Avaddon Ransomware Negotiation — Redacted Organisation

25Messages
UnknownDuration
$1.0MInitial Demand
RefusedOutcome

About This Negotiation

This transcript documents a Avaddon ransomware negotiation with a redacted victim organisation. The negotiation consisted of 25 messages exchanged over Unknown.

The initial ransom demand was $1.0M. The victim refused to pay.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Avaddon] — 15:25 12.01.2021 — Message 1/25
Hello, will you take the decryption or not?
[Victim] — 12:49 20.02.2021 — Message 2/25
Hello There! I need help my test decryption not working
[Victim] — 12:50 20.02.2021 — Message 3/25
u still there? Ready to pay!
[Victim] — 12:51 20.02.2021 — Message 4/25
by now Github Decrypted my files, thanks!
[Avaddon] — 13:16 20.02.2021 — Message 5/25
Hi sir
[Avaddon] — 13:18 20.02.2021 — Message 6/25
What do you mean "by now Github Decrypted my files, thanks!"?
[Avaddon] — 13:18 20.02.2021 — Message 7/25
Only we have a decryptor, no github decryptors will help you!
[Avaddon] — 15:34 20.02.2021 — Message 8/25
Do not rejoice, you will not be able to unblock all your servers, only we can unblock your servers, you better pay, we even reduced the price for you from $ 1,000,000 to $ 200,000, you now better buy a decryption, and finish this business already
[Victim] — 19:34 20.02.2021 — Message 9/25
Hey You know the guy that publish the free decryptor on githut and You seen it ?
[Avaddon] — 19:47 20.02.2021 — Message 10/25
we have already released a patch, so it won't help you another time)
[Avaddon] — 19:49 20.02.2021 — Message 11/25
the more we doubt that you have decrypted files, because the decryptor can decrypt files under very specific conditions
[Avaddon] — 19:50 20.02.2021 — Message 12/25
Have you seen the release of your important documents on our blog?
[Victim] — 20:08 20.02.2021 — Message 13/25
I would like to know if You will come after me again.
[Victim] — 20:12 20.02.2021 — Message 14/25
We cannot pay that even though! It is outrageous! We are drowing on debt, no payment will be released to You, We have no assurance of decryption as many customers of yours are complaining of issues decrypting their files after payment as well.;
[Victim] — 20:13 20.02.2021 — Message 15/25
We have no problem starting from scratch, Our only concern is been hit a second time like One customer of Yours did.
[Avaddon] — 20:19 20.02.2021 — Message 16/25
ok, enjoy leaking files on your blog. Our clients have no problems with decrypting files, you need to listen to negotiators less and then you will have no problems
[Victim] — 20:23 20.02.2021 — Message 17/25
We don't want to listen to them That is Why i come in here myself!
[Victim] — 20:23 20.02.2021 — Message 18/25
I am begging You
[Avaddon] — 20:36 20.02.2021 — Message 19/25
and why are you writing here?
[Victim] — 21:17 20.02.2021 — Message 20/25
Cause There is no place else to write. We Want to rear from You
[Avaddon] — 22:06 20.02.2021 — Message 21/25
It's good that you contacted us yourself. Look, we are a serious organization and every month Avaddon General Decryptor is bought by hundreds of clients and there are no problems with decryption. Those comments that you read can be written by anyone, even people who have never worked with us, in order to lower our reputation. But this is pointless, since thousands of customers who bought our decryptor will refute information about the about poor performance ability of our software.
[Avaddon] — 22:08 20.02.2021 — Message 22/25
If we do not agree on a price for the buyback and you do not pay, then we will wait until you fully restore your entire online infrastructure and we deliver a SECOND IMPACT, and believe me, this blow will be more destructive, you will lose a lot more money and get more problems. as there will be a second wave of data leakage which will be measured by terabytes of data. We are ready to discuss the new price with you and remove your company data from our data breach blog. After payment, we will give you a decryptor that will decrypt absolutely all PCs / servers on your network, delete the files (we will provide proofs that the files have been deleted) and provide you with a list of vulnerabilities, with the help of this list you can eliminate all the vulnerabilities in your network and this situation cannot happen again with you in the future
[Victim] — 11:26 21.02.2021 — Message 23/25
Will You be Our consultant perhaps? Will You tell Us how you got in because We failed to diagnose the entry point, We just found the binary. Vulnerabilities are discovered everyday and yet We failed to fix Ours with your penetration at Our Network. How low can We get on a ransom? We already lost so much, If you hit Us one more time We will no option but declare bankruptcy.
[Avaddon] — 12:00 21.02.2021 — Message 24/25
In what sense will I be your consultant?
[Avaddon] — 12:00 21.02.2021 — Message 25/25
Look, you could write to us right away, we would have settled this issue and you resumed your work a few weeks ago, but for some reason you did not want to do this ... Yes sir, vulnerabilities are found every day, but there were many holes in your network, we are ready to point you to them and tell you what to do so that they are closed, we will help you secure your network and if in the future you keep our advice it will be practically impossible to crack, but You will receive instructions on how to close the holes and secure your network only after payment. We understand that financial losses are possible in your business now and we understand perfectly well what will happen if we deliver the SECOND IMPACT, the second blow will mean an absolute collapse for you. We do not want to do this (we even reduced the price for you from 1kk to 200k), but we will have to if we do not now agree with you on the price for the buyback. Make a meeting with the management or people who are responsible for finances in your company, explain to them the current situation and what awaits you in the future, if we do not agree on the price for the ransom and offer us your price, we are waiting for an answer from you, because time is ticking, and for you, time is money.

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.