Service
Security Hardening
- Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
Hardening built around the intrusion paths ransomware actually uses: shrink internet exposure, fix credentials and remote access, patch high-risk flaws, reduce privilege, and rebuild backups that cannot be deleted.
What this service covers
Ransomware entry points are highly concentrated: remote desktop and database ports exposed to the internet, VPNs without multi-factor authentication, unpatched edge appliances and middleware, shared high-privilege accounts, and online-only backups that vanish the moment an attacker deletes them. This service works on those real paths and skips controls that do not change actual risk.
What hardening covers
- Exposure review: inventory external assets and ports, remove unnecessary public mappings, and give priority to directly exposed services such as 3389, 445, 1433, 3306 and 1521, along with exposed management consoles.
- Remote access governance: multi-factor authentication on VPN and administration channels, tighter source-address and time-window policies, cleanup of departed and shared accounts, and separately authorized, audited channels for third-party administrators.
- Patch and configuration baselines: a patch priority for edge devices, virtualization platforms, databases and middleware, remediation of high-risk flaws known to be exploited in the wild, and enforced host and service baselines.
- Privilege and segmentation: separated administrative accounts under least privilege, no reuse of local administrator passwords, and separated production, office and administration segments that limit server-to-server reachability.
- Backup rebuild: designed around keeping at least one offline or immutable copy, with restore testing and backup credentials isolated from the production domain.
- Monitoring and rehearsal: centralized retention of key logs with a defined retention period, alert rules aimed at ransomware behaviour, help drafting a response plan, and one tabletop exercise.
Note
Hardening substantially reduces both the chance of compromise and the damage if it happens, but zero risk does not exist. We deliver a verifiable hardening checklist with test results, stating which items are complete and which are currently blocked by business constraints along with the compensating measures. Plans are built on the client's existing environment and budget, and never depend on replacing equipment or purchasing a particular product.
Deliverables
- External exposure inventory with a before-and-after comparison
- Hardening checklist: item status, owner, verification method and result
- Remote access and account privilege remediation plan, including MFA rollout guidance
- Prioritized patch and configuration baseline list, flagging flaws exploited in the wild
- Backup architecture design notes and restore verification records
- Recommended ransomware-focused alert rules and a draft response plan
How it works
Discovery and asset inventory
We inventory servers, virtualization platforms, databases, NAS units, edge devices and public mappings, confirm ownership and business criticality, and understand how operations actually run: who holds administrative rights, how third parties connect, and how backups execute.
Risk identification and prioritization
Findings are ranked by whether they get exploited in reality: directly exposed remote and database ports, VPNs without MFA, edge-device flaws under active exploitation, weak and reused passwords, and single online-only backups. Those high-leverage items go first.
Plan design and sign-off
The plan is designed around availability so hardening does not cause outages: change windows, rollback procedures and impact assessments are written out per item. Items are grouped as immediate, scheduled, or deferred with compensating controls — and implemented after client sign-off.
Implementation and verification
Work is rolled out in batches and verified item by item: are the external ports genuinely closed, does MFA cover every channel, did the patches take effect, does the backup actually restore. Results go into the hardening checklist so nothing is "configured but ineffective".
Monitoring, planning and follow-up
We configure ransomware-oriented alerts — anomalous logons, bulk file renaming, shadow copy deletion, backup jobs being stopped — help draft the response plan, and run one tabletop exercise. A follow-up review within the agreed interval confirms the changes have not regressed.
When to use it
- Recovery from a ransomware incident is complete and the priority is not being hit again
- Databases, remote desktop or management consoles are directly exposed to the internet
- VPN and administration channels lack MFA and accounts are shared long-term
- The only backup is online, in the same domain and using the same credentials as production
- Virtualization platforms and edge appliances have gone long without patching
- Baseline remediation is needed ahead of a compliance review or customer audit
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
SQL Server Database Encrypted by Ransomware
When SQL Server .mdf / .ldf files are encrypted, the ERP and inventory systems built on them — Yonyou U8, Kingdee K/3, Guanjiapo, Suda — stop completely. This page covers evidence handling, how we judge whether page-level repair is viable, and the conditions for backup-plus-log restore.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
Related ransomware families
- Some versions decryptable
Mallox
Mallox (also known as TargetCompany) breaks in mainly through brute-forced MS SQL Server credentials, targets database servers specifically, and has a Linux/ESXi variant. Files encrypted between 2023 and early 2024 may be decryptable with Avast's free tool; later builds have no public decryption method.
