Ransomware : Your Worst IT Nightmare
Ransomware has become a too-frequent cyberplague that poses an existential danger for businesses poorly prepared for an assault. Different iterations of ransomware like the Reveton, Fusob, Bad Rabbit, NotPetya and MongoLock cryptoworms have been out in the wild for many years and continue to inflict damage. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, plus frequent as yet unnamed newcomers, not only encrypt online information but also infect all accessible system protection mechanisms. Data synched to off-premises disaster recovery sites can also be ransomed. In a poorly designed data protection solution, it can make any recovery impossible and effectively sets the network back to square one.
Getting back online programs and information after a ransomware outage becomes a race against the clock as the targeted business fights to contain the damage, eradicate the crypto-ransomware, and resume business-critical activity. Since crypto-ransomware requires time to move laterally throughout a targeted network, attacks are often launched at night, when successful penetrations tend to take longer to discover. This multiplies the difficulty of promptly assembling and coordinating a capable response team.
Progent makes available a variety of help services for protecting Guarulhos enterprises from crypto-ransomware events. These include team education to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's behavior-based threat defense to detect and disable day-zero modern malware attacks. Progent in addition can provide the services of expert ransomware recovery consultants with the skills and perseverance to rebuild a breached environment as urgently as possible.
Progent's Ransomware Restoration Support Services
Soon after a ransomware invasion, paying the ransom in cryptocurrency does not ensure that cyber hackers will provide the needed keys to unencrypt any or all of your data. Kaspersky Labs ascertained that seventeen percent of crypto-ransomware victims never recovered their files even after having sent off the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom can be in the millions of dollars. The other path is to setup from scratch the mission-critical parts of your Information Technology environment. Absent access to full system backups, this calls for a broad complement of skills, top notch project management, and the willingness to work continuously until the task is completed.
For two decades, Progent has made available professional Information Technology services for businesses throughout the U.S. and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have earned top certifications in foundation technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have earned internationally-renowned industry certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience in financial systems and ERP application software. This breadth of experience affords Progent the skills to knowledgably ascertain necessary systems and consolidate the surviving components of your network system following a crypto-ransomware attack and assemble them into a functioning network.
Progent's ransomware group utilizes top notch project management applications to orchestrate the complicated restoration process. Progent appreciates the importance of acting quickly and in unison with a customer's management and IT resources to assign priority to tasks and to get essential systems back on line as fast as humanly possible.
Business Case Study: A Successful Crypto-Ransomware Incident Response
A business engaged Progent after their network was taken over by Ryuk ransomware. Ryuk is generally considered to have been created by North Korean government sponsored criminal gangs, suspected of adopting technology leaked from the United States NSA organization. Ryuk attacks specific businesses with limited room for disruption and is one of the most lucrative incarnations of ransomware viruses. Major organizations include Data Resolution, a California-based information warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a single-location manufacturing business located in Chicago and has about 500 workers. The Ryuk intrusion had paralyzed all business operations and manufacturing processes. The majority of the client's system backups had been directly accessible at the beginning of the intrusion and were encrypted. The client considered paying the ransom (exceeding two hundred thousand dollars) and wishfully thinking for good luck, but ultimately brought in Progent.
Progent worked together with the customer to quickly get our arms around and prioritize the most important elements that had to be recovered to make it possible to continue company functions:
In less than two days, Progent was able to re-build Active Directory to its pre-attack state. Progent then helped perform rebuilding and storage recovery of needed servers. All Exchange schema and configuration information were usable, which facilitated the rebuild of Exchange. Progent was able to locate local OST files (Outlook Email Offline Folder Files) on team workstations and laptops in order to recover mail messages. A recent offline backup of the businesses accounting systems made them able to recover these essential applications back available to users. Although major work needed to be completed to recover fully from the Ryuk event, critical services were returned to operations quickly:
During the next month key milestones in the restoration process were accomplished in close collaboration between Progent consultants and the customer:
Conclusion
A likely business disaster was evaded by hard-working experts, a wide spectrum of knowledge, and close collaboration. Although in analyzing the event afterwards the ransomware incident detailed here could have been prevented with up-to-date cyber security technology and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, team education, and well designed security procedures for information backup and keeping systems up to date with security patches, the fact remains that state-sponsored cybercriminals from China, Russia, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware incident, feel confident that Progent's team of experts has proven experience in ransomware virus defense, mitigation, and file disaster recovery.
Download the Ransomware Removal Case Study Datasheet
To read or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Recovery Services in Guarulhos
For ransomware recovery consulting in the Guarulhos metro area, phone Progent at