Crypto-Ransomware : Your Feared Information Technology Catastrophe
Ransomware has become a modern cyber pandemic that poses an extinction-level danger for businesses vulnerable to an assault. Versions of ransomware such as Dharma, CryptoWall, Bad Rabbit, Syskey and MongoLock cryptoworms have been running rampant for years and still cause destruction. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Nephilim, along with additional unnamed malware, not only perform encryption of online data files but also infect many accessible system backup. Data synched to cloud environments can also be rendered useless. In a poorly designed environment, this can render automated restoration impossible and basically sets the network back to square one.
Getting back online applications and information following a crypto-ransomware attack becomes a sprint against the clock as the targeted business struggles to contain, remove the ransomware, and resume enterprise-critical operations. Because crypto-ransomware requires time to spread throughout a network, assaults are frequently sprung on weekends, when penetrations typically take longer to notice. This compounds the difficulty of quickly marshalling and orchestrating an experienced response team.
Progent offers an assortment of solutions for protecting Ribeirão Preto enterprises from ransomware events. These include team member education to help recognize and not fall victim to phishing scams, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based cyberthreat protection to identify and extinguish day-zero malware assaults. Progent also can provide the assistance of expert crypto-ransomware recovery professionals with the track record and commitment to rebuild a compromised environment as rapidly as possible.
Progent's Crypto-Ransomware Restoration Help
After a ransomware penetration, even paying the ransom demands in cryptocurrency does not guarantee that cyber criminals will respond with the needed codes to decrypt all your data. Kaspersky determined that seventeen percent of ransomware victims never recovered their data even after having paid the ransom, resulting in additional losses. The gamble is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger enterprises, the ransom can be in the millions of dollars. The alternative is to piece back together the mission-critical components of your Information Technology environment. Without the availability of full system backups, this calls for a broad range of IT skills, top notch team management, and the capability to work non-stop until the job is finished.
For decades, Progent has provided certified expert IT services for businesses across the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes engineers who have attained high-level industry certifications in important technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security consultants have earned internationally-renowned certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise in accounting and ERP software solutions. This breadth of experience gives Progent the capability to quickly ascertain important systems and integrate the surviving pieces of your computer network system after a ransomware attack and configure them into an operational system.
Progent's recovery team utilizes powerful project management systems to coordinate the complex restoration process. Progent appreciates the importance of working swiftly and in unison with a client's management and Information Technology staff to assign priority to tasks and to get critical systems back on line as fast as possible.
Business Case Study: A Successful Ransomware Virus Restoration
A customer engaged Progent after their organization was brought down by Ryuk ransomware virus. Ryuk is believed to have been created by North Korean state sponsored cybercriminals, possibly using techniques leaked from the U.S. NSA organization. Ryuk targets specific organizations with little ability to sustain operational disruption and is one of the most lucrative instances of ransomware viruses. High publicized organizations include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a small manufacturing business located in Chicago with around 500 staff members. The Ryuk penetration had shut down all company operations and manufacturing processes. The majority of the client's backups had been on-line at the start of the intrusion and were destroyed. The client was pursuing financing for paying the ransom demand (more than $200,000) and praying for the best, but ultimately brought in Progent.
Progent worked together with the customer to quickly get our arms around and assign priority to the key areas that had to be recovered in order to resume business operations:
In less than 2 days, Progent was able to re-build Active Directory services to its pre-virus state. Progent then accomplished setup and storage recovery on the most important systems. All Exchange Server schema and attributes were usable, which accelerated the restore of Exchange. Progent was able to find non-encrypted OST files (Outlook Email Off-Line Folder Files) on staff workstations and laptops to recover mail information. A not too old offline backup of the businesses financials/MRP software made them able to return these essential applications back servicing users. Although a lot of work still had to be done to recover fully from the Ryuk damage, critical services were returned to operations rapidly:
During the following few weeks important milestones in the restoration process were achieved through tight cooperation between Progent consultants and the client:
Conclusion
A probable enterprise-killing catastrophe was evaded with top-tier experts, a wide array of subject matter expertise, and close collaboration. Although in post mortem the ransomware penetration detailed here would have been identified and blocked with modern security technology and security best practices, user and IT administrator education, and properly executed incident response procedures for data backup and proper patching controls, the reality remains that government-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are relentless and are an ongoing threat. If you do fall victim to a crypto-ransomware attack, feel confident that Progent's team of experts has extensive experience in ransomware virus blocking, remediation, and information systems recovery.
Download the Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Recovery Expertise in Ribeirão Preto
For ransomware system recovery services in the Ribeirão Preto area, phone Progent at