Service
Attack Forensics & Attribution
- Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Reconstruct the attack timeline and entry point from logs, images and memory evidence, assess whether data was exfiltrated, and deliver a traceable forensic report.
What this service covers
Forensics answers three questions: how the attacker got in, what they did inside, and whether they took data out. Those answers drive remediation, and they determine whether the organization has defensible material for police reporting, regulator communication and notifications to customers and partners.
What the engagement covers
- Evidence acquisition following forensic procedure: disk images, memory captures, edge-device and server logs, each recorded with acquisition time, hash and responsible engineer so the chain of custody holds.
- Entry-point determination across internet-exposed services, VPN and RDP accounts, edge appliance and middleware vulnerabilities, phishing, third-party administration channels and the supply chain.
- Timeline reconstruction from initial access through privilege escalation, lateral movement, credential theft, defence evasion, data staging and exfiltration, to the final deployment of the encryptor — each step annotated with time and evidence source.
- Exfiltration assessment, combining outbound traffic records, archiving and staging artifacts, traces of cloud storage or transfer tooling, and postings on the actor's leak site, to judge likelihood and the data categories involved.
- Reporting: a forensic report that separates conclusions into confirmed, highly likely and undetermined, with an evidence index and technical appendices.
Limits
Forensic conclusions are bounded by the evidence. Where logging was off, retention was too short, the attacker wiped records, or a host has already been reinstalled, some steps cannot be reconstructed — and we mark those as undetermined in the report rather than filling the gap with a tidy-looking story. We also do not name individual attackers: open-source intelligence can support attribution to a family or crew, but identifying individuals is the remit of law enforcement. The report is suitable for filing a case with the public security authorities and for internal compliance records; whether a case is opened and how it is ultimately characterized is for the authorities to decide.
Deliverables
- Evidence inventory: image and log sources, acquisition times, hash values
- Attack timeline report, each step annotated with evidence source and confidence level
- Entry point and root cause determination, with reproducible supporting evidence
- Exfiltration assessment and the data categories potentially involved
- Indicator-of-compromise list and inventory of laterally affected assets
- Prioritized remediation checklist ordered by urgency
How it works
Scope definition and preservation
We confirm the purpose of the engagement with the client — police reporting, compliance records, internal accountability, insurance — and the scope boundary: which systems may be imaged and which data must not leave the premises. Evidence is then frozen and any operation that would overwrite logs or disks is paused.
Acquisition and integrity verification
We acquire disk and memory images from key hosts, domain controller and server logs, firewall, VPN and traffic logs, and logs from the virtualization and backup platforms. Everything is hashed and registered so the chain of custody is traceable.
Artifact analysis and correlation
We analyse authentication records, process and service creation, scheduled tasks, registry and persistence artifacts, remote-access and penetration tooling traces, and filesystem timelines, correlating them in time with outbound traffic records to locate initial access and the lateral path.
Exfiltration assessment and intelligence matching
We check for bulk outbound transfers, unusual archiving activity and use of cloud storage or transfer utilities. The ransom note, encryption characteristics and open-source intelligence are matched to attribute the family or crew, and we search the actor's leak site for related postings.
Reporting and support for filing a case
We issue the forensic report: conclusion summary, timeline, evidence index, IOC list and remediation recommendations. On request we support the client in submitting material to the public security authorities, responding to regulator enquiries, and briefing management once on the findings.
When to use it
- A case is being filed with the police and technical forensic material is required
- A regulator, group head office or customer requires an incident investigation report
- Data is suspected to have been stolen and the exfiltration scope must be assessed
- The same environment keeps getting breached and the real entry point must be found
- Responsibility boundaries with an outsourced administrator, vendor or insider need to be established
- An insurance claim or contractual dispute requires an independent technical conclusion
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
OA Collaboration System Encrypted by Ransomware
An encrypted OA system halts document circulation, approvals, contract archives, HR and knowledge bases at once — and because OA is so often published to the internet, it is frequently the attacker's first foothold. This page covers its vulnerability profile, the twin-track recovery of attachments and database, and how to check for lateral spread.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related ransomware families
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- No public decryptor
TellYouThePass
TellYouThePass is the archetypal vulnerability-driven ransomware family in China, mass-deployed against internet-facing ERP, OA, finance and middleware systems. It appends .locked and hits both Windows and Linux servers. No public decryptor exists.
