Services

Ransomware recovery and decryption

Recover encrypted data and restore operations after a ransomware attack. Free assessment, fixed quotation, and payment only when you have verified the recovered data. There is no need to contact the attackers.

No recovery, no fee

You pay only after you have opened and tested the recovered data yourself. If the data cannot be recovered, there is no charge.

No contact with the attackers

Our method does not depend on the attackers. We never open their portal, never negotiate and never pay. Nothing you do with us feeds the criminal economy.

Reports for insurers and regulators

Every engagement closes with an incident report: strain, entry point, what was recovered and how. Written for cyber insurers, auditors and UAE regulators.

What the service includes

Everything between the ransom note and working systems

1. Assessment and triage

Identification of the ransomware family and build from the ransom note and samples. Recoverability report, timeline and fixed quotation within hours.

2. Containment and evidence

Guidance on isolating systems without destroying evidence, imaging of affected storage, preservation of logs and memory for the investigation.

3. Decryption

Where the encryption implementation has a weakness, or a public or in-house decryptor exists, files are decrypted in the laboratory and returned in their original folder structure.

4. Reconstruction

Where decryption is not possible, databases, virtual disks and backup containers are rebuilt around the encrypted blocks using their internal structure. This is where most enterprise recoveries happen.

5. Storage-level recovery

Deleted shadow copies, wiped backups and overwritten files recovered from the underlying disks, RAID arrays, NAS volumes and SAN LUNs.

6. Verification and clean delivery

Recovered data is checked for integrity and malware, delivered on clean media, and verified by you before payment. Entry-point report included.

Environments

What we recover

Ransomware rarely stops at documents. These are the systems that arrive in the laboratory most often.

File servers and NAS

Windows file servers, Synology, QNAP, NetApp and other NAS devices. SMB shares, home folders, project archives.

  • Encrypted shares and snapshots
  • Deleted or wiped volumes
  • RAID 5 / 6 / 10 arrays

Virtual machines

VMware ESXi datastores, Hyper-V clusters, Proxmox, KVM, Citrix and Nutanix. Encrypted VMDK, VHDX and flat disks reconstructed to a bootable state.

  • VMFS datastore recovery
  • Snapshot and checkpoint chains
  • Guest file-system repair

Databases

Microsoft SQL Server, MySQL and MariaDB, PostgreSQL, Oracle, Access. Page-level repair of MDF, IBD and DBF files behind ERP, accounting and CRM systems.

  • Partially encrypted data files
  • Transaction log recovery
  • Integrity verification

Backups

Veeam VBK and VIB chains, Acronis, Commvault, Veritas, Windows Server Backup, NAS snapshots and LTO tape. Encrypted backups are usually the first thing we look at.

  • Container reconstruction
  • Restore-point chain repair
  • Damaged catalogues

Mail and collaboration

Exchange databases, Outlook PST archives, SharePoint and document management systems.

  • EDB and PST repair
  • Mailbox extraction
  • Document libraries

Workstations and small offices

Individual PCs, laptops and external drives hit by consumer-grade strains such as STOP/Djvu, Phobos and Dharma.

  • Offline-key cases
  • Partially encrypted large files
  • Fast turnaround
How it works

From ransom note to verified data in four steps

Simple and transparent. You decide only after you know what is recoverable and what it costs.

1
Send samples
The ransom note, two or three encrypted files of different types and sizes, and a short description of the environment. WhatsApp is fastest.
2
Free assessment
Family and build identified, recovery tested on the samples. You receive a recoverability report, a timeline and a fixed quotation. No obligation.
3
Laboratory recovery
Storage is imaged and work happens on copies. Decryption, reconstruction and repair run in the laboratory with progress updates to you.
4
Verify, then pay
You open and test the recovered databases, machines and files. Payment is made only after your confirmation. Delivery on clean media with the incident report.
Ransomware variants

Families we handle

Enterprise operations and small-business kits alike. If your extension is not listed, send the samples: identification is part of the free assessment.

Cost

How ransomware recovery is priced

Every case is quoted after the free assessment, because the work depends on the family, the volume of data and the systems involved. The quotation is fixed: it does not change during the recovery.

  • Assessment: free, no obligation.
  • Quotation: fixed price based on family, data volume and environment.
  • Payment: only after you have verified the recovered data. No recovery, no fee.
  • Insurance: our reports are written for cyber-insurance claims; many policies cover laboratory recovery.

Paying the ransom

  • Price set by criminals
  • Paid before any result
  • Decryptor may fail or corrupt data
  • Repeat attacks common
  • Sanctions and compliance risk

Laboratory recovery

  • Fixed quotation, agreed in advance
  • Paid after verification
  • Verified, clean data
  • Entry point identified
  • Report for insurer and regulator
FAQ

Ransomware recovery questions

In most cases, yes. Recovery comes from three directions: weaknesses in the ransomware's encryption, the internal structure of large files such as databases, virtual disks and backups that are only partially encrypted, and storage-level recovery of data the attackers deleted. The combination is why the laboratory reaches a 98% success rate. The free assessment tells you which route applies to your case before you decide anything.

The ransom note, two or three encrypted files of different types (a document, an image, and the first part of a large file such as a database or backup), the encrypted extension, and a short description: number of machines, hypervisors, backup product, when it happened. Send it on WhatsApp. Nothing else is needed to start.

The assessment usually takes a few hours. Recovery ranges from one to two days for a small office to a week or more for large virtualised environments with many terabytes. Critical systems such as the ERP database are prioritised so the business can restart before the full recovery completes.

No. Payment does not guarantee a working decryptor, attacker tools frequently corrupt large files, stolen data is often leaked anyway, and paid victims are attacked again. Payments to sanctioned groups can be an offence. Obtain a recovery assessment before any decision about payment. See why contacting the attackers is the weakest option.

Usually not. Backup containers are large, and modern ransomware encrypts only parts of large files. Veeam chains, VHDX files and SQL dumps are frequently rebuilt in the laboratory. Do not delete them. See when the backups are encrypted too.

Yes. Double infections happen, especially where a small-business kit such as Phobos followed an earlier intrusion. Each strain is identified and treated separately in the assessment.

Work happens on isolated laboratory systems with no internet access. An NDA is signed on request. Working copies are wiped after you confirm delivery. Consultancies and MSPs can engage us on behalf of clients without naming them.

On new, clean storage supplied by the laboratory or by you, with the original folder structure. Databases are delivered as attachable data files or verified backups, virtual machines as bootable disks. You test everything before payment.

Yes. Assessment is remote. Storage can be couriered to the laboratory from anywhere in the UAE and GCC, and engineers can attend on site for large environments.

Start with incident response.

Send the ransom note and samples now. You will know what is recoverable, how long it takes and what it costs before you decide anything.