Blog 17.09.2021r.

Ransomware Detection Through Backup: Beyond Recovery

How anomaly detection and malware scanning inside backup platforms add a detection layer against ransomware — and why backup is now a target, not just a safety net.

If they are used well, backup tools can play a key role in the battle against ransomware attacks. Contrary to popular opinion, they don’t have to be limited to simply creating backups and recovering data.

This article looks at the advanced functionality resource-protection software now offers for detecting threats — including anomaly detection and pre-restore malware scanning — and asks a question that’s only gotten more relevant since this piece was first written: can backup be an effective detection layer, not just a recovery one, when antivirus and EDR alone are struggling to keep pace with the volume and sophistication of today’s attacks?

The evolution of ransomware

The first modern crypto-ransomware attacks date to 2013. The playbook was simple: encrypt files, demand payment for the decryptor. That core model hasn’t changed — what’s changed is the scale and the business behind it. Attackers now routinely encrypt not just local data but every network resource reachable from a logged-in session, including backup targets, and double extortion — encrypting data and threatening to leak it — is no longer the exception. It’s the default: present in the large majority of ransomware claims tracked by insurers in 2025–2026.

The numbers back up how far this has scaled. Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026 — a 24.9% year-over-year increase and the fourth straight year leak-site disclosures have hit a new high. Halcyon now tracks roughly 95 active ransomware gangs globally, up about 40% year-over-year, as Ransomware-as-a-Service continues to lower the bar for entry — 55 new RaaS families emerged in a single recent year. Maze and Sodinokibi/REvil, the groups that defined this landscape when this article was first written, have since gone quiet or been dismantled; today’s most active leak-site operators, including Qilin and newer entrants like The Gentlemen, are proof the business model outlives any single gang.

It’s precisely because sensitive data can end up published — not just encrypted — that backup alone was never a complete security guarantee. Interestingly, some security teams now report being more worried about the leak than the encryption. Relying solely on prevention software without regular, verified backups is still the riskier position; conversely, air-gapped or offline media (USB drives, tape) is a real layer of defense, but it isn’t a substitute for automation — backup that depends on someone remembering to disconnect a drive is backup that will eventually fail exactly when it’s needed.

Is detecting attacks still fundamental?

If anything, detection matters more now than when this was first written. CrowdStrike’s 2025 threat report found that 79% of initial access attempts are now malware-free — attackers increasingly rely on stolen credentials, access brokers, and legitimate admin tools rather than a payload a signature-based scanner would catch. That’s the core weakness in traditional antivirus: it’s built to recognize known bad code, and an attacker who never runs known bad code walks past it.

EDR closes part of that gap but brings a different problem: it generates a volume of telemetry that requires a trained analyst to interpret, which puts effective use out of reach for many small and mid-sized teams. That gap is exactly why backup vendors have been asked to shoulder part of the detection burden — not as a replacement for endpoint security, but as an additional signal sitting closer to the data itself.

The stakes for getting this wrong keep rising: one 2024 industry study found that 94% of organizations hit by ransomware saw attackers also attempt to compromise their backups directly, and organizations whose backups were successfully compromised faced median recovery costs roughly 8x higher than those whose backups held. Backup isn’t a bystander in a ransomware incident anymore — it’s a target in its own right.

The unknown and unappreciated side of backup tools

Because ransomware targets data, backup platform security is fundamental to recovery — and backup vendors have been building out functionality in three areas: detecting attacks, protecting the backup system itself, and enabling rapid recovery. The first of these is still the least understood.

Malicious-activity detection inside backup platforms generally works two ways:

Anomaly detection. Backup software can flag unusual input/output patterns — an unexpected jump in daily incremental backup size, for instance — and alert administrators when something deviates from the normal baseline. This is valuable twice over: it’s an early warning that something may be wrong, and later, during recovery, it helps pinpoint the last known-good backup before the anomaly started.

Malware and threat scanning. After a backup completes, the copied data can be scanned for known malicious signatures without touching production performance. This can also run retroactively: once a new malware signature becomes available, deep scanning can walk back through existing backup history to find when an infection actually started and isolate the earliest clean point.

Neither function is a complete replacement for host-based endpoint security, and neither should be sold as one — but together they give an organization an additional detection layer sitting directly on the data that matters most, which is exactly the layer an attacker is now most likely to target. For a deeper look at how immutability, isolation, and anomaly detection combine into what the industry now calls cyber-resilient backup — including how it maps to DORA and NIS2 audit requirements — see Backup Isn’t Enough Anymore. For a broader walkthrough of layered ransomware defense, see Data Protection Against Ransomware.

How this looks inside Storware Backup and Recovery

At a glance: three layers of ransomware detection

Traditional antivirusEDRBackup-based detection
CatchesKnown malware signaturesBroad endpoint telemetry and behaviorUnusual backup patterns + signature scan on backup copies
NeedsRegular signature updatesA dedicated security analystNothing beyond the existing backup schedule
Blind spotNew or unknown malware, credential-based attacksAlert volume and analysis backlogDetection lag tied to backup interval, not real-time
Best fitBaseline hygieneLarger teams with a SOCTeams without a SOC; last line of defense before recovery

Frequently Asked Questions

Can backup software detect ransomware?

What's the difference between anomaly detection and malware scanning in backup tools?

Why do ransomware attackers target backups directly?

Blog

You might also like...

Borderless Data Was Never Borderless: Geopolitical Risk in Data Protection Blog

Borderless Data Was Never Borderless: Geopolitical Risk in Data Protection

AWS data loss in the Gulf, the CLOUD Act and the EU Data Act are changing how firms protect data. What digital sovereignty means for recovery in 2026.

Read more
Trilio Alternative: How Storware Compares for OpenStack Backup and Disaster Recovery Blog

Trilio Alternative: How Storware Compares for OpenStack Backup and Disaster Recovery

Looking for a Trilio alternative? Compare Storware and Trilio for OpenStack backup and DR: architecture, recovery options, immutability and licensing.

Read more
Storware Backup and Recovery 8.0: What’s New for OpenStack, Nutanix and Kubernetes News

Storware Backup and Recovery 8.0: What’s New for OpenStack, Nutanix and Kubernetes

Storware Backup and Recovery 8.0 adds OpenStack 2026.1 support, unified disk attachment, Everpure CBT, Nutanix API v4 and SUSE Virtualization.

Read more

Ready to protect your data?