Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that ransomware operators are…
Threats, Abuse & Incident Response

What are the signs that ransomware operators are using a bank network for both access and data theft?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Threats, Abuse & Incident Response

Look for repeated remote sessions from suspicious IPs, large transfers to proxy or cloud addresses, and traffic patterns that cluster around SSH or RDP ports. Malware samples tied to the same domain, unexpected logins from mobile or personal devices, and exfiltration-sized transfers shortly before a public claim are strong indicators that access and theft are both underway.

How to recognize dual-use ransomware activity in a bank network

When operators are using a bank network for both access and data theft, the pattern is usually broader than a single suspicious login or one large transfer. The key is to correlate access signals with exfiltration signals across endpoints, VPN, remote admin tools, proxy paths, and outbound destinations, then check whether those events line up with known ransomware tradecraft such as initial access, lateral movement, staging, and data theft.

The strongest evidence is rarely one alert on its own. It is the combination of repeated remote access from unusual sources, account activity that does not match normal working patterns, and outbound traffic that is large, compressed, encrypted, or routed through cloud or proxy infrastructure shortly before extortion activity becomes visible.

Access patterns that show the operator is still inside

Repeated remote sessions from suspicious IP addresses are a major clue, especially when they recur across multiple hosts or outside normal hours. Pay close attention to SSH and RDP clustering, because those protocols often appear in the same campaign when operators are moving from foothold to broader access.

Unexpected logins from personal devices, mobile devices, or fresh geographies can also indicate active operator presence rather than ordinary employee behaviour. If those sessions are followed by privilege changes, new persistence, or access to internal file shares and admin tools, treat them as part of a live intrusion rather than isolated anomalies.

Malware samples tied to the same domain or infrastructure can help connect these access events to the broader campaign. That correlation matters because it suggests the same operator is using multiple paths to preserve access while preparing for theft or encryption.

Data theft indicators that distinguish theft from simple intrusion

Exfiltration often shows up as large transfers to proxy services, cloud storage, or other external endpoints that do not match normal bank traffic patterns. The timing is important: operators frequently stage data first, then move it in a short burst, so a brief spike in outbound volume can be more meaningful than a sustained trickle.

Look for transfers that are large relative to the host role, that involve unusual compression or archive files, or that come from systems that do not normally send data outside the environment. If the same account or host also shows remote access anomalies, the event is more likely to represent theft in progress than routine file movement.

In ransomware cases, a public claim or leak-site activity often follows shortly after the theft phase. That is not proof by itself, but it is a useful contextual marker when you are deciding whether the environment has moved from intrusion to extortion preparation.

How to correlate the signals into one incident picture

The practical test is whether the access indicators and the outbound-transfer indicators line up in the same window, on the same host set, or under the same account family. A single remote session may be noise; a remote session followed by credentialed internal movement and a large outbound transfer is much stronger evidence of operator activity.

Bank environments should also consider whether the traffic path itself is suspicious. RDP, SSH, and proxy-heavy flows can indicate both control and concealment, especially when the destinations are cloud platforms or intermediary hosts rather than known business partners. This is where correlation across network logs, endpoint telemetry, and identity events becomes essential.

Risk and Threat Considerations

When ransomware operators can both authenticate into the network and move data out, the bank is dealing with a higher-impact intrusion path than simple encryption alone. The same access that enables staging and theft can also support privilege escalation, lateral movement, and faster operational disruption if responders only focus on the encryption phase.

Failure mechanism: Attackers reuse valid credentials, remote access tools, or compromised hosts to blend into legitimate traffic, then shift to high-volume outbound transfers, often through proxy or cloud infrastructure, before defenders can separate routine admin activity from malicious operator control.

Impact: This combination increases the likelihood of data loss, extortion leverage, customer exposure, and delayed containment, because the intrusion can remain active while theft is still underway.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1021 — Remote ServicesRDP and SSH clustering maps to remote-service abuse for operator access.
T1041 — Exfiltration Over C2 ChannelLarge outbound transfers to proxy or cloud destinations indicate data theft via controlled channels.
Recommendation — Map remote-service activity to lateral-movement techniques and hunt for abnormal admin access patterns. Correlate outbound transfer spikes with staging and exfiltration detections.
CIS Controls v8CIS-8 — Audit Log ManagementCorrelating access and theft requires consistent logging across remote access and outbound traffic.
Recommendation — Centralise and review remote-access and egress logs for linked intrusion and theft patterns.

Practitioner Guidance

What to prioritise: Correlate remote access, privilege use, and outbound transfer telemetry in a single investigation timeline. In practice, that means treating unusual SSH or RDP access as high priority when it is followed by archive creation, staging activity, or cloud/proxy egress.

What to verify: Confirm whether the source IP, device, and account normally belong to the user or system. If you cannot tie the access pattern to a legitimate operational need, assume the session is part of operator activity until you have evidence otherwise.

Practitioner takeaway: The decisive question is not whether the bank saw a login or a data transfer, but whether the same intrusion path is doing both, because that is what turns an incident into an active theft and extortion problem.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org