WithSecure proposes ‘undo’ button for ransomware

WithSecure’s Activity Monitor technology supposedly overcomes the shortcomings of sandbox test environments, and may be able to stop ransomware attacks from ever happening

Alex Scroxton

By

Published: 23 Feb 2023 23:45

Cyber security supplier WithSecure is piloting a newly developed technology that supposedly makes a sandbox test environment more accessible, and claims it has effectively found an “undo button” for ransomware.

The Helsinki-based firm, which has already incorporated the feature into its Elements Endpoint Protection for Servers product, says the technology, dubbed Activity Monitor, can quickly and easily undo the damage malware can cause.

In a cyber security context, sandboxes are test environments in which analysts and researchers can execute unknown code to see how it impacts systems or data, and whether or not it is harmful. Because they are isolated from other systems on the network, this can be done quite safely.

However, according to WithSecure lead researcher Broderick Aquilino, traditional sandbox environments, despite their utility, carry with them some limitations. “The analysis provided by a sandbox shows a very comprehensive picture of malware’s behaviour but consumes a lot of resources, which limits their use,” he said. “With Activity Monitor, we overcame these limitations by recreating the capabilities that sandboxes provide rather than how they work. Now we can create protection mechanisms that can bring these capabilities to more organisations.”

Rather than executing suspicious code in an isolated environment, Activity Monitor instead creates selective backups of systems and data first, and then allows the code to run on it while monitoring the session.

If, at this point, it detects changes that could be harmful, it blocks the processes, before using its backups to revert the session to the state it was in prior to the code being executed.

By this method, said WithSecure, it can offer a tool that effectively stops ransomware infections before they execute and encrypt any data. If accurate, this could save organisations billions of pounds.

Aquilino added: “We were trying to copy the sandbox approach that we use in the backend, but use it for endpoints. A sandbox works by isolating untested code and allowing it to execute, which means you can understand what suspicious code will do without putting the environment at risk. However, this takes time, and so is not very suitable for endpoints because the delay will be very noticeable to users. A user will execute a file and then will have to wait a few minutes to get the result.  

“In this case, we tried to create a sandbox, but on the endpoint,” he said. “To address the poor user experience, we decided to actually let it execute on the system, allowing it to encrypt files and everything. Then we came up with this rollback capability so that we see files getting encrypted, then do the rollback automatically, without any interaction from the user, and delete the executed file.”

For an end-user deploying the service, Activity Monitor will come as a toggle-on feature in the Elements offering. When activated, it will automatically discover all shared folders on the user’s Windows Server – admins may choose to exclude selected folders if they wish – and then go to work silently in the background. Effectively, said WithSecure, you will not notice it unless a ransomware locker attempts to encrypt your files.

Activity Monitor has two modes, report and normal. In report mode, when ransomware executes the admin will be notified but the roll-back capability will not engage automatically, a protection in pace to stop legitimate changes to systems being accidentally rolled back. If normal mode is switched on, Activity Monitor will automatically roll back the encryption process, and the admin will see two notifications, first that a ransomware has attempted to execute, then shortly after another saying the system has been successfully restored to its previous state.

However, Activity Monitor may also have potential beyond stopping ransomware in its tracks, said WithSecure Intelligence vice-president Paolo Palumbo. “This approach makes very powerful detection capabilities more efficient so they can be used in new ways,” he said.

“Efficiency is very important for security to ensure our solutions give organisations practical, effective protection without preventing them from doing their jobs or accomplishing their business goals. And as we develop new applications and features using this technology, we expect it to enable better, more efficient defence mechanisms for our clients.”

The research that produced Activity Monitor was supported by the TRUST aWARE project, which is on a mission to “provide a holistic and effective digital security and privacy framework comprising a set of novel and integrated tools and services”, with funding funnelled through the European Union’s (EU’s) Horizon 2020 research and innovation programme.

Read more on Hackers and cybercrime prevention

Read More
Georgianna Schewe

Latest

Franklin Templeton says Wall Street fears blockchain because it threatens its profits

Jenny Johnson, Franklin Templeton's CEO, said blockchain and crypto threaten a huge number of business models that exist today in traditional finance. Jun 3, 2026, 7:04 a.m. 2 min read Make preferred on The future of asset management is shifting on-chain, but the transition is exposing a major structural conflict over traditional corporate revenue. Speaking

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

Evin McMullen’s view on AI agents disrupting Google’s and Facebook’s business model was previously shared by Cardano Founder Charles Hoskinson and Cloudflare CSO Stephanie Cohen. Jun 3, 2026, 6:51 a.m. 2 min read Make preferred on The legacy financial and digital frameworks propping up the current internet architecture face an imminent, existential crisis. Evin McMullen

What Responsibilities Come With Sole Proprietorship for Self-Employed Individuals?

As a sole proprietor, you take on significant responsibilities that impact your business and personal finances. You’ll need to maintain precise financial records, file taxes using Schedule C, and guarantee compliance with local regulations. Moreover, you’re personally liable for any business debts, which underscores the importance of liability insurance. Securing the right licenses and permits

Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment

Homepage > News > Business > Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment MANILA, Philippines — The next phase of the digital economy will not be announced after the fact—it will take shape in real time at Philippine Blockchain Week (PBW) 2026. From June 19 to 21 at the SMX

Newsletter

Don't miss

Franklin Templeton says Wall Street fears blockchain because it threatens its profits

Jenny Johnson, Franklin Templeton's CEO, said blockchain and crypto threaten a huge number of business models that exist today in traditional finance. Jun 3, 2026, 7:04 a.m. 2 min read Make preferred on The future of asset management is shifting on-chain, but the transition is exposing a major structural conflict over traditional corporate revenue. Speaking

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

Evin McMullen’s view on AI agents disrupting Google’s and Facebook’s business model was previously shared by Cardano Founder Charles Hoskinson and Cloudflare CSO Stephanie Cohen. Jun 3, 2026, 6:51 a.m. 2 min read Make preferred on The legacy financial and digital frameworks propping up the current internet architecture face an imminent, existential crisis. Evin McMullen

What Responsibilities Come With Sole Proprietorship for Self-Employed Individuals?

As a sole proprietor, you take on significant responsibilities that impact your business and personal finances. You’ll need to maintain precise financial records, file taxes using Schedule C, and guarantee compliance with local regulations. Moreover, you’re personally liable for any business debts, which underscores the importance of liability insurance. Securing the right licenses and permits

Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment

Homepage > News > Business > Philippine Blockchain Week 2026 marks shift from Web3 potential to real-world deployment MANILA, Philippines — The next phase of the digital economy will not be announced after the fact—it will take shape in real time at Philippine Blockchain Week (PBW) 2026. From June 19 to 21 at the SMX

Top 7 Cloud Accounting Software Options for Small Businesses

If you’re a small business owner, choosing the right cloud accounting software can greatly impact your financial management. There are several top contenders available, each with distinct features that cater to various needs and budgets. QuickBooks Online stands out for its user-friendly interface, whereas Wave offers a free option for solo entrepreneurs. As you evaluate

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they