Crypto-Ransomware : Your Worst IT Nightmare
Ransomware  Recovery ProfessionalsCrypto-Ransomware has become a too-frequent cyber pandemic that poses an existential threat for organizations poorly prepared for an assault. Multiple generations of ransomware such as CrySIS, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been replicating for many years and continue to cause harm. Modern variants of ransomware such as Ryuk and Hermes, along with daily unnamed viruses, not only encrypt on-line data but also infect any configured system protection mechanisms. Information synched to off-site disaster recovery sites can also be corrupted. In a poorly architected environment, it can make automated recovery impossible and basically sets the network back to zero.

Getting back online applications and data after a ransomware attack becomes a race against the clock as the targeted business fights to stop the spread and cleanup the ransomware and to restore enterprise-critical activity. Since crypto-ransomware takes time to replicate, penetrations are usually launched on weekends and holidays, when penetrations may take more time to notice. This multiplies the difficulty of rapidly marshalling and orchestrating a knowledgeable response team.

Progent provides a variety of help services for protecting businesses from crypto-ransomware attacks. Among these are staff education to help identify and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for remote monitoring and management, in addition to setup and configuration of modern security appliances with AI technology to quickly discover and quarantine zero-day threats. Progent also provides the assistance of seasoned ransomware recovery consultants with the talent and perseverance to reconstruct a compromised environment as rapidly as possible.

Progent's Ransomware Restoration Help
Subsequent to a ransomware penetration, even paying the ransom demands in cryptocurrency does not ensure that distant criminals will return the keys to decrypt all your information. Kaspersky estimated that 17% of ransomware victims never recovered their information even after having sent off the ransom, resulting in additional losses. The risk is also very costly. Ryuk ransoms commonly range from 15-40 BTC ($120,000 and $400,000). This is significantly higher than the typical crypto-ransomware demands, which ZDNET determined to be around $13,000. The fallback is to piece back together the key parts of your IT environment. Without access to essential system backups, this requires a wide complement of IT skills, well-coordinated project management, and the willingness to work continuously until the task is completed.

For two decades, Progent has offered professional Information Technology services for companies in Montgomery and across the US and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes professionals who have been awarded top industry certifications in leading technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security specialists have garnered internationally-recognized industry certifications including CISM, CISSP, ISACA CRISC, and GIAC. (See Progent's certifications). Progent also has expertise with financial systems and ERP software solutions. This breadth of expertise affords Progent the skills to quickly identify critical systems and organize the surviving components of your computer network environment after a ransomware event and rebuild them into an operational system.

Progent's recovery group utilizes state-of-the-art project management applications to coordinate the complex recovery process. Progent understands the importance of acting quickly and together with a customerís management and Information Technology team members to assign priority to tasks and to get critical applications back on line as fast as humanly possible.

Customer Case Study: A Successful Crypto-Ransomware Intrusion Response
A business escalated to Progent after their organization was taken over by Ryuk crypto-ransomware. Ryuk is thought to have been deployed by North Korean government sponsored criminal gangs, suspected of adopting techniques leaked from Americaís National Security Agency. Ryuk goes after specific businesses with little room for operational disruption and is among the most lucrative examples of ransomware viruses. Headline victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturing business located in the Chicago metro area with around 500 employees. The Ryuk attack had paralyzed all company operations and manufacturing processes. Most of the client's data protection had been directly accessible at the time of the attack and were eventually encrypted. The client considered paying the ransom demand (more than two hundred thousand dollars) and praying for good luck, but in the end made the decision to use Progent.


"I cannot speak enough in regards to the help Progent gave us throughout the most fearful time of (our) businesses existence. We may have had to pay the cyber criminals behind the attack if not for the confidence the Progent team afforded us. That you could get our e-mail and key applications back into operation quicker than five days was incredible. Each person I got help from or e-mailed at Progent was amazingly focused on getting our system up and was working 24 by 7 on our behalf."

Progent worked hand in hand the client to rapidly identify and prioritize the essential elements that had to be restored in order to resume departmental functions:

  • Active Directory (AD)
  • Microsoft Exchange Server
  • MRP System
To begin, Progent adhered to AV/Malware Processes event response industry best practices by stopping the spread and cleaning systems of viruses. Progent then initiated the steps of recovering Windows Active Directory, the foundation of enterprise networks built upon Microsoft Windows technology. Microsoft Exchange Server messaging will not function without Active Directory, and the customerís MRP system leveraged Microsoft SQL Server, which depends on Windows AD for security authorization to the data.

