Understanding Destructive Cyberattacks

An intact technology stack, a destructive ransomware attack, and a rebuilt stack still containing compromised components.

The breach is just the opening act.
By Ed Bednar

Understanding cyber recovery necessitates examining how attackers deliberately compromise the systems and capabilities you’ll depend on to regain control during a destructive cyberattack.

Attackers Target Your Ability to Recover

Much of the attention on cyberattacks, including prominent headline coverage, tends to focus on data that has been stolen or rendered inaccessible.

These are the most visible and easily understood forms of cyberattack, particularly when accompanied by a ransom demand.

But sophisticated attackers go far beyond that, undermining the systems you will depend on to recover. 

Backups Are Only Part of Recovery

I was once challenged by a very senior executive at an organization I was advising who dismissed the complexity of cyber recovery, asking if their backups were immutable and insisting that they shouldn’t need much, if anything, else.

Backups are certainly essential, and immutability and storage methods matter, but successful recovery usually depends on much more than having a usable copy of your data.

This is because attackers don’t necessarily have to defeat the immutability of any underlying storage artifact if they can compromise the control plane used to administer the backup environment, its catalogs, credentials, retention policies, or recovery processes.

Recovery Denial as Strategy

Mandiant, Google Cloud’s incident-response and threat-intelligence organization, describes this strategy as recovery denial: deliberately targeting the systems and administrative pathways an organization will depend on to recover.

Its investigations show attackers targeting identity services, virtualization management planes, backup infrastructure, and other recovery-critical systems specifically to reduce or prevent your ability to recover.1

Recovery Can Be Undermined Quickly

Recovery capabilities can be undermined long before the destructive phase becomes visible, and increasingly that can happen very quickly.

Attackers may compromise identity, administrative pathways, backup infrastructure, and other recovery systems while normal operations continue.

They may be able to actively operate inside your environment while your production systems are still running, customers are still ordering, and employees are still working.

They do this to prepare your environment for the destructive phase of the cyberattack while subverting the systems that should reveal that anything is changing.

And these changes can remain hidden because many of the affected capabilities may rarely be exercised during normal operations.

Anatomy of a Destructive Cyberattack

Sophisticated cyberattacks involve a series of coordinated objectives, each advancing the attacker’s position and progressively undermining your organization’s ability to recover.

And these are not necessarily sequential phases. Attackers may pursue several of these objectives concurrently as their access and control expand.

Establish a Foothold

Every cyberattack begins by establishing a way into the environment.

And attackers have plenty of options, including exploited vulnerabilities, compromised credentials, stolen session tokens, exposed remote-access services, supply-chain compromises, social engineering, and access through third parties.

Once inside, the attacker will begin moving through the environment, accumulating the access and control needed to carry out the larger attack when they’re ready, and on their terms.

Undermine Trust

With sufficient access and control, sophisticated attackers will attempt to compromise the systems and capabilities you will eventually rely on during recovery.

For example:

  • They make backup catalogs unreliable, leaving you uncertain about what can actually be restored.
  • They alter infrastructure definitions so your own automation reproduces their modifications.
  • They poison “trusted” software images so their changes are carried into clean-room environments while configuration baselines still report everything as correct.
  • They compromise certificates and cryptographic services so systems and artifacts they control continue to appear trustworthy.

So when the attacker moves to strike, you will eventually discover that they have already turned your recovery capabilities against you.

Establish Persistence

Sophisticated attackers prepare for what you will do once the attack is discovered.

They expect you to find them, remove their access, and rebuild what they have compromised, so they establish ways to survive your response.

Before the attack becomes visible, they may create hidden administrative accounts, establish privileged cloud identities, deploy management agents, modify scheduled tasks, and create remote access paths that give them multiple ways back into the environment.

Attackers may also establish persistence inside the identity fabric itself by abusing certificate services, compromising federation signing keys to mint trusted tokens, or creating privileged identities and application credentials that survive ordinary account cleanup.

The recovery capabilities the attackers have already compromised can also provide more insidious paths back into your environment.

For example, a poisoned software image can reinstall the attacker’s access into your environment from a rebuilt server in a clean-room environment, an altered infrastructure template can recreate a privileged identity, or a compromised automation credential can reconnect as systems come back online.

So recovery is often a continuing contest for control.

You remove malware, reset credentials, close access paths, and rebuild infrastructure while the attacker watches and adapts to what you are doing. You may lock them out of one part of the environment only to have them return through another.

Your recovery effort can easily be the mechanism that allows an attack that never actually stopped to continue.

Delay Recovery

Time is another weapon, and the clock is working against you.

Once the visible attack begins, the attacker benefits from every moment you spend trying to understand what has happened and what is still happening. 

Their goal is to leave enough systems in an uncertain state that each requires investigation before you are willing to trust it again. Every unresolved question consumes time before another system can safely be returned to service.

As time passes, the pressure to make decisions with less certainty than you would ordinarily accept increases, which can lead to mistakes, including regulatory concerns. This pressure also increases the likelihood that you’ll eventually have to meet the adversary’s demands.

So it’s important to understand that the pressure is itself part of the attack.

The Fight for Recovery

Architecting for cyber recovery is about systematically determining where certainty and control must survive so your organization can contain a destructive cyberattack, rebuild compromised systems and data, and restore the business.

Next, we will detail how to engineer the trust, control, isolation, and recoverability needed to survive the attack and put the business back together in How to Architect for Cyber Recovery.

Notes:
1. Mandiant. (2026). M-Trends 2026: Data, Insights, and Strategies From the Frontlines. Google Cloud, March 23, 2026. Retrieved from https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026



Leave a Reply

Discover more from The Computer Is Going to Do Something

Subscribe now to keep reading and get access to the full archive.

Continue reading