Back Reversinglabs Rubrik + RL: Bring Threat Intelligence and Detection to Backups | RL Blog
KNP Logistics had been moving freight around the United Kingdom for 158 years. Then the Akira ransomware group guessed one employee's password. By the time the intrusion was over, KNP's data was encrypted and its servers, its backups, and its disaster recovery systems had all been destroyed. The ransom demand ran as high as £5 million. KNP could not pay it and could not restore from anything. The company shut down, and 700 people lost their jobs.
That is the scenario every backup platform exists to prevent, and it is the one ransomware operators now plan for first. Rubrik’s own research found that 96% of ransomware attacks target backup storage specifically . If attackers can reach the recovery path before they trigger encryption, there is nothing left to negotiate .
Rubrik and ReversingLabs are closing that path. Rubrik's Threat Monitoring and Threat Hunting now draw on ReversingLabs' ransomware intelligence, so the scans already running across your backup catalog are matching against one of the industry's deepest and freshest views of ransomware activity. No new console. No new agent. No data leaving where it already sits.
For readers who know Rubrik better than they know us: ReversingLabs runs one of the largest malware analysis pipelines in the industry, with a corpus of more than 420 billion goodware and malware samples behind it. Security teams use that intelligence to decide, quickly and with confidence, whether a file is safe. Now it is pointed at your backups.
Rubrik + ReversingLabs: Your Backups Might Be Infected. Now You'll Know.
Rubrik's Threat Monitoring scans backup snapshots for indicators of compromise (IoCs) directly on the infrastructure holding the data, using intelligence from Rubrik Zero Labs and other trusted sources. Nothing has to move for a scan to happen. Threat Hunting builds on that with file pattern, file hash, and YARA rule matching, scanning up to 75,000 backups in an estimated 60 seconds and walking the time-series history of snapshots to pinpoint a clean recovery point.
Both capabilities are only as good as the intelligence behind them. That is the piece ReversingLabs supplies.
RL maintains a dedicated ransomware feed built to track ransomware and ransomware-adjacent tooling: file hashes tied to known families, command-and-control infrastructure pulled from malware configurations, and payload delivery URLs. Every indicator carries MITRE ATT&CK mapping and a kill-chain stage tag — early, mid, or late. And the feed is aggressively maintained. Inactive IoCs get aged out rather than left to pile up and dilute the signal, which matters when you are matching against a catalog that spans years.
This integration wires the two together. Rubrik's Threat Monitoring and Threat Hunting now incorporate ReversingLabs' ransomware feed as part of the threat intelligence backing their scans, alongside Rubrik's existing intelligence sources. Adam Turner, Threat Detection Product Manager at Rubrik said “threat intelligence is only as valuable as it is current” .
Bringing ReversingLabs' ransomware feed into Threat Monitoring and Threat Hunting sharpens what our customers can detect in the data they will actually recover from — without asking them to move that data, stand up another service, or learn another console. Adam Turner
Bringing ReversingLabs' ransomware feed into Threat Monitoring and Threat Hunting sharpens what our customers can detect in the data they will actually recover from — without asking them to move that data, stand up another service, or learn another console.
Rubrik's Threat Monitoring can now scan backup snapshots against ReversingLabs' Ransomware Feed, backed by a corpus of more than 420 billion samples and a file reputation database covering more than 40 billion files, with each indicator tagged by MITRE ATT&CK context and ransomware kill-chain stage.
Why Backups Have Become the Primary Target, Not the Last Resort
KNP was not an outlier. The pattern shows up on an almost annual cycle, and backup software itself keeps being the way in.
In September 2024, CVE-2024-40711 highlighted a critical (9.8 CVSS) unauthenticated remote code execution flaw in Backup & Replication. Within weeks, Sophos X-Ops observed the Akira and Fog ransomware groups exploiting it in the wild, with thousands of unpatched instances still exposed a month after the patch shipped. In 2025, it was CVE-2025-23120. In March 2026, another cluster of critical flaws — CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708, each rated 9.9 — came alongside high-severity issues covering file manipulation and privilege escalation. Three years running: Same infrastructure category, same severity band, same playbook.
The industry numbers say the same thing. Sophos found that 94% of organizations hit by ransomware had attackers specifically attempt to compromise their backups, and those attempts succeeded 57% of the time. The gap in outcomes is stark: when backups were compromised, victims were 63% more likely to have their data encrypted, nearly twice as likely to pay the ransom, and faced median recovery costs of $3 million against $375,000 for organizations whose backups survived. Median ransom demands more than doubled as well, to $2.3 million from $1 million.
Sophos' 2026 report shows why that gap matters more each year, not less. Backup-based recovery now accounts for 66% of encrypted-data cases, up 12 points in a single year. Organizations are leaning on backups harder than ever — which is exactly what makes the backup worth attacking.
Attacking the backup is not an afterthought. It is frequently step one.
What This Looks Like in Practice
Built into the scan, not bolted on. RL's Ransomware Feed feeds the intelligence behind Threat Monitoring and Threat Hunting directly. There is no separate service to stand up, no per-workload setup, and no new agent to deploy.
File-first coverage that matches how backups get scanned. The feed's hash indicators (SHA-1, MD5, and SHA-256) line up with the file pattern, file hash, and YARA rule matching Threat Hunting already performs across snapshot catalogs. Command-and-control and delivery-URL indicators add context for network-facing investigation.
Scale that does not slow down. Threat Hunting scans up to 75,000 backups in an estimated 60 seconds. Richer, ransomware-specific intelligence extends what that scan catches without costing you a second of that.
Stage-aware triage. Each indicator's kill-chain tag — early reconnaissance, mid-stage lateral movement, or late-stage encryption and exfiltration — tells your team how urgent a match is the moment it lands.
Intelligence that does not go stale. RL ages out inactive indicators aggressively, so the working set stays current instead of accumulating noise across a backup catalog that can span years of snapshots.
Context that skips a step. MITRE ATT&CK mapping travels with each match, so an analyst goes from "we found something" to "here is what it does and where it fits" without opening a research tab.
Close the Gap Between New Intelligence and Old Backups
Here is the part that matters most for a backup platform specifically: Rubrik does not just scan the newest snapshot. Threat Hunting analyzes the time-series history of backups as far back as retention allows in order to pinpoint a clean recovery point.
So when RL publishes a new ransomware hash today, Threat Hunting can check it against snapshots taken weeks or months ago — backups that were clean by every measure available when they were captured, and that a scan running only at ingest would never revisit.
Ransomware intelligence has to move fast because ransomware operators do. New droppers, repacked payloads, and reused infrastructure land in RL's pipeline continuously. The question that matters is not whether a backup was clean the day it was taken. It is whether anyone goes back and checks it against what has been learned since.
That is the gap this integration closes. Every organization backing up file servers, virtual machines, or cloud storage is sitting on a growing catalog of snapshots that looked clean at capture and may not read that way against today's intelligence. Ransomware groups have shown, repeatedly and on a predictable schedule, that backup infrastructure is worth attacking directly.
Now the intelligence checking your backups keeps pace with the intelligence being used against them.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
