// Context
About This Negotiation
This transcript documents a REvil ransomware negotiation with a redacted victim organisation.
The negotiation consisted of 63 messages exchanged over Unknown.
The initial ransom demand was $6,000. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at
enquiries@binary-response.com — we will act promptly.
[Victim] — 17 days ago — Message 1/63
Hello - what do we do to get our data back?
[Victim] — 17 days ago — Message 2/63
test files
[REvil] — 17 days ago — Message 3/63
Hello
[REvil] — 17 days ago — Message 4/63
You need to make a payment and you will get a universal decryptor for your entire network.
[REvil] — 17 days ago — Message 5/63
File 1
[REvil] — 17 days ago — Message 6/63
To decrypt the second file, I need a note with the id "readme-[redacted].txt". Send it to me in this chat.
[REvil] — 17 days ago — Message 7/63
After payment, the system will generate and give you a universal decryptor that will work on any device in your network.
[REvil] — 17 days ago — Message 8/63
In this case, this incident will not be advertised in the media and, if
necessary, in this chat you can always get technical support in case of
problems.
[REvil] — 17 days ago — Message 9/63
Correction, file with id "readme-[redacted].txt" is required.
[Victim] — 17 days ago — Message 10/63
this readme?
[Victim] — 17 days ago — Message 11/63
a few things. this is weekend and everything is closed until tuesday.
we cannot even begin to figure out the process but there is no one to
speak to, I see deadline of 3 days, please increase to 7-10 days to give
us enough time to process this situation.
[Victim] — 17 days ago — Message 12/63
can you do discount on the amount you are asking? we are in the
Caribbean and financial systems are partially disabled due to covid.
[REvil] — 17 days ago — Message 13/63
File 2
[REvil] — 17 days ago — Message 14/63
I will set the timer for you until October 14, in my opinion this is
enough to make a decision. As for the discount, I might be able to
convince the boss to give it to you, but you ask for many extra days.
[REvil] — 17 days ago — Message 15/63
Everything is up to you, quick payment in a short period of time, implies a good relationship and conditions of redemption.
[REvil] — 17 days ago — Message 16/63
Prolonging the process only aggravates the problem.
[REvil] — 17 days ago — Message 17/63
Time added, refresh the page.
[Victim] — 17 days ago — Message 18/63
can you accept btc? every broker we spoke to said it will take a long
time for this amount of XMR. That is why we need time to find the right
broker who can supply xmr.
[Victim] — 17 days ago — Message 19/63
its the weekend and banking holiday
[REvil] — 17 days ago — Message 20/63
I have included the possibility of payment in BTC, refresh the page.
[Victim] — 15 days ago — Message 21/63
can you decrypt test from another office?
[Victim] — 15 days ago — Message 22/63
also --- can you provide list of what data you take? or some sample? when I speak to management it will help explain.
[REvil] — 15 days ago — Message 23/63
Here is:
[REvil] — 15 days ago — Message 24/63
Ok, we will provide you the list and any details after payment, no problem
[Victim] — 15 days ago — Message 25/63
+ I am the IT manager and I do not make decision about money, but I
would like to close this soon as possible, can you provide a list of
files or something to prove my boss that its not only decrypt?
[REvil] — 15 days ago — Message 26/63
What exactly do you want to see?
[REvil] — 15 days ago — Message 27/63
Stolen [redacted] data are published in the blog in case of payment refusal or you receive a link to the files after payment.
[REvil] — 15 days ago — Message 28/63
You can show your boss the instructive stories of other companies that refused to pay the ransom.
[REvil] — 15 days ago — Message 29/63
[REDACTED URL]
[Victim] — 15 days ago — Message 30/63
+ yes I show him this. But my company is in carribean there is no
privacy law, so easier to prove to boss what listing of the files you
take to convince. The decryptor is of secondary value to us.
[Victim] — 15 days ago — Message 31/63
I want to solve this fast too, because I did not see family for few
days now. So anything you can do to help me when talking to boss will be
much help.
[REvil] — 15 days ago — Message 32/63
What proof do you need? We got access to your network, encrypted the
data there and downloaded it, I see no point in this question, we always
do this, these are our methods, did you see our blog? You have two
options to get the files: after payment or publicly on the blog.
