Ransomware Remediation When Attackers Still Have Access

Place yourself into this scenario: There’s ransomware detected on your network. Worse, files are already being encrypted, and a threat actor hiding out in a long-term backdoor is demanding a ransom. This retained access makes you a high-value target. Now’s the time to act.

In this article, we’ll guide you through ransomware remediation with actionable, practical steps that you can take right now to push back and get attackers out of your network for good.

Topics
Ransomware Remediation When Attackers Still Have Access
Down arrow
Topics
Share

Ransomware Remediation When Attackers Still Have Access

Place yourself into this scenario: There’s ransomware detected on your network. Worse, files are already being encrypted, and a threat actor hiding out in a long-term backdoor is demanding a ransom. This retained access makes you a high-value target. Now’s the time to act.

In this article, we’ll guide you through ransomware remediation with actionable, practical steps that you can take right now to push back and get attackers out of your network for good.

What ransomware remediation is & why most organizations get it wrong

Ransomware remediation involves isolating threat(s), kicking out attackers, and ridding your systems of anything they left behind. The most important thing is to lock the door on the attacker’s way out. That step—closing every path the attacker can use to get back in—is at the core of effective ransomware remediation, and it’s crucial to making sure this doesn’t happen again. Learn how Huntress approaches ransomware remediation.

Too many organizations focus all their attention on immediately recovering files with quick fixes, like restoring online backups. Attackers know this, so they disguise backdoors as system processes that lead them right back onto your network. Before you restore anything, assess and understand how the attacker got in and address those gaps to tighten your ransomware defenses.


6 steps for ransomware remediation

If you’re handling remediation in-house, follow this six-step process to remediate ransomware attacks and protect yourself from another incident. We’ll also explain how incident response (IR) teams can help if your team doesn’t have the time or expertise to manage remediation hands on.

1. Isolate infected systems to stop lateral spread

In-house teams

First, stop the spread and minimize damage. Immediately disconnect Ethernet cables, turn off wifi and Bluetooth, and unplug external hard drives. While some suggest fully powering off your computer during this step, others suggest leaving it on so you don’t lose any evidence in temporary memory that would help with forensic analysis.

Then, disable all compromised accounts and block any suspicious processes or infrastructure. Activate your IR plans and notify your legal team.

IR firms

Depending on the firm you hire, IR teams might show up on site to handle affected endpoints, while others will do this remotely using Endpoint Detection and Response (EDR) software.

To manage compromised accounts, IR teams often terminate current sessions using Identity Threat Detection and Response (ITDR) software.

2. Identify the ransomware strain & scope of impact

In-house teams

Figure out what type of ransomware you’re dealing with to understand the potential scope of the damage. This diagnosis is critical to what comes next, so take care during this step. Certain software, like Rubrik’s Anomaly Detection and Dell PowerProtect and PowerStore, help spot the strain by reviewing encryption methods, network traffic, and file changes. Another clue is the ransom note. This often has tells or even signatures that explain who’s responsible for the breach.

IR firms

Many organizations don’t have the time or expertise to do this analysis in-house, so it’s better to hire an IR firm to do a proper forensic investigation.

Start by sending the IR team your ransom note. With it, they’ll have an idea of who’s responsible and how to respond. For example, maybe the attackers are well-known for using a specific encryption tactic. IR groups will know where to start when addressing it.

Then, they’ll typically run binaries or scripts in a secure sandbox with an EDR installed to understand the processes. If your IR firm can identify a pattern, they’ll tell you what signs to look for—like receiving emails from suspicious senders or getting unexpected attachments.

3. Threat hunting for ransomware persistence mechanisms

In-house teams

Persistence mechanisms keep the backdoor open for threat actors. Rather than re-exploiting vulnerabilities every time they want in, attackers can simply regain access through already compromised operating systems, applications, or accounts.

Finding these openings brings you one step closer to closing the door. Check for common red flags like:

  • New or unexpected administrator accounts
  • Web shells or other rogue web-facing scripts
  • Cached or dumped credentials where they don’t belong
  • Compromised or misused RMM tools
  • Suspicious scheduled tasks, services, or autoruns that launch unknown binaries
  • Backdoors disguised as legitimate software

IR firms

Now that the IR team knows what they’re looking for, they’ll comb through your network, logs, and backups to find indicators of the attack patterns they identified. This step gets complicated when attackers use built-in tools like PowerShell to perform seemingly normal administrative activities.

Log everything your IR team learns while threat hunting, and store all this information for future use. If you experience a ransomware attack like this again, you’ll know what to do. Huntress cybersecurity experts have been threat hunting for years using Managed EDR and a 24/7 AI-centric Security Operation Center (SOC), so experienced analysts can continuously threat hunt on your behalf and help you get ahead of attacker tradecraft.

4. Eradicate malware & revoke unauthorized access

In-house teams

Delete any compromised or unauthorized accounts, and scrub your systems of all the malicious software you identified. Malicious software removal tools (MSRTs) can detect and remove active malware, while antivirus platforms can flag malicious programs that aren’t currently running.

