Direct delivery still matters because it gives attackers a fallback when brokered access is disrupted or too costly. It also lets them run lower volume, targeted campaigns that can bypass assumptions built around broker activity. Defenders should assume ransomware operators will keep using whichever delivery path is cheapest, fastest, and most reliable for the current environment.
Why direct delivery still matters in a brokered-access ecosystem
Ransomware groups do not choose one delivery path forever. Direct delivery remains useful because it preserves operational optionality: if brokered access is unavailable, expensive, noisy, or has poor success rates, the attacker can still pursue an intrusion path that fits the target and the moment. That makes direct delivery a live part of the threat model, not a legacy edge case.
Direct campaigns also change defender assumptions. Teams that focus too heavily on broker-mediated intrusions can underweight smaller, lower-volume attempts that arrive through phishing, exposed services, stolen credentials, or opportunistic exploitation. A Cisco Yanluowang breach 2022 shows how initial access can still be won directly through user manipulation and credential abuse when the attacker does not wait for a brokered handoff.
The practical takeaway is that delivery method is a campaign choice, not a category boundary. A defender should read direct delivery as evidence that the operator is adapting to cost, speed, or detection pressure, not as evidence that the threat is less mature.
How direct delivery changes detection and response priorities
Broker-heavy environments often build intuition around access resale, handoff points, and post-compromise tradecraft that follows a third-party intrusion. Direct delivery breaks that mental model because the same ransomware actor may now be responsible for the full intrusion chain, from first contact to encryption. That matters for triage, because the earliest telemetry may look like ordinary phishing, endpoint malware, brute-force activity, or public-facing exploitation rather than a classic brokered intrusion pattern.
Defenders should therefore watch for the points where broker assumptions fail: unusual login geography, single-host compromise followed by rapid privilege escalation, or small and targeted intrusion attempts that do not match mass spray-and-pray activity. Direct delivery often appears less scalable, but it can be more selective and more precise, which makes early containment more important than waiting for a broader campaign signature.
That is why external threat reporting remains useful even when the access path is changing. CISA cyber threat advisories help security teams anchor their hunting to current ransomware behaviors, while MITRE ATT&CK Enterprise Matrix is useful for mapping the post-access sequence from initial foothold to credential access, lateral movement, and impact.
Why mixed access strategies are the enduring ransomware pattern
Ransomware operators optimize for whatever access path is cheapest, fastest, and most reliable at that point in time. Brokered access is attractive when it reduces effort and blends into an established criminal supply chain, but direct delivery remains attractive when the operator wants tighter control over targeting, lower dependency on third parties, or a fallback when the marketplace is disrupted.
This mixed model also means the defender cannot build one playbook around one access path. A security program that only hunts for broker artifacts may miss direct campaigns that arrive through exposed remote access, commodity malware, or social engineering. Conversely, a program that only watches for commodity phishing may miss quieter, more deliberate direct intrusions that are designed to look like ordinary administrator activity until the final stage.
For that reason, access-path diversity is part of the attacker's resilience, and it should be treated as part of the defender's resilience problem too. The right question is not whether brokers are common, but whether the organisation can detect and contain intrusion when the actor chooses any feasible path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1589 — Gather Victim Identity Information | Ransomware delivery often starts with targeting and victim-specific access preparation. |
| Recommendation — Map observed intrusion steps to ATT&CK to separate initial access from follow-on actions. | ||
| CIS Controls v8 | CIS-5 — Account Management | Direct delivery frequently succeeds through abused accounts and weak access paths. |
| Recommendation — Tighten account management and review exposure paths that enable direct intrusion. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Direct and brokered intrusions both become more damaging when privilege is excessive. |
| Recommendation — Apply least-privilege limits so a direct foothold cannot quickly expand impact. | ||
Practitioner Guidance
What to prioritise: Build detection around intrusion behaviours, not around the presumed source of access. If your triage starts with "brokered or not," you are already behind the actor's decision tree.
What to verify: Confirm that your exposure review covers both broker-friendly entry points and direct entry points, especially remote access, public-facing services, and credential abuse pathways. If a control only helps after a broker handoff, it is incomplete for ransomware defense.
Common mistake: Treating lower-volume campaigns as lower-risk. Direct delivery is often quieter, not less dangerous, and quiet activity can still lead to privilege escalation and encryption.
Practitioner takeaway: Assume ransomware operators will keep both options open, so your controls must work when the intrusion is bought, built, or improvised on the spot.
Related resources from NHI Mgmt Group
- Why do still-valid secrets matter after public disclosure?
- Why does email still matter so much in ransomware campaigns?
- How should security teams respond when ransomware operators gain initial access through stolen credentials and then move laterally across endpoints?
- What breaks when initial access brokers feed ransomware operations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org