Service
Incident Response
- Round-the-clock intake: contain first, preserve evidence second, recover third.
Emergency handling while an incident is still spreading or the attacker may still have access: contain the blast radius, remove persistence, preserve evidence, and open a safe window for recovery.
What this service covers
Incident response addresses the case where the incident is not over yet. Many organizations rush straight to recovery after discovering encryption — but if the attacker still holds domain credentials, a remote channel or a scheduled task, restored data tends to get encrypted a second time. Our order is: contain, preserve, then recover.
What the engagement covers
- Blast-radius assessment across encrypted hosts, shared paths, virtualization platforms and backup systems, including whether lateral movement already reached domain controllers and the backup domain.
- Containment and isolation: tighter segmentation and access control, disabling compromised accounts, taking down suspicious remote tooling (RDP, VPN accounts, RMM agents), and removing malicious scheduled tasks and services.
- Evidence preservation: capturing critical logs, memory and disk images before the environment is altered, so that later attribution work and compliance reporting have usable material.
- Persistence removal and re-check: locating and eliminating backdoors, web shells, newly created accounts and credential-theft tooling, then re-checking before recovery work is allowed to start.
- Recovery escort: defining a safe recovery order, supporting the data recovery team, and completing baseline hardening and credential rotation before systems go back online.
Limits
Incident response limits the damage and lowers the chance of re-encryption, but it does not by itself mean the data is recoverable — that depends on the family and version, the state of backups, and how badly files were damaged, and it is answered by the recoverability assessment. Likewise, attribution does not always reach a named actor: where logs were wiped or never enabled, we provide reasoned inference from available evidence and label the strength of that evidence in the report. We do not negotiate with attackers and take no part in ransom payment.
Deliverables
- Response log and incident timeline covering detection, containment, eradication and re-check
- Affected asset inventory and blast-radius conclusion
- Containment checklist: accounts disabled, channels closed, artifacts removed
- Eradication and re-check report for backdoors, web shells, rogue accounts and scheduled tasks
- Recommended safe recovery order and a pre-go-live checklist
- Immediate remediation items plus medium-term hardening recommendations
How it works
Intake and rapid triage
We respond quickly after intake and use a call plus a remote session to establish the incident type, when it was noticed, what has already been done, and whether it is still spreading — then issue containment instructions: isolate without powering off, do not reboot, do not reinstall, pause backup overwrites, keep the note and the logs.
Containment and evidence preservation
Evidence is fixed before anything is cleaned: memory and disk images from key hosts, firewall and VPN logs, domain controller and backup system logs. In parallel we segment the network, disable compromised credentials and shrink the exposed surface to cut the attacker's live channel.
Root cause analysis and eradication
The work centres on the entry point: internet-exposed services, weak VPN and RDP credentials, unpatched edge appliances, phishing, supply chain and administration tooling. Once located we remove backdoors, web shells, malicious services and rogue accounts, and rotate every related credential.
Recovery escort and re-verification
This runs alongside recovery: which core production systems come back first, in which isolated segment they are rebuilt, and in what order access is re-opened. Each restored system is re-checked for residual persistence before it rejoins the production network.
Post-incident review and remediation follow-up
We deliver the timeline and root-cause conclusion, list the immediate must-fix items and medium-term hardening work, hand over to forensics (for police reporting and compliance) or hardening where needed, and follow up within an agreed interval to confirm remediation actually happened.
When to use it
- Encryption is still spreading and new hosts keep appearing with ransom notes
- A domain controller or core management platform looks compromised and servers fell together
- Unexplained outbound connections, unknown accounts or unfamiliar remote-management agents are running
- A system you already restored was encrypted again, suggesting the attacker still has access
- A regulator, head office or customer requires an incident handling account and timeline
- There is no internal security team and the on-site response needs to be led from outside
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
OA Collaboration System Encrypted by Ransomware
An encrypted OA system halts document circulation, approvals, contract archives, HR and knowledge bases at once — and because OA is so often published to the internet, it is frequently the attacker's first foothold. This page covers its vulnerability profile, the twin-track recovery of attachments and database, and how to check for lateral spread.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related ransomware families
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- Some versions decryptable
Akira
Akira is a ransomware-as-a-service operation that emerged in March 2023, breaking in through VPNs without MFA and edge-device flaws, then encrypting Windows estates and VMware ESXi clusters under double extortion. CISA's November 2025 advisory update calls it an imminent threat to critical infrastructure.
