Crypto-Ransomware : Your Feared IT Nightmare
Crypto-Ransomware  Remediation ProfessionalsRansomware has become a too-frequent cyberplague that presents an existential threat for businesses of all sizes unprepared for an attack. Versions of crypto-ransomware such as CryptoLocker, CryptoWall, Locky, NotPetya and MongoLock cryptoworms have been circulating for many years and continue to cause destruction. The latest variants of ransomware such as Ryuk and Hermes, plus frequent unnamed viruses, not only encrypt on-line data files but also infiltrate all available system protection. Files synched to cloud environments can also be ransomed. In a poorly architected system, it can make any restore operations hopeless and effectively sets the network back to square one.

Getting back on-line services and information following a crypto-ransomware attack becomes a sprint against time as the targeted organization struggles to stop the spread and remove the crypto-ransomware and to resume mission-critical operations. Since crypto-ransomware requires time to move laterally, assaults are usually sprung during weekends and nights, when penetrations in many cases take longer to recognize. This compounds the difficulty of promptly marshalling and orchestrating a knowledgeable response team.

Progent has a variety of services for securing businesses from ransomware penetrations. These include team education to help recognize and avoid phishing attempts, ProSight Active Security Monitoring (ASM) for remote monitoring and management, in addition to setup and configuration of next-generation security appliances with artificial intelligence capabilities to quickly discover and suppress day-zero cyber attacks. Progent also offers the assistance of veteran ransomware recovery professionals with the talent and commitment to reconstruct a compromised network as quickly as possible.

Progent's Ransomware Recovery Services
Soon after a ransomware penetration, even paying the ransom in Bitcoin cryptocurrency does not provide any assurance that criminal gangs will respond with the needed codes to decipher all your information. Kaspersky ascertained that seventeen percent of crypto-ransomware victims never restored their data after having paid the ransom, resulting in increased losses. The gamble is also very costly. Ryuk ransoms frequently range from 15-40 BTC ($120,000 and $400,000). This is greatly above the typical crypto-ransomware demands, which ZDNET estimates to be around $13,000. The fallback is to re-install the essential components of your IT environment. Without access to complete data backups, this requires a wide range of IT skills, well-coordinated project management, and the willingness to work 24x7 until the job is over.

For two decades, Progent has offered certified expert IT services for businesses in Midtown Manhattan and across the United States and has achieved Microsoft's Gold Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes consultants who have earned advanced industry certifications in leading technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have earned internationally-renowned industry certifications including CISA, CISSP, ISACA CRISC, and GIAC. (Refer to Progent's certifications). Progent also has experience with financial systems and ERP application software. This breadth of expertise affords Progent the ability to rapidly understand critical systems and re-organize the remaining components of your Information Technology environment following a ransomware penetration and assemble them into an operational system.

Progent's ransomware team of experts uses best of breed project management tools to coordinate the complicated recovery process. Progent understands the importance of acting rapidly and together with a client's management and Information Technology resources to assign priority to tasks and to get the most important applications back online as fast as possible.

Case Study: A Successful Crypto-Ransomware Intrusion Restoration
A client escalated to Progent after their organization was brought down by Ryuk ransomware virus. Ryuk is believed to have been created by North Korean state criminal gangs, possibly using techniques exposed from the United States National Security Agency. Ryuk goes after specific businesses with limited tolerance for operational disruption and is among the most lucrative instances of ransomware. Well Known organizations include Data Resolution, a California-based data warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a regional manufacturing business headquartered in Chicago and has about 500 staff members. The Ryuk attack had shut down all essential operations and manufacturing processes. The majority of the client's information backups had been online at the beginning of the intrusion and were encrypted. The client was pursuing financing for paying the ransom demand (exceeding $200,000) and hoping for the best, but in the end called Progent.


"I canít thank you enough in regards to the care Progent gave us throughout the most critical time of (our) businesses existence. We may have had to pay the cyber criminals except for the confidence the Progent experts afforded us. That you could get our messaging and important servers back online in less than one week was something I thought impossible. Each consultant I interacted with or communicated with at Progent was urgently focused on getting our company operational and was working day and night to bail us out."

Progent worked with the client to rapidly identify and assign priority to the critical systems that had to be recovered to make it possible to continue departmental operations:

  • Active Directory (AD)
  • Electronic Mail
  • Accounting and Manufacturing Software
To start, Progent adhered to AV/Malware Processes incident mitigation industry best practices by stopping the spread and cleaning systems of viruses. Progent then began the steps of recovering Windows Active Directory, the core of enterprise networks built upon Microsoft Windows technology. Microsoft Exchange messaging will not operate without Windows AD, and the client's MRP software utilized SQL Server, which needs Active Directory for access to the information.

