Datto Ransomware Detection - Q3 2026 update

A major update to the Datto Ransomware Detection engine has been completed and is now shipping with EDR. This release expands protection against newly emerging ransomware families, detects several active strains earlier in the attack, and reduces false positives. No action is required on your part. The update is fully backward-compatible and deploys automatically.

New targeted detections for emerging ransomware

This update adds purpose-built detections for ransomware families that have emerged or grown active in recent months: LYNX, DragonForce, Gentlemen, Chaos, and CMD. Each detection is tuned to that family's specific behavior, catching attacks earlier and more reliably than generic patterns alone.

Earlier detection of active strains

Akira ransomware is now identified before it begins encrypting, stopping damage rather than just reporting it. Additional improvements include:

  • Detection timing for Qilin has been improved.
  • PLAY coverage has been strengthened.
  • Detection of the legacy WannaCry family has been reinforced, because old threats still circulate.

Fewer false positives

Existing detections have been refined in two areas:

  • Hardening against file-modification patterns that can mimic legitimate software behavior.
  • Improved handling of attacks that don't leave the usual traces, such as missing ransom notes.

The result is the same level of protection with fewer unnecessary alerts to triage.

Expanded early-warning signals

The engine now recognizes additional categories of suspicious pre-attack activity. This feeds earlier and richer context into monitoring and response workflows.

Reliability improvements

  • The agent now starts more resiliently on systems with degraded services.
  • Activity logging is more detailed to speed support case resolution.