// Context
About This Negotiation
This transcript documents a fog ransomware negotiation with a redacted victim organisation.
The negotiation consisted of 144 messages exchanged over Unknown.
The initial ransom demand was $200,000. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at
enquiries@binary-response.com — we will act promptly.
[Victim] — Monday, 29 July 2024 15:37:56 — Message 1/144
Hi
[fog] — Monday, 29 July 2024 15:40:39 — Message 2/144
hi
[fog] — Monday, 29 July 2024 15:41:22 — Message 3/144
I will give you details in a minute
[fog] — Monday, 29 July 2024 15:47:24 — Message 4/144
[provides a plain TXT files list]
this is what has been taken from your network
[Victim] — Monday, 29 July 2024 16:34:00 — Message 5/144
What are the instruction to restore our data?
[Victim] — Monday, 29 July 2024 17:21:31 — Message 6/144
Hi are you there?
[fog] — Monday, 29 July 2024 17:53:48 — Message 7/144
I will give you instructions after payment
[Victim] — Monday, 29 July 2024 18:11:40 — Message 8/144
What payment?
[fog] — Monday, 29 July 2024 18:15:24 — Message 9/144
If you want your data fully decrypted and the files we stole removed from our source, you will have to pay a fee. We will also be able to provide a security report and explain how we did it to get in. I will give you our demand soon.
[Victim] — Monday, 29 July 2024 19:59:48 — Message 10/144
Any news?
[fog] — Monday, 29 July 2024 20:07:44 — Message 11/144
If you need a proof we indeed possess your data, send me a couple of directories to the files you want to see. To test our tool, send me 3 random encrypted files and we will decrypt them for free. Our demand is $200,000.
[Victim] — Tuesday, 30 July 2024 09:53:26 — Message 12/144
Hello, we don't know how to make the payment or how to facilitate it for you. On the other hand, we are a very small company and cannot afford the payment you are mentioning. What options do we have? And about the three files what is the procedure?
[fog] — Tuesday, 30 July 2024 10:36:45 — Message 13/144
As for the files, if you need a proof we indeed possess your data, send me a couple of directories to the files you want to see. We can provide you with a $20,000 discount if you pay us this week. The price is fair for your company.
[Victim] — Tuesday, 30 July 2024 13:40:45 — Message 14/144
We are willing to cooperate, but the amount requested is far beyond our capabilities as a small company. We can offer a smaller sum and pay it as soon as possible. Additionally, we need to clearly understand the payment process and the guarantees we have to securely recover our data. Please provide detailed instructions on how to proceed and assure us that we will receive all our data without further issues
[fog] — Tuesday, 30 July 2024 14:16:50 — Message 15/144
I can't give you an additional discount until I see your number. The price can be increased at any second if you keep haggling like this.
[Victim] — Tuesday, 30 July 2024 14:20:59 — Message 16/144
What number do you mean?
[fog] — Tuesday, 30 July 2024 14:28:00 — Message 17/144
The number you are ready to pay at the moment.
[Victim] — Tuesday, 30 July 2024 14:59:21 — Message 18/144
We can offer $120,000 and want to be transparent, avoiding a prolonged negotiation. Additionally, we need to understand how to make the payment. We will provide several files for you to decrypt to verify your capabilities.
[fog] — Tuesday, 30 July 2024 15:16:50 — Message 19/144
$120,000 is not a bad offer but I can't accept this. I also want to avoid a prolonged negotiation, so our final price is $150,000. You have 2 days to gather the rest $30k and we will be done with it. I will give you our wallet for payment later.
[Victim] — Tuesday, 30 July 2024 16:03:24 — Message 20/144
We are agreeable to proceeding with the following conditions: First, we will provide several encrypted files for you to decrypt as proof of your decryption capabilities. Following this, we will make an initial payment of $120,000 in exchange for the instructions and necessary tools to decrypt the rest of our systems. Once we have successfully recovered our data, we will make a final payment of $30,000. In return, we expect a report detailing how the attack was carried out and confirmation that all our data has been removed from your possession and any related systems
[Victim] — Tuesday, 30 July 2024 16:04:57 — Message 21/144
[provides a zip archive of encrypted files]
[fog] — Tuesday, 30 July 2024 16:35:49 — Message 22/144
tell is there the file named "auth.log.fog.savepoint" somewhere near the file "auth.log.fog"?
[Victim] — Tuesday, 30 July 2024 17:04:09 — Message 23/144
We couldn't find the file you mentioned, could you tell us where this file should be located and what it contains?
