Look for repeated remote sessions from suspicious IPs, large transfers to proxy or cloud addresses, and traffic patterns that cluster around SSH or RDP ports. Malware samples tied to the same domain, unexpected logins from mobile or personal devices, and exfiltration-sized transfers shortly before a public claim are strong indicators that access and theft are both underway.
How to recognize dual-use ransomware activity in a bank network
When operators are using a bank network for both access and data theft, the pattern is usually broader than a single suspicious login or one large transfer. The key is to correlate access signals with exfiltration signals across endpoints, VPN, remote admin tools, proxy paths, and outbound destinations, then check whether those events line up with known ransomware tradecraft such as initial access, lateral movement, staging, and data theft.
The strongest evidence is rarely one alert on its own. It is the combination of repeated remote access from unusual sources, account activity that does not match normal working patterns, and outbound traffic that is large, compressed, encrypted, or routed through cloud or proxy infrastructure shortly before extortion activity becomes visible.
Access patterns that show the operator is still inside
Repeated remote sessions from suspicious IP addresses are a major clue, especially when they recur across multiple hosts or outside normal hours. Pay close attention to SSH and RDP clustering, because those protocols often appear in the same campaign when operators are moving from foothold to broader access.
Unexpected logins from personal devices, mobile devices, or fresh geographies can also indicate active operator presence rather than ordinary employee behaviour. If those sessions are followed by privilege changes, new persistence, or access to internal file shares and admin tools, treat them as part of a live intrusion rather than isolated anomalies.
Malware samples tied to the same domain or infrastructure can help connect these access events to the broader campaign. That correlation matters because it suggests the same operator is using multiple paths to preserve access while preparing for theft or encryption.
Data theft indicators that distinguish theft from simple intrusion
Exfiltration often shows up as large transfers to proxy services, cloud storage, or other external endpoints that do not match normal bank traffic patterns. The timing is important: operators frequently stage data first, then move it in a short burst, so a brief spike in outbound volume can be more meaningful than a sustained trickle.
Look for transfers that are large relative to the host role, that involve unusual compression or archive files, or that come from systems that do not normally send data outside the environment. If the same account or host also shows remote access anomalies, the event is more likely to represent theft in progress than routine file movement.
In ransomware cases, a public claim or leak-site activity often follows shortly after the theft phase. That is not proof by itself, but it is a useful contextual marker when you are deciding whether the environment has moved from intrusion to extortion preparation.
How to correlate the signals into one incident picture
The practical test is whether the access indicators and the outbound-transfer indicators line up in the same window, on the same host set, or under the same account family. A single remote session may be noise; a remote session followed by credentialed internal movement and a large outbound transfer is much stronger evidence of operator activity.
Bank environments should also consider whether the traffic path itself is suspicious. RDP, SSH, and proxy-heavy flows can indicate both control and concealment, especially when the destinations are cloud platforms or intermediary hosts rather than known business partners. This is where correlation across network logs, endpoint telemetry, and identity events becomes essential.
Risk and Threat Considerations
When ransomware operators can both authenticate into the network and move data out, the bank is dealing with a higher-impact intrusion path than simple encryption alone. The same access that enables staging and theft can also support privilege escalation, lateral movement, and faster operational disruption if responders only focus on the encryption phase.
Failure mechanism: Attackers reuse valid credentials, remote access tools, or compromised hosts to blend into legitimate traffic, then shift to high-volume outbound transfers, often through proxy or cloud infrastructure, before defenders can separate routine admin activity from malicious operator control.
Impact: This combination increases the likelihood of data loss, extortion leverage, customer exposure, and delayed containment, because the intrusion can remain active while theft is still underway.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1021 — Remote Services | RDP and SSH clustering maps to remote-service abuse for operator access. |
| T1041 — Exfiltration Over C2 Channel | Large outbound transfers to proxy or cloud destinations indicate data theft via controlled channels. | |
| Recommendation — Map remote-service activity to lateral-movement techniques and hunt for abnormal admin access patterns. Correlate outbound transfer spikes with staging and exfiltration detections. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Correlating access and theft requires consistent logging across remote access and outbound traffic. |
| Recommendation — Centralise and review remote-access and egress logs for linked intrusion and theft patterns. | ||
Practitioner Guidance
What to prioritise: Correlate remote access, privilege use, and outbound transfer telemetry in a single investigation timeline. In practice, that means treating unusual SSH or RDP access as high priority when it is followed by archive creation, staging activity, or cloud/proxy egress.
What to verify: Confirm whether the source IP, device, and account normally belong to the user or system. If you cannot tie the access pattern to a legitimate operational need, assume the session is part of operator activity until you have evidence otherwise.
Practitioner takeaway: The decisive question is not whether the bank saw a login or a data transfer, but whether the same intrusion path is doing both, because that is what turns an incident into an active theft and extortion problem.
Related resources from NHI Mgmt Group
- What are the signs that a collaboration platform breach is moving from data theft to deeper network access?
- What happens when ransomware operators can combine credential theft with lateral movement inside the network?
- What are the signs that a user is misusing SaaS access for reconnaissance or data theft?
- How should organisations respond when ransomware operators combine encryption with data theft and leak-site extortion?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org