Chat
Negotiation chat with different groups
Akira
- 20230529 – 7 message(s) voir chat
- 20230606 – 13 message(s) voir chat
- 20230616 – 80 message(s) voir chat
- 20230628 – 5 message(s) voir chat
- 20230707 – 37 message(s) voir chat
- 20230719 – 4 message(s) voir chat
- 20230722 – 9 message(s) voir chat
- 20230727 – 72 message(s) voir chat
- 20230728 – 5 message(s) voir chat
- 20230815 – 84 message(s) voir chat
- 20230929 – 58 message(s) voir chat
- 20231112 – 58 message(s) voir chat
- 20231115 – 81 message(s) voir chat
- 20231209 – 112 message(s) voir chat
- 20231217 – 67 message(s) voir chat
- 20231227 – 74 message(s) voir chat
- 20240127 – 41 message(s) voir chat
- 20240129 – 70 message(s) voir chat
- 20240131 – 75 message(s) voir chat
- 20240201 – 40 message(s) voir chat
- 20240301 – 43 message(s) voir chat
- 20240317 – 8 message(s) voir chat
- 20240329 – 65 message(s) voir chat
- 20240410 – 16 message(s) voir chat
- 20240424 – 70 message(s) voir chat
- 20240509 – 170 message(s) voir chat
- 20240531 – 55 message(s) voir chat
- 20240611 – 50 message(s) voir chat
- 20240618 – 53 message(s) voir chat
- 20240620 – 7 message(s) voir chat
- 20240718 – 105 message(s) voir chat
- 20240719 – 6 message(s) voir chat
- 20240723 – 43 message(s) voir chat
- 20240803 – 34 message(s) voir chat
- 20250104 – 13 message(s) voir chat
- 20250108 – 10 message(s) voir chat
- 20250110 – 7 message(s) voir chat
- 20250112 – 44 message(s) voir chat
- 20250117 – 70 message(s) voir chat
- 20250120 – 7 message(s) voir chat
- 20250121 – 26 message(s) voir chat
- 20250125 – 9 message(s) voir chat
- 20250216 – 14 message(s) voir chat
- 20250217 – 13 message(s) voir chat
- 20250222 – 72 message(s) voir chat
- 20250227 – 56 message(s) voir chat
- 20250306 – 9 message(s) voir chat
- 20250310 – 24 message(s) voir chat
- 20250312 – 20 message(s) voir chat
- 20250313 – 43 message(s) voir chat
- 20250321 – 25 message(s) voir chat
- 20250328 – 39 message(s) voir chat
- 20250330 – 15 message(s) voir chat
- 20250331 – 6 message(s) voir chat
- 20250408 – 12 message(s) voir chat
- 20250417 – 59 message(s) voir chat
- 20250423 – 65 message(s) voir chat
- 20250424 – 12 message(s) voir chat
- 20250425 – 6 message(s) voir chat
- 20250425b – 15 message(s) voir chat
Avaddon
- 20210112 – 25 message(s) voir chat
- 20210324 – 73 message(s) voir chat
- 20210430 – 103 message(s) voir chat
- 20210512 – 35 message(s) voir chat
- 20210518 – 17 message(s) voir chat
- 20210518_2 – 24 message(s) voir chat
- 20210518_3 – 103 message(s) voir chat
Avos
- 20210903 – 86 message(s) voir chat
Babuk
BlackBasta
- 20221011 – 50 message(s) voir chat
- 20221229 – 50 message(s) voir chat
- 20230410 – 57 message(s) voir chat
- 20230501 – 50 message(s) voir chat
- 20240814 – 50 message(s) voir chat
BlackMatter
Cloak
Conti
- 20201017 – 78 message(s) voir chat
- 20201019 – 9 message(s) voir chat
- 20201109 – 255 message(s) voir chat
- 20201121 – 6 message(s) voir chat
- 20201230 – 146 message(s) voir chat
- 20210107 – 139 message(s) voir chat
- 20210126 – 9 message(s) voir chat
- 20210219 – 12 message(s) voir chat
- 20210305 – 45 message(s) voir chat
- 20210315 – 49 message(s) voir chat
- 20210316 – 63 message(s) voir chat
- 20210426 – 12 message(s) voir chat
- 20210428 – 13 message(s) voir chat
- 20210513 – 78 message(s) voir chat
- 20210517 – 56 message(s) voir chat
- 20210517_b – 69 message(s) voir chat
- 20210520 – 101 message(s) voir chat
