Ransomware : Your Crippling Information Technology Nightmare
Crypto-Ransomware has become a modern cyber pandemic that poses an existential danger for businesses poorly prepared for an assault. Different iterations of ransomware like the CrySIS, Fusob, Locky, Syskey and MongoLock cryptoworms have been running rampant for years and continue to cause destruction. The latest versions of ransomware like Ryuk and Hermes, as well as frequent as yet unnamed viruses, not only encrypt online information but also infiltrate most available system protection. Information synched to cloud environments can also be corrupted. In a vulnerable system, it can make automatic recovery useless and basically sets the datacenter back to zero.
Restoring services and data following a ransomware intrusion becomes a race against the clock as the victim tries its best to stop lateral movement and cleanup the crypto-ransomware and to resume business-critical operations. Due to the fact that crypto-ransomware takes time to spread, assaults are often sprung during nights and weekends, when attacks are likely to take longer to notice. This multiplies the difficulty of quickly mobilizing and orchestrating an experienced mitigation team.
Progent has a variety of services for securing enterprises from ransomware events. These include staff training to become familiar with and not fall victim to phishing exploits, ProSight Active Security Monitoring for remote monitoring and management, plus installation of the latest generation security solutions with AI technology to quickly detect and disable new cyber attacks. Progent in addition offers the services of veteran crypto-ransomware recovery engineers with the track record and perseverance to re-deploy a breached system as rapidly as possible.
Progent's Ransomware Restoration Help
Subsequent to a ransomware penetration, even paying the ransom demands in cryptocurrency does not provide any assurance that merciless criminals will return the keys to decrypt any or all of your information. Kaspersky Labs determined that 17% of ransomware victims never recovered their files after having paid the ransom, resulting in more losses. The gamble is also very costly. Ryuk ransoms commonly range from 15-40 BTC ($120,000 and $400,000). This is well higher than the average crypto-ransomware demands, which ZDNET averages to be approximately $13,000. The other path is to piece back together the vital elements of your IT environment. Absent access to full information backups, this calls for a wide range of IT skills, well-coordinated team management, and the ability to work non-stop until the recovery project is over.
For decades, Progent has made available certified expert Information Technology services for businesses in Reston and across the U.S. and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes professionals who have attained high-level certifications in leading technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security experts have earned internationally-renowned certifications including CISM, CISSP-ISSAP, CRISC, and SANS GIAC. (See Progent's certifications). Progent also has experience in accounting and ERP applications. This breadth of experience gives Progent the skills to knowledgably determine important systems and organize the remaining parts of your network system following a ransomware penetration and rebuild them into a functioning system.
Progent's recovery team uses state-of-the-art project management tools to orchestrate the complex recovery process. Progent appreciates the importance of acting rapidly and in concert with a client's management and Information Technology team members to prioritize tasks and to get the most important systems back on-line as soon as humanly possible.
Case Study: A Successful Ransomware Virus Restoration
A small business sought out Progent after their network system was brought down by Ryuk crypto-ransomware. Ryuk is thought to have been developed by Northern Korean government sponsored cybercriminals, possibly using algorithms exposed from the United States National Security Agency. Ryuk goes after specific organizations with limited ability to sustain operational disruption and is among the most lucrative examples of ransomware. Well Known organizations include Data Resolution, a California-based info warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a small manufacturing business based in Chicago and has about 500 staff members. The Ryuk penetration had frozen all business operations and manufacturing processes. Most of the client's backups had been online at the time of the attack and were encrypted. The client was taking steps for paying the ransom demand (exceeding $200K) and hoping for the best, but in the end engaged Progent.
"I canít say enough in regards to the expertise Progent provided us throughout the most critical time of (our) companyís existence. We most likely would have paid the cyber criminals behind the attack if not for the confidence the Progent experts gave us. That you were able to get our messaging and critical applications back in less than 1 week was earth shattering. Every single expert I spoke to or e-mailed at Progent was amazingly focused on getting us operational and was working 24/7 on our behalf."
Progent worked hand in hand the client to quickly determine and prioritize the critical services that needed to be recovered in order to restart company operations:
To get going, Progent adhered to Anti-virus incident response industry best practices by halting the spread and removing active viruses. Progent then started the task of rebuilding Microsoft Active Directory, the key technology of enterprise environments built upon Microsoft Windows Server technology. Microsoft Exchange Server messaging will not function without Windows AD, and the client's MRP applications used SQL Server, which needs Windows AD for authentication to the databases.
