Join our Newsletter — 33% off our NHI Course

Why does intermittent encryption make ransomware harder to detect and stop?

Intermittent encryption raises risk because the malware only partially encrypts files, either in a random pattern or a regular pattern, which can make the activity faster and less obvious to detection tools. That means defenders may see less obvious file corruption while the ransomware still achieves its goal of disrupting data and accelerating extortion.

How intermittent encryption frustrates file-based detection

Intermittent encryption changes the signal defenders are looking for. Traditional ransomware often produces broad, continuous corruption across a file set, which is easier to spot through mass rewrite behaviour, unusual entropy shifts, or large volumes of modified data. When encryption is applied only to chunks or selected portions, the attack can look more like normal file activity, especially in early stages.

The practical problem is that many defensive rules and analytics depend on volume, pattern, or consistency. If only part of each file is changed, telemetry may show fewer obvious spikes in CPU, I/O, or file rewrite counts, while the underlying business impact still accumulates. That makes the malware harder to distinguish from backup software, sync activity, compression, or other legitimate bulk processing.

Why the attack stays effective even when not all data is encrypted

Ransomware does not need to fully encrypt every byte to create operational damage. Partial encryption can still break documents, databases, archives, and application files because many formats become unreadable when key sections are altered. The attacker’s goal is usually extortion leverage, not perfect cryptographic completeness, so the method is tuned to create disruption while limiting runtime overhead.

This approach also helps the malware finish faster. Shorter dwell time in a directory or on a host reduces the chance that behaviour-based controls, user reports, or security tooling will interrupt the process before enough damage is done. In other words, intermittent encryption is a trade-off: less obvious activity for defenders, enough corruption for the attacker.

One useful reference point is the MITRE ATT&CK Enterprise Matrix, which helps teams map observable behaviours such as file impact, execution, and defence evasion to the broader attack chain.

What defenders should watch for instead of full-file corruption

The detection problem shifts from “has the file been fully encrypted?” to “is the host showing suspicious partial-write behaviour across many files?” That means defenders need to look for repeated access to many user files in a short period, unusual rename or extension churn, rapid open-close cycles, and file content changes that do not match normal user workflows. The absence of a dramatic entropy jump is not reassurance.

Teams should also treat speed as a clue. Intermittent encryption often aims to minimize time spent on each file, so a process that touches many documents briefly, especially outside normal application patterns, deserves scrutiny. A file server or endpoint that suddenly shows widespread but shallow modification can be more suspicious than a host that has already been fully encrypted.

Broader threat reporting can help calibrate those signals. CISA cyber threat advisories and the ENISA Threat Landscape both provide context on ransomware tradecraft and the operational impact of extortion-driven campaigns.

Risk and Threat Considerations

Intermittent encryption increases the chance that ransomware will slip past controls that key off obvious mass corruption, giving attackers more time to disrupt operations and pressure victims before response teams recognise the pattern. The danger is not just stealth, but the combination of stealth and sufficient damage: a small amount of encrypted content can still disable critical files, shares, or application data.

Failure mechanism: The malware limits per-file changes, spreads writes over time or across file portions, and avoids the clean, high-volume signatures many controls expect, which reduces detection confidence and delays containment.

Impact: Defenders may isolate the host too late, allowing broader file damage, business interruption, and stronger extortion leverage even though the encryption footprint looks smaller than in classic ransomware.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1486 — Data Encrypted for Impact Intermittent encryption is a ransomware impact technique.
Recommendation — Map partial-encryption telemetry to T1486 and alert on unusual file-write bursts.
CIS Controls v8 CIS-8 — Audit Log Management File-impact detection depends on usable logs and alerting across hosts and shares.
Recommendation — Centralize and review endpoint and file-server logs for partial-encryption indicators.
NIST CSF 2.0 DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity events Intermittent encryption requires continuous monitoring for abnormal file activity.
RS.MA-01 — Incidents are contained Fast containment is critical once intermittent encryption is suspected.
Recommendation — Monitor file and process behaviour continuously to detect ransomware early. Isolate affected hosts immediately when partial-encryption behaviour is detected.

Practitioner Guidance

What to prioritise: Treat behavioural detection and rapid isolation as more important than waiting for obvious file corruption. Alerts should combine process behaviour, file access patterns, and unusual write activity, not just entropy or extension-based indicators.

What to verify: Confirm that your telemetry can detect partial-write patterns on endpoints and file shares, and that containment actions can stop a suspicious process quickly enough to prevent spread. If your tooling only notices fully encrypted files, your detection threshold is already too late for intermittent encryption.

Practitioner takeaway: The main lesson is that ransomware detection must be pattern-based, not corruption-based, because attackers can reduce the visual footprint of encryption without reducing its operational harm.