Skip to content
File security for Windows systems — since 2003

How FileSure Would Have Stopped the n0n Ransomware Backup Obliteration Attack

• By Gene Allen

The Attack: Backup Destruction Before Encryption

The n0n ransomware gang introduced a particularly brutal tactic: systematically destroying all accessible backups — local shadow copies, network shares, cloud snapshots — before encrypting victim files. Their ransom notes explicitly claim this capability, and the threat is real. They use VSSAdmin commands to delete Windows shadow copies, unmount network backup shares, compromise backup software management consoles, and delete cloud-based recovery points. By the time encryption starts, recovery options are gone. Victims face an existential decision: pay the ransom or lose everything.

The attack follows a predictable sequence. Initial access via RDP exploit, phishing, or unpatched vulnerability. Network reconnaissance to map backup infrastructure and locate sensitive data. Data exfiltration for double extortion leverage. Backup annihilation using administrative commands and compromised credentials. Finally, mass file encryption and ransom note deployment.

It’s an escalation that transforms a critical incident into an organizational crisis. But here’s what the article doesn’t emphasize: every phase of this attack requires Windows file system operations that can be intercepted and blocked before they succeed.

Why Backup-Focused Defense Fails

The article correctly identifies that “organizations can no longer rely solely on robust backup strategies” when those backups are actively targeted. Immutable backups, offline storage, and the 3-2-1 rule are sound advice — but they’re recovery mechanisms, not prevention. They assume the attacker already has a foothold and is executing their playbook.

The more durable intervention happens earlier: prevent the ransomware payload from landing on disk in the first place.

Ransomware delivered via phishing email, RDP session, or software exploit must write an executable file to the Windows file system before it can run. That write operation — malicious program creating an .exe, .dll, or .bat file — happens at the kernel level and can be controlled there. If the payload never lands, the entire attack chain collapses. No execution means no reconnaissance, no credential harvesting, no backup destruction, no encryption. The scumbags never get past the delivery phase.

How FileSure Blocks n0n Ransomware at the Kernel Level

FileSure Defend operates as a Windows kernel filter driver, intercepting file system operations before they complete. It enforces behavioral rules that control which programs can perform which file operations — regardless of whether the program is recognized malware or a zero-day variant nobody has seen before.

Here’s a specific rule configuration that stops n0n-style ransomware at delivery:

File name filter: *.exe, *.dll, *.bat, *.cmd, *.vbs, *.ps1 (executable file types)
Program name filter: Block all programs except authorized deployment tools and installers
Operations: Create, Write
Drive type: Hard drives, Network drives
Result: Authorized software deployment proceeds normally. Ransomware delivered via Outlook, Chrome, RDP, or any unauthorized vector attempts to write its payload to disk — and the write is blocked. The file never lands. The ransomware never executes.

If the organization is already compromised and ransomware begins encrypting files, a threshold rule provides a secondary defense:

File name filter: * (all files)
Operations: Write, Rename/Move
Drive type: Hard drives, Network drives
Threshold: 20 file modifications within 60 minutes
Result: Normal user activity (saving documents, editing spreadsheets) stays well below the threshold. Ransomware encryption — which modifies hundreds of files per minute — crosses the threshold within seconds. Further write and rename operations are blocked. Damage is contained to the files modified before the threshold fired.

The backup destruction phase also involves file operations: deleting shadow copy metadata, writing to backup configuration files, or deleting files from network backup shares. FileSure’s access control rules restrict which programs can modify those files, blocking unauthorized deletion attempts even if the attacker has compromised credentials.

The Upstream Advantage

The article recommends endpoint detection and response (EDR), network segmentation, MFA, and vulnerability patching. All valid. But EDR detects threats after they land and begin executing. Patching eliminates known vulnerabilities but introduces operational risk and doesn’t address phishing or credential compromise. MFA slows credential-based access but doesn’t stop malware execution once an attacker is inside.

FileSure’s kernel-level control operates upstream of all those mechanisms. It doesn’t wait to recognize the threat. It enforces the rule: unauthorized programs cannot write executable files to this system. Done. If the payload doesn’t land, backup obliteration becomes a theoretical tactic rather than a realized disaster.

Organizations dealing with legacy Windows systems — medical devices, industrial equipment, specialized software locked to older OS versions — face an additional problem: modern EDR tools won’t install on those systems. FileSure runs on Windows Server 2003 through Server 2022, protecting the systems that other tools have abandoned.

n0n ransomware’s backup destruction tactic is brutal, but it’s only relevant if the ransomware gets to execute in the first place. Block the payload write at the kernel level, and the entire attack chain collapses before it starts.

Start your free 21-day trial at bystorm.com and see FileSure block a simulated ransomware payload in under three minutes.


Source: n0n Ransomware: The Escalating Threat of Backup Obliteration and Next-Gen Extortion

Category: Ransomware

Tags: n0n ransomware, backup destruction, kernel filter driver, file system security, ransomware prevention, zero-day defense, vssadmin, shadow copy protection

Gene Allen

Written by

Gene Allen

Gene Allen is a Windows file security expert with over 20 years of experience developing kernel-level solutions that protect enterprise data from ransomware, unauthorized access, and data loss. As founder of ByStorm Software, he architected FileSure — a patented file auditing and security platform trusted by 200+ organizations across healthcare, financial services, and government. Gene holds two U.S. patents in file system security and access control.

Ready to protect your organization?

Start your free 21-day trial today. No credit card required.

Start Your Free 21-Day Trial