- 20210602 – 81 message(s) voir chat
- 20210611 – 48 message(s) voir chat
- 20210628 – 34 message(s) voir chat
- 20210708 – 25 message(s) voir chat
- 20210715 – 10 message(s) voir chat
- 20210805 – 47 message(s) voir chat
- 20210812 – 46 message(s) voir chat
- 20210820 – 50 message(s) voir chat
- 20210902 – 43 message(s) voir chat
- 20210904 – 17 message(s) voir chat
- 20210923 – 14 message(s) voir chat
- 20211108 – 32 message(s) voir chat
- 20211112 – 32 message(s) voir chat
- 20211205 – 63 message(s) voir chat
- 20211217 – 27 message(s) voir chat
Darkside
- 20200811 – 85 message(s) voir chat
- 20201115 – 243 message(s) voir chat
- 20210215 – 24 message(s) voir chat
- 20210413 – 63 message(s) voir chat
- 20210418 – 10 message(s) voir chat
Dragonforce
- 058f4b92-ae99-45c7-bf35-5d2d6754b3de – 19 message(s) voir chat
- 05f724f8-906e-4739-8177-815852cc2c3f – 29 message(s) voir chat
- 29BBE03074FDBB8D – 10 message(s) voir chat
- 7A313D13EB6B4E58 – 32 message(s) voir chat
- 89716D29D2CEE36F – 23 message(s) voir chat
- AB0404E049514B50 – 28 message(s) voir chat
- BD004D632D87DBA0 – 25 message(s) voir chat
- C2A3C7249797F5ED – 66 message(s) voir chat
- C42CDF65B97D0E92 – 30 message(s) voir chat
- C7CD31EAAF9DE9AC – 71 message(s) voir chat
- C8479B30418B331E – 4 message(s) voir chat
- D6DDD9B26D7D41DB – 14 message(s) voir chat
- FDA8141B6DD392E3 – 10 message(s) voir chat
- b8e14e1a-548f-4eec-bd6e-a590126e57c9 – 14 message(s) voir chat
Hive
- 20211004 – 70 message(s) voir chat
- 20211005 – 19 message(s) voir chat
- 20211026 – 46 message(s) voir chat
- 20211102 – 58 message(s) voir chat
- 20211113 – 136 message(s) voir chat
- 20211126 – 4 message(s) voir chat
- 20211213 – 15 message(s) voir chat
- 20211220 – 24 message(s) voir chat
Hunters International
- 20240510 – 29 message(s) voir chat
Mallox
- 20230427 – 62 message(s) voir chat
- 20230529 – 29 message(s) voir chat
- 20230530 – 17 message(s) voir chat
NoEscape
Pear
- 20250720 – 42 message(s) voir chat
Qilin
REvil
- 20201014 – 72 message(s) voir chat
- 20201104 – 63 message(s) voir chat
- 20201126 – 79 message(s) voir chat
- 20210320 – 13 message(s) voir chat
- 20210329 – 43 message(s) voir chat
- 20210331 – 23 message(s) voir chat
- 20210401 – 78 message(s) voir chat
- 20210407 – 15 message(s) voir chat
- 20210413 – 156 message(s) voir chat
- 20210603 – 63 message(s) voir chat
- 20210604 – 10 message(s) voir chat
- 20210609 – 58 message(s) voir chat
- 20210613 – 132 message(s) voir chat
- 20210616 – 31 message(s) voir chat
- 20210617 – 67 message(s) voir chat
- 20210622 – 52 message(s) voir chat
- 20210628 – 39 message(s) voir chat
- 20210630 – 42 message(s) voir chat
- 20210708 – 28 message(s) voir chat
- 20210709 – 1 message(s) voir chat
RansomHub
- 20240810 – 1 message(s) voir chat
Ranzy
RunSomeWares
- 20250411 – 27 message(s) voir chat
fog
- 20240517 – 27 message(s) voir chat
- 20240729 – 144 message(s) voir chat
- 20240830 – 73 message(s) voir chat
- 20240910 – 26 message(s) voir chat
- 20240927 – 60 message(s) voir chat
- 20241119 – 3 message(s) voir chat
lockbit3.0
- **************************149576 – 17 message(s) voir chat
- Leaked2025-ClientID-124 – 55 message(s) voir chat
- Leaked2025-ClientID-154 – 137 message(s) voir chat
- Leaked2025-ClientID-206 – 4 message(s) voir chat
- Leaked2025-ClientID-36 – 55 message(s) voir chat
- aguasdoporto_pt – 3 message(s) voir chat
- bakkerheftrucks_com – 27 message(s) voir chat
