The most promising option I've come across so far is Borg running in append-only mode[1] with a client-push type model.
I imagine it wouldn't help in this case, if the attacker has the creds and access to run `dd' on the backup machine directly.
Anyone had any good/bad experiences with Borg append-only (or have other suggestions?)
[1] https://borgbackup.readthedocs.io/en/stable/usage/notes.html...