Chat
Negotiation chat with different groups
Akira
- 20230529 – 7 message(s) voir chat
- 20230606 – 13 message(s) voir chat
- 20230616 – 80 message(s) voir chat
- 20230628 – 5 message(s) voir chat
- 20230707 – 37 message(s) voir chat
- 20230719 – 4 message(s) voir chat
- 20230722 – 9 message(s) voir chat
- 20230727 – 72 message(s) voir chat
- 20230728 – 5 message(s) voir chat
- 20230815 – 84 message(s) voir chat
- 20230929 – 58 message(s) voir chat
- 20231112 – 58 message(s) voir chat
- 20231115 – 81 message(s) voir chat
- 20231209 – 112 message(s) voir chat
- 20231217 – 67 message(s) voir chat
- 20231227 – 74 message(s) voir chat
- 20240127 – 41 message(s) voir chat
- 20240129 – 70 message(s) voir chat
- 20240131 – 75 message(s) voir chat
- 20240201 – 40 message(s) voir chat
- 20240301 – 43 message(s) voir chat
- 20240317 – 8 message(s) voir chat
- 20240329 – 65 message(s) voir chat
- 20240410 – 16 message(s) voir chat
- 20240424 – 70 message(s) voir chat
- 20240509 – 170 message(s) voir chat
- 20240531 – 55 message(s) voir chat
- 20240611 – 50 message(s) voir chat
- 20240618 – 53 message(s) voir chat
- 20240620 – 7 message(s) voir chat
- 20240718 – 105 message(s) voir chat
- 20240719 – 6 message(s) voir chat
- 20240723 – 43 message(s) voir chat
- 20240803 – 34 message(s) voir chat
- 20250104 – 13 message(s) voir chat
- 20250108 – 10 message(s) voir chat
- 20250110 – 7 message(s) voir chat
- 20250112 – 44 message(s) voir chat
- 20250117 – 70 message(s) voir chat
- 20250120 – 7 message(s) voir chat
- 20250121 – 26 message(s) voir chat
- 20250125 – 9 message(s) voir chat
- 20250216 – 14 message(s) voir chat
- 20250217 – 13 message(s) voir chat
- 20250222 – 72 message(s) voir chat
- 20250227 – 56 message(s) voir chat
- 20250306 – 9 message(s) voir chat
- 20250310 – 24 message(s) voir chat
- 20250312 – 20 message(s) voir chat
- 20250313 – 43 message(s) voir chat
- 20250321 – 25 message(s) voir chat
- 20250328 – 39 message(s) voir chat
- 20250330 – 15 message(s) voir chat
- 20250331 – 6 message(s) voir chat
- 20250408 – 12 message(s) voir chat
- 20250417 – 59 message(s) voir chat
- 20250423 – 65 message(s) voir chat
- 20250424 – 12 message(s) voir chat
- 20250425 – 6 message(s) voir chat
- 20250425b – 15 message(s) voir chat
Avaddon
- 20210112 – 25 message(s) voir chat
- 20210324 – 73 message(s) voir chat
- 20210430 – 103 message(s) voir chat
- 20210512 – 35 message(s) voir chat
- 20210518 – 17 message(s) voir chat
- 20210518_2 – 24 message(s) voir chat
- 20210518_3 – 103 message(s) voir chat
Avos
- 20210903 – 86 message(s) voir chat
Babuk
BlackBasta
- 20221011 – 50 message(s) voir chat
- 20221229 – 50 message(s) voir chat
- 20230410 – 57 message(s) voir chat
- 20230501 – 50 message(s) voir chat
- 20240814 – 50 message(s) voir chat
BlackMatter
Cloak
Conti
- 20201017 – 78 message(s) voir chat
- 20201019 – 9 message(s) voir chat
- 20201109 – 255 message(s) voir chat
- 20201121 – 6 message(s) voir chat
- 20201230 – 146 message(s) voir chat
- 20210107 – 139 message(s) voir chat
- 20210126 – 9 message(s) voir chat
- 20210219 – 12 message(s) voir chat
- 20210305 – 45 message(s) voir chat
- 20210315 – 49 message(s) voir chat
- 20210316 – 63 message(s) voir chat
- 20210426 – 12 message(s) voir chat
- 20210428 – 13 message(s) voir chat
- 20210513 – 78 message(s) voir chat
- 20210517 – 56 message(s) voir chat
- 20210517_b – 69 message(s) voir chat
