threat_intelligence1129 wordsRead on Arc Codex

Rubrik + RL: Bring Threat Intelligence and Detection to Backups

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialKey takeaways KNP Logistics had been moving freight around the United Kingdom for 158 years. Then the Akira ransomware group guessed one employee's password. By the time the intrusion was over, KNP's data was encrypted and its servers, its backups, and its disaster recovery systems had all been destroyed. The ransom demand ran as high as £5 million. KNP could not pay it and could not restore from anything. The company shut down, and 700 people lost their jobs. That is the scenario every backup platform exists to prevent, and it is the one ransomware operators now plan for first. Rubrik’s own research found that 96% of ransomware attacks target backup storage specifically. If attackers can reach the recovery path before they trigger encryption, there is nothing left to negotiate about. Rubrik and ReversingLabs are closing that path. Rubrik's Threat Monitoring and Threat Hunting now draw on ReversingLabs' ransomware intelligence, so the scans already running across your backup catalog are matching against one of the industry's deepest and freshest views of ransomware activity. No new console. No new agent. No data leaving where it already sits. For readers who know Rubrik better than they know us: ReversingLabs runs one of the largest malware analysis pipelines in the industry, with a corpus of more than 420 billion goodware and malware samples behind it. Security teams use that intelligence to decide, quickly and with confidence, whether a file is safe. Now it is pointed at your backups. Rubrik's Threat Monitoring scans backup snapshots for indicators of compromise (IoCs) directly on the infrastructure holding the data, using intelligence from Rubrik Zero Labs and other trusted sources. Nothing has to move for a scan to happen. Threat Hunting builds on that with file pattern, file hash, and YARA rule matching, scanning up to 75,000 backups in an estimated 60 seconds and walking the time-series history of snapshots to pinpoint a clean recovery point. Both capabilities are only as good as the intelligence behind them. That is the piece ReversingLabs supplies. RL maintains a dedicated ransomware feed built to track ransomware and ransomware-adjacent tooling: file hashes tied to known families, command-and-control infrastructure pulled from malware configurations, and payload delivery URLs. Every indicator carries MITRE ATT&CK mapping and a kill-chain stage tag — early, mid, or late. And the feed is aggressively maintained. Inactive IoCs get aged out rather than left to pile up and dilute the signal, which matters when you are matching against a catalog that spans years. This integration wires the two together. Rubrik's Threat Monitoring and Threat Hunting now incorporate ReversingLabs' ransomware feed as part of the threat intelligence backing their scans, alongside Rubrik's existing intelligence sources. Adam Turner, Threat Detection Product Manager at Rubrik said “threat intelligence is only as valuable as it is current”. Adam TurnerBringing ReversingLabs' ransomware feed into Threat Monitoring and Threat Hunting sharpens what our customers can detect in the data they will actually recover from — without asking them to move that data, stand up another service, or learn another console. Rubrik's Threat Monitoring can now scan backup snapshots against ReversingLabs' Ransomware Feed, backed by a corpus of more than 420 billion samples and a file reputation database covering more than 40 billion files, with each indicator tagged by MITRE ATT&CK context and ransomware kill-chain stage. KNP was not an outlier. The pattern shows up on an almost annual cycle, and backup software itself keeps being the way in. In September 2024, CVE-2024-40711 highlighted a critical (9.8 CVSS) unauthenticated remote code execution flaw in Backup & Replication. Within weeks, Sophos X-Ops observed the Akira and Fog ransomware groups exploiting it in the wild, with thousands of unpatched instances still exposed a month after the patch shipped. In 2025, it was CVE-2025-23120. In March 2026, another cluster of critical flaws — CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708, each rated 9.9 — came about alongside high-severity issues covering file manipulation and privilege escalation. Three years running: Same infrastructure category, same severity band, same playbook. The industry numbers say the same thing. Sophos found that 94% of organizations hit by ransomware had attackers specifically attempt to compromise their backups, and those attempts succeeded 57% of the time. The gap in outcomes is stark: when backups were compromised, victims were 63% more likely to have their data encrypted, nearly twice as likely to pay the ransom, and faced median recovery costs of $3 million against $375,000 for organizations whose backups survived. Median ransom demands more than doubled as well, to $2.3 million from $1 million. Sophos' 2026 report shows why that gap matters more each year, not less. Backup-based recovery now accounts for 66% of encrypted-data cases, up 12 points in a single year. Organizations are leaning on backups harder than ever — which is exactly what makes the backup worth attacking. Attacking the backup is not an afterthought. It is frequently step one. Here is the part that matters most for a backup platform specifically: Rubrik does not just scan the newest snapshot. Threat Hunting analyzes the time-series history of backups as far back as retention allows in order to pinpoint a clean recovery point. So when RL publishes a new ransomware hash today, Threat Hunting can check it against snapshots taken weeks or months ago — backups that were clean by every measure available when they were captured, and that a scan running only at ingest would never revisit. Ransomware intelligence has to move fast because ransomware operators do. New droppers, repacked payloads, and reused infrastructure land in RL's pipeline continuously. The question that matters is not whether a backup was clean the day it was taken. It is whether anyone goes back and checks it against what has been learned since. That is the gap this integration closes. Every organization backing up file servers, virtual machines, or cloud storage is sitting on a growing catalog of snapshots that looked clean at capture and may not read that way against today's intelligence. Ransomware groups have shown, repeatedly and on a predictable schedule, that backup infrastructure is worth attacking directly. Now the intelligence checking your backups keeps pace with the intelligence being used against them. To learn more, contact your Rubrik account team, or see how RL's ransomware intelligence works. Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence. This guide compares leading file security tools across connector coverage, throughput, file-size range, and file-type breadth. Package managers auto-pull the latest OSS version — malware included. Protect your pipelines with this free plugin.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.