citrix-xenserver-vs-kvm\" data-type=\"link\" data-id=\"https:\/\/www.znetlive.com\/blog\/server-virtualization-software-comparison-microsoft-hyper-v-vs-vmware-vsphere-vs-citrix-xenserver-vs-kvm\">infrastructure management software<\/a>, and database software\u2014as well as network and perimeter security devices are the most frequently <a href=\"https:\/\/thehackernews.com\/2024\/10\/cisa-warns-of-critical-fortinet-flaw-as.html\" data-type=\"link\" data-id=\"https:\/\/thehackernews.com\/2024\/10\/cisa-warns-of-critical-fortinet-flaw-as.html\">targeted<\/a>. Furthermore, perimeter systems are often directly exposed to the Internet and frequently experience delays in patch application. Additionally, many of these devices have limited monitoring capabilities compared to traditional workstations or servers, making early detection of an intrusion more difficult.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/brute-force-attack#:~:text=A%20brute%20force%20attack%20is,and%20organizations'%20systems%20and%20networks.\" data-type=\"link\" data-id=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/brute-force-attack#:~:text=A%20brute%20force%20attack%20is,and%20organizations'%20systems%20and%20networks.\">Brute Force Attacks<\/a> and <a href=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/cloud-security\/credential-theft\/#:~:text=Credential%20theft%20is%20the%20act,malicious%20software%20or%20phishing%20techniques.\" data-type=\"link\" data-id=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/cloud-security\/credential-theft\/#:~:text=Credential%20theft%20is%20the%20act,malicious%20software%20or%20phishing%20techniques.\">Credential Theft<\/a><\/h2>\n\n\n\n<p>Using weak or reused passwords, attackers can execute brute force attacks to gain access to valid user accounts. Likewise, credentials stolen from data breaches allow them to legitimately access corporate systems.<\/p>\n\n\n\n<p>\u2022 How does it work? Attackers use automation tools to generate multiple username and password combinations until they find a valid one. They may also use credentials stolen from previous breaches or through infostealers, data leaks, password reuse, session hijacking, or purchasing access in underground markets. Once they have a legitimate account, they attempt to access various services without the need to exploit additional vulnerabilities. The recent trend also includes the hijacking of authenticated sessions and manipulation of <a href=\"https:\/\/www.microsoft.com\/es-mx\/security\/business\/identity-access\/microsoft-entra-mfa-multi-factor-authentication\" data-type=\"link\" data-id=\"https:\/\/www.microsoft.com\/es-mx\/security\/business\/identity-access\/microsoft-entra-mfa-multi-factor-authentication\">MFA<\/a> mechanisms.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Password reuse and the lack of robust password policies facilitate these attacks\u2014for example, by not locking user accounts after multiple failed attempts. Organizations do not always implement multi-factor authentication (MFA), particularly on user accounts considered critical within the infrastructure, such as those belonging to administrators or authorized providers requiring direct access to sensitive resources. The absence of MFA on these types of accounts significantly increases the risk of compromise, as they concentrate high privileges and are typically priority targets for attackers. Cybercriminal ecosystems have professionalized the sale of compromised accesses, enabling ransomware operators to purchase previously validated credentials rather than conducting the initial intrusion themselves.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Password reuse and the lack of robust password policies facilitate these attacks\u2014for example, by not locking user accounts after multiple failed attempts. Organizations do not always implement multi-factor authentication (MFA), particularly on user accounts considered critical within the infrastructure, such as those belonging to administrators or authorized providers requiring direct access to sensitive resources. The absence of MFA on these types of accounts significantly increases the risk of compromise, as they concentrate high privileges and are typically priority targets for attackers. Cybercriminal ecosystems have professionalized the sale of compromised accesses, enabling ransomware operators to purchase previously validated credentials rather than conducting the initial intrusion themselves.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/www.proofpoint.com\/es\/threat-reference\/identity-theft\" data-type=\"link\" data-id=\"https:\/\/www.proofpoint.com\/es\/threat-reference\/identity-theft\">Theft and Access Through Legitimate Identities<\/a><\/strong><\/h2>\n\n\n\n<p>As organizations strengthen traditional security controls, ransomware operators increasingly resort to techniques that seek to abuse user trust rather than exploit technical vulnerabilities. This trend prioritizes the theft of valid identities and sessions to access corporate environments using apparently legitimate mechanisms.