Table of Contents
If they are used well, backup tools can play a key role in the battle against ransomware attacks. Contrary to popular opinion, they don’t have to be limited to simply creating backups and recovering data.
This article looks at the advanced functionality resource-protection software now offers for detecting threats — including anomaly detection and pre-restore malware scanning — and asks a question that’s only gotten more relevant since this piece was first written: can backup be an effective detection layer, not just a recovery one, when antivirus and EDR alone are struggling to keep pace with the volume and sophistication of today’s attacks?
The evolution of ransomware
The first modern crypto-ransomware attacks date to 2013. The playbook was simple: encrypt files, demand payment for the decryptor. That core model hasn’t changed — what’s changed is the scale and the business behind it. Attackers now routinely encrypt not just local data but every network resource reachable from a logged-in session, including backup targets, and double extortion — encrypting data and threatening to leak it — is no longer the exception. It’s the default: present in the large majority of ransomware claims tracked by insurers in 2025–2026.
The numbers back up how far this has scaled. Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026 — a 24.9% year-over-year increase and the fourth straight year leak-site disclosures have hit a new high. Halcyon now tracks roughly 95 active ransomware gangs globally, up about 40% year-over-year, as Ransomware-as-a-Service continues to lower the bar for entry — 55 new RaaS families emerged in a single recent year. Maze and Sodinokibi/REvil, the groups that defined this landscape when this article was first written, have since gone quiet or been dismantled; today’s most active leak-site operators, including Qilin and newer entrants like The Gentlemen, are proof the business model outlives any single gang.
It’s precisely because sensitive data can end up published — not just encrypted — that backup alone was never a complete security guarantee. Interestingly, some security teams now report being more worried about the leak than the encryption. Relying solely on prevention software without regular, verified backups is still the riskier position; conversely, air-gapped or offline media (USB drives, tape) is a real layer of defense, but it isn’t a substitute for automation — backup that depends on someone remembering to disconnect a drive is backup that will eventually fail exactly when it’s needed.
Is detecting attacks still fundamental?
If anything, detection matters more now than when this was first written. CrowdStrike’s 2025 threat report found that 79% of initial access attempts are now malware-free — attackers increasingly rely on stolen credentials, access brokers, and legitimate admin tools rather than a payload a signature-based scanner would catch. That’s the core weakness in traditional antivirus: it’s built to recognize known bad code, and an attacker who never runs known bad code walks past it.
EDR closes part of that gap but brings a different problem: it generates a volume of telemetry that requires a trained analyst to interpret, which puts effective use out of reach for many small and mid-sized teams. That gap is exactly why backup vendors have been asked to shoulder part of the detection burden — not as a replacement for endpoint security, but as an additional signal sitting closer to the data itself.
The stakes for getting this wrong keep rising: one 2024 industry study found that 94% of organizations hit by ransomware saw attackers also attempt to compromise their backups directly, and organizations whose backups were successfully compromised faced median recovery costs roughly 8x higher than those whose backups held. Backup isn’t a bystander in a ransomware incident anymore — it’s a target in its own right.
The unknown and unappreciated side of backup tools
Because ransomware targets data, backup platform security is fundamental to recovery — and backup vendors have been building out functionality in three areas: detecting attacks, protecting the backup system itself, and enabling rapid recovery. The first of these is still the least understood.
Malicious-activity detection inside backup platforms generally works two ways:
Anomaly detection. Backup software can flag unusual input/output patterns — an unexpected jump in daily incremental backup size, for instance — and alert administrators when something deviates from the normal baseline. This is valuable twice over: it’s an early warning that something may be wrong, and later, during recovery, it helps pinpoint the last known-good backup before the anomaly started.
Malware and threat scanning. After a backup completes, the copied data can be scanned for known malicious signatures without touching production performance. This can also run retroactively: once a new malware signature becomes available, deep scanning can walk back through existing backup history to find when an infection actually started and isolate the earliest clean point.
Neither function is a complete replacement for host-based endpoint security, and neither should be sold as one — but together they give an organization an additional detection layer sitting directly on the data that matters most, which is exactly the layer an attacker is now most likely to target. For a deeper look at how immutability, isolation, and anomaly detection combine into what the industry now calls cyber-resilient backup — including how it maps to DORA and NIS2 audit requirements — see Backup Isn’t Enough Anymore. For a broader walkthrough of layered ransomware defense, see Data Protection Against Ransomware.
How this looks inside Storware Backup and Recovery
At a glance: three layers of ransomware detection
| Traditional antivirus | EDR | Backup-based detection | |
|---|---|---|---|
| Catches | Known malware signatures | Broad endpoint telemetry and behavior | Unusual backup patterns + signature scan on backup copies |
| Needs | Regular signature updates | A dedicated security analyst | Nothing beyond the existing backup schedule |
| Blind spot | New or unknown malware, credential-based attacks | Alert volume and analysis backlog | Detection lag tied to backup interval, not real-time |
| Best fit | Baseline hygiene | Larger teams with a SOC | Teams without a SOC; last line of defense before recovery |
Frequently Asked Questions
Can backup software detect ransomware?
Yes. Modern backup platforms can flag ransomware activity two ways: anomaly detection (unusual changes in backup size or I/O patterns) and malware/threat scanning (checking backup copies against known signatures). Neither replaces endpoint security, but both add a detection layer sitting directly on the data an attacker is trying to reach.
What's the difference between anomaly detection and malware scanning in backup tools?
Anomaly detection asks whether a backup looks different from its normal baseline, which is what lets it catch novel or unknown attacks. Malware scanning asks whether a backup contains a known-bad signature — precise, but blind to anything without an existing signature. Used together, they cover more ground than either does alone.
Why do ransomware attackers target backups directly?
Because a clean backup is a victim’s way out of paying. The large majority of recent ransomware incidents include an attempt to compromise the backup environment itself — deleting, encrypting, or disabling it — specifically to remove that option and increase pressure to pay.

