Viruses and malware·29 questions

Viruses and malware: what to do during ransomware and how to recover?

Answer

A ransomware attack represents one of the most dangerous threats to the digital assets of users and businesses. In a situation where malware encrypts all files on the drive and demands a ransom, updates and backups play a much more important role than complex fine-tuning of the system. Attackers rely on panic and the victim's lack of up-to-date backups, so your first task is to keep a cool head and follow a pre-prepared recovery plan.

If you encounter a ransomware infection, it is strictly not recommended to rush to pay cybercriminals, as this does not guarantee the return of files and only sponsors further attacks. Instead, follow these steps:

Immediately isolate the infected device from the local network and the internet by turning off Wi-Fi and unplugging the cable to stop the network drive encryption process.
Identify the ransomware type using free online services such as ID Ransomware by NoMoreRansom to find out if free decryptors already exist.
Save the encrypted files and the ransom note itself to an external storage medium, as decryption keys for your version of the virus may appear in the future.
Perform a complete wipe of the operating system by reinstalling it from scratch via a clean installation media to completely destroy traces of malware presence.
Restore lost data from previously created backups stored on an isolated external drive or in cloud storage.

To prevent such situations from repeating in the future, fully automate the backup creation process and implement additional security measures. Set up daily or weekly creation of shadow copies and archives according to the three-two-one rule: three copies of data, on two different types of media, with one copy offsite or away from home. Be sure to enable two-factor authentication (2FA) for all accounts, cloud storages, and mailboxes so that attackers cannot gain remote access to your management panels and backups.

Was this answer helpful?

More questions in this topic

Related questions from other topics