[Victim] — 15 days ago — Message 33/63
looking for some sort of a file list if you have of our files. because
otherwise the boss is waiting for IT to finish investigation and this
will take long time. I want to do this faster. Can you send a list of
the files?
[REvil] — 15 days ago — Message 34/63
You forget that in addition to not being covered by the privacy law,
your company is exposed to the disclosure of your internal information
to the whole world, plus you incur reputational losses. Which client
will want to become a premium card holder if the companie which do not
care about their data safety?
[REvil] — 15 days ago — Message 35/63
You asked for more days to raise funds, you got this opportunity. If
you now want to communicate with us in an ultimatum form, then be
prepared to get the same effect from us and complicate an already
difficult stage of negotiations.
[REvil] — 15 days ago — Message 36/63
Now print out the whole dialogue and bring it to your boss. We can go
back to the previous timer, after which the amount will be doubled and
there will be no discounts. There is no one here who is going to play
games with you, or we make a deal and you get a decryptor + link to your
files. Or just close the dialog and do not waste your time.
[Victim] — 15 days ago — Message 37/63
I do not know if you have problem communicating in English or whether I
am speaking to an operator with bad temper but your response is not
smart business. Do not threaten us again, because if you make more money
publishing information, then good for you. Otherwise, you are taking a
possible client who is willing to pay and basically start throwing a
tantrum like a child. I would like to speak to an adult please who can
understand business and knows why I am asking for what I am asking.
[Victim] — 15 days ago — Message 38/63
Now, let me repeat. I am trying very hard to work with you and you need
to understand that we understand perfectly what position you are in,
and what position WE ARE IN. I also check your reputation and you guys
always deliver on your promise which is great and it is a strong basis
for a good business transaction.
[Victim] — 15 days ago — Message 39/63
Here is what I need to move this forward, it is a very simple ask. We
need a sample of the data you take and a file list of the files you
take. It is not difficult and it is our files anyways, so what is the
difficulty? All this will do is prove that you are indeed in a position
of power, and I will be able to convince my boss that we need to speak
about payment. I am TRYING TO HELP YOU AND ME. So work with me, or ask
your boss to put someone else to work with me. And I also ask that you
stop threatening me, your team already do the damage, so now we can
speak and reach agreement or you can play games of threats and verbal
abuse. Let's pretend we are adults ok?
[REvil] — 15 days ago — Message 40/63
My reaction is the result of your work. I don't see before me people
who value their business, I see attempts to study the possibility of
mitigation of the attack. We really keep our promises, there is no need
to doubt it. We give the decryptor, we give references to the stolen
files, we publish the files in case of a deal failure. And now we can
imagine that we are adults and can discuss the deal.
[REvil] — 15 days ago — Message 41/63
Understand one thing and bring it to your boss, decryptor and
confidentiality is need not for us, but for you. Do not scare us without
paying, there are dozens of you, it is better to concentrate on your
problem.
[REvil] — 15 days ago — Message 42/63
If my boss intervenes in this dialog, then it will not be
communication, but two words and a timer per day, you are still lucky to
deal with me, because I have time to answer you.
[REvil] — 15 days ago — Message 43/63
I am not going to enter into long correspondence and polemics anymore.
You know the terms and conditions and they will remain unchanged.
[REvil] — 15 days ago — Message 44/63
1. We fix the amount of the transaction after the final value is approved.
2. You pay the ransom in moneon or bitcoin.
3. After payment you get a universal decryptor for all infected computers.
4. You get a set of links that contain your files.
5. After downloading your files are deleted from our servers without the possibility of recovery.
6. No one but us will know about this incident.
[REvil] — 15 days ago — Message 45/63
You can read about Travalex, a very instructive story. They had the
opportunity to prevent it, as a result, this error became inexcusably
expensive for them.
[Victim] — 15 days ago — Message 46/63
I read about you in media and bleeping computer. I have no doubt you
will follow through and while my boss will make the business decision, I
am trying to follow his instructions and work with you. I am asking you
to work with me and give me what my boss is asking for. Let me further
explain, our systems are almost back-up, but I am trying to reach common
ground. Can you share the list of files you take? My boss does not care
about publicity, but he does care about protecting people, if you can
demonstrate what data you take, even just file list, it will go a long
way in the discussion here. I am not trying to waste your time or mine,
this will help no one. I know you are big group and you attack many
companies and that we are just a number. I also understand you have the
power. I am trying to be honest and explain to you what will help me
here, this is the process I need to follow. So the question is whether
it is possible for you to give me list of files or no. If no, I will
tell my boss and we can figure out next steps. But let’s try to work
together.
