Ransomware : Your Feared IT Disaster
Ransomware has become a modern cyber pandemic that poses an enterprise-level threat for businesses unprepared for an attack. Multiple generations of ransomware like the Reveton, CryptoWall, Locky, SamSam and MongoLock cryptoworms have been replicating for a long time and continue to inflict damage. Newer strains of crypto-ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, LockBit and Nephilim, as well as more unnamed newcomers, not only encrypt on-line files but also infiltrate most configured system protection mechanisms. Files replicated to off-premises disaster recovery sites can also be corrupted. In a poorly designed environment, this can render any restoration impossible and effectively knocks the entire system back to square one.
Restoring applications and information following a ransomware attack becomes a race against the clock as the targeted organization tries its best to contain the damage, remove the ransomware, and resume business-critical activity. Due to the fact that ransomware takes time to move laterally across a targeted network, assaults are usually sprung on weekends and holidays, when penetrations in many cases take longer to discover. This compounds the difficulty of promptly marshalling and orchestrating a capable mitigation team.
Progent provides an assortment of support services for securing Irvine businesses from ransomware penetrations. Among these are user education to help identify and not fall victim to phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's AI-based threat defense to identify and quarantine day-zero malware attacks. Progent also can provide the assistance of experienced ransomware recovery professionals with the track record and perseverance to re-deploy a breached network as soon as possible.
Progent's Ransomware Recovery Help
After a crypto-ransomware attack, paying the ransom demands in cryptocurrency does not provide any assurance that distant criminals will provide the codes to unencrypt any of your information. Kaspersky ascertained that 17% of ransomware victims never restored their files even after having paid the ransom, resulting in more losses. The gamble is also costly. Ryuk ransoms are often a few hundred thousand dollars. For larger enterprises, the ransom demand can reach millions of dollars. The alternative is to piece back together the critical components of your Information Technology environment. Absent access to full information backups, this requires a wide complement of IT skills, top notch project management, and the capability to work continuously until the job is done.
For twenty years, Progent has made available professional Information Technology services for businesses throughout the US and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes consultants who have been awarded top certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security consultants have earned internationally-recognized certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise in financial systems and ERP applications. This breadth of expertise affords Progent the ability to quickly understand important systems and consolidate the remaining parts of your computer network system after a ransomware penetration and configure them into a functioning network.
Progent's security team of experts utilizes state-of-the-art project management applications to coordinate the sophisticated recovery process. Progent appreciates the urgency of acting rapidly and in concert with a customer's management and IT staff to prioritize tasks and to get key services back on-line as fast as humanly possible.
Client Story: A Successful Ransomware Penetration Response
A customer sought out Progent after their network was taken over by Ryuk ransomware. Ryuk is generally considered to have been launched by North Korean state sponsored criminal gangs, possibly using strategies leaked from America's National Security Agency. Ryuk targets specific businesses with little room for disruption and is one of the most profitable examples of ransomware viruses. Headline victims include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a regional manufacturing business based in the Chicago metro area and has around 500 workers. The Ryuk intrusion had frozen all company operations and manufacturing processes. Most of the client's data protection had been on-line at the beginning of the attack and were eventually encrypted. The client was taking steps for paying the ransom demand (more than $200K) and hoping for good luck, but in the end engaged Progent.
Progent worked with the client to quickly get our arms around and assign priority to the essential applications that needed to be addressed in order to continue company functions:
In less than 2 days, Progent was able to re-build Active Directory services to its pre-virus state. Progent then performed reinstallations and hard drive recovery on mission critical systems. All Microsoft Exchange Server schema and attributes were usable, which facilitated the rebuild of Exchange. Progent was also able to collect local OST files (Microsoft Outlook Off-Line Folder Files) on various PCs in order to recover email information. A not too old offline backup of the customer's accounting/ERP systems made them able to return these essential applications back servicing users. Although major work still had to be done to recover totally from the Ryuk attack, the most important services were recovered quickly:
During the following couple of weeks important milestones in the restoration process were accomplished in tight cooperation between Progent consultants and the customer:
Conclusion
A likely business-ending catastrophe was evaded with results-oriented experts, a broad array of subject matter expertise, and tight teamwork. Although in hindsight the ransomware virus penetration detailed here would have been stopped with advanced cyber security systems and NIST Cybersecurity Framework best practices, user education, and properly executed security procedures for data protection and proper patching controls, the fact is that state-sponsored cyber criminals from China, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware penetration, feel confident that Progent's roster of professionals has extensive experience in crypto-ransomware virus defense, mitigation, and file disaster recovery.
Download the Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this ransomware incident report, click:
Progent's Crypto-Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Recovery Consulting Services in Irvine
For ransomware cleanup expertise in the Irvine metro area, phone Progent at