Ransomware Encrypts Nearly 100,000 Files in Under 45 Minutes

Since we launched SURGe last year, our team of strategic cybersecurity experts has been busy helping out security teams through various cyberattacks and security incidents. Today, we released new ransomware research, which analyzed how quickly ten major ransomware strains, including Lockbit, REvil and Blackmatter, could encrypt 100,000 files.

The research revealed that the median ransomware variant can encrypt nearly 100,000 files totalling 53.93GB in forty two minutes and fifty-two seconds. A successful ransomware infection can leave organizations without access to critical IP, employee information and customer data.

The aim of SURGe's work is to provide everyday defenders actionable knowledge, and our latest research examines an area of study that only ransomware operators seem to have explored. Many security teams focus on mitigation and response when it comes to ransomware inflections, however, the encryption speeds we discovered in our report are beyond the capabilities of most organizations. Based on this research, it’s safe to say that if an enterprise is hit with a ransomware attack, it may be too late to stop it from spreading.

Overall, the report revealed that the impact of ransomware can fluctuate across strains and resources. Key findings from the research include:

Ultimately, this research demonstrates the need for organizations to move away from response and mitigation, and concentrate on preventing ransomware infections. Practical steps and strategies organizations can take to prevent infections can include better patching, asset inventory, MFA and looking for ransomware actors on the network before they deploy their ransomware binaries. In addition, SURGe not only created the data, but will release it on bots.splunk.com network defenders to analyze and review themselves. We encourage blue teams and researchers to look at our work themselves.

This is the first of several whitepapers this year that will unveil research findings that are relevant to security teams everywhere — so get a copy of the An Empirically Comparative Analysis of Ransomware Binaries whitepaper today. In addition, please check out Shannon Davis’s blog for more information on the research.

Methodology

For this research, SURGe created a modified version of the Splunk Attack Range lab environment to execute ten samples of each of the ten ransomware variants against four hosts with mid and high hardware specs: two running the operating system Windows 10 and the other two running Server 2019. SURGe enabled Windows logging on each host to collect, synthesize and analyze the data in Splunk. This allowed the researchers to measure how fast the ransomware variants encrypted nearly 100,000 files and how the ransomware utilized system resources like processor, memory and disk.

About SURGe

Established in October 2021, SURGe is Splunk’s strategic cybersecurity research arm dedicated to researching, responding and educating on the cyberthreats impacting the world. As a trusted advisor, SURGe provides organizations with technical guidance during high-profile, time-sensitive cyberattacks via response guides and in-depth analyses in research papers, conference papers, and webinars. Organizations can count on SURGe to provide appropriate context and timely recommendations to navigate global security incidents with confidence and intelligence.

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.