- No public decryptor
Weaxor
Weaxor emerged in late 2024 as a same-lineage successor to Mallox, continuing its focus on MS SQL Server and exposed web services. It appends .rox, .weax or .wxx and drops a RECOVERY INFO.txt note. It has led infection volume in China through 2025 and 2026 (45.45% in July 2026, 65.74% in August 2026) and has no public decryptor.
- No public decryptor
Play
Play (PlayCrypt / Balloonfly) has been active since June 2022 and is one of the few closed-group ransomware operations, recompiling its encryptor for every victim. It targets FortiOS and Exchange flaws, RDP and VPN, and maintains a dedicated ESXi encryptor. CISA counted roughly 900 victims as of May 2025, and public leak-site trackers list over 1,200 entries as of September 2026.
- Some versions decryptable
Black Basta
Black Basta was a Conti-derived RaaS operation that emerged in April 2022 and affected more than 500 organisations, known for QakBot delivery and Microsoft Teams IT-impersonation social engineering. It disbanded in February 2025 after its internal chat logs leaked, though its tradecraft carried over to successors such as Cactus.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- First response
What should we do when a server is hit by ransomware?
Isolate first and do not reboot: cut the affected server off at the switch or in the cloud security group, but leave it running. Then snapshot or image the system and data disks, keep the ransom note and encrypted samples, and check read-only whether shadow copies, cloud snapshots and backups survived. If several servers are down, set a restore order by business dependency, and bring nothing back online until the entry point is closed and every credential has been changed. What can be recovered depends on the family, the encryption mode and the backups.
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
- Systems & software
What should we do when a Linux server or BT Panel is hit by ransomware?
First work out which kind of incident you have: website and database files that have genuinely been encrypted (new extensions, ransom notes in the directories), or databases that were dropped and replaced with a ransom table. The second involves no encryption, nobody can prove beforehand that the attacker kept a copy, and paying is not a recovery path. In both cases cut public access but keep the host running, do not reinstall or keep restarting the database, snapshot or image the data partition, then look for the data in backups, binlogs and disk remnants - and remove every back door before going live again.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
FAQ
Frequently asked questions
Can the forensic report be used directly to file a police report?
Yes, as the technical material submitted with the report. It contains the incident timeline, entry-point determination, compromised asset inventory, indicators of compromise and an evidence index, so investigators can grasp the case quickly.
Note that whether a case is opened and how it is characterized is decided by the public security authorities under law; we supply technical support and material, not an investigative conclusion. Filing early is generally advisable, before evidence expires or is overwritten.
How do you determine whether data was actually stolen?
Four categories of evidence: the direction, volume and timing of outbound traffic; archiving activity and staging directories on hosts; use of cloud storage clients, command-line transfer tools or remote-access file transfer; and whether the actor's leak site has published the organization's data.
When all four point the same way the conclusion is strong. Where traffic logs are missing we can only give a likelihood based on host artifacts, and the report states that uncertainty explicitly.
Operations are already restored — is forensics still worth doing?
It is. If the entry point is unknown, the same path is likely to be reused — re-encryption within weeks of a restore is something we have handled repeatedly.
Beyond that, whether data left the network affects notification duties and residual risk, and remediation needs a root cause to aim at. As long as logs and images have not been overwritten, earlier forensics means firmer conclusions.
Will forensics take our sensitive data off-site?
Not beyond what was agreed. The scope, handling method and storage location are confirmed in writing before work starts; for classified or highly sensitive environments we can work entirely on site so that no data leaves the premises and only the analytical conclusions are taken away.
All client data we touch is handled under the confidentiality terms, working copies are deleted within the agreed period after the engagement, and a deletion confirmation can be issued.
Updated