Crypto-Ransomware : Your Worst Information Technology Nightmare
Crypto-Ransomware  Recovery ExpertsCrypto-Ransomware has become a too-frequent cyber pandemic that represents an enterprise-level threat for businesses unprepared for an attack. Versions of ransomware like the CrySIS, Fusob, Locky, SamSam and MongoLock cryptoworms have been replicating for years and still cause harm. Newer variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Egregor, along with additional as yet unnamed viruses, not only perform encryption of on-line critical data but also infect all accessible system restores and backups. Files replicated to cloud environments can also be corrupted. In a poorly architected environment, it can make any recovery useless and effectively knocks the entire system back to zero.

Restoring programs and data after a ransomware attack becomes a race against time as the targeted organization fights to contain the damage, clear the crypto-ransomware, and resume enterprise-critical operations. Due to the fact that ransomware takes time to replicate throughout a network, attacks are usually sprung during weekends and nights, when attacks may take longer to notice. This multiplies the difficulty of promptly mobilizing and coordinating a capable response team.

Progent makes available an assortment of help services for protecting Lower Manhattan enterprises from ransomware attacks. These include user education to help recognize and not fall victim to phishing scams, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's AI-based cyberthreat protection to identify and disable day-zero modern malware attacks. Progent also can provide the services of expert ransomware recovery consultants with the talent and perseverance to restore a breached network as soon as possible.

Progent's Ransomware Recovery Help
Following a crypto-ransomware invasion, sending the ransom in cryptocurrency does not guarantee that cyber criminals will return the keys to decipher any of your information. Kaspersky Labs determined that 17% of crypto-ransomware victims never recovered their data after having sent off the ransom, resulting in increased losses. The gamble is also costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can be in the millions. The alternative is to re-install the mission-critical components of your Information Technology environment. Without access to complete system backups, this calls for a wide range of IT skills, professional team management, and the ability to work non-stop until the recovery project is complete.

For twenty years, Progent has offered expert IT services for businesses throughout the U.S. and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have been awarded advanced certifications in important technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity engineers have garnered internationally-renowned certifications including CISA, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has experience in financial management and ERP applications. This breadth of expertise gives Progent the skills to quickly ascertain critical systems and organize the surviving pieces of your network environment following a ransomware penetration and assemble them into a functioning network.

Progent's security team deploys state-of-the-art project management tools to orchestrate the complicated recovery process. Progent understands the importance of working swiftly and in concert with a customer's management and IT staff to prioritize tasks and to put key applications back on-line as fast as possible.

Customer Story: A Successful Crypto-Ransomware Penetration Restoration
A customer sought out Progent after their organization was penetrated by Ryuk ransomware. Ryuk is believed to have been deployed by North Korean state sponsored cybercriminals, possibly adopting algorithms exposed from the U.S. NSA organization. Ryuk attacks specific organizations with little ability to sustain disruption and is among the most profitable examples of ransomware. High publicized victims include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a single-location manufacturing company based in the Chicago metro area and has about 500 employees. The Ryuk penetration had shut down all business operations and manufacturing capabilities. The majority of the client's system backups had been on-line at the start of the intrusion and were damaged. The client was pursuing financing for paying the ransom demand (more than $200,000) and wishfully thinking for good luck, but ultimately brought in Progent.


"I cannot speak enough about the help Progent provided us throughout the most critical period of (our) businesses life. We most likely would have paid the Hackers if not for the confidence the Progent group gave us. The fact that you were able to get our e-mail and essential servers back into operation sooner than one week was amazing. Every single consultant I talked with or e-mailed at Progent was absolutely committed on getting us working again and was working at all hours on our behalf."

Progent worked with the client to quickly assess and assign priority to the mission critical elements that had to be restored to make it possible to resume company functions:

  • Active Directory (AD)
  • E-Mail
  • Accounting and Manufacturing Software
To get going, Progent adhered to AV/Malware Processes event response industry best practices by stopping lateral movement and cleaning up infected systems. Progent then started the steps of rebuilding Microsoft AD, the core of enterprise environments built upon Microsoft technology. Microsoft Exchange Server email will not function without AD, and the customer's MRP system leveraged SQL Server, which needs Windows AD for access to the database.

Within two days, Progent was able to restore Active Directory services to its pre-attack state. Progent then completed setup and storage recovery on the most important systems. All Exchange data and attributes were intact, which facilitated the restore of Exchange. Progent was also able to find non-encrypted OST files (Outlook Email Offline Folder Files) on staff workstations to recover email data. A not too old off-line backup of the customer's financials/MRP systems made them able to restore these required services back servicing users. Although a lot of work remained to recover completely from the Ryuk event, critical systems were restored rapidly:


"For the most part, the assembly line operation survived unscathed and we did not miss any customer shipments."

During the next few weeks critical milestones in the recovery process were achieved through close collaboration between Progent consultants and the client:

  • Internal web applications were returned to operation without losing any information.
  • The MailStore Exchange Server exceeding 4 million historical messages was brought online and accessible to users.
  • CRM/Orders/Invoices/Accounts Payable (AP)/Accounts Receivables (AR)/Inventory functions were 100 percent operational.
  • A new Palo Alto Networks 850 security appliance was brought online.
  • Most of the desktops and laptops were functioning as before the incident.

"A huge amount of what was accomplished in the initial days is mostly a haze for me, but my management will not soon forget the countless hours each and every one of your team put in to help get our company back. I've trusted Progent for the past 10 years, maybe more, and each time I needed help Progent has shined and delivered. This situation was a stunning achievement."

Conclusion
A probable business disaster was averted by dedicated professionals, a broad spectrum of IT skills, and tight collaboration. Although in retrospect the ransomware attack detailed here would have been identified and disabled with advanced cyber security solutions and recognized best practices, user education, and well thought out security procedures for information backup and applying software patches, the fact remains that state-sponsored cyber criminals from Russia, China and elsewhere are tireless and will continue. If you do fall victim to a crypto-ransomware incident, remember that Progent's roster of experts has extensive experience in ransomware virus blocking, remediation, and file restoration.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were contributing), I'm grateful for letting me get rested after we got over the initial fire. All of you did an impressive effort, and if any of your guys is around the Chicago area, dinner is my treat!"

Download the Ransomware Remediation Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Services in Lower Manhattan
For ransomware system restoration services in the Lower Manhattan area, call Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.