Case Study

What 53 Ransomware Strains Reveal About Backup and Recovery
This threat intelligence report from Cohesity REDLab evaluates ransomware behavior across 53 families detonated in isolated, production-grade backup environments. It delivers quantitative resilience benchmarks, MITRE ATT&CK mappings, and actionable architectural guidance to defend the data protection tier. Quantitative threat intelligence and operational benchmarks from 53 controlled ransomware detonations against enterprise backup infrastructure.
- Topic
- Security
- Published
- 25 Sept 2026

Public reporting on ransomware frequently focuses on endpoint encryption and initial access vectors, leaving a significant gap in understanding how attacks impact the backup infrastructure required for recovery. Cohesity REDLab addresses this gap by executing controlled detonations of 53 contemporary ransomware families against enterprise backup environments running Cohesity DataProtect and Cohesity NetBackup.
The report demonstrates that threat actors actively target backup infrastructure using a 5-step "Anti-Backup Kill Chain". It classifies operational outcomes into three distinct failure and success modes, highlighting how signal capabilities, such as Image Entropy, Job Metadata, and Client Offline anomalies, detect hidden encryption that bypasses endpoint defenses. To assist security and risk executives in evaluating their posture, the report provides a Backup Resilience Scorecard crosswalked with cyber insurance controls and projects critical threat shifts over the next 12 to 18 months.
Key Highlights:
Empirical Ransomware Testing: Evaluated 53 live ransomware families and 15 additional advisories in an air-gapped detonation facility.
Backup Tier Targeting: Assesses with high confidence that ransomware operators treat enterprise backup systems as a primary target rather than a secondary objective.
Anti-Backup Kill Chain: Mapped a 5-step kill chain spanning process discovery, credential harvesting, recovery sabotage, data encryption, and snapshot tamper attempts.
Outcome Classification: Categorized backup interactions into three distinct outcomes: communication disrupted (Category A), client data encrypted with intact jobs (Category B), and successful backup preservation (Category C).
The Stealth Hazard: Identifies Category B (completed backups ingesting encrypted data) as the highest risk scenario, requiring automated backup-tier anomaly detection.
Evasion-Resistant Detection: Proves that Image Entropy anomalies detect encrypted files regardless of endpoint evasion tactics like BYOVD or Living-off-the-Land.
Sub-20-Second Scoping: Demonstrates that Rapid Threat Hunt can query SHA-256 hashes across production-scale clusters to scope blast radius in seconds.
Snapshot Immutability: Observed zero mutations of immutable Cohesity snapshots across all 53 detonated ransomware strains.
Backup Resilience Scorecard: Introduces a maturity framework across TTP resistance, detection coverage, remediation validation, and time-to-validated-recovery.
Cyber Insurance Alignment: Directly maps scorecard metrics to standard cyber insurance renewal questionnaires and underwriter requirements.
Exploit Window Compression: Highlights how public CVE disclosures are being weaponized into active ransomware campaigns within hours to weeks.