- Active Directory (AD)
In less than 48 hours, Progent was able to re-build Active Directory services to its pre-attack state. Progent then accomplished setup and hard drive recovery of key servers. All Microsoft Exchange Server data and configuration information were intact, which accelerated the restore of Exchange. Progent was able to find intact OST files (Outlook Email Off-Line Folder Files) on user PCs and laptops in order to recover email information. A recent off-line backup of the customerís accounting software made them able to restore these required applications back online. Although a lot of work remained to recover fully from the Ryuk virus, core systems were restored rapidly:
"For the most part, the production operation was never shut down and we did not miss any customer sales."
Throughout the next few weeks critical milestones in the restoration project were achieved in close cooperation between Progent team members and the customer:
- Self-hosted web applications were returned to operation with no loss of data.
- The MailStore Microsoft Exchange Server with over 4 million archived messages was spun up and available for users.
- CRM/Orders/Invoicing/Accounts Payable (AP)/AR/Inventory Control modules were fully recovered.
- A new Palo Alto Networks 850 security appliance was installed.
- Ninety percent of the user desktops and notebooks were functioning as before the incident.
"Much of what was accomplished those first few days is mostly a blur for me, but we will not forget the commitment all of you put in to help get our business back. I have utilized Progent for the past ten years, maybe more, and every time Progent has impressed me and delivered as promised. This situation was a stunning achievement."
A probable enterprise-killing disaster was averted with dedicated professionals, a broad array of knowledge, and tight teamwork. Although in retrospect the ransomware penetration detailed here would have been disabled with current security technology and security best practices, team education, and properly executed incident response procedures for information backup and applying software patches, the reality is that state-sponsored hackers from Russia, North Korea and elsewhere are tireless and are not going away. If you do fall victim to a ransomware incursion, remember that Progent's roster of professionals has a proven track record in crypto-ransomware virus blocking, removal, and file restoration.
"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (and any others that were contributing), thank you for making it so I could get some sleep after we got past the initial fire. All of you did an fabulous job, and if anyone that helped is visiting the Chicago area, a great meal is the least I can do!"
To read or download a PDF version of this ransomware incident report, please click:
Progent's Ryuk Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Available from Progent
Progent can provide companies in Reston a range of online monitoring and security evaluation services designed to help you to reduce the threat from ransomware. These services include modern AI technology to detect new strains of ransomware that can evade traditional signature-based security products.
For 24x7 Reston Ransomware Removal Services, call Progent at 800-993-9400 or go to Contact Progent.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
ProSight Active Security Monitoring is an endpoint protection solution that incorporates cutting edge behavior machine learning technology to guard physical and virtual endpoints against new malware attacks such as ransomware and file-less exploits, which easily escape traditional signature-matching AV products. ProSight Active Security Monitoring safeguards on-premises and cloud resources and offers a unified platform to manage the entire malware attack lifecycle including blocking, infiltration detection, containment, cleanup, and post-attack forensics. Key capabilities include one-click rollback using Windows Volume Shadow Copy Service (VSS) and automatic network-wide immunization against newly discovered attacks. Learn more about Progent's ProSight Active Security Monitoring next-generation endpoint protection and ransomware defense.
- ProSight Enhanced Security Protection: Physical and Virtual Endpoint Protection and Exchange Email Filtering
Progent's ProSight Enhanced Security Protection services offer economical in-depth protection for physical servers and virtual machines, desktops, smartphones, and Exchange Server. ProSight ESP utilizes contextual security and advanced machine learning for continuously monitoring and reacting to cyber assaults from all vectors. ProSight ESP provides firewall protection, penetration alarms, device control, and web filtering through cutting-edge technologies packaged within one agent managed from a unified console. Progent's security and virtualization experts can assist you to plan and implement a ProSight ESP deployment that meets your organization's specific requirements and that allows you achieve and demonstrate compliance with government and industry information security standards. Progent will help you define and implement policies that ProSight ESP will enforce, and Progent will monitor your IT environment and respond to alerts that require immediate attention. Progent can also help you to install and test a backup and restore system such as ProSight Data Protection Services so you can recover quickly from a destructive cyber attack like ransomware. Learn more about Progent's ProSight Enhanced Security Protection (ESP) unified physical and virtual endpoint protection and Microsoft Exchange filtering.
