ZENTARA
Incident Response · Malware & Ransomware Recovery

Get clean. Get back online. Without paying.

Reimaging removes the symptom. Finding how they got in is what stops it happening again.

Eradication that hunts persistence rather than payloads, a clean-room rebuild so recovery doesn't become re-encryption, and staged restoration that brings the business back in the order the business actually needs.

First hour

Where recovery is won or lost

Clean-room

Nothing restored into a dirty estate

No payment

Recovery planned without funding crime

recovery operations · clean-room Restoring

Staged restoration

Tier 1 · Core banking✓ verified
Tier 1 · Payment switch✓ verified
Tier 2 · Internal apps64%
Tier 3 · File & printqueued
Tier 4 · Archivequeued

Restored into verified-clean environment · credentials rotated

Strain identified

LockBit-family

Entry vector

Closed

Persistence found

4 hosts

Backup integrity

Validated · offline copy

Worked to

NIST SP 800-61NIST SP 800-83ISO/IEC 17025UU PDPOJK / BSSN reporting

If it's happening right now

The first hour decides how bad this gets.

Most of the damage we're called in to undo was done by well-meaning people reacting fast in the first sixty minutes. Do these things; avoid these others.

Do this

Isolate, don't destroy

Pull affected systems off the network. Do not wipe, reimage, or rebuild — you will erase the evidence needed to find the entry vector, and you'll rebuild straight back into it.

Preserve everything

Keep logs, ransom notes, encrypted samples, and email. Stop log rotation if you can. This is what identifies the strain and proves what happened.

Protect the backups first

Disconnect or lock backup systems immediately. Attackers target them deliberately, and a backup reachable from a compromised network is already at risk.

Don't do this

Don't power everything off

Shutting a machine down destroys memory evidence that can reveal keys, processes, and the operator's tooling. Isolate at the network instead.

Don't contact the attacker yet

Opening a channel starts a clock and a negotiation you haven't prepared for. Get advice and legal counsel involved before any contact.

Don't restore yet

Restoring into an estate that is still owned re-encrypts your last good copy. Clean first, then restore — in that order, every time.

Systems encrypted right now?

Isolate, preserve, and call. We'll tell you what to protect in the next ten minutes.

Get help now

Which team you need

Investigate and prove. Or eradicate and restore.

In a major ransomware event you want both, running in parallel — incident response owns the investigation and the command function while this practice owns eradication and recovery engineering. For a contained infection with no regulatory dimension, this alone is enough.

Not sure which?

Call the incident line either way. Triage is the same conversation, and we'll bring the right team — you shouldn't have to diagnose your own emergency before asking for help.

IR & Forensics ↗

  • Question

    What happened, and how far?

  • Output

    Evidence & root cause

  • Audience

    Regulator, insurer, counsel

  • Discipline

    Investigation

This service

  • Question

    How do we get clean and back up?

  • Output

    A working, verified-clean estate

  • Audience

    IT, operations, the business

  • Discipline

    Restoration engineering

What we handle

Not just the thing that announced itself.

Ransomware is the loudest malware, not the most common. Most of what we remove was quiet, and had been there far longer than anyone assumed.

Ransomware & wipers

Encryption and destruction events, including double-extortion cases where data was stolen before anything was locked.

Banking trojans

Credential and session theft targeting financial applications — the dominant commodity threat against Indonesian institutions.

Webshells & server implants

Persistent access dropped on internet-facing servers, often months before anyone notices, and the usual root of repeat defacement.

Rootkits & bootkits

Implants that survive reimaging by living below the operating system, in firmware or the boot chain.

RATs & backdoors

Remote-access tooling providing hands-on-keyboard control, frequently left behind after the initial intrusion.

Cryptominers

Resource theft that is rarely the real problem — it's proof someone else can execute code on your infrastructure.

Supply-chain implants

Malicious code arriving through a trusted update, library, or managed-service provider connection.

Dormant persistence

No active payload, just a way back in — scheduled tasks, rogue accounts, and forgotten service principals.

The method

Clean first. Restore second. Never the reverse.

Seven stages, in an order that matters more than any single technique in it.

01

Isolate & preserve

Contain the spread without destroying the evidence. Network isolation, forensic images and log capture before any remediation touches a disk.

02

Identify

Strain and family identification, entry vector, dwell time, and the full IOC set needed to sweep every other system you own.