IR firms

Have the IR team run EDR and continue monitoring the system for a while to confirm there’s no residual evidence of attacker activity or tooling. A fresh perspective might catch something they missed.

Huntress’ 24/7 AI-centric SOC acts as your second pair of eyes, monitoring and responding to cyber attacks around the clock. Our team oversees every phase of ransomware response and guides you through removing ransomware safely before you start recovery.

5. Restore data from clean backups

In-house teams

Now that your network is rid of ransomware, it’s time to start restoring encrypted files. One by one, restore each device using hardened, air-gapped backups that have been thoroughly tested. After recovery, that device is ready to reconnect to the network, and you can move on to the next.

IR firms

Before restoring your systems, IR teams will review backups to make sure they predate the attack and weren’t encrypted during the incident. Once files have the all-clear, the team will then restore authentication infrastructure, primary business apps, and any supporting systems.

6. Validate systems are secure before returning to production

In-house teams

Once you’ve recovered all affected devices, run a full system check across your entire infrastructure. If your security team has the expertise to continue monitoring systems, have them pay special attention to anything resembling those patterns your IR team identified early, like suspicious credentials cropping up in caches or new web shells sprouting up where they aren’t supposed to. Then, isolate anything suspicious immediately and start again.

IR firms

Lean teams might need the IR firm’s support for this step. They’ll handle the system checks and might even run simulated attacks to see whether the security stack is doing its job.


Ransomware recovery & mitigation: Restoring operations without restoring the threat

You’ve gone through all this trouble to clean up and recover from a ransomware attack, but without closing the gaps the adversary used to breach your organization, you’re still exposed to future attacks. Adversaries know this and will return to see if the gaps were closed and defenses improved.

Proper remediation means recovering encrypted files, fixing vulnerabilities, and preventing future attacks. Keep in mind that companies with the proper backups and incident response partners shouldn’t pay the ransom. Payment doesn’t guarantee data recovery and can put you at high risk for re-targeting.

Here are a few tips on how to protect against ransomware to avoid ending up where you started:

  • Remove unnecessary remote access tools: Review all the tools used for remote work, and streamline where possible, eliminating any redundant or “nice-to-have” software that isn’t strictly necessary.
  • Set up ransomware detection: Try new detection strategies. One good option is Huntress Managed EDR, a managed detection service that continuously monitors for potential threats. Our AI-centric SOC investigates potential ransomware activity and helps you contain it quickly, slashing the time you spend chasing false positives.

How Huntress Managed EDR accelerates ransomware remediation

Most lean teams don’t have the resources to handle these steps on their own. Thankfully, Huntress Managed EDR stops hackers in their tracks. Our system watches for platform abuse, shifting attacker techniques, and lateral movement to secure endpoints. The Attack Disruption Engine alerts our 24/7 AI-centric SOC of each shady move so tradecraft doesn’t slip by undetected.

On average, our SOC maintains an industry-leading mean time to respond (MTTR) of about eight minutes. That’s all the time it takes to receive an alert, complete the investigation, launch the initial automated remediation of the threat, and send an incident report. This dramatically limits how far ransomware can spread before we intervene.

That speed often means you can focus on remediation and recovery instead of considering whether to pay the ransom.

Our SOC analysts, supported by the Huntress Managed Security Platform, constantly monitor endpoint activity, remote monitoring and management (RMM) tool usage, and user behavior to prevent ransomware attacks whenever possible. We put years of hands-on experience to work to wreck ransomware attacks.


24/7 threat detection, prevention, & remediation with Huntress

Ransomware remediation won’t last if you don’t prioritize shutting down attacker access. Managed security gives you peace of mind without adding to your to-do list. Whether you’ve been plagued by a ransomware attack or just want to shore up your defenses, Huntress offers a wide range of solutions for your organization. Managed EDR is a great first step.

Start a free trial to see why Huntress has been recognized as a top‑rated EDR and MDR solution on G2.

Frequently Asked Questions

It’s always best to assume that attackers have left themselves some way to reinfiltrate your network after recovery. The best way to find their backdoors and lingering malware is to test restored devices and software in a secure sandbox before reintroducing them to your network. That way, you can monitor for suspicious commands, processes, and credentials before they get back into your live systems.

Paying the ransom doesn’t guarantee that you’ll get your encrypted files back or prevent future attacks. Because of this, recovery and remediation should be your first strategy.

Typically, it takes several days or weeks to recover after a ransomware attack, most of it spent scanning for threat indicators, restoring devices, and testing recovered systems.

Ransomware recovery treats the symptoms by getting back encrypted files or restoring compromised devices. Remediation addresses the underlying causes, securing your network against another attack and closing vectors so they can’t be used again.

Both are essential, but in many ways, recovery is less important. Even if you lose a database of encrypted files to a ransomware attack, it’s far more important to address every vulnerability that could lead to an even bigger attack next time.


Try the Ransomware Simulator

If you were hit with ransomware, what would you do? Play through a simulated ransomware incident built from real tactics we've seen used against businesses.

Try the Simulator