Ransomware deployment
In your opinion, what's a ransomware operator's worst enemy? Yes, you're right, backups – secure and not tampered with backups. But they have a very bad weakness – they can be deleted by threat actors.
Unfortunately, system administrators often don't think about either the 3-2-1 rule (3 backup copies on 2 different media with 1 located offsite) or separate accounts and multi-factor authentication for the backup servers. What's more, nowadays, having proper secure backups isn't only important for ransomware mitigation, but also to ensure an organization meets industry regulatory requirements.
What does this mean? If the attackers obtain domain administrator credentials, they can easily access the backup servers and wipe all available backups. That's it, so the victim company has no other choice than to pay the ransom.
Also, talking about backups, some ransomware samples have built-in capabilities for wiping...