// Ransomware Negotiation Transcript
Darkside Ransomware Negotiation — Redacted Organisation
// Context
About This Negotiation
This transcript documents a Darkside ransomware negotiation with a redacted victim organisation. The negotiation consisted of 243 messages exchanged.
The initial ransom demand was $5,500. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
How to buy Bitcoin for this amount?
Hello!
Moment please, let me prepare a manual for you.
are you sure that you want to pay in bitcoin? maybe you prefer
monero? cause in case you want to pay in bitcoin, you have to pay in 20%
more because of service fees.
how monero works?
process is literally the same
give me a moment i provide a monero tutorial
ok good for monero
monero manual
here is the fastest and safest service to buy monero in your country [REDACTED URL]
alternative way is to buy bitcoin via next manual and change it to monero here [REDACTED URL]
bitcoin manual
here are some services where you can safely buy and send bitcoin
[REDACTED URL] manual how to buy and send is placed on the
main page, this is the simplest and fastest way, no any verification
required///////
[REDACTED URL] here is the short manual how to buy and send
[REDACTED URL] profile verification may be
required////////
[REDACTED URL] here is the short manual how to buy and send
[REDACTED URL] profile verification may be
required///
chose which one you like more, and buy bitcoin.
hen text in chat and we provide the wallet for transfer
ok. I'm working on it
ok. I'm working on it
Hi. The price is too high
could we find a mediation?
we do not have that amount of money. We are a little company
5.000€?
We do not make such big discounts.
Read about us on the Internet.
5000 euro is impossible. you are not a small company, we've been
working on your network, we have encryped 200tb of data, you can not be a
small company, you have a whole data center.
please give us a sustainable amount we are 80 people that works from [redacted location]
[redacted location]
we work for non profit organization like [redacted]
before the attack we checked info about your company, so it's
absolutely useless to prove us anything. discount is possible, but not
in the amount you want. you can try to take a loan and find any
cryptobrocker who will resolve all the cryptocurrency exchange.
10.000€
You are wasting our time. Write when you have serious offers.
discount x100 from first amount is impossible.
we can reduce the price by 50 000. so you have to pay 950 000 $
we do not have that amount. Is out of our business
take a loan
I can make you an offer compatible with my availability and
comparable to the time it would take if I had to restore from backups
we know everything about your backups, if you could restore, you
wouldn't text us at all. so please stop wasting our time and yours, you
know, that the only way to restore your business is to make the payment
requested
are we talking with recovery company right now? cause few hours ago this conversation had a bit another vector.
no I move from home to office
go back home, you were much more pliable from there.
I'm talking to the CEO to unadestand how much can we pay
ok we are waiting
I talked with my CEO we want to solve the issue. We can offer
75.000€ to start the decryption process and 75.000 at the end of the
decryption. (in total 150.000€)
This amount is not enough. Raise the price and we will give you an additional discount.
We can refuse payment and not give you a decryptor. Can you afford it? What will you tell your clients?
We understand you and are ready to give you a decryptor right now. Give us a good offer.
Any phased payment options are not possible. You pay first, then we
give you decryptors. If you are not sure, you can give us test files and
we will decrypt them for you.
In Linux, we specially encrypt log files, they are small in size and you can upload them to chat.
In you site you declare that you do not attack no.profit
organization. We host the site of a lot of no profit organization that
currently has the service down. Please accept our offer 150.000 all in
one
Look, if you were a non-profit organization, you wouldn't be
attacked by anyone. Everyone can say that they are helping someone.
In the current case, your offer does not meet our expectations. It will
get you nowhere and you are wasting your time. Give us a better price
and we will give you a discount.
I want you to understand one thing, it doesn't matter to me how long
it takes to discuss the price. This is important for you. The faster
you get decryptors, the faster you will continue to make money.
