REvil Ransomware Negotiation — Redacted Organisation

63Messages
UnknownDuration
$6,000Initial Demand
UnknownOutcome

About This Negotiation

This transcript documents a REvil ransomware negotiation with a redacted victim organisation. The negotiation consisted of 63 messages exchanged over Unknown.

The initial ransom demand was $6,000. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Victim] — 17 days ago — Message 1/63
Hello - what do we do to get our data back?
[Victim] — 17 days ago — Message 2/63
test files
[REvil] — 17 days ago — Message 3/63
Hello
[REvil] — 17 days ago — Message 4/63
You need to make a payment and you will get a universal decryptor for your entire network.
[REvil] — 17 days ago — Message 5/63
File 1
[REvil] — 17 days ago — Message 6/63
To decrypt the second file, I need a note with the id "readme-[redacted].txt". Send it to me in this chat.
[REvil] — 17 days ago — Message 7/63
After payment, the system will generate and give you a universal decryptor that will work on any device in your network.
[REvil] — 17 days ago — Message 8/63
In this case, this incident will not be advertised in the media and, if necessary, in this chat you can always get technical support in case of problems.
[REvil] — 17 days ago — Message 9/63
Correction, file with id "readme-[redacted].txt" is required.
[Victim] — 17 days ago — Message 10/63
this readme?
[Victim] — 17 days ago — Message 11/63
a few things. this is weekend and everything is closed until tuesday. we cannot even begin to figure out the process but there is no one to speak to, I see deadline of 3 days, please increase to 7-10 days to give us enough time to process this situation.
[Victim] — 17 days ago — Message 12/63
can you do discount on the amount you are asking? we are in the Caribbean and financial systems are partially disabled due to covid.
[REvil] — 17 days ago — Message 13/63
File 2
[REvil] — 17 days ago — Message 14/63
I will set the timer for you until October 14, in my opinion this is enough to make a decision. As for the discount, I might be able to convince the boss to give it to you, but you ask for many extra days.
[REvil] — 17 days ago — Message 15/63
Everything is up to you, quick payment in a short period of time, implies a good relationship and conditions of redemption.
[REvil] — 17 days ago — Message 16/63
Prolonging the process only aggravates the problem.
[REvil] — 17 days ago — Message 17/63
Time added, refresh the page.
[Victim] — 17 days ago — Message 18/63
can you accept btc? every broker we spoke to said it will take a long time for this amount of XMR. That is why we need time to find the right broker who can supply xmr.
[Victim] — 17 days ago — Message 19/63
its the weekend and banking holiday
[REvil] — 17 days ago — Message 20/63
I have included the possibility of payment in BTC, refresh the page.
[Victim] — 15 days ago — Message 21/63
can you decrypt test from another office?
[Victim] — 15 days ago — Message 22/63
also --- can you provide list of what data you take? or some sample? when I speak to management it will help explain.
[REvil] — 15 days ago — Message 23/63
Here is:
[REvil] — 15 days ago — Message 24/63
Ok, we will provide you the list and any details after payment, no problem
[Victim] — 15 days ago — Message 25/63
+ I am the IT manager and I do not make decision about money, but I would like to close this soon as possible, can you provide a list of files or something to prove my boss that its not only decrypt?
[REvil] — 15 days ago — Message 26/63
What exactly do you want to see?
[REvil] — 15 days ago — Message 27/63
Stolen [redacted] data are published in the blog in case of payment refusal or you receive a link to the files after payment.
[REvil] — 15 days ago — Message 28/63
You can show your boss the instructive stories of other companies that refused to pay the ransom.
[REvil] — 15 days ago — Message 29/63
[REDACTED URL]
[Victim] — 15 days ago — Message 30/63
+ yes I show him this. But my company is in carribean there is no privacy law, so easier to prove to boss what listing of the files you take to convince. The decryptor is of secondary value to us.
[Victim] — 15 days ago — Message 31/63
I want to solve this fast too, because I did not see family for few days now. So anything you can do to help me when talking to boss will be much help.
[REvil] — 15 days ago — Message 32/63
What proof do you need? We got access to your network, encrypted the data there and downloaded it, I see no point in this question, we always do this, these are our methods, did you see our blog? You have two options to get the files: after payment or publicly on the blog.
[Victim] — 15 days ago — Message 33/63
looking for some sort of a file list if you have of our files. because otherwise the boss is waiting for IT to finish investigation and this will take long time. I want to do this faster. Can you send a list of the files?
[REvil] — 15 days ago — Message 34/63
You forget that in addition to not being covered by the privacy law, your company is exposed to the disclosure of your internal information to the whole world, plus you incur reputational losses. Which client will want to become a premium card holder if the companie which do not care about their data safety?