In less than two days, Progent was able to rebuild Windows Active Directory to its pre-attack state. Progent then charged ahead with rebuilding and hard drive recovery on critical servers. All Microsoft Exchange Server ties and configuration information were intact, which accelerated the restore of Exchange. Progent was able to assemble intact OST files (Outlook Email Off-Line Data Files) on user desktop computers to recover mail data. A recent off-line backup of the client's accounting/MRP software made them able to restore these required services back available to users. Although a lot of work remained to recover totally from the Ryuk attack, the most important systems were recovered quickly:


"For the most part, the assembly line operation survived unscathed and we made all customer sales."

Throughout the next couple of weeks important milestones in the recovery process were accomplished in close cooperation between Progent engineers and the client:

  • Internal web applications were restored without losing any data.
  • The MailStore Server exceeding four million historical messages was brought on-line and available for users.
  • CRM/Customer Orders/Invoicing/Accounts Payable/Accounts Receivables/Inventory Control modules were 100% restored.
  • A new Palo Alto 850 security appliance was deployed.
  • Ninety percent of the desktops and laptops were fully operational.

"A huge amount of what was accomplished that first week is mostly a fog for me, but we will not soon forget the countless hours all of your team accomplished to give us our company back. Iíve entrusted Progent for at least 10 years, possibly more, and each time I needed help Progent has shined and delivered. This event was a testament to your capabilities."

Conclusion
A possible enterprise-killing disaster was averted by results-oriented professionals, a broad spectrum of subject matter expertise, and tight teamwork. Although in hindsight the ransomware attack described here would have been identified and disabled with up-to-date security solutions and best practices, user education, and properly executed security procedures for data protection and applying software patches, the reality remains that state-sponsored hackers from China, Russia, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware attack, feel confident that Progent's team of experts has extensive experience in ransomware virus blocking, removal, and data restoration.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were involved), thanks very much for letting me get some sleep after we made it past the initial fire. All of you did an impressive job, and if any of your team is visiting the Chicago area, a great meal is my treat!"

To read or download a PDF version of this case study, please click:
Progent's Ryuk Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Additional Ransomware Protection Services Available from Progent
Progent can provide businesses in Midtown Manhattan a range of remote monitoring and security evaluation services to help you to reduce the threat from ransomware. These services utilize modern AI technology to detect new strains of ransomware that are able to get past traditional signature-based anti-virus solutions.

  • ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
    Progent's ProSight Active Security Monitoring (ASM) is an endpoint protection service that utilizes cutting edge behavior-based analysis tools to guard physical and virtual endpoints against new malware attacks such as ransomware and email phishing, which routinely evade traditional signature-matching AV products. ProSight Active Security Monitoring safeguards on-premises and cloud-based resources and offers a single platform to automate the entire malware attack progression including filtering, detection, mitigation, cleanup, and post-attack forensics. Top capabilities include one-click rollback using Windows Volume Shadow Copy Service and real-time system-wide immunization against newly discovered threats. Find out more about Progent's ProSight Active Security Monitoring (ASM) next-generation endpoint protection and ransomware defense.

  • ProSight Enhanced Security Protection (ESP): Physical and Virtual Endpoint Protection and Exchange Filtering
    ProSight Enhanced Security Protection managed services deliver affordable multi-layer protection for physical servers and virtual machines, workstations, mobile devices, and Exchange email. ProSight ESP utilizes adaptive security and advanced machine learning for round-the-clock monitoring and reacting to security threats from all vectors. ProSight ESP provides two-way firewall protection, intrusion alarms, device management, and web filtering through leading-edge technologies packaged within a single agent managed from a single console. Progent's security and virtualization experts can assist you to design and implement a ProSight ESP deployment that addresses your company's unique needs and that allows you prove compliance with government and industry information security regulations. Progent will help you specify and implement security policies that ProSight ESP will manage, and Progent will monitor your IT environment and respond to alerts that call for urgent action. Progent's consultants can also assist your company to install and test a backup and disaster recovery system like ProSight Data Protection Services (DPS) so you can get back in business rapidly from a destructive security attack such as ransomware. Find out more about Progent's ProSight Enhanced Security Protection unified endpoint protection and Exchange email filtering.

