All Products
Search
Document Center

Elastic Compute Service:Enhance anti-ransomware capabilities for instances

Last Updated:Sep 18, 2026

Ransomware is malware that encrypts your business data, causing service disruptions, data leakage, and data loss. These attacks pose significant risks to your business. This topic describes how to enhance the anti-ransomware capabilities of your instances.

Background

As technology evolves, new types of malware emerge, and ransomware has become a common threat. Alibaba Cloud uses its extensive experience in cloud security and cutting-edge security technologies to provide comprehensive security solutions. For more information about how to defend against ransomware, see Overview of the anti-ransomware service.

Symptoms

When your instance is attacked by ransomware, its system files are encrypted, and you will find a ransom note in the user's working directory. For example, on a Windows-based instance, a ransom note like the one below typically appears.

::: Greetings :::

Little FAQ:

.1.
Q: Whats Happen?
A: Your files have been encrypted. The file structure was not damaged, we did everything possible

.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay us.

.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefit
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg

.4.
Q: How to contact with you?
A: You can write us to our mailboxes: data***@cyberfear.com or back***@swismail.com

.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use

.6.
Q: If I don't want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose you

:::BEWARE:::
DON`T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - p
Note

After ransomware encrypts or locks system files, the instance may fail to start or you may be unable to connect to it remotely. This is often one of the first signs of an anomaly. If you are suddenly unable to connect to your instance, investigate a potential ransomware attack.

Solution overview

Although preventive measures can reduce the risk of infection, they cannot entirely eliminate it. For ransomware, data backup is your last line of defense. However, when you restore data from a backup or a snapshot, any data generated between the snapshot creation and the disk rollback is lost. Therefore, you must develop a data backup strategy suitable for your business to protect your critical data.

The following are common strategies to protect against ransomware.

You can implement these protection strategies in parallel and select the ones that best suit your business needs. For example, if your business has high requirements for business continuity, you can apply all three strategies. However, this may incur charges for backups or snapshots.

Strategy 1: Use Security Center for anti-ransomware

Workflow

image

Procedure

  1. Enable the anti-ransomware service and purchase anti-ransomware capacity.

    To use the anti-ransomware feature in Security Center, you must enable the service and purchase anti-ransomware capacity. For more information, see Enable and purchase the anti-ransomware service.

    Note

    You can purchase anti-ransomware services based on your business requirements.

  2. Create a protection policy.

    After you enable the service, follow these steps to create a protection policy.

    Create a protection policy

    Before creating a policy, verify that your server's operating system is supported. If the OS version is not supported, data cannot be backed up. See Operating systems and versions supported by anti-ransomware for servers.

    1. Log on to Security Center console.

    2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    3. On the Anti-ransomware for Servers tab, click Create Anti-ransomware Policy.

    4. In the Create Anti-ransomware Policy panel, configure the basic parameters.

      Parameter

      Description

      Policy Name

      The name of the anti-ransomware policy.

      Server Type

      The type of server to which the anti-ransomware policy applies.

      Backup Route

      Required only when Server Type is set to Server Not Deployed on Alibaba Cloud. Select the communication method for data backup. Options:

      • Internet: Data is transmitted over the public network, which may incur public bandwidth charges.

      • Internal Network: To transmit data over the private network, use Alibaba Cloud VPC, Express Connect, or CEN to connect servers not deployed on Alibaba Cloud to the anti-ransomware endpoint in the selected region.

      Region

      Required only when Server Type is set to Server Not Deployed on Alibaba Cloud. Select the region where the server resides or a region that has network connectivity with the anti-ransomware endpoint. The selected region specifies the network endpoint for the anti-ransomware service. Make sure the server can communicate with the anti-ransomware endpoint in the selected region. For more information, see Network endpoint.

      Select Asset

      You can select a single asset, multiple assets across groups, or an asset group. Perform the following operations to select the assets to protect:

      • In the Asset Group section, select an asset group. All assets in the group are automatically selected. You can clear the assets that do not need protection in the Asset section.

      • In the Asset section, enter an asset name (fuzzy match is supported) and click the search icon. The related assets are displayed. Select the assets to protect.

      Note
      • When you select assets, Alibaba Cloud servers support configuring servers in multiple regions within a single policy. Servers not deployed on Alibaba Cloud support only servers in the same region within a single policy.

      • To ensure rational and effective use of protection capacity, each server can be added to only one anti-ransomware policy.

    5. In the Create Anti-ransomware Policy panel, configure the specific data backup policy and click OK.

      You can select the recommended policy or a custom policy.

      • Recommended policy: The recommended policy is a built-in policy of Security Center. It cannot be modified and is easy to configure. The specific rules are as follows:

        Setting

        Default value

        Directory to protect

        All directories (excluding system directories)

        Directory to exclude

        Displays the list of excluded directories

        Non-local mount path

        Excludes non-local mount paths (i.e., excludes OSS, NAS, and other non-local mount paths)

        File type to protect

        All file types

        First backup starts at

        Any time between 00:00 and 03:00

        Periodic backup interval

        One day

        Backup data retention period

        7 days

        Maximum backup bandwidth

        • Alibaba Cloud servers: 0 MB/s

          Note

          0 MB/s means no bandwidth limit for backups.

        • Servers not deployed on Alibaba Cloud: 5 MB/s

      • Custom policy: You can define the specific rules of the policy. This provides high flexibility. You can specify the directory to protect, directory to exclude, file type to protect, data backup start time, backup interval, backup data retention period, and maximum backup bandwidth (MB/s). The following describes the parameters.

