Crypto-Ransomware : Your Worst IT Nightmare
Ransomware has become a modern cyberplague that represents an extinction-level threat for businesses poorly prepared for an attack. Versions of ransomware such as Dharma, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been around for a long time and still inflict damage. Modern variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, along with additional as yet unnamed malware, not only encrypt online data but also infiltrate all available system protection. Files synchronized to off-premises disaster recovery sites can also be corrupted. In a poorly architected system, this can render any restore operations hopeless and effectively sets the entire system back to square one.
Getting back online programs and information following a ransomware outage becomes a sprint against time as the targeted organization fights to stop the spread, cleanup the ransomware, and resume business-critical activity. Due to the fact that ransomware takes time to replicate throughout a network, penetrations are usually sprung on weekends and holidays, when penetrations may take more time to identify. This multiplies the difficulty of quickly mobilizing and orchestrating a knowledgeable mitigation team.
Progent provides an assortment of support services for protecting Cabo Frio organizations from ransomware attacks. Among these are team member education to become familiar with and avoid phishing scams, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based threat defense to detect and disable zero-day modern malware assaults. Progent also provides the services of expert ransomware recovery engineers with the skills and perseverance to restore a compromised network as urgently as possible.
Progent's Crypto-Ransomware Restoration Help
After a crypto-ransomware event, paying the ransom in cryptocurrency does not ensure that distant criminals will respond with the keys to decipher all your files. Kaspersky estimated that seventeen percent of ransomware victims never restored their data even after having paid the ransom, resulting in additional losses. The risk is also expensive. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The other path is to setup from scratch the vital elements of your IT environment. Absent the availability of complete system backups, this requires a wide range of skills, top notch team management, and the willingness to work 24x7 until the job is completed.
For twenty years, Progent has provided expert Information Technology services for businesses across the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have been awarded top industry certifications in foundation technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity consultants have garnered internationally-recognized industry certifications including CISA, CISSP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has experience in accounting and ERP software solutions. This breadth of experience affords Progent the capability to efficiently identify necessary systems and integrate the surviving components of your network system after a ransomware event and rebuild them into a functioning network.
Progent's recovery team uses best of breed project management applications to coordinate the complex restoration process. Progent knows the importance of acting swiftly and together with a client's management and Information Technology resources to assign priority to tasks and to get key services back on line as fast as possible.
Client Story: A Successful Ransomware Virus Response
A business contacted Progent after their company was brought down by Ryuk ransomware. Ryuk is believed to have been created by North Korean state criminal gangs, suspected of using technology exposed from the U.S. National Security Agency. Ryuk attacks specific businesses with little room for disruption and is one of the most lucrative incarnations of ransomware malware. Well Known targets include Data Resolution, a California-based info warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a small manufacturing company based in the Chicago metro area with around 500 employees. The Ryuk event had frozen all essential operations and manufacturing capabilities. The majority of the client's data backups had been directly accessible at the beginning of the attack and were damaged. The client considered paying the ransom demand (in excess of two hundred thousand dollars) and hoping for the best, but in the end brought in Progent.
Progent worked hand in hand the client to quickly assess and prioritize the mission critical areas that had to be recovered in order to continue company operations:
Within two days, Progent was able to re-build Active Directory to its pre-attack state. Progent then accomplished rebuilding and hard drive recovery on mission critical applications. All Exchange Server data and attributes were intact, which facilitated the rebuild of Exchange. Progent was able to find local OST files (Outlook Email Offline Folder Files) on user PCs and laptops in order to recover email data. A not too old offline backup of the customer's manufacturing systems made them able to restore these required services back online. Although major work still had to be done to recover fully from the Ryuk virus, essential systems were restored quickly:
During the next month critical milestones in the recovery project were made through tight cooperation between Progent engineers and the client:
Conclusion
A likely business-ending disaster was avoided with dedicated experts, a wide array of technical expertise, and close teamwork. Although in retrospect the crypto-ransomware virus attack detailed here could have been identified and prevented with advanced security systems and security best practices, user education, and properly executed security procedures for data protection and applying software patches, the fact is that state-sponsored criminal cyber gangs from China, North Korea and elsewhere are tireless and are an ongoing threat. If you do fall victim to a ransomware incident, feel confident that Progent's team of experts has extensive experience in ransomware virus blocking, remediation, and file recovery.
Download the Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Ryuk Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Recovery Expertise in Cabo Frio
For ransomware recovery expertise in the Cabo Frio metro area, phone Progent at