Loading
Report

Ransomware vs.
the last line of defense

We detonated 53 live ransomware strains  against production-grade backup infrastructure in an air-gapped lab. then recorded exactly what happened.

53 strains detonated
17 months of research
1 air-gapped lab

We wanted to answer a simple question:

“When real world ransomware reaches your backup
systems, what actually happens?

Cohesity REDLab is a team of expert researchers who run an air-gapped facility, executing live malware against production-grade DataProtect and NetBackup deployments. We’re the data protection industry's only dedicated source of actionable intelligence on how malware interacts with backup infrastructure.

REDLab tested 53 ransomware strains collected in the wild over the last 17 months.

Here’s how we did it.

01 Detonate

Execute live malware against production-grade Cohesity products in an air-gapped lab using current software.

02 Map & measure

Map every strain to MITRE ATT&CK and capture the same five measurement points per detonation for cross-strain comparison.

03 Prove & reproduce

Log every test with timestamp, sample hash, and platform version.

By the numbers

Real malware, real backups
53

Live ransomware strains detonated against real backup infrastructure in our air-gapped lab

Five ways to see it
5

Backup-tier signals that catch ransomware: Client Offline, Job Metadata, Image Entropy, Threat Scan, and Rapid Threat Hunt.

Three ways it ends
3

Every detonation ends one of three ways: communication cut, backup corrupted, or recovery preserved

The road to recovery, blocked
5

Steps in the Anti-Backup Kill Chain: discover, steal credentials, disable recovery, target configs, attempt snapshot tampering

Immutable means immutable

0
Immutable snapshots successfully altered by any strain, across the entire dataset

Ransomware targets enterprise backup infrastructure

Attackers no longer hit backups by accident. They go after them deliberately, often within the first hours of an intrusion.

Multiple strains specifically encrypted backup files via the underlying OS. They did this to disrupt recovery (Find, Trial recovery, Payload).

The same attack patterns show up again and again: recovery inhibition (T1490), service stop (T1489), and abuse of valid accounts (T1078).

The Cohesity Anti-Backup Kill Chain

How malware compromises backups, and how you can stop it

01

Backup process
discovery

02

Credential harvesting of
backup admins

03

Shadow copy
disabling

04

Configuration file
encryption of backups

05

Snapshot tamper
attempts

Benchmark your backup infrastructure resilience

Icon1

Anti-backup TTP resistance

Architectural resistance to the techniques in REDLab's Anti-Backup Kill Chain (process discovery, credential harvesting, shadow-copy deletion, configuration tampering, and snapshot tampering)

Icon2

Detection coverage

Backup-tier signal availability for detecting ransomware-driven backup deviation prior to restore

Recovery remediation validation

Architectural assurance that a recovery point is clean prior to use in restore

Time-to-validated recovery

Elapsed time from initial anomaly signal to validated clean restore

Learn what live testing of 53 ransomware strains revealed about the resilience of data protection platforms
Global cyber resilience report
Loading