  • ProSight Data Protection Services: Managed Backup and Disaster Recovery
    ProSight Data Protection Services offer small and mid-sized businesses a low cost and fully managed service for reliable backup/disaster recovery. For a low monthly cost, ProSight Data Protection Services automates your backup processes and enables rapid recovery of vital files, apps and virtual machines that have become unavailable or corrupted due to hardware breakdowns, software bugs, natural disasters, human mistakes, or malware attacks such as ransomware. ProSight Data Protection Services can help you back up, recover and restore files, folders, apps, system images, as well as Microsoft Hyper-V and VMware virtual machine images. Critical data can be backed up on the cloud, to a local storage device, or to both. Progent's cloud backup consultants can deliver advanced support to configure ProSight DPS to to comply with regulatory standards such as HIPAA, FINRA, and PCI and, whenever necessary, can assist you to recover your critical information. Find out more about ProSight DPS Managed Backup.

  • ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
    ProSight Email Guard is Progent's spam filtering service that incorporates the technology of leading information security vendors to deliver centralized management and world-class protection for your inbound and outbound email. The powerful structure of Progent's Email Guard managed service combines a Cloud Protection Layer with a local security gateway appliance to offer complete protection against spam, viruses, Denial of Service Attacks, Directory Harvest Attacks, and other email-based malware. The Cloud Protection Layer acts as a preliminary barricade and keeps the vast majority of threats from making it to your security perimeter. This reduces your exposure to inbound attacks and saves network bandwidth and storage. Email Guard's onsite security gateway device provides a further layer of analysis for inbound email. For outbound email, the on-premises gateway offers AV and anti-spam filtering, DLP, and email encryption. The onsite gateway can also help Exchange Server to track and safeguard internal email that stays within your corporate firewall. For more details, see Email Guard spam filtering and data leakage protection.

  • ProSight WAN Watch: Infrastructure Management
    Progentís ProSight WAN Watch is a network infrastructure monitoring and management service that makes it easy and inexpensive for smaller businesses to diagram, monitor, reconfigure and debug their networking appliances such as routers and switches, firewalls, and load balancers as well as servers, printers, client computers and other devices. Incorporating cutting-edge RMM technology, ProSight WAN Watch makes sure that infrastructure topology maps are always updated, copies and displays the configuration information of almost all devices connected to your network, monitors performance, and generates notices when issues are discovered. By automating tedious network management processes, ProSight WAN Watch can cut hours off ordinary chores like network mapping, expanding your network, locating devices that need important software patches, or resolving performance problems. Learn more details about ProSight WAN Watch infrastructure management consulting.

  • ProSight LAN Watch: Server and Desktop Remote Monitoring
    ProSight LAN Watch is Progentís server and desktop remote monitoring managed service that uses state-of-the-art remote monitoring and management techniques to keep your network running efficiently by checking the health of critical computers that drive your information system. When ProSight LAN Watch detects an issue, an alarm is sent automatically to your specified IT personnel and your Progent consultant so all potential problems can be resolved before they have a chance to impact productivity. Learn more about ProSight LAN Watch server and desktop monitoring consulting.

  • ProSight Virtual Hosting: Hosted VMs at Progent's World-class Data Center
    With ProSight Virtual Hosting service, a small or mid-size organization can have its critical servers and apps hosted in a protected Tier III data center on a high-performance virtual host set up and managed by Progent's IT support professionals. Under Progent's ProSight Virtual Hosting model, the customer retains ownership of the data, the operating system software, and the apps. Because the system is virtualized, it can be ported immediately to a different hardware solution without a lengthy and technically risky reinstallation procedure. With ProSight Virtual Hosting, you are not tied one hosting provider. Learn more about ProSight Virtual Hosting services.

  • ProSight IT Asset Management: Network Documentation Management
    Progent's ProSight IT Asset Management service is a cloud-based IT documentation management service that makes it easy to create, update, find and safeguard data about your network infrastructure, procedures, business apps, and services. You can instantly locate passwords or IP addresses and be alerted automatically about upcoming expirations of SSL certificates or warranties. By cleaning up and organizing your network documentation, you can save as much as 50% of time thrown away trying to find vital information about your network. ProSight IT Asset Management includes a common location for holding and collaborating on all documents related to managing your business network like recommended procedures and self-service instructions. ProSight IT Asset Management also supports advanced automation for collecting and associating IT information. Whether youíre planning enhancements, doing regular maintenance, or reacting to an emergency, ProSight IT Asset Management delivers the data you require as soon as you need it. Learn more about Progent's ProSight IT Asset Management service.
For Midtown Manhattan 24/7 Ransomware Cleanup Services, call Progent at 800-993-9400 or go to Contact Progent.