Crypto-Ransomware : Your Feared Information Technology Nightmare
Crypto-Ransomware has become a modern cyberplague that presents an extinction-level danger for businesses of all sizes vulnerable to an attack. Different iterations of ransomware like the CrySIS, WannaCry, Bad Rabbit, NotPetya and MongoLock cryptoworms have been circulating for a long time and still cause harm. More recent versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Egregor, along with more as yet unnamed newcomers, not only encrypt on-line files but also infiltrate any accessible system backup. Data replicated to the cloud can also be encrypted. In a poorly architected system, it can render automated recovery useless and effectively sets the entire system back to zero.
Recovering services and information after a ransomware outage becomes a race against time as the targeted organization tries its best to stop the spread and remove the ransomware and to resume mission-critical operations. Because ransomware requires time to spread, attacks are often launched at night, when successful penetrations typically take more time to discover. This multiplies the difficulty of rapidly assembling and coordinating a qualified mitigation team.
Progent makes available a variety of solutions for protecting Brasília businesses from ransomware events. These include staff education to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for remote monitoring and management, along with setup and configuration of modern security appliances with machine learning capabilities to automatically discover and suppress new threats. Progent in addition can provide the assistance of seasoned crypto-ransomware recovery professionals with the talent and commitment to restore a breached environment as urgently as possible.
Progent's Crypto-Ransomware Recovery Support Services
Following a ransomware attack, paying the ransom demands in cryptocurrency does not ensure that merciless criminals will respond with the keys to decipher any or all of your information. Kaspersky estimated that seventeen percent of crypto-ransomware victims never restored their files after having sent off the ransom, resulting in additional losses. The risk is also expensive. Ryuk ransoms frequently range from fifteen to forty BTC ($120,000 and $400,000). This is well above the typical ransomware demands, which ZDNET determined to be in the range of $13,000 for small businesses. The alternative is to re-install the mission-critical elements of your Information Technology environment. Without the availability of complete information backups, this calls for a wide range of skills, well-coordinated team management, and the capability to work non-stop until the recovery project is completed.
For twenty years, Progent has provided expert IT services for companies across the U.S. and has achieved Microsoft's Gold Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes engineers who have been awarded high-level industry certifications in leading technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity consultants have earned internationally-renowned certifications including CISA, CISSP, CRISC, and SANS GIAC. (Refer to Progent's certifications). Progent in addition has experience with financial management and ERP applications. This breadth of expertise provides Progent the skills to knowledgably determine necessary systems and consolidate the surviving pieces of your Information Technology environment after a crypto-ransomware penetration and rebuild them into an operational network.
Progent's ransomware team utilizes best of breed project management applications to orchestrate the sophisticated recovery process. Progent appreciates the urgency of acting rapidly and together with a customer’s management and Information Technology staff to prioritize tasks and to get the most important applications back on-line as fast as humanly possible.
Case Study: A Successful Ransomware Incident Recovery
A business contacted Progent after their organization was penetrated by Ryuk ransomware virus. Ryuk is thought to have been deployed by Northern Korean government sponsored cybercriminals, possibly adopting algorithms leaked from the United States National Security Agency. Ryuk goes after specific businesses with limited ability to sustain disruption and is one of the most profitable incarnations of ransomware viruses. Well Known organizations include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a regional manufacturing business based in the Chicago metro area and has about 500 staff members. The Ryuk intrusion had shut down all company operations and manufacturing processes. Most of the client's data backups had been directly accessible at the beginning of the intrusion and were destroyed. The client considered paying the ransom (exceeding $200K) and praying for good luck, but ultimately reached out to Progent.
Progent worked with the client to quickly identify and prioritize the essential systems that had to be recovered to make it possible to restart company operations:
In less than two days, Progent was able to re-build Windows Active Directory to its pre-virus state. Progent then accomplished rebuilding and hard drive recovery of needed servers. All Exchange data and attributes were usable, which greatly helped the rebuild of Exchange. Progent was also able to assemble intact OST files (Outlook Off-Line Data Files) on staff workstations and laptops to recover mail messages. A recent off-line backup of the businesses accounting/MRP software made it possible to recover these essential applications back on-line. Although a lot of work still had to be done to recover totally from the Ryuk damage, critical systems were recovered quickly:
Throughout the following month important milestones in the restoration process were accomplished in close cooperation between Progent engineers and the customer:
Conclusion
A possible business-ending disaster was averted due to top-tier professionals, a broad range of IT skills, and close teamwork. Although in retrospect the ransomware virus attack detailed here could have been prevented with current security solutions and recognized best practices, team education, and properly executed incident response procedures for information backup and proper patching controls, the reality remains that state-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are an ongoing threat. If you do fall victim to a crypto-ransomware attack, feel confident that Progent's team of experts has a proven track record in crypto-ransomware virus defense, remediation, and data restoration.
Download the Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Ryuk Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Recovery Consulting Services in Brasília
For ransomware cleanup consulting in the Brasília area, phone Progent at