Crypto-Ransomware : Your Feared Information Technology Disaster
Ransomware  Remediation ExpertsCrypto-Ransomware has become an escalating cyberplague that poses an extinction-level danger for businesses unprepared for an assault. Multiple generations of crypto-ransomware like the CrySIS, Fusob, Locky, SamSam and MongoLock cryptoworms have been running rampant for a long time and still inflict destruction. Modern variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, plus additional unnamed newcomers, not only perform encryption of online data but also infect many available system restores and backups. Information synchronized to the cloud can also be corrupted. In a vulnerable system, it can make any recovery useless and effectively sets the network back to zero.

Getting back applications and data following a crypto-ransomware attack becomes a sprint against the clock as the targeted organization struggles to contain, clear the ransomware, and restore mission-critical operations. Since crypto-ransomware takes time to move laterally across a targeted network, assaults are usually sprung on weekends and holidays, when penetrations typically take more time to discover. This compounds the difficulty of rapidly assembling and organizing a qualified response team.

Progent has an assortment of services for protecting Allen organizations from crypto-ransomware attacks. Among these are staff education to help identify and avoid phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's AI-based threat protection to identify and quarantine day-zero modern malware attacks. Progent in addition can provide the services of experienced crypto-ransomware recovery consultants with the skills and perseverance to re-deploy a breached network as quickly as possible.

Progent's Ransomware Recovery Help
Subsequent to a ransomware penetration, paying the ransom demands in cryptocurrency does not guarantee that merciless criminals will return the keys to decrypt any of your files. Kaspersky ascertained that 17% of crypto-ransomware victims never recovered their files even after having paid the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger enterprises, the ransom demand can reach millions. The alternative is to piece back together the essential parts of your IT environment. Without access to full information backups, this calls for a broad complement of skill sets, top notch team management, and the willingness to work 24x7 until the job is over.

For two decades, Progent has offered certified expert Information Technology services for businesses throughout the U.S. and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes professionals who have been awarded high-level industry certifications in key technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have earned internationally-recognized certifications including CISM, CISSP, CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has expertise with accounting and ERP applications. This breadth of experience affords Progent the capability to rapidly determine important systems and consolidate the remaining components of your Information Technology system after a crypto-ransomware penetration and rebuild them into a functioning system.

Progent's recovery team uses powerful project management tools to coordinate the sophisticated recovery process. Progent knows the importance of acting swiftly and in concert with a customer's management and IT team members to assign priority to tasks and to put essential services back on-line as fast as possible.

Client Story: A Successful Crypto-Ransomware Virus Recovery
A customer engaged Progent after their organization was brought down by Ryuk crypto-ransomware. Ryuk is believed to have been deployed by North Korean state criminal gangs, suspected of adopting approaches leaked from the United States NSA organization. Ryuk seeks specific businesses with little or no tolerance for disruption and is among the most profitable examples of crypto-ransomware. Headline organizations include Data Resolution, a California-based data warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a regional manufacturer headquartered in the Chicago metro area and has around 500 employees. The Ryuk intrusion had shut down all business operations and manufacturing processes. Most of the client's data backups had been directly accessible at the beginning of the attack and were damaged. The client was pursuing financing for paying the ransom (in excess of $200K) and hoping for good luck, but in the end engaged Progent.


"I can't thank you enough about the expertise Progent gave us during the most fearful period of (our) businesses survival. We may have had to pay the criminal gangs except for the confidence the Progent experts gave us. The fact that you could get our e-mail system and critical applications back on-line in less than a week was something I thought impossible. Every single expert I got help from or texted at Progent was absolutely committed on getting us operational and was working non-stop on our behalf."

Progent worked with the client to quickly determine and assign priority to the most important areas that needed to be addressed in order to resume business functions:

  • Active Directory
  • Microsoft Exchange
  • Financials/MRP
To start, Progent adhered to ransomware event response best practices by halting lateral movement and cleaning systems of viruses. Progent then started the steps of rebuilding Active Directory, the heart of enterprise environments built upon Microsoft Windows Server technology. Exchange messaging will not work without AD, and the customer's accounting and MRP software used Microsoft SQL Server, which depends on Active Directory for authentication to the information.

Within two days, Progent was able to rebuild Windows Active Directory to its pre-attack state. Progent then performed reinstallations and storage recovery of key systems. All Exchange data and configuration information were usable, which facilitated the rebuild of Exchange. Progent was also able to collect non-encrypted OST files (Outlook Off-Line Data Files) on user desktop computers to recover mail messages. A recent off-line backup of the client's accounting/MRP systems made them able to restore these vital services back on-line. Although significant work was left to recover completely from the Ryuk event, essential services were restored quickly:


"For the most part, the production line operation was never shut down and we delivered all customer shipments."

During the next few weeks key milestones in the recovery process were achieved in tight cooperation between Progent engineers and the client:

  • Internal web applications were restored with no loss of information.
  • The MailStore Server with over four million archived emails was restored to operations and available for users.
  • CRM/Customer Orders/Invoicing/AP/Accounts Receivables (AR)/Inventory Control capabilities were 100 percent operational.
  • A new Palo Alto 850 security appliance was installed and configured.
  • Most of the user PCs were being used by staff.

"A lot of what occurred those first few days is mostly a blur for me, but our team will not soon forget the care each and every one of the team accomplished to help get our company back. I have utilized Progent for the past 10 years, maybe more, and each time Progent has outperformed my expectations and delivered. This time was a Herculean accomplishment."

Conclusion
A possible business extinction disaster was avoided by dedicated experts, a broad range of IT skills, and close collaboration. Although upon completion of forensics the ransomware incident described here could have been prevented with advanced cyber security technology solutions and best practices, user and IT administrator training, and well thought out security procedures for information backup and proper patching controls, the fact is that government-sponsored cyber criminals from China, North Korea and elsewhere are tireless and represent an ongoing threat. If you do fall victim to a crypto-ransomware penetration, remember that Progent's team of professionals has a proven track record in ransomware virus defense, removal, and file disaster recovery.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were involved), thank you for letting me get rested after we got through the initial push. All of you did an incredible job, and if anyone that helped is in the Chicago area, dinner is on me!"

Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ryuk Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Expertise in Allen
For ransomware recovery consulting in the Allen metro area, phone Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.