// Context
About This Negotiation
This transcript documents a Cloak ransomware negotiation with a redacted victim organisation.
The negotiation consisted of 54 messages exchanged over 26 days, beginning on 2023-08-02.
The initial demand is not clearly stated in the transcript. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at
enquiries@binary-response.com — we will act promptly.
[Cloak] — 2023-08-02 22:54:31 — Message 1/54
[Cloak] — 2023-08-19 04:33:16 — Message 2/54
Hello! If you are reading this message, your files
are encrypted and your data is compromised.In order for YOU to quickly
and without additional losses FOR YOU to regain control over your data,
strictly follow the proposed scenario:1. ONLY an AUTHORIZED
representative authorized to enter into financial agreements and
negotiate on behalf of the entire company should participate in
negotiations on your part.All other persons not endowed with such
authority (system administrators, cleaners, and others) who enter into
negotiations can cause significant harm, primarily for your own
company.2. Confirm that you are an authorized representative of your
company and briefly describe your situation.3. Stay online throughout
today until further instructions.4. If you did not receive our answer
during the day, then indicate the time, country and city in the time
zone of which you are located. Set a time convenient for you for
follow-up negotiations.5. Keep calm and be patient, they will definitely
answer you and help you with the recovery of your data.6. Remember that
mutual respect is the key to successful negotiations.
[Cloak] — 2023-08-21 13:25:23 — Message 3/54
Hello,
[Cloak] — 2023-08-21 13:25:46 — Message 4/54
We got infected and you asked to contact you.
[Cloak] — 2023-08-21 13:42:46 — Message 5/54
Hello
[Cloak] — 2023-08-21 13:43:36 — Message 6/54
you have not given me confirmation that you are authorized to negotiate on behalf of the company.
[Cloak] — 2023-08-21 13:43:49 — Message 7/54
you must understand that based on your answers, appropriate decisions will be made that will affectthroughout your company.
[Cloak] — 2023-08-21 13:44:01 — Message 8/54
So you're authorized to negotiate?
[Cloak] — 2023-08-21 13:55:04 — Message 9/54
I'm authorized to ask your intentions. We're in
[redacted], and we're not used to this kind of situation. I'll
pass on to my manager, who will decide what to do next. This is the 1st
step for him.
[Cloak] — 2023-08-21 13:56:03 — Message 10/54
ok
[Cloak] — 2023-08-21 13:56:12 — Message 11/54
So that we do not have a misunderstanding and, as a result, undesirable consequences for you, follow these 3 rules:
[Cloak] — 2023-08-21 13:56:24 — Message 12/54
1 Always answer my questions. If you don't have an
answer and need to consult with management, tell me so. 2 Never end
negotiations unilaterally. This may serve as a signal to me that you
refuse to cooperate with us. 3 If the negotiations are completed today,
be sure to indicate the time of the next meeting.
[Cloak] — 2023-08-21 13:56:55 — Message 13/54
Now I will give you a step-by-step plan of further
actions. Follow it strictly, as it is the shortest way to the to the
successful completion of the case.
[Cloak] — 2023-08-21 13:57:28 — Message 14/54
The next steps will be:
[Cloak] — 2023-08-21 13:57:37 — Message 15/54
1. We assign you a ransom amount that you must accept*.
[Cloak] — 2023-08-21 13:57:40 — Message 16/54
ok
[Cloak] — 2023-08-21 13:57:45 — Message 17/54
2. you convert the approved amount into BTC or XMR.
[Cloak] — 2023-08-21 13:58:13 — Message 18/54
3. You send us 2 encrypted files to check their reverse decryption**.
[Cloak] — 2023-08-21 13:58:22 — Message 19/54
4. we decrypt them and send them to you.
[Cloak] — 2023-08-21 13:58:33 — Message 20/54
5. you make sure the decryptor works and give us confirmation.
[Cloak] — 2023-08-21 13:58:44 — Message 21/54
6. we give you a wallet to transfer BTC or XMR.
[Cloak] — 2023-08-21 13:58:54 — Message 22/54
7. You make a trial amount transfer and wait for confirmation.
[Cloak] — 2023-08-21 13:59:05 — Message 23/54
8. After our confirmation, you transfer the entire amount.
[Cloak] — 2023-08-21 13:59:15 — Message 24/54
9. We send you the key and detailed instructions.***
[Cloak] — 2023-08-21 13:59:24 — Message 25/54
10. your data stored by us will be deleted.
