🇲🇩 Data recovery after ransomware attack in VMware environment and LTO backup

An information technology company in Moldova faced a severe ransomware incident that compromised its virtualized infrastructure and made essential systems and data unavailable for operations.

The attack primarily targeted the virtual VMDK disks of the virtual machines, as well as the structures used for backup. In a complex environment with approximately 12.6 TB of data affected, recovery required multiple approaches until a viable data source was identified.

After successive analyses of the virtual environment, the physical server, and the backup media, Digital Recovery succeeded in recovering the data using specialized techniques applied to the LTO tapes, which had undergone a Quick Erase process.

The company operates in the information technology sector, mainly in software and information systems development, as well as providing engineering services, IT consulting, data processing and management, and support for technology infrastructure.

Initial access by the attackers occurred through the exploitation of a vulnerability.

The ransomware primarily compromised the VMDK files of the virtual machines, causing the virtualized environment to become unavailable and preventing access to the systems and information stored on the VMs.

The affected environment included:

  • 1 Dell PowerEdge R510 server;
  • 8 x 4 TB disks configured in RAID 5 via a PERC H700 controller;
  • Veeam backup environment;
  • 6 Dell LTO Ultrium 5 tapes;
  • approximately 12.6 TB of affected data.

The company did not have a specific ransomware incident response plan before the attack.

Although backups existed, they had also been affected by the incident, preventing the company from simply restoring the environment and resuming operations.

The encryption of the VMDK files caused the virtual machines—and consequently the systems and data hosted on them—to become unavailable.

The client was in a critical situation. In addition to operational disruption, there was uncertainty about the possibility of recovering the information.

The complexity of the environment further increased the challenge. It was not enough to analyze a single medium or a single server. It was necessary to evaluate different data sources to discover where technically recoverable information still existed.

The priority became identifying the best source to reconstruct the data without further compromising the existing structures.

First attempt: virtual machine analysis

Initially, the client sent a file via SFTP so that Digital Recovery’s technical team could perform a first analysis.

After testing, however, it became clear that this source did not provide sufficient conditions to perform the required recovery.

In light of that result, the strategy was adapted.

The team requested that the physical device be sent to Digital Recovery’s laboratory in Wuppertal, Germany, allowing for a deeper analysis of the storage structures.

Second attempt: recovery directly from the server

With the physical equipment available in the laboratory, the specialists began working directly on the server and its RAID structure.

The goal was to locate data that could still be reconstructed from the physical disks, even with the virtualized environment compromised.

This second approach also did not yield sufficient results to recover the required information.

Instead of closing the project after the first attempts, the team moved on to another source available in the client’s environment: the tapes used by the backup system.

This decision proved decisive for the success of the case.

The challenge of LTO tapes with Quick Erase

The tape analysis revealed an additional obstacle. The LTO media had undergone a Quick Erase procedure.

This type of operation can render the data unrecognizable to conventional backup software and procedures, even though a significant portion of the information may still remain physically stored on the tape.

In practice, the data were present on the media but could no longer be accessed through traditional mechanisms.

It was necessary to work below the logical layer normally used by the backup software.

Specialized technology for backup recovery

Digital Recovery applied proprietary technologies aimed at recovering Backup & Replication environments, combined with specific techniques to analyze the structures present on the LTO tapes.

The team was able to access the remaining data on the media and reconstruct the information necessary for recovery.

After the attempts on the virtual machine and the physical server, it was precisely the third approach, using the LTO tapes, that made it possible to successfully conclude the project.

The process demonstrated the importance of analyzing all available data sources after a ransomware attack, including those that apparently were erased, corrupted, or rendered unusable.

Adapting the strategy was essential

One of the decisive factors for the outcome was the ability to adapt the technical strategy as new evidence was found.

The project went through three main stages:

  1. analysis of the virtual machine sent via SFTP;
  2. direct analysis of the physical server and its storage structure;
  3. specialized analysis of the LTO tapes used in the backup environment.

Each attempt provided important information about the state of the environment and allowed the investigation to be directed to the next alternative.

Recovery did not rely on insisting on a single approach, but on technically understanding the different sources available and identifying the one that still contained usable data.

Considering the analysis and recovery stages, the project was completed in approximately 10 days, from case intake to data approval by the client.

Throughout the process, communication was maintained in a transparent and objective manner.

The client received updates on the progress of the analyses, the results obtained in each attempt, and any technical limitations encountered, allowing decisions to be made with aligned expectations.

At the end of the work, the necessary data were successfully recovered.

The result

The recovery of the information stored on the LTO tapes represented an especially important outcome for the client.

After previous attempts had not produced sufficient results and in the face of the possibility of definitive data loss, confirmation that the data could still be recovered prompted an extremely positive reaction.

The case highlights an important point in ransomware incidents: media that appears erased, encrypted, or inaccessible to conventional tools does not necessarily mean its data have been physically destroyed.

In the case of tapes subjected to Quick Erase, the use of specialized techniques made it possible to access information that remained on the media and carry out the recovery successfully.

For complex corporate environments, especially those involving VMware, VMDK, RAID, Veeam and LTO tapes, investigating all layers and storage sources can be decisive in finding a viable recovery alternative.

We are always online

Please fill out the form, or select your preferred contact method. We will contact you to start recovering your files.

Latest insights from our experts

We can detect, contain, eradicate, and recover data after cyber attacks.

Post-incident