Crypto-Ransomware : Your Crippling IT Nightmare
Ransomware has become a too-frequent cyber pandemic that represents an enterprise-level threat for organizations poorly prepared for an assault. Different iterations of ransomware such as CryptoLocker, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been circulating for a long time and still cause destruction. Newer variants of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, along with frequent as yet unnamed newcomers, not only encrypt on-line files but also infect most configured system backups. Files replicated to cloud environments can also be corrupted. In a poorly designed system, this can render automatic recovery impossible and basically knocks the entire system back to square one.
Recovering applications and data following a ransomware attack becomes a sprint against time as the targeted organization struggles to stop lateral movement, remove the crypto-ransomware, and restore business-critical operations. Because crypto-ransomware requires time to replicate throughout a targeted network, attacks are frequently launched during weekends and nights, when attacks tend to take longer to recognize. This multiplies the difficulty of quickly mobilizing and orchestrating an experienced mitigation team.
Progent makes available a variety of solutions for protecting Tacoma businesses from ransomware attacks. Among these are team member training to help recognize and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's behavior-based threat defense to identify and suppress day-zero malware attacks. Progent also can provide the services of expert crypto-ransomware recovery engineers with the track record and perseverance to rebuild a compromised environment as quickly as possible.
Progent's Ransomware Recovery Services
Subsequent to a crypto-ransomware attack, sending the ransom demands in cryptocurrency does not provide any assurance that criminal gangs will respond with the needed keys to decrypt any of your data. Kaspersky Labs ascertained that 17% of crypto-ransomware victims never recovered their data even after having paid the ransom, resulting in increased losses. The risk is also costly. Ryuk ransoms are often several hundred thousand dollars. For larger organizations, the ransom can be in the millions. The other path is to piece back together the mission-critical components of your Information Technology environment. Absent access to complete information backups, this calls for a broad complement of skills, well-coordinated project management, and the ability to work non-stop until the recovery project is finished.
For twenty years, Progent has made available certified expert Information Technology services for businesses across the U.S. and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes professionals who have been awarded advanced industry certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security consultants have garnered internationally-recognized industry certifications including CISM, CISSP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise in financial systems and ERP application software. This breadth of experience provides Progent the capability to rapidly ascertain critical systems and re-organize the surviving parts of your IT environment following a ransomware event and assemble them into a functioning system.
Progent's security group utilizes state-of-the-art project management tools to orchestrate the complex recovery process. Progent knows the importance of working quickly and together with a client's management and IT staff to assign priority to tasks and to put essential services back on-line as fast as possible.
Case Study: A Successful Ransomware Incident Restoration
A customer contacted Progent after their network was crashed by the Ryuk ransomware. Ryuk is generally considered to have been developed by North Korean government sponsored cybercriminals, possibly adopting algorithms exposed from America's National Security Agency. Ryuk targets specific organizations with little or no ability to sustain disruption and is among the most lucrative examples of ransomware malware. Major victims include Data Resolution, a California-based data warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a regional manufacturer located in Chicago with about 500 workers. The Ryuk intrusion had disabled all essential operations and manufacturing capabilities. The majority of the client's data backups had been directly accessible at the time of the intrusion and were damaged. The client was evaluating paying the ransom demand (more than two hundred thousand dollars) and wishfully thinking for good luck, but ultimately brought in Progent.
Progent worked together with the customer to quickly determine and prioritize the most important applications that needed to be addressed to make it possible to resume company operations:
In less than two days, Progent was able to restore Windows Active Directory to its pre-intrusion state. Progent then initiated setup and hard drive recovery of critical applications. All Microsoft Exchange Server schema and attributes were intact, which accelerated the rebuild of Exchange. Progent was also able to find intact OST files (Microsoft Outlook Offline Data Files) on team workstations and laptops to recover mail messages. A not too old off-line backup of the customer's financials/ERP systems made them able to recover these vital programs back on-line. Although significant work needed to be completed to recover completely from the Ryuk virus, critical services were returned to operations rapidly:
Throughout the following few weeks key milestones in the restoration process were achieved through close cooperation between Progent consultants and the client:
Conclusion
A possible business extinction disaster was averted through the efforts of dedicated professionals, a wide array of knowledge, and tight teamwork. Although in analyzing the event afterwards the crypto-ransomware penetration detailed here should have been identified and stopped with modern security technology solutions and recognized best practices, user and IT administrator education, and well designed incident response procedures for data backup and applying software patches, the fact is that state-sponsored hackers from China, Russia, North Korea and elsewhere are relentless and will continue. If you do get hit by a ransomware penetration, remember that Progent's roster of professionals has extensive experience in crypto-ransomware virus blocking, cleanup, and information systems recovery.
Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer case study, please click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Restoration Services in Tacoma
For ransomware cleanup services in the Tacoma metro area, call Progent at