// Ransomware Negotiation Transcript
REvil Ransomware Negotiation — Redacted Organisation
// Context
About This Negotiation
This transcript documents a REvil ransomware negotiation with a redacted victim organisation. The negotiation consisted of 43 messages exchanged.
The initial demand is not clearly stated in the transcript. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
price is error ?
how much btc ?
Hello.This amount was formed after a detailed audit of your company and
it fully corresponds to your level and size of your company.
The system works as follows: you transfer the amount in crypt currency Monero (XMR) to the wallet specified on your page.
After payment you receive:
- Universal decryptor for your all network
- 100% confidentiality of this incident and all terms of the transaction on our part.
Ten million ?
it's the first time i see the price , it's very exaggeration
what's is the lowest price ?
wait for answer.
Nope. You need to pay the requested amount of money. It is not a market.
You pay for fullfill decryption your files and we tell you about your
vulnerabilities and how to fix them. Otherwise you will face new
different attacks, sooner or later it will lead to leaks of your and
your client's data and other valuable data again and again.
We recommend that you transfer this information to the management.
We are ready for dialogue if you want to solve this problem.
We will not drag out negotiations.
We know the level of damage done to your network.
Also, our team received a large amount of important information that
will become publicly available if you do not pay or try to make too low
offers.
For our part, we are ready to provide a 20% discount if payment reaches us by Wednesday.This is our goodwill gesture.
[REDACTED URL]
When the time expires, this post will be published.
maybe more discount ?
I must have more bargaining chips to convince the boss
Excessive amounts must be paid by the Board of Directors, and it takes too much time
You can submit your proposal and my boss will review it.
The faster the payment arrives, the more discount we will give you.
As proof, we can provide any of your data.
Have any R&D information or personal information?
The data provided should be sufficient to understand what we own.
We have been download personal information from 2015.
My boss is not ready to drag out this dialogue.
Make an offer and my boss will consider it.
Can you give me some data?
I will discuss with my boss
The more destructive the better
hello?
wait for answer.
We don't have time to download tens of gigabytes of information.
We will give you an example of 1/10000 of your file tree.
My boss is open to your suggestions, but we don't expect little money from you.
File.
Decrypt password?
i need more file list
The more the better
I must tell my boss this is serious
He didn’t realize the severity
Password: 123123
This is enough to understand that we have a lot of valuable information.
Tell your boss that it is very serious. The data received from your
trusts is enough to deliver you problems for many years.
Our advice, do not pull the time to not repeat the fate of the SolarWind.
I need more evidence, this is a global paralysis
We have provided you with sample proof of what has been downloaded from your network.
You understand the seriousness of the situation for your company, and you need to explain this to your boss.
You are losing money every day.
Your time is running out, and very soon we will publish your data on the blog, it will bring you even more problems.
It is in your interests to quickly agree on the ransom amount and pay
quickly, and we will give you a discount. We are waiting for suggestions
from you.
I don't have enough chips
You have worked so hard, and the results are not far away
What I need is the trust and support of the boss
But if we talk no results, we can’t continue
What results do you want to tell about? We've done enough to keep you in trouble for years to come.
Now we are waiting for a clear proposal from you.
If it is not received tomorrow, Forbes and the WSJ will report a breach in your headquarters systems and all servers.
I am very actively trying to resolve this matter
But the data you gave me didn’t allow me to convince my boss
Then we'll do it.
What you need is money
What I need is my job and the trust of my boss
But you don't give me a bargaining chip to talk to my boss
I'm really in difficulty like this
So your boss has to get in touch with us himself. You're an incompetent negotiator.
....
Are we gonna talk about money? There will be no more dates, don't ask more about it.
// Analysis
Analyst Observations
- REvil (also known as Sodinokibi) was responsible for high-profile attacks including Kaseya and JBS. The group was disrupted by law enforcement in late 2021 and early 2022.