[fog] — Tuesday, 30 July 2024 17:39:30 — Message 24/144
it should be in the same directory with the file auth.log.fog that your gave me
[Victim] — Tuesday, 30 July 2024 17:40:44 — Message 25/144
Isn't in this directory
[fog] — Admin 19:02:03 — Message 26/144
[provides 2 decrypted files]
I will give you everything right away when I received the full 150k payment. Let's resolve the issue quickly.
[fog] — Admin 19:03:52 — Message 27/144
[redacted] this is id for payment
[Victim] — Admin 19:09:35 — Message 28/144
We understand your position, but we must adhere to our agreed-upon model. We need to follow the steps we outlined previously: first providing a portion of the payment, receiving the necessary decryption instructions, and then completing the full payment upon confirmation. Additionally, specify which cryptocurrency it is for the payment.
[fog] — Admin 19:27:14 — Message 29/144
We work with bitcoins. We cannot violate our policy, which means we cannot accept fractional payments.
[Victim] — Admin 20:32:49 — Message 30/144
Once the payment is made, how does the decryption process work? What guarantees do we have that all our data will be fully recovered and secured? We also want to understand what you will provide to us after the payment. Please understand that we are concerned due to our lack of experience with situations like this and need reassurance that everything will be resolved properly.
[fog] — Admin 20:48:18 — Message 31/144
Once the payment is made, you will get the .exe files that you will need to run on your systems (win or esxi) to decrypt your files. We guarantee that you will be able to recover all the encrypted data. We will give you a deletion log file which means the files we stole .were removed from our source.
[Victim] — Admin 21:08:16 — Message 32/144
We need to finalize the financial and legal aspects on our end before proceeding with the payment. Once everything is ready and the payment is made, we will notify you immediately.
[fog] — Admin 21:14:23 — Message 33/144
Standing by, thanks.
[Victim] — Wednesday, 31 July 2024 08:08:12 — Message 34/144
We are currently reviewing the payment method, and since we are not familiar with this process, we are unsure how to proceed. Could you explain how this is typically done and which services are usually used? We want to ensure that everything is handled correctly.
[fog] — Wednesday, 31 July 2024 09:34:36 — Message 35/144
see the link [REDACTED URL]
[Victim] — Wednesday, 31 July 2024 09:54:27 — Message 36/144
Thanks ,we are checking, but the registration process and validation will take some time.
[fog] — Wednesday, 31 July 2024 10:38:24 — Message 37/144
sure
[fog] — Wednesday, 31 July 2024 14:10:07 — Message 38/144
How's your progress with that?
[Victim] — Wednesday, 31 July 2024 14:39:30 — Message 39/144
The cryptocurrency purchase platform needs to verify the user, and this won't be completed until tomorrow. The process is turning out to be quite long and complex for us.
[fog] — Wednesday, 31 July 2024 14:52:24 — Message 40/144
tell me when you have updates
[Victim] — Wednesday, 31 July 2024 15:21:43 — Message 41/144
Sure
[Victim] — Thursday, 01 August 2024 09:37:55 — Message 42/144
We have conducted an initial test to verify that the process we're following is correct. Could you confirm that you have received the first transfer of $5? Meanwhile, we are in the process of acquiring the total amount of cryptocurrency needed for the full payment, but it is taking some time.
[fog] — Thursday, 01 August 2024 10:00:09 — Message 43/144
I received 0.000082
[Victim] — Thursday, 01 August 2024 10:29:02 — Message 44/144
Okay, we are in the process of obtaining the full amount. Once we have it, we will proceed with the transfer.
[Victim] — Thursday, 01 August 2024 10:29:43 — Message 45/144
Once the payment is received, what are the next steps?
[fog] — Thursday, 01 August 2024 10:43:53 — Message 46/144
I will give you the decrypter after I see the money in the wallet
[fog] — Thursday, 01 August 2024 10:44:05 — Message 47/144
and instructions of course
[Victim] — Thursday, 01 August 2024 17:18:25 — Message 48/144
We are gathering the payment in the exchange, but we need to proceed gradually with the euro money transfers to the wallet. I believe we can have it ready in less than 48 hours. Maybe in 24 hours. I'll keep you informed.
[Victim] — Thursday, 01 August 2024 17:20:04 — Message 49/144
From the moment we make the payment transfer, how long will it take you to send me the decryptors for Windows files and virtual machines? Will you send them here, or should I give you an email?