- bankbsi_co_id – 27 message(s) voir chat
- chsf_fr – 42 message(s) voir chat
- colonialgeneral_com – 25 message(s) voir chat
- continental_com – 37 message(s) voir chat
- datair_com – 106 message(s) voir chat
- emunworks_com – 8 message(s) voir chat
- entrust_com – 29 message(s) voir chat
- gavresorts_com_br – 6 message(s) voir chat
- genusplc_com – 34 message(s) voir chat
- gocontec_com – 52 message(s) voir chat
- guardiananalytics_com – 27 message(s) voir chat
- hgc_com_hk – 8 message(s) voir chat
- kaycan_com – 94 message(s) voir chat
- lapostemobile_fr – 93 message(s) voir chat
- millennia_pro – 43 message(s) voir chat
- myerspower_com – 99 message(s) voir chat
- newbridge_org – 70 message(s) voir chat
- nicklaus_com – 43 message(s) voir chat
- okcu_edu – 56 message(s) voir chat
- omscomponents_it – 66 message(s) voir chat
- plasticproductsco_com – 28 message(s) voir chat
- porcelanosa-usa_com – 8 message(s) voir chat
- preflooring_com – 17 message(s) voir chat
- psenergy_com – 25 message(s) voir chat
- qsi-q3_de – 20 message(s) voir chat
- royalmailgroup_com – 103 message(s) voir chat
- samyang_com – 237 message(s) voir chat
- scohil_com – 29 message(s) voir chat
- sirva_com – 78 message(s) voir chat
- software-line_it – 30 message(s) voir chat
- tapcocu_org – 215 message(s) voir chat
- vitalityhp_net – 73 message(s) voir chat
- vsainc_com – 21 message(s) voir chat
- wabteccorp_com – 39 message(s) voir chat
- wcinet_com – 34 message(s) voir chat
mount-locker
- 20201016 – 60 message(s) voir chat
trinity
- 0001 – 2 message(s) voir chat
- 0002 – 52 message(s) voir chat
- 0003 – 298 message(s) voir chat
- 0004 – 170 message(s) voir chat
- 0005 – 14 message(s) voir chat
- 0006 – 11 message(s) voir chat
- 0007 – 36 message(s) voir chat
- 0008 – 13 message(s) voir chat
- 0009 – 6 message(s) voir chat
- 0010 – 8 message(s) voir chat
- 0011 – 50 message(s) voir chat
- 0012 – 15 message(s) voir chat
- 0013 – 32 message(s) voir chat
- 0014 – 6 message(s) voir chat
Akira
> Hello. You've reached Akira support chat. Currently, we are preparing the list of data we took from your network. For now you have to know that dealing with us is the best possible way to settle this quick and cheap. Keep in touch and be patient with us. We will reach out to you soon. Do you have a permission to conduct a negotiation on behalf of your organization? Once we get a response you will be provided with all the details.
Victim
> Yes, I am authorized to speak with you on behalf of our organization. Why would you do this to us? We are a non-profit organization who offers free services for poor and homeless women. This is a terrible thing that has happened to us and you are hurting these women the most by this action. We desperately ask you reconsider what you have done and let us get our operations back to normal as quickly as possible. These people need our help and we need yours to get back to normal. We beg of you to do the right thing here.
Akira
> So, let's do the right thing here settle this quickly and the people you care of will continue getting help.
Akira
> List.txt // 812 KB
Akira
> These files were taken from your network prior to encryption. You can pick 2-3 random files from the list and we will upload them to this chat as a proof of possession. To prove that we can properly decrypt your data you can upload 2-3 encrypted files to our chat and we will upload decrypted copies back.