I sent you a small files
[redacted].txt.[redacted]
8.95 kB
File
[redacted].txt
8.81 kB
Hi, we had a crisis committee meeting. We evaluated your proposal. I
know that you don't want waste time but trust me we are not so big as
you think. We need time to get a reasonable amount of MONERO or
BITCOIN. We try deliver an extra special effort and we can raise to
250.000€. We hope that this offers meet your expectation
i'm moving to home becouse of lock down and we had to go home at 10pm
We are ready to accept 700k dollars. We will give you a discount of $ 300k.
We want to pay but we do not have 700k. We did the best effort to offer you 250.000
here is midnigth, i need to sleep and I hope to found some good news.
Let's get back to this question in the morning! you need to rest, you are right! Goodnight!
good moring......I hope
We've made you a 30% discount. Give us a better price and we will try to give you an additional discount.
Trust me. We host site for no-profit organization that do not have a
lot of money. You found a lot of data but this are our kind of
customer. We made the best 250.000€ is a very high amount for us. We
had also a problem to find this amount in a few days. The site that you
suggested offer MONERO at block of 5000 or 10.000€
We are 60 employee and only 6 on IT....we are working on this problem 24 hours....we need your help
I spoke to my boss and explained your situation to him. He approved a payment of 350k dollars.
There will be no more discounts. Now you are offering 300k dollars, raise your price by 50k and we will close this deal now.
do you have a quick way to get that amount of MONERO?
we accept your proposal
Price updated. Reload the page.
ok. Give us a reference to get that amount of monero
Yes, have you considered buying through the exchange? Or are you having trouble with it?
If you find it difficult to get Monero - buy Bitcoin first. Then change it to Monero.
We want to buy through the exchange. But they exchange at block of 10.000€.
I think it is not difficult to buy bitcoin in your country. Use exchangers or crypto exchanges (binance, et al.).
ok. I will update you
we have to do change € on our wallet or directly charge on your wallet
Change money on your wallet and then send us cryptocurrency
Hi, just to tell you that we are working to get cryptocurrency
OK, we wait.
Good moring. Very difficult to move on BTC that amount on one wallet. You need transaction from one wallet alone?
can we make in more transcation?
could you Decrypt some server?
We are waiting for xmr from you, not btc. If you decided to pay with btc, you have to pay additional 20%.
And you can use several transaction
After payment you will receive decryptor for all your network.
several transaction from same wallet or we could use different wallet?
You can use different wallet
How many BTC we had to pay? Yesterday i saw 25.18, now I see 23.3
Pay the amount that you see now
Btc rate is not stable, so don't wait and pay quickly
do not change anymore because we had a lot o difficult to get crypto BTC
i can fixed the rate, but you have to pay for 6 hours
will pay for this time?
we'll try in 12 hours , but i'm not sure, maybe 24.
i have fixed your btc amount, for the next 24 hours it doesn't depend from btc rate
but you must pay as soon as possible
ok
help us as soon as possible. We are very little to pay that amount
but we do....and also we had to work a lot of other days....give an hand
as soon as you can....trust us
After payment I will immediately give you decryptors.
Hi. Why the rate changed again?
you promise me to block the rate of BTC to 23.3
we already had a trade for that amount and we need to fix it
Are you there?
Hello
Rate was changed yesterday, before i fixed it
You actual amount for the next 12 hours 23.61 BTC
we bought yesterday 23.3 by an exchanger and we are waiting for the transaction. We cannot change the amount now
the payment is in process
okay, waiting for 23.3 BTC from you in next several hours
ok. May I ask a partial decrypion of one server?
After payment you'll immediately receive decryptor for all network
You have the last 3 hours to pay the fixed btc amount after that time the rate will be float again.
be patient
the transaction is in progress with our exchanger
technical time
Our btc wallet is always actual and the same, so send as quickly as it possible.
what do you mean?
The wallet that you see on your page is always relevant
i'm here
operation is in progress
ok
be patient operation with exchanger is taking too long time
please
How many time you need?
The exchanger told me that operation should be in the morning. Now here are 20:47
Take in mind, that after 35 hours your price will be doubled and this action cannot be undone.
we know. My mind now is about 23.3 BTC becouse operation is for that amount
If you don't pay tomorrow, i'll enable float rate again and don't fixed it anymore.