- 20210520 – 101 message(s) voir chat
- 20210602 – 81 message(s) voir chat
- 20210611 – 48 message(s) voir chat
- 20210628 – 34 message(s) voir chat
- 20210708 – 25 message(s) voir chat
- 20210715 – 10 message(s) voir chat
- 20210805 – 47 message(s) voir chat
- 20210812 – 46 message(s) voir chat
- 20210820 – 50 message(s) voir chat
- 20210902 – 43 message(s) voir chat
- 20210904 – 17 message(s) voir chat
- 20210923 – 14 message(s) voir chat
- 20211108 – 32 message(s) voir chat
- 20211112 – 32 message(s) voir chat
- 20211205 – 63 message(s) voir chat
- 20211217 – 27 message(s) voir chat
Darkside
- 20200811 – 85 message(s) voir chat
- 20201115 – 243 message(s) voir chat
- 20210215 – 24 message(s) voir chat
- 20210413 – 63 message(s) voir chat
- 20210418 – 10 message(s) voir chat
Dragonforce
- 058f4b92-ae99-45c7-bf35-5d2d6754b3de – 19 message(s) voir chat
- 05f724f8-906e-4739-8177-815852cc2c3f – 29 message(s) voir chat
- 29BBE03074FDBB8D – 10 message(s) voir chat
- 7A313D13EB6B4E58 – 32 message(s) voir chat
- 89716D29D2CEE36F – 23 message(s) voir chat
- AB0404E049514B50 – 28 message(s) voir chat
- BD004D632D87DBA0 – 25 message(s) voir chat
- C2A3C7249797F5ED – 66 message(s) voir chat
- C42CDF65B97D0E92 – 30 message(s) voir chat
- C7CD31EAAF9DE9AC – 71 message(s) voir chat
- C8479B30418B331E – 4 message(s) voir chat
- D6DDD9B26D7D41DB – 14 message(s) voir chat
- FDA8141B6DD392E3 – 10 message(s) voir chat
- b8e14e1a-548f-4eec-bd6e-a590126e57c9 – 14 message(s) voir chat
Hive
- 20211004 – 70 message(s) voir chat
- 20211005 – 19 message(s) voir chat
- 20211026 – 46 message(s) voir chat
- 20211102 – 58 message(s) voir chat
- 20211113 – 136 message(s) voir chat
- 20211126 – 4 message(s) voir chat
- 20211213 – 15 message(s) voir chat
- 20211220 – 24 message(s) voir chat
Hunters International
- 20240510 – 29 message(s) voir chat
Mallox
- 20230427 – 62 message(s) voir chat
- 20230529 – 29 message(s) voir chat
- 20230530 – 17 message(s) voir chat
NoEscape
Pear
- 20250720 – 42 message(s) voir chat
Qilin
REvil
- 20201014 – 72 message(s) voir chat
- 20201104 – 63 message(s) voir chat
- 20201126 – 79 message(s) voir chat
- 20210320 – 13 message(s) voir chat
- 20210329 – 43 message(s) voir chat
- 20210331 – 23 message(s) voir chat
- 20210401 – 78 message(s) voir chat
- 20210407 – 15 message(s) voir chat
- 20210413 – 156 message(s) voir chat
- 20210603 – 63 message(s) voir chat
- 20210604 – 10 message(s) voir chat
- 20210609 – 58 message(s) voir chat
- 20210613 – 132 message(s) voir chat
- 20210616 – 31 message(s) voir chat
- 20210617 – 67 message(s) voir chat
- 20210622 – 52 message(s) voir chat
- 20210628 – 39 message(s) voir chat
- 20210630 – 42 message(s) voir chat
- 20210708 – 28 message(s) voir chat
- 20210709 – 1 message(s) voir chat
RansomHub
- 20240810 – 1 message(s) voir chat
Ranzy
RunSomeWares
- 20250411 – 27 message(s) voir chat
fog
- 20240517 – 27 message(s) voir chat
- 20240729 – 144 message(s) voir chat
- 20240830 – 73 message(s) voir chat
- 20240910 – 26 message(s) voir chat
- 20240927 – 60 message(s) voir chat
- 20241119 – 3 message(s) voir chat
lockbit3.0
- **************************149576 – 17 message(s) voir chat
- Leaked2025-ClientID-124 – 55 message(s) voir chat
- Leaked2025-ClientID-154 – 137 message(s) voir chat
- Leaked2025-ClientID-206 – 4 message(s) voir chat
- Leaked2025-ClientID-36 – 55 message(s) voir chat
