The Picus Blue Report 2026 data reveals a concerning trend in ransomware prevention effectiveness, with only 13% of tested attack activity being stopped by security controls This article explores picus analyzed ransomware. . This finding highlights the growing challenge for defenders as organizations often rely on multiple security products but may not always prevent attackers from using advanced techniques during real intrusions.
Picus analyzed ten ransomware families with the lowest prevention scores, including Play, BlackByte, LockBit, BabLock, Magniber, FAUST, Sodinokibi/REvil, Hive, BlackKingdom, and Maori. BabLock has been observed using legitimate uninstallers to remove security software, shutting down backup and database services, and deleting Security and System logs. Picus Mitigation Library, Vendor-specific Prevention Signatures (Source: picussecurity) T1055: Process Injection was also extensively utilized.
Magniber employs thread hijacking by pausing a target process's thread, injecting malicious code into memory, redirecting execution, and resuming the thread. Ransomware employs T1036: Masquerading to make its malicious activities seem legitimate by staging tools in trusted-looking public directories and using a service name that resembles the Sysinternals PsExec service. This can cause malicious files and services to blend into normal administrative activity, as seen with BlackByte's disguise of command-and-control-delivered key material as a PNG image file.
Other common techniques include registry modifications, reflective code loading, hidden artifacts, abusing trusted Windows binaries, and execution guardrails. Detect, investigate, and respond faster with ANY.RUN's in-browser data inspection.