So, hurry up your exchanger.
Good morning! Any updates?
I had a meeting scheduled with exchanger at 1PM
i don't know why he 's taking time. We yesterday moved € to exchanger
Well, if anything, do not hesitate to write about the results
we need cryptocurrency to close the deal with you and my family will be happy becouse I have to work all weekend
I understand you, as far as I know in Europe there are bitcoin ATMs for a long time
never seen
[REDACTED URL]
We won't give you extra time, after 16 hours you price will be doubled, make payment faster.
Hi, i'm in call with exchanger
we had to wait for the transfer of the amount
technica time between bank
I have the document that prove that we are moving money
but we need more time
till monday
in the week end bank do not operate
Send the documents.
upload in progress
IMG_20201120_152201.jpg
5.4 MB
3 pages
IMG_20201120_152152.jpg
4.8 MB
last page
IMG_20201120_152145__02__01.jpg
5.06 MB
Ok, added time.
da you update the countdown on this page
?
Time ends on 23 Nov 2020, 09:51
in the morning is too eearly
the bank open in the morning
please set the deadline to 24 November 9 AM
so we are sure than on monday close the transaction
Refresh the page
Ok thanks
Hi, we are at work.
Hello! We, too, how is the exchange process going?
only the bank does not work on the week end
the decryption tool work per single file?
You will receive a master (universal) decryptor for your Linux and Windows network after payment
it runs recursively o per file?
the process works as when encrypting only in the opposite direction, we
will also send all instructions, and provide support until you decrypt
the all network
see you tomorrow
Ok! Have a nice day!
After 17 hours your price will be doubled and we won't change it.
i'm here
good morning
we are almost ready
i'm worried about decryption process
there are a lot of file on a lot of volume
Hello! the process of decryption is similar to the encryption process,
you do not need to worry, maximum 4-5 hours and your files will be
decrypted
on vmware do i need to execute decryption on one host esx that is
connected to all volume or do I have to execute on every single host?
You should upload decryptor to each esxi, set 777 permissions and
run. That's all you need, after small time your esxis will be ready for
work.
can we test the decryption process on one single vmdk file?
We will send decryptor after payment and help with all. Don't worry, it's too easy.
we are doing the first transaction
what description in the transaction?
we sent the first little amount in order to test the correct transaction
it is ok?
we can see your transaction
you can send all amount
ok
we proceed
and after 3 confirmation of bitcoin network we will send you decryptors and instruction
with the next trance
we sent half amount
please give us linux or windows decryptor now
we will send your decryptors only after you send us full amount.
we are waiting for next part
one moment
sent
ok, we can see your transaction
waiting for 3 confirmation and then send you decryptors
we are waiting for decryptor
Windows:
The decryptor works in 2 modes:
1. GUI
2. Console
Three functions are available in GUI mode:
1. "DECRYPT ALL" - search and decrypt ALL encrypted files on the local
PC and on network resources (Shares), where this PC has access.
2. "DECRYPT FOLDER" - decrypts files in the specified folder, which you
can select in the "Browse for folders" window or drag and drop the
folder into the decryptor window.
3. "DECRYPT ONE FILE" - decrypts a single file, which you can open in
the "Open" window or drag and drop the encrypted file into the decryptor
window.
IMPORTANT!
Extension of encrypted files may not coincide with the extension of files, which the decryptor suggests to open!
To open encrypted files with other extensions, in the "Open" window
select, in the lower right corner of "All Files (*. *)" or just drag and
drop the given file into the decryptor window.
File extension does not affect the decryption of file!
Console mode has two parameters:
1. "-all" - search and decrypt ALL encrypted files on the local PC and on network resources (Shares), where this PC has access.
You can also use Group Policy to quickly decrypt your entire network.
2. "-path" - decrypts files in the specified folder or a single file.
3. Dragging and dropping an encrypted file or folder with encrypted files onto the decryptor file.
In this mode, the console window will open automatically, which will display the decryption process.
