Ransomware : Your Worst Information Technology Catastrophe
Ransomware has become a modern cyber pandemic that presents an extinction-level threat for organizations vulnerable to an assault. Different versions of ransomware such as CrySIS, Fusob, Bad Rabbit, SamSam and MongoLock cryptoworms have been out in the wild for years and continue to inflict destruction. More recent versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, LockBit and Nephilim, as well as frequent unnamed viruses, not only perform encryption of online data but also infect any accessible system backup. Information replicated to cloud environments can also be rendered useless. In a vulnerable environment, this can render any restore operations hopeless and basically knocks the datacenter back to square one.
Getting back online applications and data after a ransomware intrusion becomes a race against time as the targeted organization fights to contain, cleanup the virus, and restore mission-critical activity. Since ransomware needs time to replicate throughout a network, assaults are often launched on weekends and holidays, when attacks are likely to take more time to uncover. This multiplies the difficulty of quickly mobilizing and coordinating a qualified mitigation team.
Progent makes available a range of solutions for protecting Hialeah enterprises from crypto-ransomware events. These include user training to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat defense to identify and disable day-zero malware assaults. Progent in addition provides the services of veteran ransomware recovery consultants with the talent and perseverance to re-deploy a breached environment as rapidly as possible.
Progent's Ransomware Recovery Support Services
After a ransomware event, paying the ransom demands in cryptocurrency does not provide any assurance that distant criminals will return the needed codes to decrypt any or all of your data. Kaspersky Labs ascertained that 17% of ransomware victims never recovered their files even after having paid the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions. The fallback is to re-install the vital components of your IT environment. Absent the availability of complete system backups, this requires a broad complement of skills, top notch team management, and the capability to work 24x7 until the job is over.
For two decades, Progent has provided professional IT services for businesses throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes professionals who have earned advanced industry certifications in key technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity specialists have earned internationally-recognized certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience in financial management and ERP application software. This breadth of experience affords Progent the skills to rapidly understand necessary systems and re-organize the surviving pieces of your network environment following a ransomware attack and rebuild them into a functioning system.
Progent's security team of experts utilizes state-of-the-art project management tools to orchestrate the complicated restoration process. Progent understands the urgency of working swiftly and in concert with a customer's management and IT team members to prioritize tasks and to get essential systems back on-line as fast as humanly possible.
Case Study: A Successful Ransomware Virus Recovery
A customer contacted Progent after their network system was brought down by Ryuk ransomware. Ryuk is generally considered to have been developed by North Korean state sponsored hackers, possibly using technology leaked from the United States National Security Agency. Ryuk attacks specific organizations with limited tolerance for operational disruption and is one of the most profitable examples of ransomware malware. Headline victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturing business located in Chicago with around 500 staff members. The Ryuk penetration had shut down all essential operations and manufacturing capabilities. Most of the client's data protection had been directly accessible at the time of the intrusion and were damaged. The client was pursuing financing for paying the ransom demand (more than $200,000) and hoping for good luck, but ultimately utilized Progent.
Progent worked with the client to rapidly determine and prioritize the most important applications that had to be recovered to make it possible to resume departmental operations:
In less than 2 days, Progent was able to re-build Active Directory to its pre-penetration state. Progent then assisted with setup and hard drive recovery of the most important servers. All Exchange Server ties and attributes were intact, which accelerated the rebuild of Exchange. Progent was able to collect intact OST files (Outlook Email Offline Data Files) on user workstations to recover email information. A not too old offline backup of the businesses accounting/ERP software made them able to restore these essential programs back available to users. Although significant work was left to recover totally from the Ryuk virus, the most important services were recovered quickly:
Throughout the next month critical milestones in the restoration process were accomplished through tight cooperation between Progent consultants and the client:
Conclusion
A probable enterprise-killing disaster was averted through the efforts of hard-working experts, a wide spectrum of technical expertise, and tight teamwork. Although upon completion of forensics the ransomware penetration detailed here could have been disabled with modern cyber security solutions and security best practices, team training, and well designed security procedures for data protection and proper patching controls, the reality is that government-sponsored cyber criminals from China, Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware penetration, remember that Progent's roster of professionals has proven experience in ransomware virus blocking, cleanup, and file disaster recovery.
Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Cleanup Expertise in Hialeah
For ransomware cleanup consulting services in the Hialeah area, call Progent at