Ransomware : Your Feared IT Catastrophe
Ransomware has become an escalating cyberplague that poses an extinction-level danger for businesses of all sizes vulnerable to an assault. Different versions of ransomware such as CryptoLocker, Fusob, Locky, SamSam and MongoLock cryptoworms have been running rampant for a long time and continue to inflict damage. Modern variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch or Egregor, plus more as yet unnamed viruses, not only do encryption of online data files but also infect all configured system backup. Data synchronized to off-site disaster recovery sites can also be rendered useless. In a poorly architected data protection solution, this can render automated restore operations hopeless and basically knocks the network back to zero.
Getting back online programs and information following a ransomware intrusion becomes a race against the clock as the targeted organization struggles to contain and cleanup the ransomware and to restore mission-critical operations. Due to the fact that crypto-ransomware takes time to replicate, penetrations are usually sprung on weekends, when successful attacks in many cases take longer to notice. This compounds the difficulty of promptly marshalling and organizing an experienced response team.
Progent makes available a range of solutions for protecting organizations from ransomware attacks. Among these are staff training to help recognize and avoid phishing exploits, ProSight Active Security Monitoring for remote monitoring and management, plus deployment of modern security solutions with AI capabilities from SentinelOne to discover and disable zero-day cyber threats rapidly. Progent also provides the assistance of expert ransomware recovery professionals with the talent and commitment to reconstruct a breached network as rapidly as possible.
Progent's Ransomware Recovery Help
Following a ransomware attack, even paying the ransom demands in cryptocurrency does not ensure that distant criminals will provide the needed codes to unencrypt any of your files. Kaspersky ascertained that 17% of ransomware victims never restored their information after having paid the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms commonly range from 15-40 BTC ($120,000 and $400,000). This is greatly higher than the typical ransomware demands, which ZDNET determined to be in the range of $13,000. The other path is to re-install the mission-critical parts of your Information Technology environment. Absent the availability of full system backups, this requires a broad range of IT skills, well-coordinated team management, and the willingness to work continuously until the job is finished.
For two decades, Progent has provided expert IT services for companies in Corpus Christi and throughout the United States and has achieved Microsoft's Gold Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have attained advanced industry certifications in important technologies such as Microsoft, Cisco, VMware, and major distros of Linux. Progent's cybersecurity experts have earned internationally-renowned industry certifications including CISA, CISSP, CRISC, and SANS GIAC. (See Progent's certifications). Progent in addition has experience with financial management and ERP applications. This breadth of expertise gives Progent the capability to quickly determine critical systems and consolidate the remaining parts of your computer network system after a crypto-ransomware attack and assemble them into a functioning system.
Progent's ransomware team of experts utilizes state-of-the-art project management tools to orchestrate the complicated restoration process. Progent knows the urgency of acting swiftly and in concert with a client's management and IT staff to prioritize tasks and to put the most important systems back on-line as fast as humanly possible.
Client Story: A Successful Crypto-Ransomware Penetration Response
A small business engaged Progent after their network was crashed by Ryuk ransomware virus. Ryuk is believed to have been launched by North Korean state sponsored cybercriminals, suspected of using approaches exposed from the U.S. National Security Agency. Ryuk goes after specific organizations with little room for disruption and is one of the most profitable incarnations of ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a single-location manufacturing business located in the Chicago metro area and has about 500 employees. The Ryuk penetration had brought down all essential operations and manufacturing processes. Most of the client's backups had been online at the beginning of the intrusion and were encrypted. The client was pursuing financing for paying the ransom demand (exceeding $200K) and wishfully thinking for the best, but ultimately utilized Progent.
"I can't thank you enough about the expertise Progent provided us during the most fearful period of (our) businesses existence. We would have paid the Hackers if not for the confidence the Progent team gave us. The fact that you could get our e-mail and important applications back online quicker than seven days was amazing. Each expert I spoke to or e-mailed at Progent was totally committed on getting my company operational and was working all day and night on our behalf."