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work?<\/strong> Attackers combine phone calls, instant messaging, email, fake websites, and <a href=\"https:\/\/azure.microsoft.com\/es-es\/resources\/cloud-computing-dictionary\/what-is-saas\" data-type=\"link\" data-id=\"https:\/\/azure.microsoft.com\/es-es\/resources\/cloud-computing-dictionary\/what-is-saas\">SaaS<\/a> platforms to persuade users to surrender credentials or approve access. In some cases, they impersonate IT personnel or legitimate vendors.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Organizations have strengthened their technical controls, leading attackers to directly exploit user trust. This approach allows them to obtain legitimate access without the need to deploy malware or exploit complex vulnerabilities.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/www.welivesecurity.com\/es\/malware\/infostealers-5-tipos-malware-roban-informacion-mas-activos\" data-type=\"link\" data-id=\"https:\/\/www.welivesecurity.com\/es\/malware\/infostealers-5-tipos-malware-roban-informacion-mas-activos\">Infostealers<\/a><\/strong><\/h2>\n\n\n\n<p>Infostealers are a class of malware designed to steal confidential information, such as passwords, <a href=\"https:\/\/allaboutcookies.org\/cookies-de-sesion\" data-type=\"link\" data-id=\"https:\/\/allaboutcookies.org\/cookies-de-sesion\">session cookies<\/a>, financial data, and other personal data stored on infected devices (especially in web browsers). Additionally, they are leveraged by threat actors to download and execute other threats, including ransomware. A growth in <em><a href=\"https:\/\/xfe-integration.xforce.ibm.com\/osint\/guid:261ba8494f464be58cf4c3e2cdc9be47\" data-type=\"link\" data-id=\"https:\/\/xfe-integration.xforce.ibm.com\/osint\/guid:261ba8494f464be58cf4c3e2cdc9be47\">ClickFix-type<\/a><\/em> campaigns has also been observed, where victims are deceived into manually executing malicious commands under the pretext of resolving a supposed technical error, completing a <a href=\"https:\/\/knowledge.workspace.google.com\/admin\/getting-started\/what-is-captcha?hl=es-419\" data-type=\"link\" data-id=\"https:\/\/knowledge.workspace.google.com\/admin\/getting-started\/what-is-captcha?hl=es-419\">CAPTCHA<\/a>, updating an application, or verifying their identity.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work? <\/strong>This type of malware is installed on the victim&#8217;s device, typically through phishing emails, pirated software downloads, or <em><a href=\"https:\/\/www.fortinet.com\/lat\/resources\/cyberglossary\/malvertising\" data-type=\"link\" data-id=\"https:\/\/www.fortinet.com\/lat\/resources\/cyberglossary\/malvertising\">malvertising<\/a><\/em>. Once installed, it collects sensitive information and sends it to the attacker without the victim&#8217;s awareness. In some cases, it also downloads additional malware.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> The lack of security solutions such as <a href=\"https:\/\/www.group-ib.com\/resources\/knowledge-hub\/edr-endpoint-detection-and-response\" data-type=\"link\" data-id=\"https:\/\/www.group-ib.com\/resources\/knowledge-hub\/edr-endpoint-detection-and-response\">EDR<\/a> or antivirus, as well as the downloading of unverified software, the installation of software not approved by the organization, and the absence of security policies and guidelines along with their proper implementation facilitate the propagation of infostealers. For their part, ClickFix campaigns have increased because they leverage user interaction to execute actions that evade certain traditional security controls, becoming an efficient source for feeding the compromised access market. Stolen data is sold in underground markets and cybercriminal forums that provide attackers with privileged information that can be used for fraud or as a gateway to access organizational user accounts.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/www.huntress.com\/ransomware-guide\/initial-access-brokers-ransomware\" data-type=\"link\" data-id=\"https:\/\/www.huntress.com\/ransomware-guide\/initial-access-brokers-ransomware\">Initial Access Brokers<\/a><\/strong><\/h2>\n\n\n\n<p>Initial access brokers are specialized actors that compromise organizations to subsequently sell the obtained access to other criminal groups, including ransomware and extortion operators. This has given rise to a criminal economy where initial access is commercialized as a service.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work?<\/strong> They obtain access through stolen credentials, vulnerabilities, or exposed services, validate the level of access achieved, and subsequently sell it to other actors to continue the intrusion.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> It allows the distribution of different attack phases among specialized groups, increasing efficiency and reducing operational costs. While some actors focus on obtaining access at scale, others specialize in extortion, data exfiltration, or ransomware deployment, which accelerates operations and facilitates the reuse of compromised accesses against multiple organizations.