Ransomware : Your Feared Information Technology Nightmare
Ransomware has become a too-frequent cyber pandemic that presents an enterprise-level threat for businesses poorly prepared for an assault. Different iterations of ransomware such as Reveton, WannaCry, Bad Rabbit, SamSam and MongoLock cryptoworms have been out in the wild for a long time and continue to cause havoc. Newer variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Egregor, plus more as yet unnamed viruses, not only perform encryption of on-line data files but also infiltrate any accessible system backup. Information synchronized to cloud environments can also be ransomed. In a poorly architected system, it can make automatic restoration useless and basically sets the network back to square one.
Retrieving programs and data after a ransomware event becomes a sprint against the clock as the targeted organization struggles to stop lateral movement, remove the ransomware, and restore mission-critical operations. Because ransomware needs time to spread across a targeted network, attacks are usually launched during nights and weekends, when successful attacks in many cases take longer to identify. This compounds the difficulty of rapidly assembling and organizing an experienced response team.
Progent provides an assortment of services for protecting Washington enterprises from crypto-ransomware penetrations. These include team training to help identify and not fall victim to phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's AI-based threat defense to detect and quarantine zero-day modern malware attacks. Progent in addition can provide the assistance of experienced ransomware recovery engineers with the track record and commitment to re-deploy a breached system as urgently as possible.
Progent's Crypto-Ransomware Recovery Help
Subsequent to a crypto-ransomware attack, sending the ransom in cryptocurrency does not provide any assurance that cyber hackers will return the needed codes to decipher any of your files. Kaspersky Labs estimated that 17% of ransomware victims never restored their information after having sent off the ransom, resulting in increased losses. The gamble is also costly. Ryuk ransoms are often a few hundred thousand dollars. For larger enterprises, the ransom can reach millions of dollars. The alternative is to piece back together the key elements of your Information Technology environment. Absent the availability of full information backups, this calls for a broad complement of skill sets, professional project management, and the capability to work 24x7 until the job is complete.
For twenty years, Progent has provided professional Information Technology services for businesses throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes professionals who have earned top certifications in foundation technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security engineers have garnered internationally-renowned industry certifications including CISM, CISSP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience with financial systems and ERP applications. This breadth of experience provides Progent the capability to knowledgably determine necessary systems and integrate the surviving parts of your computer network system after a ransomware event and rebuild them into a functioning system.
Progent's ransomware group utilizes powerful project management applications to orchestrate the complicated restoration process. Progent knows the urgency of acting rapidly and together with a customer's management and Information Technology resources to assign priority to tasks and to put the most important applications back on line as fast as humanly possible.
Business Case Study: A Successful Ransomware Incident Restoration
A customer contacted Progent after their network system was crashed by the Ryuk ransomware. Ryuk is thought to have been developed by North Korean state sponsored cybercriminals, suspected of using technology leaked from the United States NSA organization. Ryuk targets specific organizations with little tolerance for disruption and is one of the most profitable incarnations of ransomware. Headline victims include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a small manufacturer located in Chicago with around 500 workers. The Ryuk intrusion had frozen all business operations and manufacturing processes. Most of the client's system backups had been directly accessible at the start of the attack and were destroyed. The client was taking steps for paying the ransom (in excess of two hundred thousand dollars) and praying for the best, but ultimately utilized Progent.
Progent worked hand in hand the client to quickly get our arms around and prioritize the mission critical applications that needed to be addressed in order to resume departmental functions:
Within 2 days, Progent was able to restore Active Directory services to its pre-intrusion state. Progent then charged ahead with reinstallations and hard drive recovery of needed servers. All Exchange Server data and attributes were usable, which greatly helped the rebuild of Exchange. Progent was also able to find intact OST files (Outlook Email Off-Line Folder Files) on various workstations in order to recover email messages. A not too old offline backup of the client's financials/ERP systems made it possible to recover these required services back online for users. Although a large amount of work still had to be done to recover completely from the Ryuk attack, core systems were restored quickly:
Throughout the next couple of weeks key milestones in the recovery project were achieved through tight collaboration between Progent engineers and the customer:
Conclusion
A possible business-ending disaster was evaded with top-tier professionals, a wide spectrum of subject matter expertise, and close collaboration. Although in analyzing the event afterwards the ransomware virus incident detailed here would have been stopped with advanced cyber security technology and ISO/IEC 27001 best practices, user and IT administrator education, and well thought out security procedures for information protection and applying software patches, the fact remains that government-sponsored hackers from China, Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware incident, remember that Progent's roster of professionals has extensive experience in ransomware virus defense, cleanup, and information systems recovery.
Download the Crypto-Ransomware Remediation Case Study Datasheet
To read or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Restoration Consulting Services in Washington
For ransomware cleanup consulting services in the Washington metro area, call Progent at