Progent worked together with the customer to quickly get our arms around and assign priority to the key applications that had to be restored in order to continue company operations:
- Microsoft Active Directory
- Microsoft Exchange Email
- Financials/MRP
To begin, Progent adhered to ransomware penetration mitigation industry best practices by stopping the spread and clearing infected systems. Progent then started the process of recovering Active Directory, the key technology of enterprise environments built upon Microsoft Windows technology. Microsoft Exchange messaging will not work without AD, and the client's financials and MRP applications used Microsoft SQL Server, which requires Active Directory for authentication to the information.
In less than 48 hours, Progent was able to restore Windows Active Directory to its pre-penetration state. Progent then helped perform setup and hard drive recovery on key systems. All Exchange Server ties and configuration information were intact, which accelerated the rebuild of Exchange. Progent was also able to find intact OST files (Microsoft Outlook Off-Line Folder Files) on team PCs and laptops in order to recover email information. A not too old offline backup of the client's financials/MRP software made it possible to recover these vital services back online. Although a lot of work needed to be completed to recover fully from the Ryuk attack, core systems were recovered quickly:
"For the most part, the production line operation was never shut down and we made all customer deliverables."
Throughout the following few weeks key milestones in the recovery process were accomplished in close collaboration between Progent team members and the client:
- Self-hosted web applications were returned to operation with no loss of information.
- The MailStore Exchange Server exceeding 4 million historical emails was restored to operations and available for users.
- CRM/Customer Orders/Invoicing/AP/Accounts Receivables (AR)/Inventory modules were fully functional.
- A new Palo Alto Networks 850 security appliance was deployed.
- Ninety percent of the user PCs were being used by staff.
"A huge amount of what occurred that first week is nearly entirely a blur for me, but our team will not soon forget the care all of you put in to give us our business back. I have trusted Progent for the past 10 years, maybe more, and every time Progent has shined and delivered. This time was a Herculean accomplishment."
Conclusion
A possible business-killing catastrophe was evaded through the efforts of results-oriented experts, a wide spectrum of knowledge, and tight collaboration. Although upon completion of forensics the crypto-ransomware virus penetration described here should have been disabled with modern security technology solutions and NIST Cybersecurity Framework best practices, team education, and well designed security procedures for data backup and applying software patches, the reality is that state-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are tireless and will continue. If you do get hit by a ransomware attack, remember that Progent's roster of professionals has extensive experience in ransomware virus defense, cleanup, and information systems disaster recovery.
"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were contributing), thanks very much for letting me get rested after we made it over the first week. Everyone did an amazing job, and if any of your guys is visiting the Chicago area, a great meal is on me!"
To review or download a PDF version of this ransomware incident report, click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Offered by Progent
Progent offers companies in Corpus Christi a portfolio of remote monitoring and security assessment services to assist you to reduce the threat from ransomware. These services utilize next-generation machine learning capability to detect new strains of crypto-ransomware that are able to escape detection by legacy signature-based security products.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
ProSight Active Security Monitoring is an endpoint protection (EPP) service that incorporates SentinelOne's cutting edge behavior-based analysis tools to defend physical and virtual endpoint devices against modern malware attacks like ransomware and file-less exploits, which routinely get by traditional signature-matching anti-virus products. ProSight ASM safeguards on-premises and cloud resources and provides a unified platform to automate the complete threat progression including protection, detection, mitigation, cleanup, and forensics. Top features include single-click rollback with Windows Volume Shadow Copy Service (VSS) and real-time system-wide immunization against newly discovered threats. Progent is a SentinelOne Partner, dealer, and integrator. Read more about Progent's ProSight Active Security Monitoring (ASM) next-generation endpoint protection and ransomware defense.
- ProSight Enhanced Security Protection: Endpoint Security and Exchange Filtering
Progent's ProSight Enhanced Security Protection services deliver economical multi-layer protection for physical servers and virtual machines, workstations, smartphones, and Microsoft Exchange. ProSight ESP uses adaptive security and advanced machine learning for round-the-clock monitoring and responding to security threats from all vectors. ProSight ESP provides two-way firewall protection, penetration alerts, endpoint control, and web filtering through cutting-edge tools packaged within a single agent accessible from a unified control. Progent's data protection and virtualization experts can assist you to plan and implement a ProSight ESP environment that meets your company's specific requirements and that helps you achieve and demonstrate compliance with legal and industry data protection standards. Progent will help you define and configure security policies that ProSight ESP will enforce, and Progent will monitor your network and react to alarms that call for immediate action. Progent can also assist you to set up and verify a backup and restore solution such as ProSight Data Protection Services (DPS) so you can recover quickly from a potentially disastrous cyber attack like ransomware. Read more about Progent's ProSight Enhanced Security Protection (ESP) unified physical and virtual endpoint protection and Microsoft Exchange filtering.
