reconx-logo

Meet Druva’s dedicated ransomware research function.

Staying ransomware-ready means keeping up with a threat landscape that never sits still.

Active Threats

critical
Identity and cloud infrastructure compromise
Identity abuse, Scattered Spider, ESXi compromise
critical
Ransomware groups targeting virtualized infrastructure and enterprise backups
critical
AI-powered campaigns accelerating bad actor speed and scale
AI-on-AI, frontier models, Claude Code weaponization
high
Emerging hypervisor vulnerabilities threatening cloud platforms
Host-level exploitation, control bypassing
high
Democratization of AI tools for rapid exploit development
Interlock group, automated threat tooling, AI-assisted malware

Threat Research Blogs

Access proprietary research from ReconX Labs.

Knowledge Base

Research new and emerging ransomware strains and families.

Top Hits View All

ReconX Reports & Resources

Enhance your security and recovery postures with curated reports, whitepapers, and findings from our threat research experts.

The Recovery Orange Book

The definite incident response playbook for quick, clean ransomware recovery.

recovery-orange-book-thumbnail

What Makes ReconX Unique

Real-World Insights Icon

Real-World Insights

We surface practical knowledge from real-world ransomware incidents—correlating relevant threat insights across the industry with proprietary frontline recovery experience.

Actionable Best Practices Icon

Actionable Best Practices

Our intelligence is democratized broadly through on-demand whitepapers, research, advisories, and expert-driven publications, enabling IT and security practitioners to strengthen ransomware and recovery postures.

In-Platform Intelligence Icon

In-Platform Intelligence

What we discover in the field doesn't stay in a report—it is continuously embedded into the Druva platform to sharpen your organization's ability to detect exposure, understand blast radius, and act with precision when it matters most—all natively within the Druva platform.