The Kraken ransomware operation introduced a new benchmarking phase that helps the group decide how to encrypt each system. This change gives the attackers a faster and more adaptive method of damaging networks while making detection more difficult for defenders.
How the attack begins
Kraken operators prefer simple and reliable entry points. They search for exposed SMB services, weak RDP setups or unpatched systems. They also abuse stolen credentials to access internal networks. Once inside, they escalate privileges, disable protection tools and prepare the environment for encryption.
The attackers move through the network using remote administration tools, tunnelling utilities and scripted automation. Their goal is to reach critical systems with enough access to apply encryption across servers, workstations and virtualised infrastructure.
A new benchmarking technique
The latest Kraken samples include a performance-testing routine that runs before encryption begins. The malware creates a temporary file filled with random content. It encrypts that file, measures the time needed to complete the process and deletes the file immediately after the test.
Kraken then uses the collected data to choose between full encryption and partial encryption. Fast systems receive full encryption. Slower systems receive partial encryption to avoid detection through sudden performance drops. This approach increases reliability and helps attackers achieve consistent results across diverse environments.
Targets across Windows and Linux
Kraken supports several platforms. On Windows systems, it targets SQL servers, Hyper-V environments, mapped drives and network shares. It kills processes that may block encryption and clears event logs to limit forensic visibility.
On Linux and VMware ESXi hosts, Kraken stops running virtual machines and attacks their disk images directly. The malware uses the same benchmarking logic to adjust its approach. This gives the group one unified method that works across physical and virtual environments.
Why this tactic matters
Benchmarking allows Kraken to adapt its strategy to each system’s capabilities. Partial encryption reduces noise on slower machines and delays alerts. Full encryption strikes quickly on powerful hardware and destroys access to critical files.
This method increases the pressure on defenders because it removes predictable patterns. The ransomware changes behaviour in real time, which complicates automated detection and response workflows.
How organisations can defend themselves
Organisations can reduce their exposure through focused controls:
Strengthen network entry points
- Require strong multi-factor authentication.
- Block unnecessary SMB and RDP access.
- Patch exposed services quickly.
Improve visibility
- Detect unusual temporary file creation.
- Track encryption-related activity on virtual machine hosts.
- Monitor sudden attempts to stop security tools.
Protect backups
- Use offline or immutable backups.
- Test restore procedures often.
- Store recovery data outside the production network.
Segment infrastructure
- Enforce strict isolation for hypervisor hosts.
- Limit administrative credentials to essential personnel.
- Monitor lateral movement between critical systems.
Conclusion
Kraken ransomware now benchmarks systems to choose the best encryption method. This improvement gives attackers an efficient and flexible approach that increases the difficulty of detection. Strong authentication, tight segmentation and resilient backups help organisations reduce the impact of this evolving threat.


0 responses to “Kraken Ransomware Benchmarks Systems Before Encryption”