Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Cohesity REDLab's new report delivers what we believe is the industry's first quantitative resilience benchmark for enterprise backup infrastructure—built on real detonations, not assumptions.
Everyone knows ransomware operators hunt for your backups. The logic is brutal and simple: destroy the backups and recovery dies with them. No restore. No "business as usual." Game over.
So, we asked the question nobody had actually answered: what happens when ransomware reaches the backup tier?
To find out, Cohesity REDLab did something we believe no vendor has done before. Over 17 months, we took 53 live ransomware strains and detonated them against real backup infrastructure—in a lab built for exactly this kind of chaos. We mapped every strain to MITRE ATT&CK, gathered the telemetry, and logged every test.
The results answer the questions most teams can only guess at: how ransomware actually attacks your backup tier, and how to make backup infrastructure more resilient to threats.
Some of what we found we expected. Some of it we didn't. It's all in Ransomware vs. The Last Line of Defense. Keep reading for the highlights, then download the full report.
Our findings confirm that the backup tier isn’t a late-stage target anymore. The old picture—encrypt production, then trip over the backups during cleanup—is out of date. Several 2025 and 2026 strains went straight for the recovery machinery in the native OS, encrypting configuration files alongside the primary data and disrupting communication to break recovery on purpose.
When that happened, the failed job was flagged for an admin. Gagakick, LockBit 5.0, MedusaLocker v3, and SafePay all behaved this way. The takeaway is uncomfortable but simple: Assume your backup plane is in play in the first hours of an intrusion. Treat any alert about its status as urgent. Investigate immediately, not when you get around to it.
You invest in prevention and detection. You should. But those systems can’t stop everything—and the strains we tested and tracked are genuinely good at evading them.
Akira loads vulnerable signed drivers to switch off EDR. Qilin lives off the land with tools like PowerShell and PsExec. DireWolf hides beneath the operating system itself. At the endpoint, these tactics work—the tooling goes dark.
But none of it changed what showed up at the backup tier.
Encryption raises the entropy of data no matter how cleverly the malware got there, and the entropy alarm doesn’t care how the endpoint was evaded. The backup tier sees the state of the files—one thing an attacker can’t disguise. This is another reason why your backup estate should be an integral part of your threat detection capabilities.
Once malware is inside, how does it hunt down your data protection infrastructure? We watched it happen 53 times, and the same sequences kept appearing: the Anti-Backup Kill Chain. Attackers locate the backup assets, get hold of credentials, disable the recovery mechanisms—shadow copies, backup services, restore points—then go after the data and configuration to poison recovery. Credential compromise is the hinge.
In our data, the strains that did real damage almost always did it with compromised credentials, not by exploiting the platform itself.
The good news for Cohesity customers: in our testing, not one strain in the set was able to alter an immutable snapshot.
Here’s the finding that should keep you up at night. A backup job can finish, report success, and still contain ransomware.
For research purposes, we detonated some ransomware strains on the platform without enabling key features like anomaly detection or threat protection. In a whole category of our tests, the malware encrypted the data, the next job ran without complaint, and it dutifully backed up the encrypted files.
So how do you catch what a green checkmark hides? The platform identified anomalies in encrypted data: file counts, sizes, and dedupe ratios drifting outside their normal range, and entropy climbing the way it only does when there’s an encryption event.
For dormant ransomware strains, REDLab used the platform’s threat hunting capabilities. These features flagged malicious artifacts before anyone restored them. In one April test, a single threat hunt swept 11 production-scale clusters and came back with actionable results in 18 seconds.
So, don’t blindly trust a successful backup. Use anomaly detection and scan for threats before you restore, or you’ll just put malware back.
We turned what we saw into a scorecard, a useful way to grade the resilience posture of your own backup infrastructure.
It rates four things on a one-to-five scale, fragile to resilient:
The report also features a six-point checklist that turns each scorecard dimension into a yes-or-no question. It covers immutable snapshots, isolated credentials, SOC-wired anomaly detection, gated recovery, and blast-radius scoping. Read it to see where your backup infrastructure stands.
Cohesity REDLab aims to be the data protection industry’s best dedicated source of actionable intelligence on the interaction between malware and backup infrastructure.
Our research is written for the people who answer for recovery when an incident hits: IR teams, CISOs, CIOs, infrastructure and security leaders, architects, and the underwriters who price their risk.
Across all strains we ran against Cohesity DataProtect, the backup kept working, and a clean, recoverable copy survived in each test we ran—every single time. For Cohesity NetBackup, whenever communication was disrupted in backup processes, REDLab observed at least one backup-tier anomaly signal.
The products performed well because of their architecture: immutable snapshots, credentials that don’t cross between workload and backup, alerts that surface where your SOC actually looks, and a scan step you can’t skip before a restore. Get those right and the last line of defense holds.
You’ve seen the highlights. The full report has the strain-by-strain data, the complete kill chain, and the scorecard you can run against your own environment.
Learn more:
Written By
Amol Sarwate
Head of Security Research and REDLab, Cohesity