Crypto-Ransomware : Your Worst Information Technology Disaster
Ransomware  Remediation ProfessionalsCrypto-Ransomware has become a too-frequent cyber pandemic that presents an existential danger for organizations vulnerable to an attack. Multiple generations of ransomware like the CrySIS, Fusob, Bad Rabbit, SamSam and MongoLock cryptoworms have been around for many years and continue to cause damage. More recent variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Egregor, as well as more as yet unnamed viruses, not only perform encryption of online data but also infiltrate any available system protection mechanisms. Data synched to the cloud can also be corrupted. In a poorly designed environment, it can render automated restoration impossible and effectively knocks the entire system back to square one.

Restoring services and data after a ransomware attack becomes a race against the clock as the victim tries its best to contain the damage, clear the ransomware, and restore enterprise-critical operations. Because ransomware requires time to spread across a network, attacks are frequently sprung at night, when successful penetrations in many cases take more time to recognize. This multiplies the difficulty of quickly assembling and coordinating a knowledgeable mitigation team.

Progent has a range of support services for securing Montreal businesses from crypto-ransomware attacks. Among these are user education to help identify and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat protection to discover and quarantine zero-day malware attacks. Progent also provides the services of veteran ransomware recovery consultants with the talent and commitment to reconstruct a breached network as rapidly as possible.

Progent's Crypto-Ransomware Recovery Help
After a crypto-ransomware attack, sending the ransom demands in cryptocurrency does not guarantee that cyber hackers will return the needed keys to decrypt any or all of your data. Kaspersky Labs ascertained that seventeen percent of ransomware victims never recovered their files after having sent off the ransom, resulting in more losses. The gamble is also very costly. Ryuk ransoms are often several hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The fallback is to re-install the mission-critical parts of your Information Technology environment. Absent the availability of complete information backups, this calls for a wide range of skills, professional project management, and the ability to work 24x7 until the task is finished.

For decades, Progent has made available expert IT services for companies throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes engineers who have been awarded advanced certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security engineers have earned internationally-recognized industry certifications including CISM, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has experience in financial management and ERP software solutions. This breadth of expertise affords Progent the ability to knowledgably determine important systems and consolidate the remaining components of your computer network environment after a ransomware penetration and rebuild them into a functioning system.

Progent's ransomware team deploys top notch project management systems to orchestrate the sophisticated restoration process. Progent knows the importance of working rapidly and in unison with a client's management and Information Technology team members to assign priority to tasks and to put the most important applications back on-line as soon as humanly possible.

Client Story: A Successful Ransomware Incident Recovery
A customer escalated to Progent after their network system was taken over by the Ryuk ransomware. Ryuk is generally considered to have been deployed by North Korean government sponsored criminal gangs, possibly using approaches leaked from the United States NSA organization. Ryuk attacks specific companies with little room for operational disruption and is among the most profitable incarnations of ransomware. Well Known victims include Data Resolution, a California-based info warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturing company located in Chicago and has around 500 staff members. The Ryuk intrusion had paralyzed all company operations and manufacturing processes. Most of the client's backups had been on-line at the beginning of the attack and were destroyed. The client was actively seeking loans for paying the ransom (more than two hundred thousand dollars) and praying for good luck, but in the end utilized Progent.


"I cannot thank you enough about the support Progent gave us throughout the most critical time of (our) company's existence. We would have paid the criminal gangs except for the confidence the Progent group afforded us. The fact that you could get our e-mail and important servers back into operation in less than 1 week was incredible. Every single expert I worked with or texted at Progent was laser focused on getting us restored and was working 24/7 to bail us out."

Progent worked together with the client to quickly get our arms around and assign priority to the mission critical areas that had to be restored in order to continue company operations:

  • Active Directory (AD)
  • Email
  • Financials/MRP
To get going, Progent followed Anti-virus event response best practices by stopping lateral movement and cleaning systems of viruses. Progent then started the process of restoring Active Directory, the heart of enterprise networks built on Microsoft technology. Exchange messaging will not work without AD, and the businesses' accounting and MRP software leveraged Microsoft SQL, which requires Active Directory for security authorization to the databases.

In less than two days, Progent was able to restore Windows Active Directory to its pre-intrusion state. Progent then initiated setup and hard drive recovery on needed applications. All Microsoft Exchange Server schema and attributes were intact, which greatly helped the rebuild of Exchange. Progent was also able to collect local OST files (Microsoft Outlook Offline Data Files) on staff workstations and laptops to recover mail information. A not too old offline backup of the businesses manufacturing systems made them able to recover these vital applications back servicing users. Although a lot of work remained to recover fully from the Ryuk event, core systems were restored rapidly:


"For the most part, the manufacturing operation did not miss a beat and we did not miss any customer deliverables."

Over the next month important milestones in the restoration process were achieved in tight collaboration between Progent consultants and the customer:

  • Self-hosted web applications were brought back up with no loss of data.
  • The MailStore Microsoft Exchange Server exceeding 4 million historical emails was spun up and available for users.
  • CRM/Orders/Invoicing/Accounts Payable/AR/Inventory functions were 100% recovered.
  • A new Palo Alto Networks 850 security appliance was set up and programmed.
  • 90% of the desktop computers were fully operational.

"A lot of what transpired in the initial days is mostly a haze for me, but my team will not soon forget the countless hours all of your team accomplished to give us our company back. I've utilized Progent for the past ten years, possibly more, and every time I needed help Progent has come through and delivered. This time was a life saver."

Conclusion
A potential business catastrophe was dodged through the efforts of dedicated professionals, a broad array of technical expertise, and tight teamwork. Although upon completion of forensics the crypto-ransomware penetration detailed here would have been identified and stopped with modern security systems and recognized best practices, team training, and well designed security procedures for data protection and keeping systems up to date with security patches, the fact is that state-sponsored cybercriminals from China, North Korea and elsewhere are tireless and are not going away. If you do fall victim to a ransomware virus, feel confident that Progent's team of professionals has proven experience in ransomware virus blocking, cleanup, and data recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (along with others that were contributing), thank you for allowing me to get some sleep after we made it through the most critical parts. All of you did an incredible job, and if any of your team is visiting the Chicago area, a great meal is the least I can do!"

Download the Ransomware Remediation Case Study Datasheet
To read or download a PDF version of this customer case study, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Services in Montreal
For ransomware system restoration expertise in the Montreal metro area, phone Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.