Victim
> So what is it you want from us if you don't care to help reverse what you have done?
Akira
> We're looking through your files to calculate a fair demand to you. I will let you know the sum shortly. We offer:
1) full decryption assistance;
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future.
Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
1) full decryption assistance;
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future.
Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
Victim
> We need everything back to normal
Victim
> We are a non-profit. We don't have much money.
Akira
> We won't ask much money. We will ask what you can afford.
Akira
> So, we've gone through your files to define your financial abilities. We've been looking through your bank statements, net income, cyber liability limits, financial audits - all the info that might help us calculate our demand to you. We're willing to set a $250,000 price for ALL the services we offer.
Victim
> Don't let the financials confuse you. We are a non-profit, meaning all of our funds coming in is not income. It is spent on the free services we provide to more than [redacted],000 women every year. Food, housing, counseling, and many other services to help these women survive. We do all of this for free and all of the money we use for this is donated to us. If we give you that kind of money then it means there are many people that we can’t help. That means people that can’t eat or have a place to sleep. Please consider being more reasonable and think about if one of these women was someone you care about. Someone you love. You have to have some sense of humanity inside you to do the proper thing here.
Akira
> We are not really confused by your financials. If you care of people and are responsible for them you should protect them. If you take a look at the list we gave you, you would see what kind of information we obtained about the people your are in charge of. How did it happen? They were not protected enough and their documents were stolen. Imagine that docs was someone's you really care about. But as you have a cyber insurance, you can prevent the leak. So do this. Let me know if you are interested in proofs or a test decryption so we can speed everything up. If you act quick, we can give you a 20% discount.
Victim
> Please show these 3 files
Victim
> [redacted].xls
Victim
> [redacted].pdf
Victim
> [redacted].pdf
Akira
> Please wait.
Akira
> [redacted].rar // 304 KB
Akira
> Do you want to check our decryption tool?
Victim
> yes we want to check, but need to access the files. We don't have them yet
Akira
> When can we expect the files approximately?
Victim
> [redacted].vbm.akira // 797 KB
Victim
> [redacted].vbm.akira // 515 KB
Victim
> [redacted].vbm.akira // 844 KB
Victim
> Please show us you can unlock these
Akira
> We will upload them decrypted soon.
Akira
> [redacted].vbm // 797 KB
Akira
> [redacted].vbm // 515 KB
Akira
> [redacted].vbm // 844 KB
Akira
> You can review the files.
Victim
> We are going to have to find where we can raise the funds to pay for this. As a homeless shelter all of our money is donations and we don't have this much money so we are going to see what we can come up with. We can get back to you on Monday so that we can hopefully make a deal.
Victim
> We just checked these files and there are no changes. They are still encrypted.
Akira
> We will review and get back to you.
Akira
> [redacted].vbm // 796 KB
Akira
> [redacted].vbm // 514 KB
Akira
> [redacted].vbm // 844 KB
Akira
> Please check these.
Akira
> We will wait until Monday for your offer. Have a good weekends.
Victim
> As mentioned, it is very difficult for us to have much money. What we are able to offer you at this time is only $50,000. Please understand that as a homeless shelter this is 200 times more money than we started off with as an organization. We rely on this money to serve the homeless community and we still hope and pray you will take pity on us, and offer to get us back for free. If you can find the good will within yourselves that is.
Akira
> We can't accept this modest amount for sure. You had to to start with 6 figure sums at least.
Victim
> What are we supposed to do if we don't have that kind of money? We are a charity! Why can't you help us out? We're trying to give you something here. We're doing what we can.
Victim
> Is there something you can do for us so we can pay you an amount that you can accept? This is our operational funds we have to use. That means degredation of our services to the people we are helping.
Victim
> *degradation
Akira
> We're well aware of you're a charity. We also know that you have enough funds to cover our initial demand. Anyway, the leadership has approved $190,000 amount. The best option for you to get back on track and continue to help people.
