Industry solution
Construction and Real Estate Ransomware Response
In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.
Critical business systems
- Cost estimating and budgeting software and its databases
- BIM model repositories and collaborative design platforms
- CAD drawing shares and project documentation libraries
- Project management systems and OA collaboration
- Contract, tender and as-built archive systems
- Finance and cost management ERP
- Project-site NAS units, file servers and shared drives
- Site endpoints and remote working devices
Threat landscape
Information systems in construction and real estate have an unusual shape: the core production asset is files, not database records, and those files are inherently scattered across many project sites, design institutes, subcontractors and personal computers. That creates a distinctive risk set:
- Project sites are the weak link. A site typically runs one NAS or one Windows server for drawing sharing, on a temporary network, with lagging IT maintenance and simple passwords — and some expose the NAS or RDP directly to the internet so drawings can be retrieved remotely. This is the sector's most common entry point.
- Overly broad share permissions. For collaboration convenience, drawing directories are often set to everyone-read-write, so one infected endpoint can encrypt an entire project's drawing library along a mapped drive. Public reporting shows the Phobos and Makop lineages, which enter chiefly through weak-password RDP, along with GlobeImposter and Crysis/Dharma, recurring persistently in file-server encryption cases.
- Many external collaborators. Design institutes, supervisors, subcontractors and suppliers exchange files constantly, and USB drives, cloud shares, email and temporary shared accounts add further risk.
- Weak backup practice. Many projects hold their drawings in exactly one place on a NAS, with no version retention or offline copy, and the "sync equals backup" misconception is especially widespread here.
- High irreplaceability. As-built drawings, change orders, site instruction records and tender documents carry legal and settlement value, and cannot readily be reconstructed.
Business impact
- Construction and design work stops. With drawings and models unavailable, site work, technical briefings, detailed design and change handling all stall, and schedule pressure converts directly into cost.
- Lost bids and contract risk. Losing tender documents, pricing and technical proposals in preparation can mean missing a submission deadline, while missing contracts, site instructions and change records create disputes at settlement.
- Difficult settlement and audit. Cost data, bills of quantities, and instruction and variation records are the basis for settlement, and gaps directly affect payment collection and audit clearance.
- Risk to as-built and archival records. As-built drawings and acceptance documentation are statutory records that must be retained long-term; reconstructing them is extremely costly and may even affect acceptance and filing.
- Multi-project knock-on. Where project sites share one credential scheme, or head office provides shared storage, one incident can affect several live projects simultaneously.
- Exposure of knowledge assets. Leaked design proposals, cost models, supplier pricing and contract terms damage competitive position and commercial relationships.
Our response plan
Stop writing and inventory dispersed storage
Immediately disconnect affected NAS units, file servers and endpoints from the network. The single most important action is to stop all writes to the storage, since that directly determines how much of the deleted originals can be carved back. Never reset a NAS, rebuild its RAID or initialise its storage pool. Then inventory every location that may hold drawings and project documentation: site NAS units, head office file servers, designers' computers, external drives, cloud sync folders, and copies held by collaborators.
Identify the family and assess encryption by file type
Identify the family and entry point, focusing on internet-exposed NAS units and RDP, weak site passwords and external collaborator accounts. At the same time, sample entropy by file type: BIM models, point clouds, render files, video and archives are large and often only header- or segment-encrypted, carrying real repair value, while DWG drawings, Office documents and PDFs are mid-sized or small and usually fully encrypted, depending instead on backups, snapshots and carving. That classification drives both the recovery plan and the effort estimate.
Prioritise by project value and urgency
Agree a priority list with each project lead rather than working through directories in order. The usual sequence: live tender documents and pricing near deadline, then current-revision drawings and change records for projects under construction, then settlement and site instruction records, then as-built and archival material, then historical projects and reference material. This restores the most urgent work first and gives recovery a concrete acceptance standard — named projects and named drawing packages.
Recover from multiple sources and verify drawing revisions
Use every source at once: read-only NAS snapshots and backups, carving of deleted originals, partial-encryption repair on large files, and distributed copies — designers' local folders, cloud version history, email attachments, the same files held by collaborators (design institutes, supervisors, subcontractors), and printed or plotted archives. Afterwards, verify revisions: confirm whether each drawing is the current or a superseded version, so construction does not proceed on the wrong one. The project's technical lead must take part in that verification.
Govern project-site IT and rebuild backups
Hardening centres on bringing project sites — the management blind spot — into unified governance: keep NAS units and servers off the public internet, enable read-only or immutable snapshots, minimise share permissions by project and role, deploy EDR and patching uniformly on endpoints, and move remote access to VPN. The backup architecture must cover every project drawing library with version history and at least one offline or immutable copy, and a standard channel for exchanging files with collaborators should replace ad hoc USB drives and temporary shared accounts.
Common ransomware families
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
Makop
Makop has operated as a RaaS since 2020, with affiliates breaking in mainly through brute-forced remote desktop credentials and deploying by hand. Extensions include .makop, .mkp and .baseus, with a readme-warning.txt note. It ranks consistently high in Chinese infection statistics and has no public decryptor.
