Cloak Ransomware Negotiation — Redacted Organisation

54Messages
26 daysDuration
UnknownInitial Demand
UnknownOutcome

About This Negotiation

This transcript documents a Cloak ransomware negotiation with a redacted victim organisation. The negotiation consisted of 54 messages exchanged over 26 days, beginning on 2023-08-02.

The initial demand is not clearly stated in the transcript. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Cloak] — 2023-08-02 22:54:31 — Message 1/54
[Cloak] — 2023-08-19 04:33:16 — Message 2/54
Hello! If you are reading this message, your files are encrypted and your data is compromised.In order for YOU to quickly and without additional losses FOR YOU to regain control over your data, strictly follow the proposed scenario:1. ONLY an AUTHORIZED representative authorized to enter into financial agreements and negotiate on behalf of the entire company should participate in negotiations on your part.All other persons not endowed with such authority (system administrators, cleaners, and others) who enter into negotiations can cause significant harm, primarily for your own company.2. Confirm that you are an authorized representative of your company and briefly describe your situation.3. Stay online throughout today until further instructions.4. If you did not receive our answer during the day, then indicate the time, country and city in the time zone of which you are located. Set a time convenient for you for follow-up negotiations.5. Keep calm and be patient, they will definitely answer you and help you with the recovery of your data.6. Remember that mutual respect is the key to successful negotiations.
[Cloak] — 2023-08-21 13:25:23 — Message 3/54
Hello,
[Cloak] — 2023-08-21 13:25:46 — Message 4/54
We got infected and you asked to contact you.
[Cloak] — 2023-08-21 13:42:46 — Message 5/54
Hello
[Cloak] — 2023-08-21 13:43:36 — Message 6/54
you have not given me confirmation that you are authorized to negotiate on behalf of the company.
[Cloak] — 2023-08-21 13:43:49 — Message 7/54
you must understand that based on your answers, appropriate decisions will be made that will affectthroughout your company.
[Cloak] — 2023-08-21 13:44:01 — Message 8/54
So you're authorized to negotiate?
[Cloak] — 2023-08-21 13:55:04 — Message 9/54
I'm authorized to ask your intentions. We're in [redacted], and we're not used to this kind of situation. I'll pass on to my manager, who will decide what to do next. This is the 1st step for him.
[Cloak] — 2023-08-21 13:56:03 — Message 10/54
ok
[Cloak] — 2023-08-21 13:56:12 — Message 11/54
So that we do not have a misunderstanding and, as a result, undesirable consequences for you, follow these 3 rules:
[Cloak] — 2023-08-21 13:56:24 — Message 12/54
1 Always answer my questions. If you don't have an answer and need to consult with management, tell me so. 2 Never end negotiations unilaterally. This may serve as a signal to me that you refuse to cooperate with us. 3 If the negotiations are completed today, be sure to indicate the time of the next meeting.
[Cloak] — 2023-08-21 13:56:55 — Message 13/54
Now I will give you a step-by-step plan of further actions. Follow it strictly, as it is the shortest way to the to the successful completion of the case.
[Cloak] — 2023-08-21 13:57:28 — Message 14/54
The next steps will be:
[Cloak] — 2023-08-21 13:57:37 — Message 15/54
1. We assign you a ransom amount that you must accept*.
[Cloak] — 2023-08-21 13:57:40 — Message 16/54
ok
[Cloak] — 2023-08-21 13:57:45 — Message 17/54
2. you convert the approved amount into BTC or XMR.
[Cloak] — 2023-08-21 13:58:13 — Message 18/54
3. You send us 2 encrypted files to check their reverse decryption**.
[Cloak] — 2023-08-21 13:58:22 — Message 19/54
4. we decrypt them and send them to you.
[Cloak] — 2023-08-21 13:58:33 — Message 20/54
5. you make sure the decryptor works and give us confirmation.
[Cloak] — 2023-08-21 13:58:44 — Message 21/54
6. we give you a wallet to transfer BTC or XMR.
[Cloak] — 2023-08-21 13:58:54 — Message 22/54
7. You make a trial amount transfer and wait for confirmation.
[Cloak] — 2023-08-21 13:59:05 — Message 23/54
8. After our confirmation, you transfer the entire amount.
