Index Engines has released new research showing ransomware operators are increasingly using corruption techniques designed to avoid traditional indicators of an attack, potentially making compromised data appear safe for recovery.
The Holmdel, New Jersey-based cyber resilience company analyzed 1,064 ransomware strains acquired and detonated by its CyberSense Research Lab during the first half of 2026. Directory-entry destruction appeared in 47.8% of the strains, compared with 18.3% that exhibited full encryption.
Researchers also identified ransomware that preserved file extensions and timestamps, maintained low entropy, encrypted data slowly or targeted only selected portions of files. Those techniques can reduce indicators commonly used by security tools to identify ransomware activity.
“Bad actors know what scanning tools look for, and the variants we detonated this year are built to hide it,” said Jim McGann, chief marketing officer at Index Engines. He cited one variant, Encoder, that damaged files while leaving their names, sizes, timestamps and entropy unchanged.
Attack speed remains another challenge. According to the research, ransomware in the lab detonations corrupted a median of approximately 97,321 files per hour, reaching 10,000 affected files in about six minutes.
Index Engines also found polymorphism in 64.7% of the samples. These variants maintained their functional code while changing their file signatures between builds, complicating detection by tools that rely on previously identified signatures.
None of the 1,064 strains analyzed showed artificial intelligence making decisions about data at the destructive payload stage. Index Engines noted that other industry research has identified AI use earlier in the attack lifecycle, including reconnaissance and lateral movement.
The findings have implications for recovery strategies because files that retain familiar names, timestamps and other characteristics may still contain corrupted data. Index Engines said organizations should validate data integrity before selecting recovery copies rather than relying solely on conventional signs of encryption or modification.
The company cautioned that the findings represent ransomware variants acquired and tested by its research lab and should not be interpreted as estimates of how frequently each technique occurs in real-world attacks. Individual samples also could exhibit multiple behaviors.
Index Engines develops cyber resilience technology focused on detecting ransomware-related data corruption. Its CyberSense platform uses content and structural analysis to identify compromised data and help organizations determine clean recovery points.
Click Here For The Original Source.