In less than 48 hours, Progent was able to re-build Windows Active Directory to its pre-intrusion state. Progent then assisted with reinstallations and storage recovery on the most important applications. All Microsoft Exchange Server schema and attributes were usable, which greatly helped the restore of Exchange. Progent was able to assemble non-encrypted OST files (Microsoft Outlook Offline Data Files) on team PCs in order to recover email information. A recent offline backup of the businesses accounting/MRP software made them able to recover these required services back available to users. Although a large amount of work was left to recover completely from the Ryuk attack, the most important systems were restored rapidly:


"For the most part, the production operation did not miss a beat and we did not miss any customer sales."

During the following few weeks key milestones in the recovery process were accomplished through tight cooperation between Progent team members and the customer:

  • In-house web applications were restored without losing any data.
  • The MailStore Server containing more than four million archived messages was restored to operations and available for users.
  • CRM/Product Ordering/Invoicing/AP/Accounts Receivables/Inventory Control functions were completely recovered.
  • A new Palo Alto Networks 850 firewall was brought online.
  • Nearly all of the user desktops and notebooks were operational.

"So much of what went on during the initial response is nearly entirely a blur for me, but my team will not forget the countless hours each of your team accomplished to help get our business back. I have been working together with Progent for at least 10 years, maybe more, and each time I needed help Progent has outperformed my expectations and delivered as promised. This situation was the most impressive ever."

Conclusion
A possible company-ending catastrophe was avoided through the efforts of dedicated professionals, a broad range of technical expertise, and close collaboration. Although in hindsight the crypto-ransomware incident described here should have been shut down with advanced security technology and best practices, team education, and well designed incident response procedures for information backup and keeping systems up to date with security patches, the fact remains that state-sponsored cybercriminals from Russia, China and elsewhere are relentless and are not going away. If you do fall victim to a ransomware incursion, remember that Progent's team of experts has proven experience in crypto-ransomware virus defense, removal, and data disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Tony and Chris (along with others who were helping), Iím grateful for allowing me to get some sleep after we made it through the initial fire. Everyone did an fabulous effort, and if anyone that helped is around the Chicago area, a great meal is the least I can do!"

To read or download a PDF version of this customer case study, click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Additional Ransomware Protection Services Offered by Progent
Progent offers businesses in Montgomery a portfolio of online monitoring and security assessment services to assist you to reduce the threat from crypto-ransomware. These services include modern artificial intelligence technology to detect new variants of ransomware that are able to evade traditional signature-based security solutions.

  • ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
    ProSight Active Security Monitoring is an endpoint protection service that incorporates cutting edge behavior machine learning technology to guard physical and virtual endpoints against new malware assaults like ransomware and file-less exploits, which easily escape traditional signature-matching AV products. ProSight ASM protects on-premises and cloud resources and provides a unified platform to address the complete threat progression including blocking, infiltration detection, containment, remediation, and forensics. Key features include one-click rollback using Windows VSS and real-time network-wide immunization against new attacks. Learn more about Progent's ProSight Active Security Monitoring endpoint protection and ransomware defense.

  • ProSight Enhanced Security Protection: Endpoint Security and Exchange Filtering
    ProSight Enhanced Security Protection (ESP) services deliver affordable multi-layer security for physical servers and VMs, workstations, smartphones, and Exchange email. ProSight ESP utilizes contextual security and advanced heuristics for round-the-clock monitoring and responding to cyber assaults from all vectors. ProSight ESP provides firewall protection, penetration alerts, endpoint management, and web filtering via cutting-edge tools incorporated within a single agent managed from a unified control. Progent's data protection and virtualization consultants can help you to design and implement a ProSight ESP environment that meets your organization's unique needs and that helps you demonstrate compliance with government and industry data security regulations. Progent will help you define and configure policies that ProSight ESP will manage, and Progent will monitor your network and react to alarms that call for immediate action. Progent's consultants can also help your company to set up and test a backup and disaster recovery system like ProSight Data Protection Services so you can get back in business quickly from a potentially disastrous cyber attack like ransomware. Read more about Progent's ProSight Enhanced Security Protection unified physical and virtual endpoint protection and Exchange filtering.

