Most of the ransomware attacks targeting the enterprises occur outside working hours, during the nighttime or during the weekend. The timing of the attacks is not casual, attackers attempt to deploy the malware when the presence of the IT staff is reduced and the likelihood to be detected is low. The majority of these incidents appeared to be post-compromise infections, and we believe that threat actors are accelerating use of tactics including post compromise deployment to increase the likelihood of ransom payment. The dwell time between the first evidence of malicious activity compromise and the actual ransomware attack is on average three days.”]
Source: https://securityaffairs.co/wordpress/99844/malware/ransomware-deployments-report.html

