Chapter 14. Eradicate the Threat
You’ve contained the attack. Infected systems are isolated and shut down. The ransomware can’t spread another inch. Your forensic evidence is preserved. The walls you built around the infection are holding strong. Chapters 9–13 got you to this point. The threat is boxed in, dormant but dangerous.
Now comes the hard part: erasing it from existence.
The steps in this chapter are remarkably easy; what’s not easy is deciding which steps to take. We have some further thoughts on that on our companion site, StopRansomware.com.
Welcome to the eradication phase. This is where you hunt down and permanently remove every trace of the ransomware from every infected system. Every component. Every backdoor. Every persistence mechanism the attackers planted. You’ll make decisions about cleaning, wiping, or replacing hardware. You’ll reinstall operating systems from clean sources. You’ll scrutinize data to ensure it’s truly clean before you dare restore it.
This is where 80% of reinfection happens. Organizations rush through eradication because the pressure to get back online is enormous. They do a quick antivirus scan, see no immediate threats, and declare victory. Three days later, sometimes three weeks later, the ransomware resurfaces. All that containment work was for nothing.
Northforge thought they’d eradicated Lorenz completely. They wiped the obviously infected drives, reinstalled Windows, and brought systems back online. Forty-eight hours later, a scheduled ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access