[fog] — Thursday, 01 August 2024 19:20:05 — Message 50/144
I will send the decrypters via this chat after full sum received
[Victim] — Friday, 02 August 2024 12:29:16 — Message 51/144
Hi, I already have the funds available. I'm going to make a small test transfer from this wallet, and then the rest will be ok?
[fog] — Friday, 02 August 2024 12:43:01 — Message 52/144
Sure. But you have already sent a test amount of 0.000082 BTC. Anyway, you can send another one.
[Victim] — Friday, 02 August 2024 14:14:33 — Message 53/144
Please give me 3 hours and we will proceed. I write to you here. Thank you.
[fog] — Friday, 02 August 2024 14:36:49 — Message 54/144
Standing by.
[Victim] — Friday, 02 August 2024 15:48:05 — Message 55/144
Hi, we just did the test transfer. Please tell me everything is ok.
[Victim] — Friday, 02 August 2024 15:48:29 — Message 56/144
When you verify it we make the final large transfer.
[fog] — Friday, 02 August 2024 15:59:04 — Message 57/144
I see 0.003 confirming
[Victim] — Friday, 02 August 2024 15:59:37 — Message 58/144
ok Sr.
[Victim] — Friday, 02 August 2024 16:00:15 — Message 59/144
We proceed to make the payment. Can you confirm that I will have the decrypters instantly please?
[Victim] — Friday, 02 August 2024 16:18:32 — Message 60/144
You're online?
[fog] — Friday, 02 August 2024 16:19:23 — Message 61/144
I can confirm
[Victim] — Friday, 02 August 2024 16:19:47 — Message 62/144
ok, thanks. wait a minute please
[fog] — Friday, 02 August 2024 16:20:01 — Message 63/144
ok
[Victim] — Friday, 02 August 2024 16:21:36 — Message 64/144
we are working on it, give me just 2 minutes. please prepare the decrypters to send me.
[fog] — Friday, 02 August 2024 16:22:13 — Message 65/144
preparing
[Victim] — Friday, 02 August 2024 16:26:27 — Message 66/144
it's OK.
[Victim] — Friday, 02 August 2024 16:26:34 — Message 67/144
Transfer OK.
[Victim] — Friday, 02 August 2024 16:29:42 — Message 68/144
It has arrived, can you confirm it for me?
[fog] — Friday, 02 August 2024 16:30:49 — Message 69/144
confirming
[Victim] — Friday, 02 August 2024 16:30:57 — Message 70/144
Thanks!
[fog] — Friday, 02 August 2024 16:31:01 — Message 71/144
give me a minute
[Victim] — Friday, 02 August 2024 16:31:15 — Message 72/144
ok, sr.
[fog] — Friday, 02 August 2024 16:44:47 — Message 73/144
Esxi
chmod +x unlocker
./unlocker --id [redacted] --log --target "/vmfs/volumes/"
Windows
unlocker.exe -nomutex -console -target \\SERVER\C$
unlocker.exe -nomutex -console -target C:\
[fog] — Friday, 02 August 2024 16:45:06 — Message 74/144
[provides a zip file with the decryptor]
[Victim] — Friday, 02 August 2024 16:48:51 — Message 75/144
OK, we'll try it out and I'll write to you if there are any questions or problems. Thanks.
[fog] — Friday, 02 August 2024 17:14:35 — Message 76/144
ok I am here
[Victim] — Admin 18:45:50 — Message 77/144
[provides a PNG file]
It gives us an error with the ESXI, I attach an image
[Victim] — Admin 19:03:42 — Message 78/144
maybe too many files on the machine?
[fog] — Admin 19:14:23 — Message 79/144
specify one vm in directory of decrypter
[Victim] — Admin 23:08:27 — Message 80/144
we are having some problems. I leave you screenshots:[provides 2 PNG files]
[Victim] — Admin 23:11:35 — Message 81/144
I am attaching the files that we cannot decrypt. Let's see if you can help us since they are very important to be able to operate:[provides 3 TXT files]
[Victim] — Admin 23:13:47 — Message 82/144
We have carried out the test of specifying a machine instead of a folder and it does not give an error, but it does not decrypt either.
[Victim] — Admin 23:14:03 — Message 83/144
It is a very serious problem for us. Please, help.
[Victim] — Saturday, 03 August 2024 06:42:29 — Message 84/144
For example, these files are impossible to decrypt (and they are small):[provides 8 .FOG files]
[fog] — Saturday, 03 August 2024 08:12:52 — Message 85/144
my team is working on it
[fog] — Saturday, 03 August 2024 09:05:55 — Message 86/144
how many vms did you already fix and run?