- ProSight Data Protection Services: Managed Backup and Disaster Recovery Services
Progent has partnered with leading backup/restore software providers to produce ProSight Data Protection Services (DPS), a portfolio of subscription-based management outsourcing plans that provide backup-as-a-service (BaaS). ProSight DPS products automate and track your backup operations and allow non-disruptive backup and rapid recovery of vital files/folders, apps, system images, and virtual machines. ProSight DPS lets you recover from data loss resulting from equipment failures, natural calamities, fire, cyber attacks such as ransomware, user error, malicious insiders, or application bugs. Managed services in the ProSight Data Protection Services portfolio include ProSight Altaro VM Backup, ProSight 365 Total Backup (formerly Altaro 365 Backup), ProSight ECHO Backup using Barracuda dedicated hardware, and ProSight MSP360 Hybrid Backup. Your Progent service representative can assist you to identify which of these managed services are most appropriate for your IT environment.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam filtering and email encryption service that incorporates the technology of leading data security vendors to provide web-based control and comprehensive security for your inbound and outbound email. The hybrid architecture of Email Guard managed service combines cloud-based filtering with an on-premises gateway appliance to provide advanced protection against spam, viruses, Denial of Service (DoS) Attacks, Directory Harvest Attacks (DHAs), and other email-borne threats. Email Guard's cloud filter acts as a first line of defense and keeps the vast majority of threats from making it to your network firewall. This decreases your exposure to inbound threats and conserves system bandwidth and storage. Email Guard's on-premises security gateway device adds a deeper layer of analysis for incoming email. For outbound email, the local gateway provides anti-virus and anti-spam filtering, protection against data leaks, and email encryption. The local security gateway can also assist Microsoft Exchange Server to track and safeguard internal email that stays inside your corporate firewall. For more details, see Email Guard spam filtering and data leakage protection.
- ProSight WAN Watch: Network Infrastructure Management
ProSight WAN Watch is a network infrastructure management service that makes it easy and inexpensive for small and mid-sized organizations to map, track, reconfigure and debug their connectivity appliances such as routers and switches, firewalls, and wireless controllers plus servers, printers, endpoints and other devices. Using cutting-edge Remote Monitoring and Management (RMM) technology, WAN Watch makes sure that infrastructure topology maps are kept updated, copies and displays the configuration information of almost all devices on your network, tracks performance, and generates notices when issues are detected. By automating time-consuming management activities, WAN Watch can knock hours off ordinary chores such as network mapping, expanding your network, locating appliances that need important software patches, or resolving performance bottlenecks. Learn more details about ProSight WAN Watch infrastructure management services.
- ProSight LAN Watch: Server and Desktop Remote Monitoring
ProSight LAN Watch is Progent's server and desktop monitoring service that incorporates advanced remote monitoring and management (RMM) technology to keep your network operating at peak levels by checking the state of vital computers that drive your business network. When ProSight LAN Watch detects an issue, an alarm is transmitted immediately to your specified IT management personnel and your assigned Progent consultant so any looming problems can be addressed before they have a chance to impact your network. Learn more details about ProSight LAN Watch server and desktop monitoring services.
