Ransomware : Your Worst IT Nightmare
Ransomware has become a modern cyberplague that poses an existential danger for businesses of all sizes unprepared for an assault. Multiple generations of ransomware like the Dharma, WannaCry, Locky, Syskey and MongoLock cryptoworms have been running rampant for many years and still inflict harm. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, along with additional unnamed malware, not only encrypt online files but also infect all available system restores and backups. Information replicated to the cloud can also be corrupted. In a poorly designed system, it can render automatic recovery impossible and basically sets the datacenter back to square one.
Restoring programs and data following a crypto-ransomware attack becomes a sprint against the clock as the targeted organization tries its best to stop the spread, remove the virus, and resume mission-critical activity. Because ransomware requires time to replicate across a network, penetrations are often launched at night, when attacks tend to take more time to uncover. This compounds the difficulty of rapidly mobilizing and coordinating a knowledgeable mitigation team.
Progent has a variety of help services for protecting New Orleans businesses from crypto-ransomware penetrations. These include team member training to help identify and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's behavior-based threat protection to detect and disable day-zero malware attacks. Progent also can provide the services of experienced ransomware recovery consultants with the talent and commitment to reconstruct a compromised network as soon as possible.
Progent's Ransomware Recovery Services
After a ransomware attack, even paying the ransom demands in cryptocurrency does not provide any assurance that cyber criminals will provide the needed codes to decipher any or all of your information. Kaspersky Labs ascertained that seventeen percent of ransomware victims never recovered their data even after having sent off the ransom, resulting in more losses. The risk is also expensive. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom can reach millions. The alternative is to setup from scratch the mission-critical parts of your Information Technology environment. Absent the availability of essential system backups, this requires a broad range of IT skills, professional team management, and the ability to work 24x7 until the recovery project is over.
For twenty years, Progent has offered expert IT services for businesses throughout the United States and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes professionals who have been awarded advanced industry certifications in foundation technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security experts have garnered internationally-renowned industry certifications including CISM, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience in financial systems and ERP application software. This breadth of experience provides Progent the skills to quickly understand critical systems and integrate the surviving parts of your Information Technology system following a crypto-ransomware penetration and rebuild them into a functioning system.
Progent's security team deploys best of breed project management systems to coordinate the complicated restoration process. Progent understands the importance of working rapidly and in concert with a client's management and Information Technology resources to assign priority to tasks and to get the most important applications back on-line as soon as humanly possible.
Client Story: A Successful Ransomware Intrusion Restoration
A customer engaged Progent after their organization was penetrated by the Ryuk ransomware. Ryuk is believed to have been developed by North Korean government sponsored criminal gangs, possibly adopting algorithms exposed from America's National Security Agency. Ryuk attacks specific organizations with little or no tolerance for operational disruption and is among the most profitable instances of ransomware. Well Known targets include Data Resolution, a California-based info warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a small manufacturer located in the Chicago metro area and has around 500 employees. The Ryuk attack had brought down all business operations and manufacturing processes. Most of the client's information backups had been directly accessible at the start of the intrusion and were eventually encrypted. The client was actively seeking loans for paying the ransom (exceeding two hundred thousand dollars) and hoping for good luck, but in the end made the decision to use Progent.
Progent worked hand in hand the client to rapidly get our arms around and assign priority to the mission critical systems that had to be recovered to make it possible to continue company operations:
In less than two days, Progent was able to re-build Active Directory to its pre-virus state. Progent then completed reinstallations and hard drive recovery on the most important applications. All Exchange Server schema and attributes were usable, which greatly helped the restore of Exchange. Progent was also able to find intact OST data files (Microsoft Outlook Off-Line Data Files) on staff desktop computers to recover mail data. A not too old offline backup of the client's accounting/ERP systems made them able to recover these essential services back available to users. Although significant work needed to be completed to recover completely from the Ryuk attack, the most important systems were restored rapidly:
Throughout the next couple of weeks critical milestones in the recovery project were completed in close cooperation between Progent consultants and the customer:
Conclusion
A possible business extinction disaster was dodged by top-tier professionals, a broad array of subject matter expertise, and close teamwork. Although in retrospect the ransomware attack described here should have been identified and disabled with up-to-date cyber security solutions and best practices, user and IT administrator education, and well designed security procedures for data protection and keeping systems up to date with security patches, the reality remains that state-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a crypto-ransomware virus, feel confident that Progent's team of experts has proven experience in ransomware virus defense, removal, and data restoration.
Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Cleanup Services in New Orleans
For ransomware system restoration consulting services in the New Orleans metro area, call Progent at