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Access Through Remote Services Such as <a href=\"https:\/\/www.zdnet.com\/article\/security-researchers-say-this-scary-exploit-could-render-all-vpns-useless\" data-type=\"link\" data-id=\"https:\/\/www.zdnet.com\/article\/security-researchers-say-this-scary-exploit-could-render-all-vpns-useless\">VPN<\/a>, <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/citrix-discovers-two-vulnerabilities-both-exploited-in-the-wild\" data-type=\"link\" data-id=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/citrix-discovers-two-vulnerabilities-both-exploited-in-the-wild\">Citrix<\/a>, and <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/vpn-rdp-exploitation-common-attack\" data-type=\"link\" data-id=\"https:\/\/www.infosecurity-magazine.com\/news\/vpn-rdp-exploitation-common-attack\">RDP<\/a> with Weak Security Configuration<\/strong><\/h2>\n\n\n\n<p>Attackers exploit weak configurations or vulnerabilities in VPN, Citrix, and RDP (Remote Desktop Protocol) services to gain unauthorized access to internal networks and sensitive data.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work? <\/strong><a href=\"https:\/\/www.cloudflare.com\/es-es\/learning\/access-management\/what-is-the-remote-desktop-protocol\" data-type=\"link\" data-id=\"https:\/\/www.cloudflare.com\/es-es\/learning\/access-management\/what-is-the-remote-desktop-protocol\">RDP<\/a> protocols and other remote access technologies with deficient security configurations have become key targets. Attackers search for <a href=\"https:\/\/attack.mitre.org\/techniques\/T1133\" data-type=\"link\" data-id=\"https:\/\/attack.mitre.org\/techniques\/T1133\">exposed<\/a> RDP services, VPNs, or Citrix servers and use tools that automate password searching to gain entry, or exploit critical vulnerabilities to obtain access to corporate networks. Once inside, they can move laterally through the network, steal data, and deploy malware. In the specific case of RDP, attackers leverage misconfigurations or weak credentials to remotely access systems.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Misconfigurations, the lack of multi-factor authentication, and the failure to apply security patches facilitate these attacks. Adversaries can find and exploit these vulnerabilities to penetrate corporate networks and compromise organizational security. Furthermore, the growing adoption of remote work has increased the exposure of services such as RDP, transforming them into an attractive target for cybercriminals. Many organizations continue to depend on these services to enable remote work and third-party access. Their Internet exposure, combined with weak or poorly implemented configurations such as MFA or insufficient monitoring, makes them priority targets for adversaries.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/us.norton.com\/blog\/emerging-threats\/software-piracy\">Pirated Software<\/a>, <a href=\"https:\/\/www.incibe.es\/aprendeciberseguridad\/malvertising\" data-type=\"link\" data-id=\"https:\/\/www.incibe.es\/aprendeciberseguridad\/malvertising\">Malvertising<\/a>, and <a href=\"https:\/\/www.godaddy.com\/resources\/es\/marketing\/black-hat-seo\" data-type=\"link\" data-id=\"https:\/\/www.godaddy.com\/resources\/es\/marketing\/black-hat-seo\">Black Hat SEO<\/a>:<\/strong><\/h2>\n\n\n\n<p>Pirated software refers to legitimate software that has been intentionally modified to evade license verification systems. This type of software typically includes backdoors or malware and is distributed through unofficial channels or low-trust domains. Attackers employ malvertising through malicious ads on legitimate web search engines, which redirect users to infected pages that automatically download malware without it being evident.<\/p>\n\n\n\n<p><em>Black Hat SEO<\/em>, also known as <em>BlackSEO<\/em>, is a practice that enables better positioning of a website in online search engine results. Through algorithms and techniques such as keyword repetition within site content, attackers alter the organic positioning of web search engines, allowing their malicious sites to be listed in the top positions to increase their probability of being selected and compromising their victim.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work?<\/strong> The infected software is installed on users&#8217; devices, providing attackers with remote access and control over compromised systems; additionally, it grants the ability to install other types of malware such as infostealers or even ransomware. On the other hand, malvertising\u2014malicious advertisements on legitimate websites\u2014redirects users to malicious pages from which this malware is downloaded.