        Setting

        Description

        Directory to protect

        Select the directories to back up. You can select the following types:

        • Specific Directory: backs up the specified directories of the selected assets. You must add the directory paths to protect in Directory Address. Configuration example:

          • Windows: C:\Program Files (x86)\

          • Linux: /usr/bin/

          You can add up to 20 directory paths. Security Center runs backup jobs for each directory path in sequence. If a directory contains many files, it may consume significant server resources (CPU and memory). You can split a directory into multiple directory paths and run backup jobs in sequence to reduce resource usage.

        • All Directories: backs up all directories of the selected assets.

        Directory to exclude

        Specifies the directories to exclude from backup. Security Center provides default directories to exclude. You can modify these directories.

        Non-local Mount Path

        Select whether to exclude non-local mount paths. Non-local mount paths refer to OSS, NAS, and other mount paths.

        File type to protect

        Select the file types to protect. You can select the following types:

        • All File Types: backs up and protects all file types.

        • Specific File Types: backs up and protects specified file types. You can select document types, image types, and more.

          Important

          You can select multiple file types. Security Center backs up only the selected file types on the assets.

        First backup starts at

        Set the data backup start time.

        Important

        After a policy is created, the first backup performs a full backup of all protected directories, which consumes a certain amount of CPU and memory resources. To avoid impacting your business, we recommend that you perform data backup during off-peak hours.

        Periodic backup interval

        Set the backup interval. Default: one day.

        Backup data retention period

        Set the backup data retention period. Default: 7 days.

        Important

        After the retention period expires, backup data is automatically cleared. We recommend that you set a reasonable retention period based on your business requirements.

        You can select the following retention methods:

        • Permanent: Backup data is retained until the Security Center service expires, the protection policy is deleted, or the server is removed from the policy.

        • Custom: Custom retention period. Minimum: 1 day. Maximum: 65,535 days.

        Maximum backup bandwidth

        Set the network bandwidth threshold for backup data. Value range: 0 MB/s to unlimited.

        Backup data for Alibaba Cloud servers uses only the private network bandwidth and does not affect the public network bandwidth. Backup data for servers not deployed on Alibaba Cloud uses the public or private network bandwidth. You can set the bandwidth threshold to prevent backup jobs from consuming excessive bandwidth and affecting your business.

        • Alibaba Cloud servers: 0 MB/s by default.

          Note

          0 MB/s means no bandwidth limit for backups.

        • Servers not deployed on Alibaba Cloud: 5 MB/s by default.

    6. After the protection policy is created, the policy status is enabled by default. Security Center automatically installs the anti-ransomware agent on the server and backs up the protected directories of the effective servers based on the backup conditions set in the policy.

      Warning

      Pay attention to the status of the anti-ransomware agent and handle abnormal statuses promptly to ensure that anti-ransomware backup and restoration tasks are properly executed. For more information, see View the status of the anti-ransomware agent.

  3. (Optional) Restore data from a valid backup in Security Center.

    1. Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.

    2. If your instance is attacked by ransomware, you can use a backup from Security Center to quickly restore your services. Follow these steps to restore your data.

      Create a restoration task

      1. Log on to Security Center console.

      2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

      3. On the Anti-ransomware for Servers tab, find the server for which you want to create a restore job in the policy list.

        Note

        Use the search box above the policy list to find the target server by policy name or server name.

      4. Click More actions to expand the drop-down list. Find the target server and click Restore in the Actions column.

      5. In the Create Restoration Task panel, configure the following parameters, and then click OK.

        Parameter

        Description

        Backup Version

        Select the backup version to restore. All recoverable files in the selected version are displayed in the file list. You can select files as needed.

        Files to Restore

        Select the files to restore.

        Destination Folder

        Enter the destination path on the target server. The folder must exist and have write permissions. Otherwise, the restore job fails.

        Target Server

        Select the server to restore data to. You can select any protected server in the same account, not limited to the originally attacked server.

      6. A Restoration task created. message appears. Log on to the target server and navigate to the destination folder to verify that the backup files are restored and accessible.

Strategy 2: Use automatic snapshots

Workflow

image

Procedure

Creating backups for an instance by using snapshots allows you to recover data after a ransomware attack. Note that this strategy provides only post-incident recovery capabilities and is not a substitute for proactive protection measures.

  1. Create an automatic snapshot policy for the instance. For more information, see Create an automatic snapshot policy.

  2. (Optional) Restore data from a valid snapshot that was created before the instance was infected.

    1. Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.

      Important

      A disk rollback is irreversible. Data generated between the snapshot creation and the rollback is lost. To prevent data loss from accidental operations, we recommend that you create a snapshot to back up your data before you roll back a disk.

    2. For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).

    3. To learn how to use a snapshot to restore data to a system disk or a data disk, see Roll back a disk by using a snapshot.

Strategy 3: Use security groups and firewalls

Workflow

image

Procedure

Security policies, such as those for security groups and firewalls, can enhance an instance's protection against ransomware. However, this requires you to have technical expertise in network security.

  1. For best practices for security group and firewall policies, see Best practices for ECS security groups (inbound rules) and Configuration guide for Windows Firewall policies.

  2. (Optional) Contact a third-party company to decrypt and restore data.

    1. Create a snapshot for the system disk and data disks of the instance that is infected with ransomware. For more information, see Create a manual snapshot.

    2. For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).

    3. After you reinitialize the system disk of the compromised instance, if you have not backed up important data or created a snapshot, you can contact a third-party company to decrypt and restore the data.

      Warning

      The data decryption capabilities provided by third-party companies after a ransomware attack are independent of Alibaba Cloud. Alibaba Cloud is not responsible for the success of data recovery or any data corruption.

Related documents