Crypto-Ransomware : Your Feared Information Technology Nightmare
Ransomware  Recovery ConsultantsCrypto-Ransomware has become a modern cyber pandemic that poses an enterprise-level threat for businesses unprepared for an attack. Versions of ransomware such as CrySIS, CryptoWall, Locky, SamSam and MongoLock cryptoworms have been circulating for a long time and continue to cause harm. More recent strains of crypto-ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, as well as additional unnamed viruses, not only perform encryption of on-line files but also infiltrate any configured system protection mechanisms. Information synchronized to the cloud can also be rendered useless. In a poorly architected data protection solution, it can make automated recovery useless and basically sets the datacenter back to zero.

Restoring applications and information after a ransomware outage becomes a sprint against the clock as the targeted organization fights to contain, clear the ransomware, and resume mission-critical activity. Due to the fact that ransomware takes time to move laterally across a network, penetrations are frequently launched during weekends and nights, when successful penetrations are likely to take longer to identify. This multiplies the difficulty of promptly marshalling and organizing a capable mitigation team.

Progent provides a variety of help services for protecting Salem enterprises from ransomware events. Among these are staff education to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's AI-based cyberthreat protection to detect and quarantine zero-day malware assaults. Progent also provides the assistance of expert crypto-ransomware recovery consultants with the talent and perseverance to restore a compromised environment as urgently as possible.

Progent's Crypto-Ransomware Recovery Help
Soon after a crypto-ransomware event, sending the ransom demands in cryptocurrency does not provide any assurance that merciless criminals will provide the codes to decrypt any or all of your files. Kaspersky Labs determined that 17% of crypto-ransomware victims never restored their files after having sent off the ransom, resulting in increased losses. The risk is also expensive. Ryuk ransoms are often several hundred thousand dollars. For larger organizations, the ransom demand can be in the millions of dollars. The alternative is to re-install the critical elements of your Information Technology environment. Absent access to full data backups, this requires a broad range of skill sets, top notch project management, and the ability to work continuously until the recovery project is finished.

For two decades, Progent has provided certified expert Information Technology services for companies throughout the US and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes consultants who have earned advanced industry certifications in important technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have earned internationally-recognized industry certifications including CISM, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience with financial management and ERP software solutions. This breadth of experience gives Progent the skills to quickly identify important systems and consolidate the surviving components of your Information Technology environment after a ransomware penetration and configure them into a functioning network.

Progent's security team of experts uses best of breed project management tools to orchestrate the complex restoration process. Progent understands the importance of acting swiftly and together with a customer's management and IT staff to prioritize tasks and to get the most important systems back on line as soon as possible.

Client Story: A Successful Crypto-Ransomware Intrusion Recovery
A small business engaged Progent after their network system was taken over by Ryuk ransomware. Ryuk is thought to have been launched by North Korean government sponsored cybercriminals, suspected of using algorithms exposed from the U.S. NSA organization. Ryuk goes after specific businesses with little ability to sustain disruption and is among the most lucrative instances of ransomware. Major targets include Data Resolution, a California-based data warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturing business based in the Chicago metro area and has around 500 employees. The Ryuk attack had disabled all essential operations and manufacturing processes. The majority of the client's data backups had been online at the start of the intrusion and were encrypted. The client was taking steps for paying the ransom (exceeding two hundred thousand dollars) and wishfully thinking for the best, but in the end engaged Progent.


"I can't thank you enough in regards to the care Progent gave us throughout the most fearful period of (our) company's existence. We most likely would have paid the cyber criminals behind the attack if it wasn't for the confidence the Progent group afforded us. That you could get our messaging and critical applications back faster than one week was amazing. Every single consultant I talked with or communicated with at Progent was hell bent on getting us restored and was working all day and night on our behalf."

Progent worked hand in hand the customer to quickly assess and prioritize the critical areas that needed to be recovered in order to continue departmental functions:

  • Active Directory (AD)
  • Electronic Messaging
  • Accounting and Manufacturing Software
To get going, Progent followed ransomware incident mitigation best practices by stopping lateral movement and removing active viruses. Progent then started the work of rebuilding Active Directory, the foundation of enterprise systems built upon Microsoft Windows Server technology. Microsoft Exchange Server messaging will not work without Windows AD, and the businesses' financials and MRP applications used Microsoft SQL, which depends on Active Directory for access to the database.

In less than two days, Progent was able to restore Windows Active Directory to its pre-penetration state. Progent then accomplished setup and storage recovery of key applications. All Exchange Server data and configuration information were usable, which greatly helped the restore of Exchange. Progent was also able to assemble intact OST data files (Outlook Email Off-Line Folder Files) on user workstations and laptops in order to recover mail messages. A recent off-line backup of the businesses financials/ERP software made them able to recover these vital services back on-line. Although a large amount of work needed to be completed to recover completely from the Ryuk virus, core services were recovered quickly:


"For the most part, the production line operation was never shut down and we delivered all customer sales."

During the following month critical milestones in the recovery process were made through tight collaboration between Progent consultants and the customer:

  • Internal web sites were brought back up with no loss of information.
  • The MailStore Server with over four million historical emails was brought on-line and accessible to users.
  • CRM/Product Ordering/Invoicing/Accounts Payable (AP)/Accounts Receivables/Inventory Control functions were completely restored.
  • A new Palo Alto 850 firewall was installed and configured.
  • 90% of the user workstations were being used by staff.

"So much of what occurred those first few days is mostly a blur for me, but my team will not forget the urgency each of the team accomplished to give us our business back. I've utilized Progent for the past 10 years, maybe more, and each time Progent has shined and delivered. This time was no exception but maybe more Herculean."

Conclusion
A potential business disaster was evaded with hard-working professionals, a wide spectrum of IT skills, and close collaboration. Although in analyzing the event afterwards the ransomware penetration detailed here could have been shut down with modern security systems and recognized best practices, user training, and properly executed security procedures for information backup and keeping systems up to date with security patches, the reality is that state-sponsored cybercriminals from China, Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware virus, feel confident that Progent's team of professionals has proven experience in ransomware virus blocking, cleanup, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (along with others who were involved), I'm grateful for making it so I could get rested after we got over the most critical parts. Everyone did an incredible job, and if anyone that helped is around the Chicago area, a great meal is the least I can do!"

Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer case study, please click:
Progent's Ryuk Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Expertise in Salem
For ransomware cleanup consulting services in the Salem area, call Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.