Ransomware

Ransomware

Survive a ransomware attack in real time.

What Is Ransomware?

You open what looks like a routine invoice. Seconds later files are renaming themselves, programs stop responding, and a ransom note appears. This exercise puts you in the first minutes of an attack, where every choice counts: disconnect, shut down, call IT, or close the file and hope. You will see how ransomware spreads through shared drives and mapped resources, learn the warning signs that come before encryption, and practice isolating the machine and preserving evidence.

What You'll Learn in Ransomware

Ransomware — Training Steps

  1. A Suspicious Phone Call

    It's a typical Monday morning, and Alice is settling into her desk. As she organizes her tasks, her mobile phone rings, displaying 'Unknown' on the caller ID.

  2. Urgent Request

    Curious, Alice answers the call. The caller introduces himself as Bob from IT. 'Hello, Alice. We're rolling out a critical security update today. You'll receive an email with instructions to install it immediately. Please follow them promptly.' Alice thanks the caller and hangs up, feeling a sense of urgency to comply.

  3. Checking the Email

    After the call, Alice opens her email client to check for the promised message. Among her inbox, she notices an email from 'IT Support' with the subject line 'Urgent: Security Update Required.' The email stands out due to its urgent tone, and Alice recalls the phone call, believing it's the legitimate update she was told about.

  4. Reading the Email

    Alice opens and reads the email. The email appears professional, and the attachment seems consistent with the phone call. Alice, trusting the source, decides to proceed.

  5. Antivirus Warning

    Alice clicks to download the attachment, and 'security_update.exe' appears in her file manager. A brief antivirus warning pops up, suggesting the file might be suspicious. Reassured by the phone call and email's urgency, Alice dismisses the warning, thinking it's a routine update from Nexlify Solutions' IT team.

  6. The Ransomware Attack

    As soon as Alice runs the file, her screen flickers, and a menacing message appears: 'All your files have been encrypted. To regain access, pay 1 BTC. Do not attempt to remove this software, or you will lose your files forever.' Alice's heart sinks as she realizes she's fallen victim to a ransomware attack. Her critical work files are now inaccessible, and she feels panic and regret.

  7. Resisting the Ransom

    Alice takes a moment to collect herself. She recalls a Nexlify Solutions training session advising against paying ransoms, as it doesn't guarantee file recovery and funds cybercriminals. Determined not to give in to Bob's demands, she decides to follow proper protocol to address the situation.

  8. Disconnecting from the Network

    To prevent the ransomware from spreading to other Nexlify Solutions systems, Alice has to get her machine off the network right now. The first choice is always to cut the network link and leave the machine running, because volatile memory can hold forensic evidence and, occasionally, encryption keys. Alice's workstation is docked and the ransom note has locked up the screen, so she cannot reach the network settings. When you cannot isolate a machine any other way, powering it down is the accepted fallback.

  9. Recognizing the Fake Email Address

    Still shaken, Alice uses her second PC and reopens the malicious email to understand what went wrong. She notices the sender's address, 'itsupport@nexlifysolution.com', is slightly off from the legitimate Nexlify Solutions domain, 'itsupport@nexlifysolutions.com'.

  10. Internal Support System

    Alice knows she must inform Nexlify Solutions' IT department promptly. She uses the web browser to open the company's internal IT support ticketing system and signs into her account.

Security Framework Coverage

MITRE ATT&CK

  • T1486 Data Encrypted for Impact

CIS Controls

  • CIS 10 Malware Defenses
  • CIS 11 Data Recovery

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.PS Platform Security
  • DE.CM Continuous Monitoring
  • PR.DS Data Security
  • RC.RP Incident Recovery Plan Execution