Victim
> I thank you for working with us. This is greatly appreciated. However, I don't know how to make you understand WE DON'T actually have the funds to cover the initial amount, and to be frank even this amount. This would break us and we would have to shut down. We wouldn't be able to help anyone then. The homeless shelters we have operated for over 50 years would have to shut down. The cold weather is quickly approaching and that would mean thousands of women we wouldn’t be able to house who will face even more challenges than they already have. In that case it wouldn’t make sense to pay you if it means maintaining our survival. I will go back and see what we can do, but we ask you to please do the same. Please visit our website and see our mission and the people who are depending on us. [redacted]. Let’s work together on a solution where we all get what we want. I’ll get back to you after I see what we can do more.
Akira
> Standing by.
Victim
> Because of all the expenses from this incident and what we have to pay to recover we don't have the operational funds on our own to cover everything plus pay you. Luckily I have found someone gracious enough to donate some money to us. The additiional amount we can secure will bring us up to $75,000. Please tell us you will accept this because otherwise we won't have any options left.
Akira
> Thank you for the update. We see that you want to resolve the incident with us, so we can come down with the price and accept $170,000. We can wait a bit for a better offer from you. May be there will be another donation that will allow you to finish our deal.
Victim
> Can I speak with your boss or someone else higher? Because I don't think you understand. If we can't work out a deal then you are going to get nothing. I don't know how we can get more to give you.
Victim
> I'm having a nervous breakdown here worried sick about our organization. Please answer me. We really need to figure out a solution to this problem. We don't have that kind of money.
Akira
> I'll let you know soon.
Victim
> Thank you
Akira
> My team is pretty aware of the situation. It was confirmed to me that we cannot accept any sum less that 6 numbers from you. We'd like to finish this quick but there are rules.
Akira
> Well, we've discussed the case internally. Taking into account your financial situation my leadership decided to move towards you and receive $135,000 for closing the case.
Victim
> I wish we had that much to give you so we can finish this process. Unfortunately we do not have that. After moving some things around on our side and making additional cuts, I can offer you $88,500 and then we can be done. That's the best I'm able to do during this difficult time for us.
Victim
> I'm hoping this is close enough to 6 figures for you to consider.
Akira
> We see that we are close to the resolving as never before. So we're ready to accept $100,000 within the next 24 hours. So there is an extra discount from us and you have time to gather the sum. I suppose that is the best finish for both sides at this moment. You can fund this BTC wallet when you are ready [redacted]
Victim
> I will see what I can do to get there. I'll let you know. Thanks.
Victim
> Just so I'm clear, all of these things you said you would give are still applicable? "1) full decryption assistance; 2) evidence of data removal; 3) security report on vulnerabilities we found; 4) guarantees not to publish or sell your data; 5) guarantees not to attack you in the future."
Akira
> Yes, they are.
Victim
> Okay thanks. I'll be in touch.
Akira
> Standing by.
Victim
> Okay, we have figured out the funding and can pay you $100,000. We will work on getting this to you today. I will let you know more on timing as it gets closer.
Akira
> OK. Thanks.
Victim
> We are ready. The address [redacted] is correct?
Victim
> hello?
Akira
> Yes, the address [redacted]
Victim
> Thanks. Stand by for payment
Victim
> payment has been sent
Victim
> please confirm you received it
Akira
> We confirm the receipt. Please wait.
Victim
> How long do you think it will take?
Akira
> decryptors.zip // 3.04 MB
Akira
> unlocker.exe -p="path_to_unlock"
unlocker.exe -s="C:\paths.txt"
where "paths.txt" is a list of paths for the decryptor, each path on a new line
same arguments work with the esxi decryptor
unlocker.exe -s="C:\paths.txt"
where "paths.txt" is a list of paths for the decryptor, each path on a new line
same arguments work with the esxi decryptor
Victim
> Thank you. Please provide proof of data removal and the security report on vulnerabilities you found
Akira
> Please wait for the rest items within 24 hours.
Victim
> Any update for me?
Akira
> Wait a bit.
Akira
> Deletion [redacted].txt // 2.05 MB
Akira
> Initial access to your network was purchased on the dark web. Then kerberoasting was carried out and we got passwords hashes. Then we just bruted these and got domain admin password. Spending weeks inside of your network we've managed to detect some fails we highly recommend to eliminate: 1. None of your employees should open suspicious emails, suspicious links or download any files, much less run them on their computer.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc. We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc. We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
Auteur/autrice
sdgadmin@tux.ovh