Ransomware : Your Worst IT Catastrophe
Ransomware has become an escalating cyberplague that presents an extinction-level threat for businesses vulnerable to an attack. Versions of crypto-ransomware like the CrySIS, WannaCry, Bad Rabbit, SamSam and MongoLock cryptoworms have been around for a long time and still inflict harm. Modern variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, as well as additional unnamed viruses, not only encrypt online data but also infect all configured system backup. Data replicated to cloud environments can also be encrypted. In a vulnerable system, this can render automated recovery hopeless and basically sets the datacenter back to square one.
Retrieving programs and data following a ransomware intrusion becomes a sprint against time as the targeted organization tries its best to contain the damage, clear the ransomware, and restore enterprise-critical activity. Because ransomware needs time to spread throughout a network, penetrations are usually launched during weekends and nights, when attacks are likely to take more time to detect. This multiplies the difficulty of quickly mobilizing and coordinating a qualified mitigation team.
Progent has a variety of support services for protecting Carlsbad enterprises from ransomware attacks. These include user education to become familiar with and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's AI-based cyberthreat protection to discover and disable day-zero malware attacks. Progent in addition provides the assistance of experienced crypto-ransomware recovery professionals with the track record and perseverance to reconstruct a breached system as rapidly as possible.
Progent's Ransomware Restoration Services
After a ransomware invasion, even paying the ransom demands in cryptocurrency does not ensure that distant criminals will return the codes to decipher any of your data. Kaspersky Labs determined that 17% of ransomware victims never restored their files after having paid the ransom, resulting in additional losses. The risk is also expensive. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom demand can reach millions of dollars. The fallback is to piece back together the key components of your IT environment. Without the availability of full information backups, this requires a wide complement of skills, top notch project management, and the capability to work continuously until the task is complete.
For two decades, Progent has made available expert Information Technology services for companies across the United States and has earned Microsoft's Gold Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes engineers who have attained top industry certifications in foundation technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have garnered internationally-renowned certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise in accounting and ERP applications. This breadth of experience affords Progent the capability to quickly understand important systems and integrate the surviving components of your IT environment after a ransomware attack and rebuild them into an operational system.
Progent's ransomware group deploys powerful project management applications to coordinate the complicated recovery process. Progent understands the importance of working swiftly and in concert with a client's management and IT team members to assign priority to tasks and to put essential applications back online as soon as humanly possible.
Business Case Study: A Successful Crypto-Ransomware Penetration Restoration
A customer sought out Progent after their network was taken over by Ryuk ransomware. Ryuk is generally considered to have been deployed by North Korean government sponsored cybercriminals, suspected of using technology leaked from the United States NSA organization. Ryuk goes after specific companies with little or no tolerance for disruption and is among the most lucrative incarnations of ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a regional manufacturing business based in Chicago with about 500 employees. The Ryuk event had disabled all essential operations and manufacturing processes. Most of the client's information backups had been on-line at the beginning of the attack and were damaged. The client considered paying the ransom (more than $200,000) and wishfully thinking for good luck, but in the end called Progent.
Progent worked with the customer to rapidly understand and prioritize the most important services that had to be restored in order to resume business operations:
Within 2 days, Progent was able to re-build Windows Active Directory to its pre-penetration state. Progent then charged ahead with setup and storage recovery on mission critical systems. All Microsoft Exchange Server schema and configuration information were usable, which facilitated the rebuild of Exchange. Progent was also able to collect non-encrypted OST data files (Outlook Offline Folder Files) on team PCs and laptops in order to recover mail messages. A not too old off-line backup of the client's accounting/MRP systems made them able to return these vital programs back servicing users. Although a lot of work still had to be done to recover completely from the Ryuk damage, the most important services were recovered quickly:
During the following couple of weeks key milestones in the restoration project were made in tight collaboration between Progent team members and the client:
Conclusion
A likely business catastrophe was avoided with dedicated experts, a wide range of IT skills, and close teamwork. Although in hindsight the ransomware attack detailed here would have been shut down with advanced security technology and best practices, user education, and appropriate incident response procedures for information backup and proper patching controls, the fact remains that government-sponsored criminal cyber gangs from Russia, China and elsewhere are relentless and represent an ongoing threat. If you do get hit by a ransomware virus, feel confident that Progent's team of experts has substantial experience in ransomware virus blocking, removal, and information systems restoration.
Download the Ransomware Removal Case Study Datasheet
To read or download a PDF version of this case study, click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Recovery Expertise in Carlsbad
For ransomware cleanup consulting in the Carlsbad metro area, phone Progent at