lockbit3.0 Ransomware Negotiation — Redacted Organisation

55Messages
4 daysDuration
$80,000Initial Demand
UnknownOutcome

About This Negotiation

This transcript documents a lockbit3.0 ransomware negotiation with a redacted victim organisation. The negotiation consisted of 55 messages exchanged over 4 days, beginning on 2024-12-23.

The initial ransom demand was $80,000. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[lockbit3.0] — 2024-12-23 10:56:21 — Message 1/55
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat.\r\n\r\nIf your archive weighs more than 10 megabytes, please use our file sharing service.\r\n[REDACTED URL] security reasons we do not click on other links you send in chat.\r\nPlease wait for a reply, sometimes it takes several hours due to possible time zone differences.
[Victim] — 2024-12-23 10:57:33 — Message 2/55
hello sir, can you help me what you need to decrypt my files?
[Victim] — 2024-12-23 10:58:55 — Message 3/55
[redacted].pdf.usKv553SJ this is a sample file
[lockbit3.0] — 2024-12-23 11:31:23 — Message 4/55
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat.\n\nIf your archive weighs more than 10 megabytes, please use our file sharing service.\n[REDACTED URL]
[Victim] — 2024-12-23 12:28:50 — Message 5/55
[Victim] — 2024-12-23 13:10:53 — Message 6/55
could you please how much it will cost to recover my files because we need to know the costs involved.
[lockbit3.0] — 2024-12-23 14:50:20 — Message 7/55
wait, tech support will send your test files
[lockbit3.0] — 2024-12-23 14:51:56 — Message 8/55
price decrypt 80k in bitcoin, for all hosts and files
[Victim] — 2024-12-23 15:47:11 — Message 9/55
sir this amount is very high to be paid. We would like to work with you because it will take much time to recover our infrastructure. So some questions from our side \n1. Can you please provide a generous discount so it\'s easier for us to consider your solution?\n2. How fast the recovery process will take if we work with you ?
[lockbit3.0] — 2024-12-23 16:08:06 — Message 10/55
we can\'t offer you a discount
[lockbit3.0] — 2024-12-23 16:12:12 — Message 11/55
if you pay quickly and restore the infostructure on the same day
[lockbit3.0] — 2024-12-23 16:14:28 — Message 12/55
I saw your financial report, our price is not big for you
[lockbit3.0] — 2024-12-23 16:16:24 — Message 13/55
[Victim] — 2024-12-23 16:38:16 — Message 14/55
Thank you for the file.\nIt\'s been a very hard year for our company, also as you know we are in Greece and since 2010 it\'s been very tough times for businesses. And the end of the year is always very hard financially with cashflows.\n\nThat\'s why i am asking for your understanding in price, so I can make an easier decision for my manager to decide.\nPlease if you can convince your own management to consider a generous discount it will help us in our decision with positive result. \nFrom our side we want our files faster and without loses than the options we have now. \nIt seems that you can provide this service from the proof you sent.\nIt would be nice if we can find an agreement on a price we can pay so we can pay you.\nRight now the amount you said is far beyond our real financial capability so we cannot consider this an option.
[lockbit3.0] — 2024-12-23 16:46:36 — Message 15/55
ok, we can do a 20% discount
[Victim] — 2024-12-23 17:14:17 — Message 16/55
First of all thank you for your understanding and the discount you provided. \nI appreciate your help on this. \nBut still we are very far away from what we can really pay. \nStill the amount you mentioned after the discount is very hard to find in cash.\nWe need to take some serious IT decisions tomorrow as most consultants advised us to format and start from latest offline files which will take several days.\nSo please if you can give us a more grounded financial proposal do so since the purpose here is to see if we can use your services.
[lockbit3.0] — 2024-12-23 17:19:57 — Message 17/55
I don\'t care whether you pay me or not, there will be no more talk about discounts
[lockbit3.0] — 2024-12-23 17:25:20 — Message 18/55
If you don\'t make a decision, the price will be 2x tomorrow.
[Victim] — 2024-12-23 17:29:26 — Message 19/55
Please don\'t misunderstand the interest to find a way to pay you with insult. This was not my point. I respect you are talking with us right now and understanding our side. I just want to make it work for our company based on our limitations in cashflow in the end of the year. I know that you don\'t care about us. You attacked us after all. I understand that it\'s just business for you. Some pay, some don\'t. We want us to both benefit from this incident. We gain knowledge and you gain money. But we wanted to get an amount that we can be able to pay you realistically. We are not here to play either. Unfortunately if your purpose is to raise the price there is no point of discussing any more. Even if we find the correct amount we can pay, we will need at least 7 working days to pay you. Regulations are hard with this kind of transactions.
[lockbit3.0] — 2024-12-23 17:35:39 — Message 20/55
the price will be 60k your decision to pay or not.
[Victim] — 2024-12-23 17:56:21 — Message 21/55
Is there a way to recover 2-3 computers with 15k and get a partial service from your side? So we can see the quality of your service that is valid and then during next year purchase some more bundle of computers? I am just exploring options here to help our operations based on our cashflows.
