Join our Newsletter — 33% off our NHI Course

Big Game Hunting

Big game hunting is a ransomware strategy that targets large organisations perceived to have greater ability to pay. Attackers use higher initial demands and more intense extortion pressure to maximise returns from fewer victims. The approach contrasts with spray and pray attacks aimed at many smaller organisations.

What Big Game Hunting Means in Practice

Big game hunting is a ransomware strategy built around selective targeting, where attackers focus on organisations that are more likely to absorb a large extortion demand and pay quickly. The operational logic is simple: fewer victims, higher pressure, larger expected return.

This approach usually differs from opportunistic mass campaigns because the attacker is making a deliberate choice about target value, disruption tolerance, and reputational leverage. In other words, the threat is not just encryption, but the calculated use of business criticality as an extortion multiplier.

How Attackers Use It to Increase Leverage

Big game hunting often pairs initial access with careful reconnaissance so the attacker can identify which systems, backups, and business processes matter most. Once inside, the goal is to maximise leverage by threatening data theft, operational interruption, and public exposure rather than relying on a single ransom prompt.

This makes the tactic especially dangerous in environments with high-value data, tight uptime requirements, or visible brand risk. Attackers do not need to compromise every asset; they only need enough reach to create a credible business crisis.

That pressure is amplified when defenders have weak visibility into privileged access, poor offboarding, or exposed secrets. NHIMG’s Ultimate Guide to Non-Human Identities notes that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which helps explain why abused credentials can become a fast path to high-impact extortion.

Why Large Organisations Are Attractive Targets

Large organisations tend to have more complex estates, more third-party connections, and more dispersed recovery dependencies. Those conditions create more opportunities for attackers to find weak control points, move laterally, and identify the most painful disruption path.

The tactic also works because big organisations often face asymmetric costs. Even when ransom payment is not the right response, recovery, legal review, customer notification, and service restoration can be expensive enough to make the attacker’s threat look credible.

Visibility and control gaps matter here. If defenders cannot reliably inventory privileged access, secrets, and service accounts, attackers can hide in the same complexity that sustains normal operations. That is why resource categories such as OWASP Non-Human Identity Top 10 and SPIFFE workload identity specification are relevant to the broader attack surface, even when the extortion event itself is not about identity in the abstract.

For broader detection and response coordination, the NIST Cybersecurity Framework 2.0 remains a useful way to connect governance, protection, detection, response, and recovery around this kind of high-impact incident.

What Distinguishes It From Other Ransomware Campaigns

The defining feature is selectivity. Spray-and-pray ransomware tries to scale volume across many smaller victims, while big game hunting concentrates effort on a smaller number of targets that can plausibly pay more. That usually means more reconnaissance, more careful access staging, and more tailored extortion messaging.

It is also common for big game hunting to involve double extortion, where data theft is used alongside encryption to increase pressure. The attacker’s objective is not merely to restore access, but to force a decision under time pressure and reputational risk.

Defenders should think of this as a business impact problem as much as a malware problem. The more an organisation can segment critical services, reduce standing privilege, and limit the blast radius of compromised accounts, the less attractive it becomes as a high-value extortion target.

Risk and Threat Considerations

Big game hunting raises the stakes of ransomware because attackers deliberately aim for the places where operational interruption, data exposure, and public pressure are most damaging. The threat is not only encryption, but the possibility that a targeted intrusion will reach the systems that make recovery slow, visible, and expensive.

Failure mechanism: Attackers gain privileged or persistent access, identify critical systems and data, and then apply maximum extortion leverage through encryption, theft, and threat of disclosure.

Impact: The result can be widespread outage, delayed recovery, regulatory exposure, and a much stronger incentive to pay than in indiscriminate ransomware campaigns.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1486 — Data Encrypted for Impact Big game hunting commonly uses encryption as the extortion lever.
T1657 — Financial Theft Ransomware extortion is economically motivated and targets payers.
Recommendation — Map encryption events to T1486 and prioritize isolation, containment, and recovery actions. Treat the campaign as profit-driven extortion and track attacker pressure indicators.
CIS Controls v8 CIS 5 — Account Management Big game hunting often exploits weak or excessive account access paths.
CIS 8 — Audit Log Management Attackers rely on low visibility while staging and expanding access.
CIS 10 — Malware Defenses Ransomware payloads and loaders are core delivery and execution mechanisms.
Recommendation — Enforce account governance to remove unnecessary access that can enable ransomware spread. Centralize and protect logs so lateral movement and extortion staging are detectable. Use malware defenses to block execution and contain ransomware payloads early.
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control Reducing privilege and access breadth limits the attacker's ability to reach high-value assets.
DE.CM — Continuous Monitoring Early detection of reconnaissance, staging, and unusual access is critical in targeted ransomware.
RC.RP — Recovery Plan Execution Big game hunting depends on making recovery slow enough to increase extortion leverage.
Recommendation — Restrict privileged access so a foothold cannot quickly reach crown-jewel systems. Monitor for abnormal access, privilege use, and lateral movement across critical assets. Test and execute recovery plans so restoration is faster than the attacker expects.

Practitioner Guidance

Why practitioners should care: Big game hunting is designed to exploit the gap between technical compromise and business disruption. The practical priority is reducing the attacker’s ability to find, reach, and weaponise the most valuable parts of the environment.

What to watch for: A credible defence against this tactic depends on knowing which identities, systems, and data paths matter most, then constraining how far an intrusion can travel once one foothold is lost. Strong segmentation, rapid restoration, and disciplined access governance matter more here than generic alert volume.

Practitioner takeaway: If an organisation looks easy to disrupt at the highest-value layer, it also looks attractive to a big game hunter.