Crypto-Ransomware : Your Worst Information Technology Disaster
Ransomware  Recovery ProfessionalsRansomware has become a too-frequent cyberplague that presents an existential danger for businesses of all sizes unprepared for an attack. Different iterations of ransomware like the CryptoLocker, CryptoWall, Bad Rabbit, SamSam and MongoLock cryptoworms have been circulating for years and still cause harm. The latest strains of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti or Nephilim, along with more unnamed malware, not only encrypt on-line critical data but also infiltrate most configured system restores and backups. Files synchronized to off-site disaster recovery sites can also be ransomed. In a poorly architected system, it can make automated restore operations useless and effectively sets the datacenter back to square one.

Retrieving applications and information after a ransomware attack becomes a race against the clock as the targeted business struggles to stop lateral movement and cleanup the ransomware and to restore enterprise-critical activity. Since ransomware requires time to replicate, penetrations are usually sprung on weekends and holidays, when penetrations in many cases take longer to detect. This multiplies the difficulty of quickly marshalling and coordinating a knowledgeable response team.

Progent offers a range of services for securing enterprises from ransomware penetrations. These include team education to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for remote monitoring and management, along with installation of the latest generation security gateways with machine learning capabilities to rapidly identify and extinguish new cyber attacks. Progent also offers the services of seasoned ransomware recovery consultants with the skills and commitment to restore a compromised network as urgently as possible.

Progent's Ransomware Restoration Services
After a crypto-ransomware penetration, even paying the ransom in Bitcoin cryptocurrency does not provide any assurance that cyber criminals will respond with the keys to decipher any of your files. Kaspersky Labs estimated that 17% of ransomware victims never restored their data after having paid the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms commonly range from fifteen to forty BTC ($120,000 and $400,000). This is significantly higher than the average ransomware demands, which ZDNET averages to be around $13,000. The alternative is to piece back together the critical components of your Information Technology environment. Absent access to essential information backups, this requires a broad complement of skills, professional project management, and the ability to work 24x7 until the recovery project is complete.

For twenty years, Progent has provided professional Information Technology services for businesses in Garland and throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes consultants who have earned top industry certifications in key technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity engineers have garnered internationally-recognized industry certifications including CISM, CISSP, CRISC, and SANS GIAC. (Refer to Progent's certifications). Progent in addition has experience in financial systems and ERP software solutions. This breadth of expertise affords Progent the ability to quickly understand necessary systems and integrate the remaining pieces of your IT system following a ransomware event and assemble them into an operational system.

Progent's security team of experts has top notch project management systems to orchestrate the complicated restoration process. Progent appreciates the importance of working swiftly and together with a client's management and Information Technology resources to prioritize tasks and to get critical applications back on-line as fast as humanly possible.

Client Case Study: A Successful Ransomware Incident Recovery
A small business escalated to Progent after their organization was attacked by Ryuk ransomware. Ryuk is believed to have been launched by Northern Korean state cybercriminals, suspected of adopting approaches exposed from the United States National Security Agency. Ryuk seeks specific companies with limited room for operational disruption and is among the most lucrative instances of ransomware malware. High publicized targets include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a single-location manufacturing company located in the Chicago metro area and has around 500 workers. The Ryuk intrusion had shut down all company operations and manufacturing capabilities. The majority of the client's backups had been online at the start of the intrusion and were destroyed. The client considered paying the ransom (exceeding two hundred thousand dollars) and praying for good luck, but ultimately brought in Progent.


"I cannot thank you enough about the support Progent gave us throughout the most critical time of (our) businesses existence. We most likely would have paid the cyber criminals behind the attack if not for the confidence the Progent team afforded us. The fact that you could get our e-mail system and key servers back on-line quicker than 1 week was beyond my wildest dreams. Each person I spoke to or communicated with at Progent was amazingly focused on getting our system up and was working breakneck pace on our behalf."

Progent worked together with the customer to quickly assess and prioritize the essential elements that needed to be addressed to make it possible to restart business functions:

  • Active Directory
  • Exchange Server
  • Accounting/MRP
To get going, Progent followed Anti-virus event mitigation best practices by isolating and cleaning up infected systems. Progent then began the work of recovering Active Directory, the foundation of enterprise systems built on Microsoft technology. Microsoft Exchange messaging will not operate without Windows AD, and the client's MRP software used Microsoft SQL, which depends on Active Directory services for authentication to the database.