[lockbit3.0] — 2024-12-23 17:58:44 — Message 22/55
no, the decryptor will be available for all your files with the extension
[Victim] — 2024-12-24 16:32:59 — Message 23/55
Hello sir, could you please accept the price of 30000$ before the end of the year so we can catch up with the processes to pay you in full for the full service you provide? It will take a lot of effort for us to return to normality so we can see this as a successful penetration test from your team and justify the expenses we need to pay to your work. Mention we need some days to manage to pay this huge amount of money so we need your understanding on this.
[lockbit3.0] — 2024-12-24 18:04:24 — Message 24/55
you can pay 50k, but the offer will be available for a some days\nif you can\'t pay on the weekend, I\'ll refund price.
[Victim] — 2024-12-24 21:03:25 — Message 25/55
Please stay with me on this. Even if we find a way to work together, the amount is too big to find it these days. Last two years it\'s been very hard for us and it\'s the end of the year. We are trying to find whatever resources are available in cash and let you know. In the following two days we will have a better picture on our financials. We need at least 6-7 days to find 30k, we will need more to get more money to you. There is very limited cashflow in the end of the year which makes things very hard. Let me see what we can do and get back to you. I will try my best, because we want this to finish soon. There is big spending in the end of the year and limited cash receivable. Need more time to see what we can do for you.
[Victim] — 2024-12-27 10:16:45 — Message 26/55
hello sir, can you please let us know how we can do the payment?
[lockbit3.0] — 2024-12-27 12:54:26 — Message 27/55
hello, btc wallet: [redacted]
[Victim] — 2024-12-27 13:08:42 — Message 28/55
We managed to gather this amount you requested. It\'s been very hard. \n\nPlease let us know if you accept the following.\nWhen we pay 50.000$ USD to this wallet [redacted] you will keep your promise to:\n1. Give us a tool to decrypt all our files in ESXi and all computers affected and we will decrypt today\n2. Provide technical support from your side in case something doesn\'t work\n3. Promise you will never attack us in the future\n4. Help us understand how we can prevent such incidents again in the future and explain how you managed to get in our infrastructure along with technical details.\n\nWhen we have your replies and confirmation for the above we proceed in the payment.
[lockbit3.0] — 2024-12-27 13:18:22 — Message 29/55
1. there will be no problems with the decryptor,for esxi and all windows files\n2. you will need to disable your av and just run the .exe decryptor\n3. it could be someone else\n4. you know your pass P@ssw0rd
[Victim] — 2024-12-27 13:20:28 — Message 30/55
if we pay in the next hour when we will get decryptor?
[lockbit3.0] — 2024-12-27 13:24:37 — Message 31/55
i make a request to tech support, it can take from an hour to five hours
[Victim] — 2024-12-27 13:26:16 — Message 32/55
shall we sent 10$ just you to confirm and then send the rest 49990 ?
[lockbit3.0] — 2024-12-27 13:27:13 — Message 33/55
ok
[Victim] — 2024-12-27 13:31:24 — Message 34/55
[REDACTED URL] can you confirm you received this ?
[lockbit3.0] — 2024-12-27 13:34:48 — Message 35/55
yes 0.00010389
[Victim] — 2024-12-27 14:12:01 — Message 36/55
bitcoin seller sais you got the money. Please confirm\n[REDACTED URL]
[lockbit3.0] — 2024-12-27 14:19:47 — Message 37/55
is ok, thank you
[lockbit3.0] — 2024-12-27 14:24:03 — Message 38/55
wait pls, tech support will drop decryptor here
[Victim] — 2024-12-27 14:24:15 — Message 39/55
ok
[lockbit3.0] — 2024-12-27 14:27:31 — Message 40/55
[Victim] — 2024-12-27 14:32:37 — Message 41/55
this is not decryptor
[lockbit3.0] — 2024-12-27 14:37:36 — Message 42/55
yes, decryptor we wait
[lockbit3.0] — 2024-12-27 15:49:34 — Message 43/55
[Victim] — 2024-12-27 15:55:19 — Message 44/55
What about esxi ?
[lockbit3.0] — 2024-12-27 15:55:52 — Message 45/55
Give me readme file from esxi
[Victim] — 2024-12-27 15:57:26 — Message 46/55
ok give me 5 minutes
[Victim] — 2024-12-27 16:18:02 — Message 47/55
[Victim] — 2024-12-27 16:30:50 — Message 48/55
the VMDK files cannot be decrypter with the .exe decryptor. could you please send decryptor for VMDK in ESxi based on the txt file i sent you 15 minutes ago ?
[lockbit3.0] — 2024-12-27 16:31:33 — Message 49/55
yes
[lockbit3.0] — 2024-12-27 16:31:38 — Message 50/55
wait 5 minutes
[lockbit3.0] — 2024-12-27 16:36:55 — Message 51/55
[Victim] — 2024-12-27 16:40:14 — Message 52/55
is there a way to decrypt VMDK files on windows? i have a copy of them and the windows decryptor doesn\'t work with them
[lockbit3.0] — 2024-12-27 16:40:31 — Message 53/55
only linux
[Victim] — 2024-12-27 16:42:05 — Message 54/55
please provide command line instructions to run linux
[Victim] — 2024-12-27 16:55:40 — Message 55/55
1. Could you please tell me which commands to run on ESXi step by step in order to decrypt all files?\n2. Is there a chance that something goes wrong when i execute this decrypt_ESXI_X64 command on ESXi? Do i lose all the VMDK files in the server?

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.