Ransomware : Your Crippling Information Technology Nightmare
Ransomware has become an escalating cyber pandemic that represents an existential danger for businesses unprepared for an attack. Different versions of ransomware like the CryptoLocker, Fusob, Locky, NotPetya and MongoLock cryptoworms have been running rampant for a long time and continue to cause harm. Newer versions of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, as well as more as yet unnamed malware, not only encrypt online critical data but also infect any accessible system backups. Information replicated to off-premises disaster recovery sites can also be ransomed. In a vulnerable environment, it can render automated restoration impossible and basically sets the entire system back to zero.
Getting back on-line programs and data following a crypto-ransomware attack becomes a sprint against time as the targeted business fights to stop lateral movement, remove the virus, and restore business-critical activity. Because ransomware takes time to move laterally across a targeted network, attacks are usually launched during nights and weekends, when penetrations in many cases take longer to uncover. This compounds the difficulty of rapidly marshalling and organizing a knowledgeable response team.
Progent makes available an assortment of support services for protecting Chatsworth businesses from ransomware events. These include user training to help identify and avoid phishing scams, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's AI-based cyberthreat protection to identify and quarantine zero-day malware assaults. Progent in addition provides the assistance of experienced ransomware recovery engineers with the track record and perseverance to reconstruct a breached network as rapidly as possible.
Progent's Ransomware Recovery Help
After a ransomware penetration, even paying the ransom in cryptocurrency does not guarantee that distant criminals will provide the needed codes to decrypt any or all of your data. Kaspersky ascertained that 17% of ransomware victims never recovered their information even after having sent off the ransom, resulting in more losses. The gamble is also very costly. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom demand can be in the millions of dollars. The alternative is to setup from scratch the essential components of your Information Technology environment. Without access to complete system backups, this requires a wide range of skill sets, top notch project management, and the willingness to work non-stop until the job is completed.
For two decades, Progent has provided certified expert IT services for companies across the United States and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes consultants who have earned high-level industry certifications in foundation technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security consultants have garnered internationally-recognized industry certifications including CISM, CISSP, CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise in accounting and ERP applications. This breadth of expertise affords Progent the ability to knowledgably identify necessary systems and organize the surviving pieces of your network system following a crypto-ransomware penetration and configure them into an operational network.
Progent's security team of experts uses state-of-the-art project management applications to coordinate the sophisticated recovery process. Progent knows the urgency of working rapidly and together with a customer's management and IT staff to assign priority to tasks and to get critical systems back online as soon as humanly possible.
Customer Story: A Successful Crypto-Ransomware Incident Response
A customer hired Progent after their company was penetrated by the Ryuk crypto-ransomware. Ryuk is generally considered to have been created by North Korean state sponsored hackers, possibly using technology leaked from America's National Security Agency. Ryuk attacks specific companies with little or no ability to sustain operational disruption and is among the most profitable incarnations of ransomware malware. High publicized organizations include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturing business headquartered in Chicago and has around 500 workers. The Ryuk intrusion had disabled all business operations and manufacturing processes. The majority of the client's backups had been directly accessible at the time of the intrusion and were destroyed. The client considered paying the ransom demand (exceeding $200K) and praying for good luck, but ultimately called Progent.
Progent worked together with the customer to rapidly determine and prioritize the key areas that needed to be addressed in order to resume business operations:
Within two days, Progent was able to re-build Windows Active Directory to its pre-penetration state. Progent then initiated setup and hard drive recovery on needed systems. All Microsoft Exchange Server schema and attributes were usable, which accelerated the rebuild of Exchange. Progent was able to collect intact OST files (Outlook Offline Folder Files) on user workstations and laptops to recover email information. A not too old off-line backup of the client's accounting/ERP systems made them able to return these essential services back available to users. Although significant work remained to recover completely from the Ryuk damage, the most important services were recovered quickly:
Over the following few weeks key milestones in the restoration process were made in tight cooperation between Progent engineers and the customer:
Conclusion
A probable business-ending disaster was evaded with hard-working experts, a broad array of IT skills, and tight teamwork. Although in hindsight the ransomware virus attack described here would have been blocked with current security solutions and recognized best practices, user education, and properly executed incident response procedures for backup and proper patching controls, the fact remains that government-sponsored criminal cyber gangs from China, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware incursion, feel confident that Progent's team of experts has a proven track record in crypto-ransomware virus blocking, removal, and information systems recovery.
Download the Ransomware Recovery Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Recovery Expertise in Chatsworth
For ransomware system recovery expertise in the Chatsworth area, call Progent at