03

Eradicate

Remove payload and persistence — scheduled tasks, services, registry keys, boot records, webshells, rogue accounts, and stolen credentials.

04

Clean-room rebuild

Stand up a verified-clean environment with rotated credentials and closed vectors. Nothing gets restored into a dirty estate.

05

Restore

Backup integrity tested before trust is placed in it, then staged restoration ordered by business criticality with validation at each tier.

06

Verify & watch

Estate-wide IOC sweep and a defined period of heightened monitoring, because reinfection usually arrives from a system nobody checked.

07

Harden

Close the vector that let them in and fix the conditions that let them spread — segmentation, privilege, MFA, and backup isolation.

Why reimaging alone fails

  • The entry vector is still open — they walk back in the same way
  • Credentials were stolen before encryption; new machines, same logins
  • Persistence sits on a system nobody flagged as affected
  • Backups restore the implant along with the data
  • Firmware and boot-level implants survive the rebuild entirely

The payment question

We plan your recovery assuming you won't pay.

Whether to pay is a board decision made with your own legal counsel — never a technical one, and never one made at 3am under pressure from a countdown timer. What we owe you is an accurate picture of what payment does and doesn't buy.

It doesn't guarantee recovery

Attacker-supplied decryptors are routinely slow, partial, or corrupt data as they run. You are trusting the engineering of someone who just extorted you.

It doesn't unsteal your data

If information was exfiltrated before encryption, a key returns nothing. 'Proof of deletion' cannot be verified, by you or by anyone.

It may carry legal exposure

Depending on the group behind the attack, payment can breach sanctions and financial-crime obligations. That question belongs to counsel, before any contact.

It marks you

Organizations that pay are disproportionately targeted again, sometimes by the same operators using the access they never gave up.

Our position, stated plainly

Zentara does not negotiate with threat actors and does not handle or transfer ransom payments.

We will give you the technical facts you need — strain, exfiltration evidence, realistic recovery paths and timelines with and without a key — so that you and your counsel can make an informed decision. Then we recover you the best way available.

Always checked first

Some ransomware families were built badly or had keys leaked, and free decryptors exist. Correct strain identification is occasionally the difference between a free recovery and a catastrophic one — so it's the first thing we do, every time.

The backup reality check

Recovery speed is decided long before the attack.

Nothing determines how this ends more than the state of your backups on the day it happens — and that is the one variable you can still fix right now.

Reachable backups aren't backups

If it's on the domain and mounted, the attacker had it too. Immutable or genuinely offline copies are the ones that survive.

Untested backups aren't backups

Most organizations discover their restore process is broken during the only event that matters. Test restores on a schedule, not in a crisis.

Incomplete backups aren't recovery

Databases without application state, or servers without configuration, restore to something that doesn't run the business.

Not in an incident right now?

Then this is the cheapest hour you will ever spend on ransomware: verify that at least one backup copy is genuinely offline or immutable, and actually restore from it as a test. Most organizations we recover discover the answer during the incident. Yours doesn't have to.

Reporting duties start early

The 72-hour clock may already be running.

Ransomware with data exfiltration is a personal-data breach in most realistic scenarios — which under UU PDP means written notification to the authority and affected individuals, with additional OJK or BSSN obligations depending on your sector. We provide the technical facts your counsel needs to make that call.

What you get

Proof it's gone — and how it got in.

Eradication & restoration report
Entry vector and root-cause analysis
Full IOC set for estate-wide sweeping
Backup integrity assessment
Reinfection-prevention hardening plan
Regulatory notification support pack

FAQ

Straight answers, including the uncomfortable ones

What executives and IT leads ask during a ransomware event — answered the way we'd answer them on the call.

They're siblings and they usually run together, but they answer different questions. IR & Digital Forensics investigates and proves — what happened, how, how far it went, and the evidence a regulator or insurer will ask for. This practice eradicates and restores — get clean, get the business running, and make sure it doesn't come back. In a major ransomware event you want both: IR runs the investigation and the command function while we run eradication and recovery engineering. For a contained malware infection with no regulatory or legal dimension, this service alone is usually enough.

Encrypted? Isolate, preserve, and call.

Don't wipe anything. Don't restore yet. Don't contact the attacker. Bring us in and we'll tell you what to protect in the next ten minutes — then get you clean and back online.