- Some versions decryptable
LockBit
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- Some versions decryptable
Mallox
Mallox (also known as TargetCompany) breaks in mainly through brute-forced MS SQL Server credentials, targets database servers specifically, and has a Linux/ESXi variant. Files encrypted between 2023 and early 2024 may be decryptable with Avast's free tool; later builds have no public decryption method.
- Some versions decryptable
GlobeImposter
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
Hardening recommendations
- Never expose project-site NAS units or servers to the internet. Remove router port forwards and UPnP and route remote drawing access through a VPN. This is the sector's principal entry point and also its easiest fix.
- Enable read-only or immutable snapshots. Turn on snapshots with a sensible retention period on the NAS, and use immutable snapshots where available — they sit outside the permission scope of the encrypted filesystem and are the most effective single defence for a drawing library.
- Minimise share permissions by project and role. Remove Everyone / Full Control, make archive and as-built directories read-only, and scope read-write access by role on live projects — directly shrinking the reach of any single encryption run.
- Backup cannot mean sync. Cloud sync and real-time NAS sync push encrypted files off-site; use versioned backup with retention, and keep one offline copy such as an external drive detached between runs.
- Manage endpoints centrally. Bring designers' and estimators' computers into central patch and EDR management, remove unnecessary local administrator rights, and restrict automatic execution from unknown USB devices.
- Govern remote access and accounts. Remove internet-facing RDP in favour of VPN with MFA, issue collaborators time-limited accounts, and revoke them when the project ends.
- Standardise file exchange with collaborators. Use a single file exchange platform or controlled shared directory instead of permanently open shared accounts and casual USB copying.
- Keep critical records in more than one place. For as-built drawings, site instructions and contracts with legal and settlement value, retain paper or offline archives alongside electronic backups, with a named custodian.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Synology NAS Encrypted by Ransomware
Synology incidents come in two shapes: the NAS itself is compromised (DSM exposed to the internet, accounts brute-forced), or an infected Windows host on the LAN encrypts it over SMB. The handling and recovery paths differ completely. This page explains how to tell them apart and what Btrfs snapshots and Hyper Backup can actually do.
SQL Server Database Encrypted by Ransomware
When SQL Server .mdf / .ldf files are encrypted, the ERP and inventory systems built on them — Yonyou U8, Kingdee K/3, Guanjiapo, Suda — stop completely. This page covers evidence handling, how we judge whether page-level repair is viable, and the conditions for backup-plus-log restore.
OA Collaboration System Encrypted by Ransomware
An encrypted OA system halts document circulation, approvals, contract archives, HR and knowledge bases at once — and because OA is so often published to the internet, it is frequently the attacker's first foothold. This page covers its vulnerability profile, the twin-track recovery of attachments and database, and how to check for lateral spread.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related services
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
FAQ
Frequently asked questions
An entire project's drawings are encrypted — how much can be recovered?
The rate varies sharply by file type, so a single figure is meaningless. The general pattern: large files — BIM models, point clouds, renders, video, archives — have more room, because many families encrypt only headers or segments above a size threshold. DWG drawings and Office documents are mid-sized or small and usually fully encrypted, depending instead on read-only snapshots, backups, carving of deleted originals, and distributed copies. During assessment we sample encryption coverage by file category and set expectations per project and per drawing package, rather than quoting one percentage.
The site NAS is encrypted — can we reset it or rebuild the RAID?
Absolutely not. Resetting the device, rebuilding the RAID or initialising the storage pool genuinely erases the underlying data and turns a recoverable case into an unrecoverable one — the most common and most fatal mistake in this sector. The correct approach: remove port forwards at the router, disconnect, leave the device untouched with no writes, and record the original drive slot order. Where low-level work is needed, a team with NAS experience takes read-only block-level images, reassembles the array on the copies, and evaluates snapshots, carving and the repair value of the encrypted files.
We are mid-tender and the drawings and bid documents are gone — what now?
Run two things in parallel. On recovery, make the tender files the highest priority and concentrate on snapshots, backups and distributed copies — bid documents very often exist on the handler's computer, in sent-mail records, in cloud version history, and as attachments in correspondence with design institutes and subcontractors, which in practice is the fastest route to recovering them. On the business side, assess in parallel whether to inform the tendering party, request an extension or adjust your bid strategy. With a deadline looming, both tracks must run together rather than waiting for recovery to finish.
How do we confirm recovered drawings are the current revision?
Revision verification is a mandatory step here, because building to the wrong revision can be worse than losing the drawing. Available references include the revision block and date on the drawing itself, change orders and technical clarification records, receipt logs from the supervisor and client, printed copies in use on site, the same file held by collaborators, and issue records in the project management system or OA. After recovery, the project's technical lead should confirm each drawing package, and anything whose revision cannot be established should be explicitly flagged with a plan to verify it.
Several project sites use NAS units — how do we protect them consistently?
The practical answer is to bring project-site IT under a head office standard rather than relying on local maintenance. A minimum viable set of requirements: keep the NAS off the public internet (remove port forwards and UPnP); disable the default administrator and enforce strong passwords with two-factor authentication; enable read-only or immutable snapshots with a retention period; minimise share permissions by role; keep backup job destinations off the device with an offline copy retained; and update firmware and packages regularly. Combined with a head office asset register and periodic checks, that substantially reduces the sector's principal risk.
Updated