[Victim] — Saturday, 03 August 2024 10:08:09 — Message 87/144
We are very concerned because those machines are the SAP and two other environments we use to operate the business. Without these environments, we cannot function. Let me tell you which machines they are:
[Victim] — Saturday, 03 August 2024 10:08:36 — Message 88/144
1 - [redacted]-flat.vmdk
1 - [redacted].vmdk
0 - [redacted]-flat.vmdk
0 - [redacted]-flat.vmdk
[redacted]-flat.vmdk
[redacted]-flat.vmdk
0 - [redacted]-flat.vmdk
0 - [redacted].vmdk
[redacted]-flat.vmdk
[redacted]-ctk.vmdk
[Victim] — Saturday, 03 August 2024 10:08:57 — Message 89/144
And swap files:
vmx-[redacted].vswp
vmx-0 - [redacted].vswp
vmx-[redacted].vswp
vmx-[redacted].vswp
[redacted].vswp
[Victim] — Saturday, 03 August 2024 10:09:22 — Message 90/144
And .vmsd file:
0 - [redacted].vmsd
[Victim] — Saturday, 03 August 2024 10:10:06 — Message 91/144
And also many other files in .log format that are secondary and not needed to start the machines.
[Victim] — Saturday, 03 August 2024 10:10:45 — Message 92/144
How can we solve this? Do you need me to share more files that we cannot decrypt?
[Victim] — Saturday, 03 August 2024 10:11:10 — Message 93/144
I have shared some small files above that cannot be decrypted.
[Victim] — Saturday, 03 August 2024 10:12:03 — Message 94/144
All the files we cannot decrypt are these (I already listed them above, but here they are again for your reference):
[Victim] — Saturday, 03 August 2024 10:14:42 — Message 95/144
This is very urgent because we cannot operate the business without it. We have tried everything possible. We have tried decrypting locally, on other machines, specifying directory paths, and the final paths of the machines.
[fog] — Saturday, 03 August 2024 10:51:40 — Message 96/144
there are some options for solving this
[fog] — Saturday, 03 August 2024 10:52:59 — Message 97/144
start decryption of the following folders using --threads 16
/vmfs/volumes/[redacted]/
/vmfs/volumes/[redacted]/
/vmfs/volumes/[redacted]/
/vmfs/volumes/[redacted]/
/vmfs/volumes/[redacted]/
[fog] — Saturday, 03 August 2024 11:02:31 — Message 98/144
when you have 'error open file' try to recheck permissions of a file copying it to another folder because permissions could change. use the command ls -la. Example: -rw-r--r-- 1 root root 8024 Aug
Decrypter should be run as host
file permissions -rw
If host and permission don't match, then change host using 'chown' or change permissions using 'chmod'
[fog] — Saturday, 03 August 2024 11:03:33 — Message 99/144
Or another options is to try replace a file to another folder an run decrypter to decrypt exactly this one file
[Victim] — Saturday, 03 August 2024 11:06:17 — Message 100/144
ok let's try it.
[Victim] — Saturday, 03 August 2024 11:26:12 — Message 101/144
Using -- threads 16 and other parameters that we have tried does not work, I attach an image:[provides a PNG file]
[Victim] — Saturday, 03 August 2024 11:26:43 — Message 102/144
Let's test the permissions issue of the second option. However, we run it as root.
[Victim] — Saturday, 03 August 2024 11:27:03 — Message 103/144
We tried the third option yesterday and this morning and it doesn't work for us.
[Victim] — Saturday, 03 August 2024 11:27:14 — Message 104/144
Now I'll tell you about the issue of permissions.
[Victim] — Saturday, 03 August 2024 12:21:04 — Message 105/144
None of the options work.
[Victim] — Saturday, 03 August 2024 12:21:33 — Message 106/144
Without these files we cannot operate, they are the core of the organization.
[Victim] — Saturday, 03 August 2024 12:22:30 — Message 107/144
Do you want me to upload virtual machines to the cloud, or give you access to a system?
[Victim] — Saturday, 03 August 2024 12:22:46 — Message 108/144
please help
[fog] — Saturday, 03 August 2024 13:10:04 — Message 109/144
my team is working on the trouble
[fog] — Saturday, 03 August 2024 13:52:08 — Message 110/144
Upload to the cloud we will fix the file
[Victim] — Saturday, 03 August 2024 13:58:04 — Message 111/144
OK sr. Thanks!!!![provides a .vswp.fog file]
[Victim] — Saturday, 03 August 2024 17:52:52 — Message 112/144
I'm sending you this small file so that your team can analyze why the decrypter doesn't decrypt. We followed all your instructions. Let's see if you can try it in your environment. It's 83Mb of file so you don't have to pass anything bigger that is difficult to handle.
