How Ransomware Can Lie Dormant for Months

Sleeping malware can wake at the worst possible moment.

Ransomware sometimes remains inactive until conditions are ideal. This “dormant” phase avoids detection by antivirus software. Once triggered—by date, network, or user action—it activates, encrypting files rapidly. This strategy increases success and avoids early exposure. Dormancy complicates investigation and response.

Why This Matters

It matters because attacks may strike long after infection. Detection requires proactive monitoring.

It also challenges forensic investigations and legal recourse.

Did You Know?

Some ransomware can remain inactive for months before activating.

Source

[McAfee, mcafee.com]

AD 1
AD 2