Crypto-Ransomware : Your Feared IT Catastrophe
Ransomware  Recovery ConsultantsRansomware has become a too-frequent cyberplague that represents an extinction-level threat for organizations poorly prepared for an attack. Versions of ransomware such as Reveton, WannaCry, Locky, NotPetya and MongoLock cryptoworms have been replicating for a long time and still inflict damage. Newer variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, plus more unnamed malware, not only encrypt online information but also infect all configured system protection. Files synched to cloud environments can also be ransomed. In a poorly designed environment, it can make automated restoration useless and basically sets the datacenter back to zero.

Recovering services and data after a crypto-ransomware outage becomes a race against the clock as the targeted organization struggles to stop the spread, remove the virus, and resume business-critical activity. Due to the fact that crypto-ransomware requires time to replicate throughout a targeted network, attacks are usually sprung on weekends, when attacks tend to take longer to discover. This compounds the difficulty of rapidly mobilizing and orchestrating a knowledgeable mitigation team.

Progent has a range of services for securing Brooklyn organizations from crypto-ransomware penetrations. These include staff education to help recognize and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's behavior-based threat defense to detect and extinguish day-zero malware assaults. Progent in addition can provide the services of experienced ransomware recovery engineers with the skills and perseverance to re-deploy a compromised environment as rapidly as possible.

Progent's Ransomware Recovery Help
Subsequent to a ransomware invasion, even paying the ransom demands in cryptocurrency does not provide any assurance that criminal gangs will return the keys to decrypt any of your information. Kaspersky Labs estimated that 17% of crypto-ransomware victims never recovered their information even after having paid the ransom, resulting in increased losses. The gamble is also very costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can be in the millions of dollars. The alternative is to re-install the vital parts of your Information Technology environment. Absent access to essential system backups, this calls for a broad complement of skill sets, top notch team management, and the capability to work 24x7 until the task is completed.

For two decades, Progent has offered professional IT services for companies across the United States and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes engineers who have earned high-level industry certifications in key technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security engineers have garnered internationally-recognized certifications including CISM, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise in accounting and ERP applications. This breadth of experience gives Progent the skills to rapidly determine necessary systems and consolidate the remaining parts of your network system following a ransomware penetration and configure them into a functioning system.

Progent's recovery team of experts deploys top notch project management tools to orchestrate the complicated restoration process. Progent knows the importance of working quickly and together with a client's management and Information Technology team members to prioritize tasks and to put essential systems back on line as fast as possible.

Client Case Study: A Successful Ransomware Incident Recovery
A small business engaged Progent after their network system was penetrated by Ryuk crypto-ransomware. Ryuk is believed to have been developed by North Korean government sponsored cybercriminals, possibly adopting algorithms leaked from America's National Security Agency. Ryuk targets specific companies with limited tolerance for operational disruption and is among the most lucrative iterations of ransomware. Major organizations include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturer located in the Chicago metro area with about 500 staff members. The Ryuk intrusion had brought down all company operations and manufacturing capabilities. Most of the client's backups had been online at the start of the intrusion and were encrypted. The client was actively seeking loans for paying the ransom demand (in excess of $200,000) and praying for good luck, but ultimately brought in Progent.


"I can't thank you enough in regards to the expertise Progent gave us during the most fearful period of (our) company's existence. We most likely would have paid the cyber criminals behind the attack except for the confidence the Progent experts provided us. That you could get our e-mail and essential applications back into operation sooner than seven days was something I thought impossible. Each expert I talked with or communicated with at Progent was laser focused on getting our company operational and was working at all hours to bail us out."

Progent worked together with the customer to rapidly get our arms around and assign priority to the critical systems that had to be recovered in order to resume company functions:

  • Active Directory (AD)
  • Electronic Mail
  • Financials/MRP
To begin, Progent adhered to AV/Malware Processes event response industry best practices by halting the spread and disinfecting systems. Progent then initiated the process of rebuilding Microsoft Active Directory, the key technology of enterprise networks built upon Microsoft Windows technology. Exchange email will not function without Active Directory, and the client's MRP applications leveraged Microsoft SQL Server, which depends on Active Directory for access to the information.

In less than two days, Progent was able to re-build Windows Active Directory to its pre-virus state. Progent then performed setup and storage recovery on critical systems. All Microsoft Exchange Server data and attributes were usable, which facilitated the rebuild of Exchange. Progent was able to collect intact OST data files (Outlook Email Off-Line Folder Files) on user desktop computers in order to recover mail information. A recent offline backup of the client's accounting systems made it possible to recover these required applications back available to users. Although a large amount of work was left to recover totally from the Ryuk attack, the most important services were recovered rapidly:


"For the most part, the production operation ran fairly normal throughout and we delivered all customer deliverables."

Throughout the following couple of weeks critical milestones in the recovery process were accomplished in tight collaboration between Progent consultants and the client:

  • Internal web sites were brought back up without losing any data.
  • The MailStore Microsoft Exchange Server containing more than 4 million archived messages was spun up and accessible to users.
  • CRM/Customer Orders/Invoices/AP/Accounts Receivables/Inventory capabilities were fully restored.
  • A new Palo Alto 850 security appliance was installed.
  • Most of the user PCs were being used by staff.

"A lot of what was accomplished those first few days is nearly entirely a haze for me, but we will not forget the dedication each of you accomplished to help get our business back. I've been working with Progent for the past 10 years, maybe more, and every time Progent has impressed me and delivered as promised. This situation was a stunning achievement."

Conclusion
A probable enterprise-killing disaster was evaded due to dedicated experts, a broad spectrum of knowledge, and tight teamwork. Although upon completion of forensics the ransomware attack detailed here could have been identified and disabled with current security solutions and recognized best practices, user and IT administrator training, and properly executed incident response procedures for information protection and keeping systems up to date with security patches, the reality remains that government-sponsored cyber criminals from Russia, North Korea and elsewhere are relentless and represent an ongoing threat. If you do get hit by a ransomware virus, feel confident that Progent's team of professionals has extensive experience in ransomware virus blocking, mitigation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were involved), thank you for making it so I could get some sleep after we got over the initial push. Everyone did an fabulous effort, and if anyone that helped is visiting the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Recovery Case Study Datasheet
To review or download a PDF version of this ransomware incident report, click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Expertise in Brooklyn
For ransomware cleanup services in the Brooklyn metro area, phone Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.