Command line examples:
> decryptor.exe -all
> decryptor.exe -path C:\Folder
> decryptor.exe -path C:\Folder\file.txt.[redacted]
win_decryptor.exe
76.5 kB
linux decryptor works alsa per files?
also
linux decryptor decrypts all system, it cant decrypt certain files
may I ran on host that see all encrypted volume?
just run the decryptor on each esxi, that's all, you don't need to do anything anymore
after decryption you can use your vms as before that
we are at work
Linux decryption instruction:
1. Upload decryptor to esxi.
2. Set run permissions: chmod 777 decryptor
3. Run decryptor: ./decryptor
jump_decryptor.out
2.38 MB
Use this one decryptor for you esxi
what is the difference?
the decryptor did not decrypt some file
on esx
Try the last decryptor.
Which file was not decrypted? Give more information.
/vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted]-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V185E016/V185E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V157E016/V157E016_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V066E016 - [redacted]/V066E016 - [redacted]_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V079E016 - [redacted]/V079E016 - [redacted]-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V195E016/V195E016_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000REPP/V000REPP_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000PAS2/V000PAS2_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V060E016/V060E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000TS1P_2012/V000TS1P_2012-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V144E016/V144E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V189E016/V189E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V067E016/V067E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000AMQP/V000AMQP-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000AMMP/V000AMMP_3-flat.vmdk.darkside
/vmfs/volumes/[redacted]/[redacted] - ArcGis DataStore/[redacted] - ArcGis DataStore-flat.vmdk.darkside
have other files been decrypted? Are virtual machines working?
Use the last decryptor. He will decrypt them.
i will try the other decryptor becouse when i try to start [redacted] seems that a disk is missing
Try the last one and write to me.
[START #11] File
Path.........../vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside
[INFO] File Size................0mb (4096 Bytes)
[ERROR] File Too Small, Ignored
What is the size of this file? Problem with one file or multiple?
42
seems that some filese were modified and disk size of the VM was set to 0
so the VM does not start
what 42?
42 useful file was not decrypted
and how much was decrypted?
a lot
If the reason for the non-decryption is that there is 0 size, then I
cannot help you. The decryptor cannot decrypt what is not.
Check all file sizes and tell me them. When you tried to start virtual
machines, the hypervisor could damage the encrypted files.
I mean before you got the decryptor.
Are you having a problem with virtual machines on the same hypervisor? or at all?
we are having some problem
answer the questions so that I could understand what to tell you.
the probelm is on esx
Task name
Power On virtual machine
Target
WD_[redacted]
Status
File /vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted].vmdk was not found
Look through ssh. Do you have a file?
have a file of 4K with .darkside extension
we lost some vm
sigh!
The decryptor checks all checksums, it could not damage virtual
machines. This is the first time that a client talks about problems.
Did you check the sized before decryption?
How many virtual machines have you failed to recover? Were they on the same esxi?
You showed me a log in which the decryptor is trying to decrypt empty files. So the problem arose before decryption.
Why so, I can not answer you, there can be a lot of reasons.
If you have any other problems with decryption - I will help you, just give me not empty files.
the empty file has data of creation on 15Nov in the night
i don't know why
there is a format job runnin
I need your little but useful help. On veem the volume where we have
the backup , this morning was accessible but now the volume is RAW.
I don't quite understand what you mean
the tool that you used to encrypt our backup. At the end of encrypion does it do disprutive action?
No, it doesn't. If backups are on Windows - use the Windows decryptor.
Never interrupt the decryption process by closing the program
manually. The program may freeze during decryption, this is normal.
Hi.
we trusted in you
but we need some files that miss
We gave you decryptors and they work, if you have problems with them, I will help you.
Before buying decryptors, you saw that some files were empty and you could not pay.
We fulfilled our part of the deal, I don't know why you have empty files. You didn't even tell me how many there are.
// Analysis
Analyst Observations
- This is an unusually long negotiation, suggesting extended back-and-forth and significant engagement from both parties.
- DarkSide is best known for the Colonial Pipeline attack in May 2021. The group shut down shortly after due to law enforcement pressure.