[Cloak] — 2023-08-21 13:59:32 — Message 26/54
11. we provide you with a penetration report indicating the exploited vulnerabilities.****
[Cloak] — 2023-08-21 13:59:45 — Message 27/54
notes:
[Cloak] — 2023-08-21 14:00:20 — Message 28/54
* we know about your income so do not humiliate
yourself.Discounts can only be granted to those companies that have
applied to us in a timely manner and strictly comply with all our
instructions.**Files must not be important, and their maximum size must
be no more than 5 MB each.*** We will keep in touch with you until your
network is fully restored.**** The report is provided to everyone who
paid the full amount of the ransom.
[Cloak] — 2023-08-21 14:01:49 — Message 29/54
1?
[Cloak] — 2023-08-21 14:03:36 — Message 30/54
This is the general plan.I will discuss the specific
amount of the ransom only with an authorized person who owns the right
to conclude financial agreements.
[Cloak] — 2023-08-21 14:06:26 — Message 31/54
if such a person is in touch with you, then tell him this and let him join our negotiations.
[Cloak] — 2023-08-21 18:29:30 — Message 32/54
I'm still here and waiting for your representative for further negotiations
[Cloak] — 2023-08-22 10:26:45 — Message 33/54
Your silence will only make things worse for
yourself.We have more than 60 GB of your private data at our
disposal.Urgently appoint an authorized representative and enter into
negotiations.Otherwise, we will sell your data to a third party
[Cloak] — 2023-08-23 10:02:51 — Message 34/54
As I warned you, your data is for sale.While the
timer is running, no one else can see your files.After the time expires,
your data will be available to our buyers, but it will not be available
to you.Enter into negotiations quickly and we will stop this.
[Cloak] — 2023-08-23 10:03:18 — Message 35/54
[REDACTED URL]
[Cloak] — 2023-08-23 10:03:32 — Message 36/54
[redacted]
[Cloak] — 2023-08-23 10:03:44 — Message 37/54
[redacted]
[Cloak] — 2023-08-23 10:04:37 — Message 38/54
[redacted]
[Cloak] — 2023-08-23 13:44:20 — Message 39/54
[redacted]
[Cloak] — 2023-08-24 17:08:44 — Message 40/54
Why are you keeping silent?you are running out of time.
[Cloak] — 2023-08-27 03:14:55 — Message 41/54
[redacted].com hi sir this data need also
[Cloak] — 2023-08-27 03:16:54 — Message 42/54
[REDACTED URL] my link not working so i contact this way
[Cloak] — 2023-08-27 03:25:30 — Message 43/54
pls need decrypt tool
[Cloak] — 2023-08-27 06:32:44 — Message 44/54
pls help me
[Cloak] — 2023-08-27 11:38:31 — Message 45/54
Hello!To help you I need to understand who I'm
dealing with?Have you been authorized to negotiate on behalf of the
entire company?
[Cloak] — 2023-08-27 11:45:52 — Message 46/54
As for [redacted].com, I can tell you that we can also solve this issue.Pass this on to your management.
[Cloak] — 2023-08-27 12:09:24 — Message 47/54
Get the point. Without the participation of your
leadership, we will not be able to conclude an agreement with you.It is
up to your bosses to decide whether or not they should pay us to decrypt
the files and return the data.Therefore, I strongly recommend that you
tell them about it. Let them give you a representative.This is the only
way we will find a way out of this situation.
[Cloak] — 2023-08-27 12:56:03 — Message 48/54
how much price
[Cloak] — 2023-08-27 12:56:05 — Message 49/54
[redacted].com
[Cloak] — 2023-08-27 14:45:16 — Message 50/54
wait a bit, I'll make some clarifications on this
[Cloak] — 2023-08-27 15:23:53 — Message 51/54
for those who want to recover files on [redacted].com. I have a question. How did you get access to this chat?
[Cloak] — 2023-08-27 15:25:08 — Message 52/54
After your answer, we will move on to discussing the price.
[Cloak] — 2023-08-28 11:30:22 — Message 53/54
Why did you stop communicating?Files on your computers won't decrypt themselves
[Cloak] — 2023-08-28 15:26:38 — Message 54/54
we are ready to cooperate.Give me an answer and we will move on to the question of price