- No public decryptor
Weaxor
Weaxor emerged in late 2024 as a same-lineage successor to Mallox, continuing its focus on MS SQL Server and exposed web services. It appends .rox, .weax or .wxx and drops a RECOVERY INFO.txt note. It has led infection volume in China through 2025 and 2026 (45.45% in July 2026, 65.74% in August 2026) and has no public decryptor.
- Some versions decryptable
Akira
Akira is a ransomware-as-a-service operation that emerged in March 2023, breaking in through VPNs without MFA and edge-device flaws, then encrypting Windows estates and VMware ESXi clusters under double extortion. CISA's November 2025 advisory update calls it an imminent threat to critical infrastructure.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
BeijingCrypt
BeijingCrypt takes its name from the .beijing extension used by early builds. It is a persistently prevalent family in China, deployed by hand after brute-forcing remote desktop or database credentials, and has cycled through .beijing, .360, .520, .halo and .bixi variants. No public decryptor exists.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
- Systems & software
What should we do when a Linux server or BT Panel is hit by ransomware?
First work out which kind of incident you have: website and database files that have genuinely been encrypted (new extensions, ransom notes in the directories), or databases that were dropped and replaced with a ransom table. The second involves no encryption, nobody can prove beforehand that the attacker kept a copy, and paying is not a recovery path. In both cases cut public access but keep the host running, do not reinstall or keep restarting the database, snapshot or image the data partition, then look for the data in backups, binlogs and disk remnants - and remove every back door before going live again.
- Systems & software
What should we do when Guanjiapo or Suda account sets are encrypted by ransomware?
Isolate the server holding the account sets from the network but keep it powered on. Do not reinstall the accounting software, restore an account set over the original disk, or run decryptors from the internet. Guanjiapo, Suda, Chanjet T+ and T3, Kingdee KIS Professional and similar products mostly keep account sets in SQL Server, with built-in automatic backups on the same machine, so both tend to be encrypted together. How much comes back depends on the family and how it encrypted, whether a clean backup exists beyond that server, and whether the database files were only partly encrypted. After recovery, reconcile stock, receivables and payables line by line, and close the entry point before going back online.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
FAQ
Frequently asked questions
After hardening, are we safe from ransomware?
That is not a promise we make. Hardening closes the entry points attackers commonly use, shrinks the reachable lateral surface, and builds the recovery capability for the worst case — which substantially lowers both the odds and the damage.
What really decides how bad the worst case gets is backup: with one offline or immutable copy that has been test-restored, a second incident can be resolved on your own, without the ransom ever entering the discussion.
Do we need to buy new equipment or software?
Most of the high-value items do not. Removing unnecessary public mappings, enabling MFA, patching flaws under active exploitation, separating administrative accounts and taking one backup copy offline are largely configuration and process changes.
Where the existing environment genuinely cannot meet a requirement, we state the gap and the options and leave the spending decision to the client. We are not tied to any vendor's products.
Will hardening disrupt operations?
We work impact-first: assess the effect, agree a change window, keep a rollback. Anything that could affect operations — closing ports, changing authentication policy, installing patches — is preceded by a dependency check and scheduled in a low-traffic window.
Some items genuinely require a brief restart or interruption; we notify the expected duration in writing in advance and proceed only after confirmation.
What actually makes a backup safe?
Three things matter:
- At least one offline or immutable copy. Tape, disconnected removable media, or object storage with an immutability policy are all far safer than "another server that is always online".
- Credentials isolated from production. The backup system should not run under a domain administrator account or share passwords with production.
- Regular restore testing. A backup that has never been restored is not a backup; we run one real restore exercise during hardening.
Updated