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Excessive user trust in software sources and the lack of verification of the sites they are accessing allow pirated software to spread. Attackers exploit this trust to infiltrate corporate and personal systems. The fact that threat actors employ malicious advertisements and customize their campaigns depending on seasons\u2014such as tax season, mortgage payment periods, and government procedures, among others\u2014allows them to leverage search result manipulation, advertising campaigns, and falsified sites to direct victims toward malicious content.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/blog.barracuda.com\/2024\/10\/09\/novel-phishing-techniques-ascii-based-qr-codes-blob-uri\">Phishing<\/a> and <a href=\"https:\/\/www.incibe.es\/aprendeciberseguridad\/spear-phishing\">Spear-Phishing Emails<\/a><\/strong><\/h2>\n\n\n\n<p>Attackers send emails that appear legitimate to deceive victims into clicking on malicious links or downloading infected attachments. To increase their effectiveness, these emails may be highly personalized, employing spear-phishing techniques targeting specific individuals within an organization.<\/p>\n\n\n\n<p>\u2022 How does it work? Attackers send emails that impersonate legitimate organizations. These emails appear to come from trusted sources but contain malicious links, infected attachments, or even QR codes in images or with ASCII characters that evade email filtering devices. The objective is to deceive victims or direct specific campaigns against executives to obtain credentials or induce malware downloads.<\/p>\n\n\n\n<p>\u2022 Why does it happen? These techniques leverage social engineering, manipulating people&#8217;s emotions and trust. Attackers can personalize emails based on information gathered about the victim, which increases the probability of success.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Exploitation of Vulnerabilities in <a href=\"https:\/\/www.ibm.com\/mx-es\/think\/topics\/ai-agent-security\" data-type=\"link\" data-id=\"https:\/\/www.ibm.com\/mx-es\/think\/topics\/ai-agent-security\">AI Services and Agents<\/a><\/strong><\/h2>\n\n\n\n<p>Attackers seek <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\">vulnerabilities<\/a> in AI platforms, corporate assistants, extensions, connectors, retrieval systems, or services that interact with enterprise information.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work?<\/strong> Attackers may abuse insecure configurations, improper data exposure, or excessive permissions in AI integrations.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> The accelerated adoption of AI tools has caused many organizations to integrate new services without having fully matured their security controls. Although it does not yet represent the dominant vector for exploitation in ransomware attacks, it is beginning to emerge as an attack surface associated with information theft, identity abuse, and privilege escalation leveraging the interconnection and operational capabilities that many organizations are beginning to implement in their operations.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/www.cloudflare.com\/learning\/security\/what-is-a-supply-chain-attack\">Supply Chain Attacks<\/a><\/strong><\/h2>\n\n\n\n<p>Attackers compromise software providers, managed services, technology integrators, or third parties with privileged access to multiple clients to insert malware into legitimate software updates, affecting multiple organizations simultaneously. This type of attack is particularly dangerous because it can be introduced into internal systems through a trusted channel.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How does it work? <\/strong>Attackers compromise software providers or third-party services to insert malware into legitimate updates that, from a single point of compromise, can affect numerous organizations.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Why does it happen?<\/strong> Companies increasingly depend on interconnected provider ecosystems. A compromised access at a third party can provide privileged access to multiple victims with significantly less effort than attacking each organization individually.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The purpose of this publication is to provide updated information on the primary initial access methods most commonly used by<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-1610","post","type-post","status-publish","format-standard","hentry","category-ransomware"],"_links":{"self":[{"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/posts\/1610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/comments?post=1610"}],"version-history":[{"count":1,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/posts\/1610\/revisions"}],"predecessor-version":[{"id":1612,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/posts\/1610\/revisions\/1612"}],"wp:attachment":[{"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/media?parent=1610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/categories?post=1610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.scilabs.mx\/en\/wp-json\/wp\/v2\/tags?post=1610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}