In less than 48 hours, Progent was able to re-build Active Directory services to its pre-virus state. Progent then completed setup and hard drive recovery of critical systems. All Microsoft Exchange Server ties and configuration information were intact, which accelerated the restore of Exchange. Progent was able to locate non-encrypted OST data files (Outlook Email Off-Line Data Files) on various workstations and laptops in order to recover email information. A recent offline backup of the customerís accounting/MRP systems made them able to return these essential applications back online for users. Although a large amount of work remained to recover totally from the Ryuk event, critical systems were recovered quickly:


"For the most part, the assembly line operation never missed a beat and we did not miss any customer sales."

Throughout the following month critical milestones in the recovery project were made in close collaboration between Progent team members and the customer:

  • In-house web sites were returned to operation without losing any information.
  • The MailStore Microsoft Exchange Server exceeding four million archived messages was brought online and accessible to users.
  • CRM/Orders/Invoicing/Accounts Payable (AP)/AR/Inventory Control functions were 100% recovered.
  • A new Palo Alto Networks 850 security appliance was brought on-line.
  • Most of the user desktops were back into operation.

"Much of what occurred in the early hours is nearly entirely a haze for me, but our team will not soon forget the care each of your team accomplished to help get our business back. Iíve trusted Progent for the past ten years, maybe more, and every time Progent has outperformed my expectations and delivered. This time was the most impressive ever."

Conclusion
A probable enterprise-killing disaster was dodged with dedicated professionals, a broad range of IT skills, and close teamwork. Although in retrospect the ransomware virus attack detailed here could have been identified and blocked with up-to-date security technology solutions and best practices, user and IT administrator training, and properly executed incident response procedures for information backup and proper patching controls, the reality is that state-sponsored hackers from Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware incursion, feel confident that Progent's team of professionals has substantial experience in crypto-ransomware virus defense, remediation, and file recovery.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were helping), thanks very much for letting me get some sleep after we got over the initial fire. Everyone did an fabulous effort, and if any of your guys is in the Chicago area, dinner is on me!"

To review or download a PDF version of this ransomware incident report, please click:
Progent's Crypto-Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Additional Ransomware Protection Services Available from Progent
Progent can provide companies in Garland a variety of online monitoring and security assessment services designed to assist you to minimize your vulnerability to ransomware. These services incorporate modern AI capability to uncover new strains of crypto-ransomware that are able to escape detection by traditional signature-based anti-virus products.

  • ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
    ProSight Active Security Monitoring is an endpoint protection solution that incorporates next generation behavior machine learning tools to guard physical and virtual endpoints against new malware attacks such as ransomware and file-less exploits, which routinely evade legacy signature-matching AV products. ProSight Active Security Monitoring safeguards local and cloud-based resources and offers a single platform to manage the complete threat lifecycle including filtering, detection, mitigation, remediation, and post-attack forensics. Key features include single-click rollback with Windows Volume Shadow Copy Service and real-time network-wide immunization against newly discovered threats. Find out more about Progent's ProSight Active Security Monitoring (ASM) endpoint protection and ransomware defense.

  • ProSight Enhanced Security Protection: Physical and Virtual Endpoint Protection and Exchange Email Filtering
    ProSight Enhanced Security Protection (ESP) managed services deliver affordable multi-layer security for physical and virtual servers, desktops, mobile devices, and Exchange email. ProSight ESP utilizes contextual security and modern behavior analysis for continuously monitoring and reacting to cyber assaults from all attack vectors. ProSight ESP offers two-way firewall protection, intrusion alerts, endpoint management, and web filtering through cutting-edge tools incorporated within one agent managed from a single console. Progent's security and virtualization consultants can help you to plan and configure a ProSight ESP deployment that addresses your company's unique needs and that allows you achieve and demonstrate compliance with government and industry information security standards. Progent will help you define and configure policies that ProSight ESP will enforce, and Progent will monitor your IT environment and react to alerts that call for immediate action. Progent's consultants can also help you to set up and verify a backup and disaster recovery solution like ProSight Data Protection Services (DPS) so you can get back in business rapidly from a destructive cyber attack like ransomware. Find out more about Progent's ProSight Enhanced Security Protection (ESP) unified physical and virtual endpoint security and Microsoft Exchange filtering.