- aguasdoporto_pt – 3 message(s) voir chat
- bakkerheftrucks_com – 27 message(s) voir chat
- bankbsi_co_id – 27 message(s) voir chat
- chsf_fr – 42 message(s) voir chat
- colonialgeneral_com – 25 message(s) voir chat
- continental_com – 37 message(s) voir chat
- datair_com – 106 message(s) voir chat
- emunworks_com – 8 message(s) voir chat
- entrust_com – 29 message(s) voir chat
- gavresorts_com_br – 6 message(s) voir chat
- genusplc_com – 34 message(s) voir chat
- gocontec_com – 52 message(s) voir chat
- guardiananalytics_com – 27 message(s) voir chat
- hgc_com_hk – 8 message(s) voir chat
- kaycan_com – 94 message(s) voir chat
- lapostemobile_fr – 93 message(s) voir chat
- millennia_pro – 43 message(s) voir chat
- myerspower_com – 99 message(s) voir chat
- newbridge_org – 70 message(s) voir chat
- nicklaus_com – 43 message(s) voir chat
- okcu_edu – 56 message(s) voir chat
- omscomponents_it – 66 message(s) voir chat
- plasticproductsco_com – 28 message(s) voir chat
- porcelanosa-usa_com – 8 message(s) voir chat
- preflooring_com – 17 message(s) voir chat
- psenergy_com – 25 message(s) voir chat
- qsi-q3_de – 20 message(s) voir chat
- royalmailgroup_com – 103 message(s) voir chat
- samyang_com – 237 message(s) voir chat
- scohil_com – 29 message(s) voir chat
- sirva_com – 78 message(s) voir chat
- software-line_it – 30 message(s) voir chat
- tapcocu_org – 215 message(s) voir chat
- vitalityhp_net – 73 message(s) voir chat
- vsainc_com – 21 message(s) voir chat
- wabteccorp_com – 39 message(s) voir chat
- wcinet_com – 34 message(s) voir chat
mount-locker
- 20201016 – 60 message(s) voir chat
trinity
- 0001 – 2 message(s) voir chat
- 0002 – 52 message(s) voir chat
- 0003 – 298 message(s) voir chat
- 0004 – 170 message(s) voir chat
- 0005 – 14 message(s) voir chat
- 0006 – 11 message(s) voir chat
- 0007 – 36 message(s) voir chat
- 0008 – 13 message(s) voir chat
- 0009 – 6 message(s) voir chat
- 0010 – 8 message(s) voir chat
- 0011 – 50 message(s) voir chat
- 0012 – 15 message(s) voir chat
- 0013 – 32 message(s) voir chat
- 0014 – 6 message(s) voir chat
Victim
> hi how much for decryption?
Akira
> Hello. You've reached an Akira support chat. Currently, we are preparing the list of data we took from your network. For now you have to know that dealing with us is the best possible way to settle this quick and cheap. Keep in touch and be patient with us. We will reach out to you soon. Do you have a permission to conduct a negotiation on behalf of your organization? Once we get a response you will be provided with all the details.
Victim
> yes
Akira
> List.7z // 141 KB
Akira
> These files were taken from your network prior to encryption. You can pick 2-3 random files up to 10 MB each from the list and we will upload them to this chat as a proof of possession. To prove that we can properly decrypt your data you can upload 2-3 encrypted files up to 10 MB each to our chat and we will upload decrypted copies back. We're looking through your financial papers to come up with a reasonable demand to you. We offer: 1) full decryption assistance;
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future. Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future. Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
Victim
> we need the decryptor. evidence of data removal, and guarantee to not publish or sell data
Akira
> We will let you know the price soon.