[REvil] — 15 days ago — Message 47/63
At this stage of negotiations - my answer is no. The situation may
change if we find a compromise and reach an agreement. I do the same as
you and follow the instructions of my boss. Tonight he will get
acquainted with the dialogue and if there are new instructions, you will
learn about it.
[REvil] — 15 days ago — Message 48/63
And I work with you, at your request was given +4 days, as well as
enabled mode of bitcoins to accelerate the process of receiving funds.
This is done first of all for you so that you can recover your systems
faster and get back to work.
[Victim] — 13 days ago — Message 49/63
At this stage of negotiations - we cannot proceed unless you provide us
with the list of files and 2-3 random sample files you took. If you
break negotiations at this point, you are going to publish the data
anyways, so there is zero difference between giving us the information
or publishing. The only key difference is that if you publish instead of
giving us the information we need, there will be zero chance of further
negotiations. I hope your boss reconsiders his position so that we can
finally move forward.
[REvil] — 13 days ago — Message 50/63
Ok, but in return I reduce the timer for decision making.
[REvil] — 13 days ago — Message 51/63
[REDACTED URL]
[REvil] — 13 days ago — Message 52/63
This link is not yet visible to anyone except you.
[Victim] — 13 days ago — Message 53/63
First, thank you for finally providing this information which will
allow me to work with the boss. Second, I will certainly push to make a
decision as fast as possible. HOWEVER - reducing the timer will not
work. Actually because you delay the analysis for no real reason we will
need more time. Given the amount it will not happen before Friday. You
can try and push and you are doing a great job of that, but in a company
that needs to follow process, it will not work and all you will do is
end up losing this opportunity to close the issue for both side. Please
increase the timer as we are asking. I am trying to work with you.
[REvil] — 13 days ago — Message 54/63
We gave you enough time to make a decision. If your boss doesn't want
to pay $6kk but wants to get off with a smaller amount, let him hurry.
[Victim] — 13 days ago — Message 55/63
We can argue together and you can argue you gave us enough time. In a
company that is publicly listed, 3 days is not enough time. So let's
stop with the games here, we are trying to work with you and I have no
interest to play games, I tell you what I need not because I feel like
it for fun and giggles. It is also not my money, so all threats mean
nothing. I am speaking to you because of genuine interest to solve the
problem and make sure we conclude this successfully. If you run the
timer and publish the conversation is over. I know you do not care
either but I am sure we are both interested in getting this to
successfully conclude. You took the first step in showing me what I
needed, now do whatever you need, but I am telling you that your new
deadline is not going to happen. Your call how we do this.
[REvil] — 13 days ago — Message 56/63
Companies that are traded on stock exchanges, solve the problem in 12
hours, I say this because I know. I see that your actions are only aimed
at delaying the solution of this incident.
[REvil] — 13 days ago — Message 57/63
4 days ago you have asked for additional time to buy XMR, at now you
write like you only now start consider payment process. Who play games?
You already had plenty of time to make a decision and consider different
options. Now your task is to go to the boss and come to me with the
answer. The timer will not be moved until I get information about the
deal.
[Victim] — 13 days ago — Message 58/63
You decision, your rules. I will pass on your message certainly.
[Victim] — 13 days ago — Message 59/63
and just so you know... Carribean rules because of USD embargo during
Covid, Maybe do some research on this. Either way, you are not changing
your position, I understand. Please understand that when timer expires
if you publish this conversation is over and second, there will not even
be a negotiation on price until the boss does his analysis. Thank you
and have a wonderful day.
[REvil] — 13 days ago — Message 60/63
Think not about the fact that we will not make a profit, think about
the problems that will arise after publication. Have a good day, too.
[Victim] — 13 days ago — Message 61/63
Understood. It is a 2-way street my friend. We either try to work
together or you already decide to publish etc. That is why I asked for
the data so that I can prove to the boss that it is a serious situation.
But it took you time, now I need the time to work on the boss.
[REvil] — 13 days ago — Message 62/63
I do not need to be persuaded, go to the boss and come back with an answer, you have little time left.
[REvil] — 13 days ago — Message 63/63
You will have another day after the publication sees the world. For now there will be no link to downloads.