[REvil] — 15 days ago — Message 35/63
You asked for more days to raise funds, you got this opportunity. If you now want to communicate with us in an ultimatum form, then be prepared to get the same effect from us and complicate an already difficult stage of negotiations.
[REvil] — 15 days ago — Message 36/63
Now print out the whole dialogue and bring it to your boss. We can go back to the previous timer, after which the amount will be doubled and there will be no discounts. There is no one here who is going to play games with you, or we make a deal and you get a decryptor + link to your files. Or just close the dialog and do not waste your time.
[Victim] — 15 days ago — Message 37/63
I do not know if you have problem communicating in English or whether I am speaking to an operator with bad temper but your response is not smart business. Do not threaten us again, because if you make more money publishing information, then good for you. Otherwise, you are taking a possible client who is willing to pay and basically start throwing a tantrum like a child. I would like to speak to an adult please who can understand business and knows why I am asking for what I am asking.
[Victim] — 15 days ago — Message 38/63
Now, let me repeat. I am trying very hard to work with you and you need to understand that we understand perfectly what position you are in, and what position WE ARE IN. I also check your reputation and you guys always deliver on your promise which is great and it is a strong basis for a good business transaction.
[Victim] — 15 days ago — Message 39/63
Here is what I need to move this forward, it is a very simple ask. We need a sample of the data you take and a file list of the files you take. It is not difficult and it is our files anyways, so what is the difficulty? All this will do is prove that you are indeed in a position of power, and I will be able to convince my boss that we need to speak about payment. I am TRYING TO HELP YOU AND ME. So work with me, or ask your boss to put someone else to work with me. And I also ask that you stop threatening me, your team already do the damage, so now we can speak and reach agreement or you can play games of threats and verbal abuse. Let's pretend we are adults ok?
[REvil] — 15 days ago — Message 40/63
My reaction is the result of your work. I don't see before me people who value their business, I see attempts to study the possibility of mitigation of the attack. We really keep our promises, there is no need to doubt it. We give the decryptor, we give references to the stolen files, we publish the files in case of a deal failure. And now we can imagine that we are adults and can discuss the deal.
[REvil] — 15 days ago — Message 41/63
Understand one thing and bring it to your boss, decryptor and confidentiality is need not for us, but for you. Do not scare us without paying, there are dozens of you, it is better to concentrate on your problem.
[REvil] — 15 days ago — Message 42/63
If my boss intervenes in this dialog, then it will not be communication, but two words and a timer per day, you are still lucky to deal with me, because I have time to answer you.
[REvil] — 15 days ago — Message 43/63
I am not going to enter into long correspondence and polemics anymore. You know the terms and conditions and they will remain unchanged.
[REvil] — 15 days ago — Message 44/63
1. We fix the amount of the transaction after the final value is approved. 2. You pay the ransom in moneon or bitcoin. 3. After payment you get a universal decryptor for all infected computers. 4. You get a set of links that contain your files. 5. After downloading your files are deleted from our servers without the possibility of recovery. 6. No one but us will know about this incident.
[REvil] — 15 days ago — Message 45/63
You can read about Travalex, a very instructive story. They had the opportunity to prevent it, as a result, this error became inexcusably expensive for them.
[Victim] — 15 days ago — Message 46/63
I read about you in media and bleeping computer. I have no doubt you will follow through and while my boss will make the business decision, I am trying to follow his instructions and work with you. I am asking you to work with me and give me what my boss is asking for. Let me further explain, our systems are almost back-up, but I am trying to reach common ground. Can you share the list of files you take? My boss does not care about publicity, but he does care about protecting people, if you can demonstrate what data you take, even just file list, it will go a long way in the discussion here. I am not trying to waste your time or mine, this will help no one. I know you are big group and you attack many companies and that we are just a number. I also understand you have the power. I am trying to be honest and explain to you what will help me here, this is the process I need to follow. So the question is whether it is possible for you to give me list of files or no. If no, I will tell my boss and we can figure out next steps. But let’s try to work together.