- ProSight Data Protection Services: Managed Backup and Recovery
ProSight Data Protection Services offer small and mid-sized organizations an affordable end-to-end solution for reliable backup/disaster recovery. For a low monthly price, ProSight DPS automates and monitors your backup processes and allows fast recovery of critical data, apps and virtual machines that have become lost or damaged as a result of hardware failures, software glitches, natural disasters, human mistakes, or malicious attacks such as ransomware. ProSight Data Protection Services can help you back up, recover and restore files, folders, apps, system images, plus Microsoft Hyper-V and VMware images/. Critical data can be backed up on the cloud, to an on-promises device, or mirrored to both. Progent's cloud backup specialists can provide world-class support to configure ProSight Data Protection Services to be compliant with government and industry regulatory standards such as HIPAA, FIRPA, and PCI and, when necessary, can help you to recover your critical data. Learn more about ProSight DPS Managed Cloud Backup.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam filtering service that uses the infrastructure of top data security vendors to deliver web-based management and comprehensive security for all your email traffic. The hybrid structure of Progent's Email Guard combines a Cloud Protection Layer with an on-premises security gateway device to offer advanced defense against spam, viruses, Dos Attacks, Directory Harvest Attacks (DHAs), and other email-borne threats. The cloud filter acts as a preliminary barricade and blocks most unwanted email from reaching your network firewall. This decreases your exposure to external attacks and conserves system bandwidth and storage. Email Guard's onsite gateway appliance adds a further layer of inspection for inbound email. For outbound email, the on-premises security gateway provides AV and anti-spam protection, DLP, and email encryption. The on-premises gateway can also help Microsoft Exchange Server to monitor and safeguard internal email traffic that originates and ends within your corporate firewall. For more details, visit Email Guard spam and content filtering.
- ProSight WAN Watch: Network Infrastructure Management
ProSight WAN Watch is an infrastructure monitoring and management service that makes it simple and affordable for smaller businesses to diagram, track, reconfigure and debug their networking hardware like switches, firewalls, and load balancers plus servers, printers, client computers and other networked devices. Using cutting-edge RMM technology, WAN Watch makes sure that infrastructure topology maps are kept updated, copies and displays the configuration of almost all devices connected to your network, monitors performance, and generates notices when issues are discovered. By automating complex management activities, WAN Watch can knock hours off common chores such as network mapping, expanding your network, locating appliances that require important software patches, or isolating performance problems. Find out more details about ProSight WAN Watch network infrastructure monitoring and management services.
- ProSight LAN Watch: Server and Desktop Monitoring and Management
ProSight LAN Watch is Progentís server and desktop remote monitoring managed service that incorporates state-of-the-art remote monitoring and management techniques to keep your network operating efficiently by tracking the health of critical computers that power your business network. When ProSight LAN Watch uncovers a problem, an alert is transmitted automatically to your specified IT management staff and your assigned Progent engineering consultant so that all potential issues can be addressed before they can disrupt your network. Find out more about ProSight LAN Watch server and desktop remote monitoring consulting.
- ProSight Virtual Hosting: Hosted VMs at Progent's Tier III Data Center
With ProSight Virtual Hosting service, a small or mid-size organization can have its key servers and applications hosted in a protected Tier III data center on a high-performance virtual host configured and managed by Progent's IT support experts. Under Progent's ProSight Virtual Hosting service model, the client owns the data, the operating system platforms, and the applications. Since the environment is virtualized, it can be moved easily to a different hardware solution without requiring a lengthy and difficult reinstallation procedure. With ProSight Virtual Hosting, you are not locked into a single hosting provider. Find out more about ProSight Virtual Hosting services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is a cloud-based IT documentation management service that allows you to capture, maintain, retrieve and protect data about your IT infrastructure, processes, applications, and services. You can quickly locate passwords or IP addresses and be warned automatically about impending expirations of SSL certificates or warranties. By cleaning up and managing your IT infrastructure documentation, you can eliminate as much as half of time wasted searching for vital information about your network. ProSight IT Asset Management features a common repository for storing and collaborating on all documents related to managing your business network such as standard operating procedures (SOPs) and How-To's. ProSight IT Asset Management also supports advanced automation for gathering and relating IT data. Whether youíre making improvements, performing regular maintenance, or reacting to a crisis, ProSight IT Asset Management delivers the information you need as soon as you need it. Find out more about Progent's ProSight IT Asset Management service.