  • ProSight Data Protection Services: Managed Backup and Disaster Recovery
    ProSight Data Protection Services from Progent offer small and mid-sized organizations a low cost end-to-end service for secure backup/disaster recovery. Available at a fixed monthly rate, ProSight DPS automates and monitors your backup activities and allows fast recovery of critical data, apps and virtual machines that have become lost or damaged due to hardware failures, software glitches, natural disasters, human mistakes, or malware attacks such as ransomware. ProSight Data Protection Services can help you back up, retrieve and restore files, folders, applications, system images, plus Microsoft Hyper-V and VMware images/. Critical data can be protected on the cloud, to a local storage device, or mirrored to both. Progent's backup and recovery consultants can provide advanced expertise to configure ProSight DPS to be compliant with regulatory requirements like HIPAA, FINRA, and PCI and, when needed, can help you to recover your business-critical information. Read more about ProSight DPS Managed Cloud Backup.

  • ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
    ProSight Email Guard is Progent's spam and virus filtering and email encryption service that uses the technology of leading information security vendors to deliver web-based management and comprehensive protection for all your inbound and outbound email. The powerful structure of Progent's Email Guard combines a Cloud Protection Layer with an on-premises gateway appliance to provide complete protection against spam, viruses, Denial of Service Attacks, Directory Harvest Attacks, and other email-based threats. Email Guard's cloud filter acts as a first line of defense and blocks the vast majority of unwanted email from reaching your network firewall. This decreases your exposure to external threats and saves system bandwidth and storage. Email Guard's onsite security gateway appliance provides a further level of inspection for incoming email. For outbound email, the on-premises security gateway provides AV and anti-spam filtering, protection against data leaks, and email encryption. The onsite security gateway can also assist Microsoft Exchange Server to monitor and safeguard internal email traffic that stays within your security perimeter. For more details, visit Email Guard spam and content filtering.

  • ProSight WAN Watch: Network Infrastructure Remote Monitoring and Management
    Progentís ProSight WAN Watch is a network infrastructure monitoring and management service that makes it easy and affordable for smaller organizations to map, monitor, enhance and debug their connectivity appliances like routers and switches, firewalls, and wireless controllers as well as servers, client computers and other devices. Incorporating cutting-edge RMM technology, WAN Watch ensures that network diagrams are always current, copies and displays the configuration information of almost all devices on your network, monitors performance, and sends alerts when problems are discovered. By automating time-consuming management processes, WAN Watch can cut hours off ordinary tasks such as making network diagrams, reconfiguring your network, finding appliances that require important updates, or isolating performance problems. Find out more details about ProSight WAN Watch network infrastructure monitoring and management consulting.

  • ProSight LAN Watch: Server and Desktop Monitoring and Management
    ProSight LAN Watch is Progentís server and desktop monitoring service that incorporates state-of-the-art remote monitoring and management (RMM) techniques to help keep your IT system operating efficiently by tracking the health of vital computers that power your information system. When ProSight LAN Watch detects a problem, an alert is sent immediately to your specified IT staff and your Progent consultant so all potential issues can be resolved before they have a chance to impact productivity. Learn more about ProSight LAN Watch server and desktop remote monitoring consulting.

  • ProSight Virtual Hosting: Hosted Virtual Machines at Progent's World-class Data Center
    With Progent's ProSight Virtual Hosting service, a small organization can have its critical servers and apps hosted in a secure Tier III data center on a fast virtual host configured and managed by Progent's IT support experts. With Progent's ProSight Virtual Hosting model, the client retains ownership of the data, the operating system platforms, and the apps. Since the environment is virtualized, it can be ported easily to a different hosting solution without requiring a lengthy and difficult configuration procedure. With ProSight Virtual Hosting, your business is not locked into a single hosting service. Find out more details about ProSight Virtual Hosting services.

  • ProSight IT Asset Management: Network Documentation Management
    Progent's ProSight IT Asset Management service is a cloud-based IT documentation management service that makes it easy to capture, update, find and protect information related to your IT infrastructure, procedures, applications, and services. You can quickly locate passwords or serial numbers and be alerted automatically about upcoming expirations of SSLs or domains. By updating and managing your IT infrastructure documentation, you can save up to half of time thrown away looking for vital information about your network. ProSight IT Asset Management features a centralized location for storing and sharing all documents required for managing your network infrastructure like recommended procedures and self-service instructions. ProSight IT Asset Management also offers advanced automation for collecting and relating IT data. Whether youíre making enhancements, doing regular maintenance, or reacting to a crisis, ProSight IT Asset Management gets you the information you need when you need it. Read more about Progent's ProSight IT Asset Management service.
For Montgomery 24x7 Crypto Remediation Consultants, reach out to Progent at 800-993-9400 or go to Contact Progent.