[REvil] — 15 days ago — Message 47/63
At this stage of negotiations - my answer is no. The situation may change if we find a compromise and reach an agreement. I do the same as you and follow the instructions of my boss. Tonight he will get acquainted with the dialogue and if there are new instructions, you will learn about it.
[REvil] — 15 days ago — Message 48/63
And I work with you, at your request was given +4 days, as well as enabled mode of bitcoins to accelerate the process of receiving funds. This is done first of all for you so that you can recover your systems faster and get back to work.
[Victim] — 13 days ago — Message 49/63
At this stage of negotiations - we cannot proceed unless you provide us with the list of files and 2-3 random sample files you took. If you break negotiations at this point, you are going to publish the data anyways, so there is zero difference between giving us the information or publishing. The only key difference is that if you publish instead of giving us the information we need, there will be zero chance of further negotiations. I hope your boss reconsiders his position so that we can finally move forward.
[REvil] — 13 days ago — Message 50/63
Ok, but in return I reduce the timer for decision making.
[REvil] — 13 days ago — Message 51/63
[REDACTED URL]
[REvil] — 13 days ago — Message 52/63
This link is not yet visible to anyone except you.
[Victim] — 13 days ago — Message 53/63
First, thank you for finally providing this information which will allow me to work with the boss. Second, I will certainly push to make a decision as fast as possible. HOWEVER - reducing the timer will not work. Actually because you delay the analysis for no real reason we will need more time. Given the amount it will not happen before Friday. You can try and push and you are doing a great job of that, but in a company that needs to follow process, it will not work and all you will do is end up losing this opportunity to close the issue for both side. Please increase the timer as we are asking. I am trying to work with you.
[REvil] — 13 days ago — Message 54/63
We gave you enough time to make a decision. If your boss doesn't want to pay $6kk but wants to get off with a smaller amount, let him hurry.
[Victim] — 13 days ago — Message 55/63
We can argue together and you can argue you gave us enough time. In a company that is publicly listed, 3 days is not enough time. So let's stop with the games here, we are trying to work with you and I have no interest to play games, I tell you what I need not because I feel like it for fun and giggles. It is also not my money, so all threats mean nothing. I am speaking to you because of genuine interest to solve the problem and make sure we conclude this successfully. If you run the timer and publish the conversation is over. I know you do not care either but I am sure we are both interested in getting this to successfully conclude. You took the first step in showing me what I needed, now do whatever you need, but I am telling you that your new deadline is not going to happen. Your call how we do this.
[REvil] — 13 days ago — Message 56/63
Companies that are traded on stock exchanges, solve the problem in 12 hours, I say this because I know. I see that your actions are only aimed at delaying the solution of this incident.
[REvil] — 13 days ago — Message 57/63
4 days ago you have asked for additional time to buy XMR, at now you write like you only now start consider payment process. Who play games? You already had plenty of time to make a decision and consider different options. Now your task is to go to the boss and come to me with the answer. The timer will not be moved until I get information about the deal.
[Victim] — 13 days ago — Message 58/63
You decision, your rules. I will pass on your message certainly.
[Victim] — 13 days ago — Message 59/63
and just so you know... Carribean rules because of USD embargo during Covid, Maybe do some research on this. Either way, you are not changing your position, I understand. Please understand that when timer expires if you publish this conversation is over and second, there will not even be a negotiation on price until the boss does his analysis. Thank you and have a wonderful day.
[REvil] — 13 days ago — Message 60/63
Think not about the fact that we will not make a profit, think about the problems that will arise after publication. Have a good day, too.
[Victim] — 13 days ago — Message 61/63
Understood. It is a 2-way street my friend. We either try to work together or you already decide to publish etc. That is why I asked for the data so that I can prove to the boss that it is a serious situation. But it took you time, now I need the time to work on the boss.
[REvil] — 13 days ago — Message 62/63
I do not need to be persuaded, go to the boss and come back with an answer, you have little time left.
[REvil] — 13 days ago — Message 63/63
You will have another day after the publication sees the world. For now there will be no link to downloads.

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.