- ProSight Virtual Hosting: Hosted VMs at Progent's Tier III Data Center
With ProSight Virtual Hosting service, a small or mid-size organization can have its critical servers and apps hosted in a protected fault tolerant data center on a fast virtual machine host configured and managed by Progent's IT support experts. Under the ProSight Virtual Hosting service model, the client retains ownership of the data, the operating system software, and the applications. Since the system is virtualized, it can be moved immediately to a different hardware solution without a time-consuming and technically risky reinstallation procedure. With ProSight Virtual Hosting, you are not tied a single hosting service. Learn more about ProSight Virtual Hosting services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is an IT infrastructure documentation management service that allows you to create, update, retrieve and safeguard data about your IT infrastructure, procedures, applications, and services. You can instantly locate passwords or IP addresses and be warned about impending expirations of SSLs or warranties. By updating and organizing your network documentation, you can save as much as half of time thrown away trying to find vital information about your IT network. ProSight IT Asset Management includes a centralized location for holding and sharing all documents related to managing your business network such as standard operating procedures and self-service instructions. ProSight IT Asset Management also supports advanced automation for collecting and associating IT information. Whether you're making improvements, performing maintenance, or responding to a crisis, ProSight IT Asset Management delivers the information you need the instant you need it. Learn more about ProSight IT Asset Management service.
- Progent Active Protection Against Ransomware: Machine Learning-based Ransomware Detection and Cleanup
Progent's Active Protection Against Ransomware is an endpoint protection (EPP) service that utilizes next generation behavior-based analysis tools to guard endpoint devices as well as physical and virtual servers against new malware attacks like ransomware and email phishing, which routinely escape legacy signature-based anti-virus products. Progent Active Security Monitoring services safeguard on-premises and cloud resources and offers a unified platform to manage the complete malware attack progression including filtering, detection, containment, cleanup, and post-attack forensics. Top features include single-click rollback using Windows Volume Shadow Copy Service (VSS) and automatic network-wide immunization against newly discovered threats. Read more about Progent's ransomware defense and cleanup services.
- Progent's Outsourced/Shared Call Center: Call Center Managed Services
Progent's Help Center managed services permit your information technology staff to offload Call Center services to Progent or split responsibilities for Service Desk support transparently between your internal network support resources and Progent's nationwide roster of IT service engineers and subject matter experts. Progent's Co-managed Service Desk provides a seamless extension of your corporate IT support resources. Client access to the Help Desk, provision of support services, issue escalation, trouble ticket generation and tracking, efficiency measurement, and maintenance of the support database are cohesive regardless of whether issues are taken care of by your internal network support resources, by Progent, or a mix of the two. Learn more about Progent's outsourced/shared Help Desk services.
- Patch Management: Software/Firmware Update Management Services
Progent's managed services for software and firmware patch management offer businesses of any size a versatile and cost-effective alternative for assessing, testing, scheduling, implementing, and tracking updates to your dynamic information network. Besides maximizing the security and reliability of your computer network, Progent's patch management services permit your in-house IT team to focus on more strategic projects and tasks that deliver the highest business value from your information network. Read more about Progent's patch management support services.
- ProSight Duo Two-Factor Authentication: Identity Validation, Endpoint Remediation, and Protected Single Sign-on
Progent's Duo authentication managed services incorporate Cisco's Duo cloud technology to defend against password theft through the use of two-factor authentication (2FA). Duo supports single-tap identity confirmation with iOS, Google Android, and other out-of-band devices. With 2FA, whenever you log into a protected application and enter your password you are asked to verify your identity on a unit that only you possess and that is accessed using a different network channel. A wide selection of devices can be utilized as this second means of authentication including an iPhone or Android or watch, a hardware token, a landline phone, etc. You can register multiple verification devices. To learn more about Duo two-factor identity validation services, refer to Duo MFA two-factor authentication (2FA) services for access security.
- ProSight Reporting: Real-time and In-depth Reporting for Ticketing and Network Monitoring Applications
ProSight Reporting is a growing line of real-time management reporting plug-ins created to integrate with the top ticketing and remote network monitoring platforms such as ConnectWise Manage, ConnectWise Automate, Customer Thermometer, Auvik, and SentinelOne. ProSight Reporting uses Microsoft Graph and utilizes color coding to surface and contextualize critical issues like spotty support follow-up or machines with out-of-date AVs. By exposing ticketing or network health concerns concisely and in near-real time, ProSight Reporting improves productivity, reduces management hassle, and saves money. For more information, visit ProSight Reporting for ticketing and network monitoring applications.
For Corpus Christi 24-7 Ransomware Removal Consulting, reach out to Progent at 800-462-8800 or go to Contact Progent.