Akira
> We're willing to set a $600,000 price for ALL the services we offer. We accept payments in BTC. To gain bitcoins you need to go to any exchange platform as binance or coinbase. Here are the guides: https://www.coinbase.com/how-to-buy/bitcoin
https://www.binance.com/en/how-to-buy/bitcoin You also can buy bitcoin from any local brokers. If you withdraw funds from your bank account, then you have to inform the bank that you need this money for investment purposes only. Do you have any file requests?
https://www.binance.com/en/how-to-buy/bitcoin You also can buy bitcoin from any local brokers. If you withdraw funds from your bank account, then you have to inform the bank that you need this money for investment purposes only. Do you have any file requests?
Akira
> Are you going to work with us?
Victim
> yes. the VMs are encrypted so hard time to get to the file to provide sample.
Victim
> can we give you a directory and file name and you can provide the file as proof of possession?
Akira
> Yes, please do asap.
Victim
> yes, the team is looking at the list to pick out file to show proof of possession.
Akira
> Any success?
Victim
> yes, they are sending directories to me soon and i will send to you.
Victim
> F:\[redacted].com\unpack\[redacted].docx
Victim
> F:\[redacted].com\unpack\[redacted].pdf
Victim
> F:\[redacted].com\unpack\[redacted].csv
Victim
> F:\[redacted].com\unpack\[redacted].html
Victim
> hello? we are ready to work with you for payment.
Akira
> files.rar // 214 KB
Akira
> You can review. Do you want to test our decryption tool before payment?
Victim
> yes, can we test the decryption tool?
Akira
> Sure. Provide the files today.
Akira
> Hello. Have you managed to gather files?
Victim
> sorry. this site was offline for a while
Akira
> Now it is on. Where are the files?
Victim
> how much for just evidence of data deletion and not leaing data?
Victim
> we will pay
Akira
> $320,000 for the rest options.
Victim
> No cyber insurance. Can you work with us? can we do $35,000? We can get you paid today if so.
Akira
> No. You have to be serious. $35,0000 won't work at all. Please reconsider asap.
Victim
> yea. just evidence of deletion and not leaking data. what about $95000?
Akira
> $260,000 if you pay today.
Victim
> we can do $155,000 today.
Akira
> $220,000 today. Here is our BTC wallet [redacted]. Let us know when you are ready to make payment.
Victim
> we can't do 220K. we're already loss of business because you entrypted us and we are shut down. let's get you paid. $160,000 today.
Akira
> Don't tell us stories. $200,000 is the lowest we can accept. Take it or leave it.
Victim
> it's the truth but we want this over with. let's meet in the middle at $180k. say yes and we are sending to [redacted]
Akira
> Guys, we've already reduced the price significantly. $200,000 is the lowest possible.
Victim
> yes and we appreciate it. let me check to make sure we can do that.
Victim
> ok. we are buying the BTC to send over.
Akira
> What's your progress?
Victim
> we'll have it today. delay with bank. we will let you know when we are sending. we will first send a smaller amount to confirm receipt.
Akira
> Standing by. Thank you.
Victim
> still waiting on bank. thank you for your patience
Akira
> Waiting.
Victim
> yep we are still waiting on bank transfers to complete
Akira
> Keep us posted.
Victim
> will do. still waiting on bank
Akira
> Any success?
Victim
> yea, we have the money. purchasing BTC now. can you resend your wallet again? we will send $500 first to make sure you get it. then we will send the rest.
Victim
> $500 sent to [redacted]. Confirm reciept.
Akira
> 0.005 received. You can proceed with the full amount.
Victim
> how will you provide evidence of data deletion?
Victim
> can with get video evidence of data deletion?
Akira
> You will receive a deletion log which means the raid drives that contained the only copy of your data are fully formatted and erased.
Victim
> and guarantee that no data is leaked?
Akira
> Sure. Guarantees will be provided as well. Are you going to send the rest?
Victim
> yes, sending now.
Victim
> the send is under review.
Victim
> rest of the money has been sent over. please provide deletion logs.
Akira
> Received. Please wait.
Akira
> Deletion.7z // 316 KB
Akira
> Initial access to your network was purchased on the dark web. Then kerberoasting was carried out and we got passwords hashes. Then we just bruted these and got domain admin password. Spending weeks inside of your network we've managed to detect some fails we highly recommend to eliminate: 1. None of your employees should open suspicious emails, suspicious links or download any files, much less run them on their computer.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc. We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc. We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
Auteur/autrice
sdgadmin@tux.ovh