[Cloak] — 2023-08-21 13:59:15 — Message 24/54
9. We send you the key and detailed instructions.***
[Cloak] — 2023-08-21 13:59:24 — Message 25/54
10. your data stored by us will be deleted.
[Cloak] — 2023-08-21 13:59:32 — Message 26/54
11. we provide you with a penetration report indicating the exploited vulnerabilities.****
[Cloak] — 2023-08-21 13:59:45 — Message 27/54
notes:
[Cloak] — 2023-08-21 14:00:20 — Message 28/54
* we know about your income so do not humiliate yourself.Discounts can only be granted to those companies that have applied to us in a timely manner and strictly comply with all our instructions.**Files must not be important, and their maximum size must be no more than 5 MB each.*** We will keep in touch with you until your network is fully restored.**** The report is provided to everyone who paid the full amount of the ransom.
[Cloak] — 2023-08-21 14:01:49 — Message 29/54
1?
[Cloak] — 2023-08-21 14:03:36 — Message 30/54
This is the general plan.I will discuss the specific amount of the ransom only with an authorized person who owns the right to conclude financial agreements.
[Cloak] — 2023-08-21 14:06:26 — Message 31/54
if such a person is in touch with you, then tell him this and let him join our negotiations.
[Cloak] — 2023-08-21 18:29:30 — Message 32/54
I'm still here and waiting for your representative for further negotiations
[Cloak] — 2023-08-22 10:26:45 — Message 33/54
Your silence will only make things worse for yourself.We have more than 60 GB of your private data at our disposal.Urgently appoint an authorized representative and enter into negotiations.Otherwise, we will sell your data to a third party
[Cloak] — 2023-08-23 10:02:51 — Message 34/54
As I warned you, your data is for sale.While the timer is running, no one else can see your files.After the time expires, your data will be available to our buyers, but it will not be available to you.Enter into negotiations quickly and we will stop this.
[Cloak] — 2023-08-23 10:03:18 — Message 35/54
[REDACTED URL]
[Cloak] — 2023-08-23 10:03:32 — Message 36/54
[redacted]
[Cloak] — 2023-08-23 10:03:44 — Message 37/54
[redacted]
[Cloak] — 2023-08-23 10:04:37 — Message 38/54
[redacted]
[Cloak] — 2023-08-23 13:44:20 — Message 39/54
[redacted]
[Cloak] — 2023-08-24 17:08:44 — Message 40/54
Why are you keeping silent?you are running out of time.
[Cloak] — 2023-08-27 03:14:55 — Message 41/54
[redacted].com hi sir this data need also
[Cloak] — 2023-08-27 03:16:54 — Message 42/54
[REDACTED URL] my link not working so i contact this way
[Cloak] — 2023-08-27 03:25:30 — Message 43/54
pls need decrypt tool
[Cloak] — 2023-08-27 06:32:44 — Message 44/54
pls help me
[Cloak] — 2023-08-27 11:38:31 — Message 45/54
Hello!To help you I need to understand who I'm dealing with?Have you been authorized to negotiate on behalf of the entire company?
[Cloak] — 2023-08-27 11:45:52 — Message 46/54
As for [redacted].com, I can tell you that we can also solve this issue.Pass this on to your management.
[Cloak] — 2023-08-27 12:09:24 — Message 47/54
Get the point. Without the participation of your leadership, we will not be able to conclude an agreement with you.It is up to your bosses to decide whether or not they should pay us to decrypt the files and return the data.Therefore, I strongly recommend that you tell them about it. Let them give you a representative.This is the only way we will find a way out of this situation.
[Cloak] — 2023-08-27 12:56:03 — Message 48/54
how much price
[Cloak] — 2023-08-27 12:56:05 — Message 49/54
[redacted].com
[Cloak] — 2023-08-27 14:45:16 — Message 50/54
wait a bit, I'll make some clarifications on this
[Cloak] — 2023-08-27 15:23:53 — Message 51/54
for those who want to recover files on [redacted].com. I have a question. How did you get access to this chat?
[Cloak] — 2023-08-27 15:25:08 — Message 52/54
After your answer, we will move on to discussing the price.
[Cloak] — 2023-08-28 11:30:22 — Message 53/54
Why did you stop communicating?Files on your computers won't decrypt themselves
[Cloak] — 2023-08-28 15:26:38 — Message 54/54
we are ready to cooperate.Give me an answer and we will move on to the question of price

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.