Source: The Adversary Co.
Author: By: Matt Millen
URL: https://adversaryco.com/blog/breaking-bad-backups.html
https://adversaryco.com/blog/breaking-bad-backups.html
ONE SENTENCE SUMMARY:
Real pentests show misconfigured backup infrastructure, especially domain-joined Veeam, enables credential theft, backup destruction, and full domain compromise.
MAIN POINTS:
- Ransomware increasingly targets backup repositories to block recovery and force ransom payments.
- Veeam’s report shows backups were targeted in 89% of ransomware victim organizations.
- Joining backup servers to production AD creates bidirectional compromise pathways between domain and backups.
- Weak segmentation often exposes consoles and repositories to general workstation networks.
- Legacy name-resolution and broadcast protocols enable credential interception and relay during AiTM positions.
- HTTP WSUS configurations allow network attackers to deliver malicious updates and gain SYSTEM execution.
- Local admin control of Veeam enables DPAPI decryption of stored credentials from configuration databases.
- Rogue vSphere endpoints can capture Veeam service credentials in plaintext during SOAP authentication.
- Unencrypted backup files on permissive SMB shares allow offline extraction of NTDS.dit and hashes.
- Hardening requires isolation, least privilege, restricted console access, encryption, immutability, logging, and rapid patching.
TAKEAWAYS:
- Separate backup infrastructure from production AD using a workgroup or isolated management forest.
- Enforce dedicated VLANs, strict firewalling, and admin via jump hosts or privileged workstations only.
- Replace Domain Admin backup accounts with tightly-scoped service accounts and MFA-protected administration.
- Turn on per-job AES-256 encryption and immutable repositories to prevent theft and backup sabotage.
- Treat backups like tier-zero assets: monitor access, audit configuration changes, and patch urgently.