- No public decryptor
Qilin
Qilin (formerly Agenda) is a Rust-rewritten cross-platform RaaS operation focused on VMware ESXi and Linux estates. It has ranked as the world's most active ransomware group for several consecutive quarters since 2025, with confirmed victims among electronics manufacturers in Taiwan and Hong Kong.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
RansomHub
RansomHub launched in February 2024 as a rebrand of Knight/Cyclops and rapidly absorbed affiliates from ALPHV and LockBit with a 90% revenue share, accumulating hundreds of victims within a year. Its infrastructure went offline in early April 2025 and the operation has been dormant since, with affiliates largely migrating to Qilin and DragonForce.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- First response
What should we do when a server is hit by ransomware?
Isolate first and do not reboot: cut the affected server off at the switch or in the cloud security group, but leave it running. Then snapshot or image the system and data disks, keep the ransom note and encrypted samples, and check read-only whether shadow copies, cloud snapshots and backups survived. If several servers are down, set a restore order by business dependency, and bring nothing back online until the entry point is closed and every credential has been changed. What can be recovered depends on the family, the encryption mode and the backups.
- Ransom & cost
How much does ransomware decryption cost, and how long does recovery take?
There is no fixed price and no fixed timeline. Cost and duration depend mainly on whether the family and version can be decrypted, how many hosts and how much data are affected, how hard database and virtual machine repair will be, whether work is remote or on site, and whether overnight parallel work is needed. We do not quote over the phone: we assess first, then issue a written quotation covering scope, deliverables and expected timing, and start once both sides confirm. An initial family read usually takes hours; a full recoverability assessment normally takes one to several business days.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- First response
My files all have a new extension and won't open - what should I do?
Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
- Systems & software
What should we do when a Linux server or BT Panel is hit by ransomware?
First work out which kind of incident you have: website and database files that have genuinely been encrypted (new extensions, ransom notes in the directories), or databases that were dropped and replaced with a ransom table. The second involves no encryption, nobody can prove beforehand that the attacker kept a copy, and paying is not a recovery path. In both cases cut public access but keep the host running, do not reinstall or keep restarting the database, snapshot or image the data partition, then look for the data in backups, binlogs and disk remnants - and remove every back door before going live again.
- Systems & software
What should we do when Guanjiapo or Suda account sets are encrypted by ransomware?
Isolate the server holding the account sets from the network but keep it powered on. Do not reinstall the accounting software, restore an account set over the original disk, or run decryptors from the internet. Guanjiapo, Suda, Chanjet T+ and T3, Kingdee KIS Professional and similar products mostly keep account sets in SQL Server, with built-in automatic backups on the same machine, so both tend to be encrypted together. How much comes back depends on the family and how it encrypted, whether a clean backup exists beyond that server, and whether the database files were only partly encrypted. After recovery, reconcile stock, receivables and payables line by line, and close the entry point before going back online.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
FAQ
Frequently asked questions
What is the very first thing to do after discovering encryption?
Three things, in order:
- Isolate. Unplug or switch-isolate the affected hosts, and cut their connections to shared drives, virtualization platforms and backup systems.
- Do not touch. No shutdown or reboot, no reinstall, no formatting, no disk repair utilities, and do not delete the ransom note.
- Preserve. Keep the original note, encrypted samples, firewall and VPN logs, and pause any automated backup job that might overwrite data.
Then contact us with when it was noticed, how many hosts are affected, and what has already been done.
Are incident response and data recovery the same thing?
No. Incident response answers whether the attack is ongoing, where it came in and how to stop the bleeding. Data recovery answers whether the data can be retrieved and how.
They normally run in parallel: recovering without responding invites a second encryption, while responding without recovering leaves the business down. We schedule both under one engagement so they do not interfere with each other.
Can this be handled remotely, or is an on-site visit required?
We provide 24/7 remote response, and most incidents can be contained and handled remotely — usually faster that way. Remote access goes through a controlled channel with an operation log kept as the client requires.
We send engineers on site when the environment is fully air-gapped, external access is not permitted, physical disks must be imaged locally, or the client wants someone present to work alongside internal procedures. On-site coverage extends nationwide.
We keep very few logs — can anything still be determined?
It depends on what evidence survives. Even with application logs missing, edge-device logs, domain controller security logs, system events, registry and filesystem timelines and leftover tooling artifacts often reconstruct the main links of the attack path.
Where key evidence really was wiped or overwritten, we say which conclusions are reasoned inference rather than confirmed fact, and label the evidence strength in the report instead of overstating it.
Will you communicate or negotiate with the attacker for us?
No. We do not contact attackers on a client's behalf, do not negotiate, and take no part in ransom payment or cryptocurrency purchase.
What we do provide is a path that does not depend on the attacker: recoverability assessment, data recovery, backup and business rebuild planning, and the forensic material needed to report the crime to the police.
Updated