[Victim] — Saturday, 03 August 2024 18:19:43 — Message 113/144
[provides a JPG file]
In this image more information with the permissions:[provides another JPG file]
[fog] — Saturday, 03 August 2024 18:43:48 — Message 114/144
ok
[fog] — Saturday, 03 August 2024 18:43:53 — Message 115/144
wait
[Victim] — Saturday, 03 August 2024 18:45:15 — Message 116/144
Thanks!!!!
[fog] — Saturday, 03 August 2024 18:59:50 — Message 117/144
I will have news for you most likely on Sunday
[Victim] — Saturday, 03 August 2024 19:08:42 — Message 118/144
OK, thank you very much for your attention. We will be waiting for your news.
[fog] — Saturday, 03 August 2024 22:02:43 — Message 119/144
send me vmdk or vmdk-flat file
[Victim] — Saturday, 03 August 2024 22:15:08 — Message 120/144
In a few hours you will have the files in a repository. Does that seem okay to you? This way we will not be able to share so many gigabytes. Thank you very much, without these virtual machines our entire company cannot work. It is the core of the business.
[Victim] — Saturday, 03 August 2024 22:15:21 — Message 121/144
Thank you very much
[Victim] — Sunday, 04 August 2024 11:30:20 — Message 122/144
We almost have a machine uploaded to the cloud to share the link with you. We have uploaded a "small" 1.2Gb file of those that also cause problems and are on critical routes for us:
[Victim] — Sunday, 04 August 2024 11:30:27 — Message 123/144
[REDACTED URL]
[Victim] — Sunday, 04 August 2024 11:30:56 — Message 124/144
Give me a few minutes and I'll send you the link for the vdmk machine
[Victim] — Sunday, 04 August 2024 11:31:36 — Message 125/144
Thank you for your help. Without these operational vdmk machines our company would go bankrupt.
[Victim] — Sunday, 04 August 2024 11:38:18 — Message 126/144
We have the vdmk uploaded to the cloud. I am sending you credentials:
[Victim] — Sunday, 04 August 2024 11:38:36 — Message 127/144
sftp://[redacted].vmdk.fog
[Victim] — Sunday, 04 August 2024 11:38:54 — Message 128/144
Password: [redacted]
[Victim] — Sunday, 04 August 2024 11:39:49 — Message 129/144
We are waiting for your news. With these files and the 83Mb one I sent you earlier that is also causing problems, I think your programmers could see what is wrong with the decrypter.
[Victim] — Sunday, 04 August 2024 11:40:24 — Message 130/144
We are very concerned because all the critical files of vmdk virtual machines are in this situation. (8 machines)
[fog] — Sunday, 04 August 2024 13:08:02 — Message 131/144
got it
[fog] — Sunday, 04 August 2024 13:08:43 — Message 132/144
I wait for something from my team
[Victim] — Sunday, 04 August 2024 13:37:47 — Message 133/144
Thanks
[Victim] — Sunday, 04 August 2024 17:34:18 — Message 134/144
Hi, sorry to bother you. I wanted to know if we'll receive any updates today on how to resolve the file decryption issues. We are overwhelmed as we cannot decrypt files like the ones I mentioned in the conversation. Thank you, sorry for the insistence.
[Victim] — Sunday, 04 August 2024 17:36:02 — Message 135/144
Please, if you don't help us, our company will close, and we will lose our jobs.
[fog] — Sunday, 04 August 2024 17:56:36 — Message 136/144
we will help
[fog] — Sunday, 04 August 2024 17:56:43 — Message 137/144
wait
[Victim] — Sunday, 04 August 2024 18:03:19 — Message 138/144
Thanks!!!!
[Victim] — Sunday, 04 August 2024 22:29:58 — Message 139/144
Can we turn off the SFTP machine where we have uploaded the .vmdk file?
[Victim] — Sunday, 04 August 2024 22:30:35 — Message 140/144
We can leave it active if necessary.
[fog] — Monday, 05 August 2024 06:33:17 — Message 141/144
let it be active for some time
[Victim] — Monday, 05 August 2024 06:42:52 — Message 142/144
Ok thanks
[fog] — Monday, 05 August 2024 11:25:13 — Message 143/144
try to copy a vmdk file to a separate folder and run it after removing extension .fog
[Victim] — Monday, 05 August 2024 12:55:22 — Message 144/144
OK,wait a moment.