  • ProSight Data Protection Services: Managed Backup and Disaster Recovery
    ProSight Data Protection Services from Progent offer small and medium-sized businesses a low cost and fully managed solution for secure backup/disaster recovery (BDR). For a low monthly cost, ProSight Data Protection Services automates and monitors your backup activities and enables fast recovery of critical data, applications and VMs that have become lost or damaged as a result of component breakdowns, software glitches, disasters, human error, or malware attacks such as ransomware. ProSight Data Protection Services can help you back up, recover and restore files, folders, applications, system images, plus Microsoft Hyper-V and VMware images/. Critical data can be backed up on the cloud, to an on-promises device, or to both. Progent's cloud backup consultants can provide advanced support to configure ProSight Data Protection Services to be compliant with government and industry regulatory requirements such as HIPAA, FIRPA, PCI and Safe Harbor and, whenever necessary, can help you to restore your business-critical data. Learn more about ProSight Data Protection Services Managed Cloud Backup.

  • ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
    ProSight Email Guard is Progent's spam and virus filtering service that uses the technology of leading data security companies to provide centralized management and world-class security for your inbound and outbound email. The powerful structure of Progent's Email Guard managed service combines a Cloud Protection Layer with a local gateway device to provide complete protection against spam, viruses, Dos Attacks, Directory Harvest Attacks (DHAs), and other email-based malware. Email Guard's cloud filter serves as a first line of defense and keeps most unwanted email from reaching your network firewall. This reduces your vulnerability to external attacks and saves network bandwidth and storage. Email Guard's onsite gateway appliance provides a further level of inspection for incoming email. For outbound email, the onsite security gateway provides AV and anti-spam filtering, DLP, and email encryption. The local security gateway can also assist Microsoft Exchange Server to monitor and safeguard internal email that originates and ends inside your corporate firewall. For more details, visit Email Guard spam filtering and data leakage protection.

  • ProSight WAN Watch: Network Infrastructure Management
    Progentís ProSight WAN Watch is a network infrastructure management service that makes it easy and affordable for smaller businesses to map out, monitor, optimize and debug their connectivity hardware such as switches, firewalls, and load balancers as well as servers, client computers and other devices. Incorporating cutting-edge RMM technology, WAN Watch makes sure that infrastructure topology diagrams are kept updated, copies and manages the configuration of virtually all devices on your network, monitors performance, and sends notices when issues are detected. By automating tedious management activities, ProSight WAN Watch can cut hours off common chores like making network diagrams, expanding your network, locating appliances that need critical software patches, or resolving performance issues. Learn more details about ProSight WAN Watch infrastructure monitoring and management consulting.

  • ProSight LAN Watch: Server and Desktop Remote Monitoring and Management
    ProSight LAN Watch is Progentís server and desktop remote monitoring service that uses advanced remote monitoring and management (RMM) techniques to keep your IT system operating efficiently by tracking the state of critical assets that drive your business network. When ProSight LAN Watch detects an issue, an alert is transmitted immediately to your specified IT staff and your Progent consultant so any looming problems can be addressed before they have a chance to disrupt your network. Find out more about ProSight LAN Watch server and desktop monitoring consulting.

  • ProSight Virtual Hosting: Hosted VMs at Progent's World-class Data Center
    With Progent's ProSight Virtual Hosting service, a small or mid-size organization can have its critical servers and apps hosted in a protected fault tolerant data center on a high-performance virtual machine host set up and managed by Progent's network support experts. Under the ProSight Virtual Hosting service model, the client owns the data, the operating system platforms, and the apps. Since the environment is virtualized, it can be moved easily to a different hardware solution without a lengthy and difficult configuration procedure. With ProSight Virtual Hosting, your business is not tied one hosting provider. Learn more about ProSight Virtual Hosting services.

  • ProSight IT Asset Management: Network Documentation Management
    Progent's ProSight IT Asset Management service is a cloud-based IT documentation management service that allows you to capture, maintain, find and protect data about your IT infrastructure, procedures, applications, and services. You can instantly find passwords or IP addresses and be warned about impending expirations of SSL certificates or warranties. By cleaning up and organizing your network documentation, you can eliminate up to half of time spent searching for critical information about your IT network. ProSight IT Asset Management includes a centralized repository for storing and collaborating on all documents required for managing your network infrastructure like standard operating procedures (SOPs) and self-service instructions. ProSight IT Asset Management also offers a high level of automation for collecting and relating IT data. Whether youíre making enhancements, performing regular maintenance, or reacting to an emergency, ProSight IT Asset Management gets you the data you need the instant you need it. Learn more about Progent's ProSight IT Asset Management service.
For 24-7 Garland Ransomware Cleanup Support Services, call Progent at 800-462-8800 or go to Contact Progent.