Ransomware : Your Feared Information Technology Nightmare
Ransomware has become a too-frequent cyberplague that presents an extinction-level threat for organizations poorly prepared for an attack. Versions of ransomware such as CrySIS, Fusob, Locky, NotPetya and MongoLock cryptoworms have been out in the wild for years and still cause damage. More recent variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Egregor, along with daily as yet unnamed viruses, not only encrypt online critical data but also infect all configured system protection. Files synched to cloud environments can also be encrypted. In a poorly architected environment, it can make any recovery hopeless and basically knocks the entire system back to square one.
Restoring services and information following a crypto-ransomware attack becomes a race against the clock as the targeted business struggles to stop lateral movement, remove the crypto-ransomware, and restore mission-critical activity. Due to the fact that ransomware takes time to replicate across a targeted network, attacks are usually sprung during nights and weekends, when penetrations are likely to take longer to discover. This compounds the difficulty of rapidly marshalling and coordinating a knowledgeable response team.
Progent offers a range of solutions for protecting Rockville businesses from crypto-ransomware penetrations. These include user education to become familiar with and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's AI-based cyberthreat protection to detect and quarantine zero-day malware attacks. Progent also offers the services of experienced crypto-ransomware recovery engineers with the skills and commitment to re-deploy a breached network as rapidly as possible.
Progent's Crypto-Ransomware Restoration Help
Soon after a ransomware invasion, sending the ransom in cryptocurrency does not guarantee that distant criminals will provide the needed keys to unencrypt all your files. Kaspersky estimated that seventeen percent of ransomware victims never recovered their information after having sent off the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms are often several hundred thousand dollars. For larger enterprises, the ransom demand can be in the millions of dollars. The alternative is to setup from scratch the key parts of your Information Technology environment. Absent access to essential information backups, this requires a broad complement of skills, well-coordinated team management, and the ability to work non-stop until the recovery project is complete.
For twenty years, Progent has made available expert IT services for companies throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have earned high-level certifications in foundation technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security engineers have earned internationally-renowned certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has experience in financial management and ERP software solutions. This breadth of expertise affords Progent the skills to rapidly ascertain necessary systems and consolidate the remaining parts of your Information Technology environment following a crypto-ransomware event and rebuild them into an operational network.
Progent's ransomware team of experts deploys best of breed project management systems to orchestrate the complicated restoration process. Progent appreciates the importance of working swiftly and in concert with a client's management and Information Technology staff to assign priority to tasks and to put key applications back on line as fast as humanly possible.
Client Story: A Successful Ransomware Attack Restoration
A client engaged Progent after their network was brought down by Ryuk crypto-ransomware. Ryuk is generally considered to have been created by North Korean state sponsored criminal gangs, suspected of using techniques exposed from the United States NSA organization. Ryuk attacks specific businesses with little room for disruption and is among the most profitable versions of ransomware viruses. Headline victims include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturing business based in the Chicago metro area and has around 500 employees. The Ryuk event had frozen all business operations and manufacturing capabilities. The majority of the client's system backups had been on-line at the time of the attack and were eventually encrypted. The client was evaluating paying the ransom demand (exceeding two hundred thousand dollars) and hoping for the best, but ultimately engaged Progent.
Progent worked hand in hand the client to quickly identify and assign priority to the most important areas that had to be restored in order to restart business functions:
In less than 2 days, Progent was able to rebuild Active Directory to its pre-intrusion state. Progent then helped perform rebuilding and storage recovery on the most important systems. All Microsoft Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was also able to find non-encrypted OST files (Outlook Off-Line Data Files) on staff PCs in order to recover mail messages. A recent off-line backup of the customer's accounting/MRP software made them able to return these essential applications back available to users. Although a large amount of work needed to be completed to recover fully from the Ryuk virus, core systems were recovered rapidly:
During the next couple of weeks key milestones in the restoration process were achieved through tight cooperation between Progent team members and the customer:
Conclusion
A possible company-ending disaster was evaded through the efforts of results-oriented professionals, a broad spectrum of technical expertise, and tight teamwork. Although in analyzing the event afterwards the crypto-ransomware virus incident detailed here could have been blocked with current security solutions and recognized best practices, team training, and properly executed security procedures for backup and proper patching controls, the fact remains that state-sponsored cyber criminals from China, North Korea and elsewhere are tireless and are not going away. If you do fall victim to a ransomware incident, remember that Progent's team of professionals has a proven track record in ransomware virus blocking, removal, and information systems disaster recovery.
Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Recovery Services in Rockville
For ransomware recovery consulting services in the Rockville metro area, call Progent at