Ransomware Groups Target Backup Systems, Threatening Recovery

Summary
Ransomware operators are targeting backup systems and recovery points. The sponsored article reviews incidents involving BlackCat, BlackMatter and Gunra, and recommends isolated, immutable backups, stronger access controls, timely patching and restore testing.
Key points
- Ransomware operators may wipe recovery points and disrupt backup infrastructure before encrypting production systems.
- BlackMatter attackers used compromised administrator credentials to locate and erase or reformat backups on the same network as affected systems.
- In a Gunra case cited in a joint CISA and FBI advisory, stolen credentials enabled attackers to delete backup data at both a primary data center and a disaster recovery site.
- Shared networks and credentials can let one compromised account expose production systems and backups; the article recommends isolating backup environments and using MFA and role-based access controls.
- Immutable, write-once backup copies can prevent alteration or deletion, including by users with administrator credentials.
- The article also recommends patching backup software promptly and regularly testing restores, including through attack simulations.
Article Details
- Defense Focus
- Keep ransomware operators from destroying every usable recovery copy.
- Detection Methods
- Extend logging, monitoring, and alerting to backup infrastructure rather than monitoring only production systems.
- Data Sources
- Backup server logs
- Defensive Actions
- Separate critical backups from production networks and credentials so one compromised account cannot reach every copy.
- Use immutable, write-once backup storage that administrators cannot alter or delete.
- Require multi-factor authentication and role-based access controls for backup administration.
- Patch backup software with the same urgency as production systems.
- Regularly test restores, including attack scenario simulations.
MITRE ATT&CK
T1078 · Valid AccountsBlackMatter used compromised administrator credentials to locate backup stores and appliances; in a documented Gunra case, stolen credentials provided access to both backup locations.T1486 · Data Encrypted for ImpactALPHV/BlackCat encrypted Change Healthcare systems, and BlackMatter encrypted systems after destroying backups.T1490 · Inhibit System RecoveryBlackMatter wiped or reformatted backup stores and appliances before encryption; attackers in a documented Gunra case deleted backup and archived data at both primary and disaster recovery sites.