// Ransomware Negotiation Transcript
Avaddon Ransomware Negotiation — Redacted Organisation
// Context
About This Negotiation
This transcript documents a Avaddon ransomware negotiation with a redacted victim organisation. The negotiation consisted of 103 messages exchanged.
The initial ransom demand was $300,000. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
Hello from Avaddon Team .Price for you is
$300,000. We have downloaded a lot of critical data, which will be
published on our news website ([REDACTED URL] if you do
not make a payment. After the payment we will decrypt all your systems,
give you listing of files that we have taken, remove data from our
servers and give you proofs of deletion. Also we will provide you with
security report, so you can fix all your vulnerabilities and be safe
again.
We are ready to talk to you and discuss on this matter ....
hi
is anyone here?
Hello!
wnat to talk to you about this situation
your price is very expensive for us
300.000$ is our 3 year budget
tell us the real possible price and we ready to pay
How much can you pay at most?
give me 5 minute
i will talk with my chief
ok
redy to pay 3000$
This is a joke?
Your price is $ 300,000.
300.000$ is a joke
becauuse we havn't this amount of money
3000$ we can pay or go ahead to reainstall all our systems
search on map our country Armenia
300.000 is out country budget how we can pay this kind of money?
Perhaps the price is too high for you and we are ready to make a small discount.
But on $ 3,000 we will never agree.
Reinstalling all systems and restoring the
workflow will take a very long time and you will incur heavy losses. The
best option would be to pay and get back to normal quickly.
yes you are right
we will lose money while trying to
reainstall all systems and getting back informtion from external backups
but don't lose so much as you want
3000$ ready to pay, agree or not?
We have a lot of your important files that
we will publish on our blog if you do not cooperate with us.
I know all this
but we havn't money!
what can we do?!
You will never be able to get your files
back without our decryptor! Only we have a unique key to decrypt your
files. Don't waste time and money trying to decrypt files yourself.
I know that very well
I comunicate with you before
I know all this processes
and now that we cant decrypt our files
we just can reinstall all systemss and restore backups but it will take too long for us
We are ready to make a very big discount for
you. If you pay within 67 hours, we will offer you a 50% discount. Then
the price will again be $ 300,000.
so we ready to pay as much as we can
Now you need to pay $ 150,000.
what's your name?
It does not matter.
you know our country?
how the small firm in Armenia can pay you 150.000?
my house cost 15.000$ in all
Sir, you are offering us a ridiculous price,
it does not suit us at all. Before we set you a price of $150,000, we
analyzed your profitability and your capabilities in general, this price
was taken not from the sky, but according to specific criteria, and by
analysis.
what can I say, your analysis is wrong...
last time a year ago I paid 1700$ for your decrypting key
And we will tell you that $ 15,000 is still
not enough, and we do not agree to such a small amount. Suggest more or
we will use other methods. We can share your financial statements, your
employee and customer data, and more in the public domain. Use DDOS. We
can completely ruin the reputation of your business. Then you will have a
lot of problems and you will suffer a lot of damage. You choose ...
I don't event suggest 15.000$, because I havn't
We want to talk to your boss.
I called him, will be here in 15 minutes
Hi, I'm CEO
my name is [redacted]
ready to cooperate with you ...
Hello, [redacted]!
Are you already aware of the situation?
yes, of course
but unfortunately your requirements are in not compatible with the budget of our company ...
How much can you offer? As we already wrote,
the amount of $ 15,000 or $ 20,000 does not interest us.
:)
and how much you want if you don't agree with 15.000 or 20.000?
You're not serious! You do not understand
the magnitude of the problems for your company. Are you ready to incur
losses and ruin your reputation or will you cooperate and offer a higher
amount?
We have already offered you a very large
discount, which we do not do for other clients. We have made a 50%
discount for you.
I asked how much you want?
I perfectly understand all the risks
The price for you is $ 150,000.
After the expiration of the time, the price will double and then it will be $ 300,000.
it's not serious my company is not able to
pay you that kind of money let my IT specialists stay awake for several
days and restore archives or pay you this money as they want
by
You cannot recover files without our unique key.
You have 66 hours to start working with us or you will have a lot of problems.
After 7 o'clock your amount to double. This is the last chance to pay at such a low price.
Hi guys are you there ?
Contact us if you see this, it looks like we have a misunderstanding.
hi
what you mean?
Sir, we found out that one of the branches
of your network is located in Armenia, our policy of work does not allow
working in the CIS countries, so we will give you a decryptor general
with which you can decrypt your entire network. We strongly apologize
for this unpleasant incident and would like to say that we will help you
restore your systems even if you have any problems.
really? this is a great news
despite the fact that we already recover
most of our information, we will be thankful if you give us the key
You can download the decryptor.
from where? give link please
is it free software?
[REDACTED URL]
look like it's work...
can you also help us to understand how you did that?
we want to found out loophole in our network
Weak passwords.
but how you could come in to our network?
I will clarify this point.
we will wait for your clarifying ant will be very thankful for your support
Ok
You guys should do penetration tests more
often. Hire a professional company and they will find all loopholes in
your network. It will cost you few ten thousends but you will be safe.
Update all services with outside internet, especially Ms Exchange server.
you used zerologon exploit ?
We cannot say anything more for security reasons for personal purposes.
ok , we understood , thanks for information ,
we will upgrade our exchange server and do several things for security
Ok guys, excuse us again, I hope you didn't report this to the police? :)
))
What does it mean ?:)
don't worry about that
Ok sir , good luck
// Analysis
Analyst Observations
- This is an unusually long negotiation, suggesting extended back-and-forth and significant engagement from both parties.