Ransomware negotiation(s) with  mount-locker



Greetings! We are ready to help you! What are your problems?

2020-10-16 17:33:32
Avatar

What happened? The bad news is that we have hacked your network and encrypted your servers. We have also downloaded more than 500GB of your private data including financial, contracts, databases and other papers containing SSN DOB addresses and other private customers info. In case of publishing this data you will have huge legal and government fines. The good news is that we are businessmans and we want to get a ransom for everything to unlock and keep in secret.

2020-10-17 04:21:17
Avatar
Avatar

[redacted]

2020-10-21 19:18:15

We're confused about your message. We'd like to start negotiations. Would you like to protect this chat with password to avoid unauthorized access?

2020-10-21 20:49:47
Avatar
Avatar

How do we start negotiations?

2020-10-22 05:53:00

Glad to see you,your price for decryption and data removal is $9'000'000. We have somewhat about 1TB of financial reports, contracts etc. downloaded.

2020-10-22 08:47:16
Avatar

You can also protect our chat from untrusted staff with a password. Just ask us and we will open protection feature for you.

2020-10-22 08:47:40
Avatar

Please, be careful - if you try to decrypt or change your files - you will destroy all the information. We hope to reach an agreement. Thank you.

2020-10-22 08:56:02
Avatar
Avatar

That price is very high for us.

2020-10-22 15:43:14

Of course, the price is high, but it is much, much more cheaper, than pay to all the lawsuits, that your clients will send to you, because you have lost so much of their data. Companies of your size can lost tens of millions in such cases. https://www.zdnet.com/article/easyjet-faces-18-billion-class-action-lawsuit-over-data-breach/ this is one of the examples

2020-10-22 16:22:23
Avatar

We also inform you that before payment you can decrypt any file not exceeding 5MB as a test, we are also ready to provide a small amount of data downloaded from your network. In the future, after payment, we will provide you with a complete log tree, information on how the attack was carried out, as well as comprehensive recommendations from technical specialists. We also guarantee the deletion of all downloaded data and the provision of decryption keys for your entire network.

2020-10-22 21:25:17
Avatar

In case of refusal, all information will become public (including confidential) http://mountnewsokhwilx.onion/, the recovery keys will be deleted. We also remind you that your time is limited ...

2020-10-22 21:28:48
Avatar
Avatar

We want to handle this in a professional way. To avoid confusion please only communicate with us on this website only, and stop all other communications to us outside of this chat. The price you suggest is too high. We would like to come to an agreeable term to clear this up quickly.

2020-10-23 02:27:10

We appreciate your desire to resolve this situation quickly and are waiting for your specific proposals?

2020-10-23 10:07:41
Avatar
Avatar

Thank you for your professionalism. We researched your group and we know you are serious people. Please please understand that between COVID and the California Wildfires, our revenue is already decimated this year. This is just going to do us in. Our staff have been through a lot. We would hope you would keep that in mind when offering any kind of discount. The amount you have asked is just huge. We don’t have that kind of money available. Is there anything we can do to move this to something more achievable?

2020-10-23 21:32:14

Unfortunately, COVID-19 has affected all industries, but we sincerely hope that you will not only recover in the near future, but also earn much more. We made you the best offer, but I never heard from you the opposite (taking into account all the circumstances) ...

2020-10-23 23:55:01
Avatar

Here we prepared some proofs. https://privatlab.com/s/v/[redacted] pass: zxcffk)(*&%$#!@#$%^&*UH,;l;l

2020-10-25 07:30:21
Avatar

Just small amount of your private data, including claims, personal info, contacts with mobile phones, addresses, date of birth, therapy and other sensitive data. Head of your partners companies, which surely be happy of their personal info got published online. They all have lawyers and they like courts, which very like legal fines.

2020-10-25 07:32:56
Avatar

Amount of money we want is just a small piece of your possible losses including but not limiting direct expenses such as payments for data recovery, dramatic cash flow drop, legal & government fines, attorneys & lawyers interests, but also reputation impact resulting in long-term customer abandonment.

2020-10-25 07:46:12
Avatar

But there is another option. After payment you get decryptor tool returning you in business within 1-2 hours (with instruction), security report with advice how to prevent such incidents in future, full directory listing of your stolen private info, complete data deletion. No data will be posted ever. Everything will be kept in secret.

2020-10-25 07:51:52
Avatar

According to your financial reports your situation is much better than you say. As a group with an estimated yearly revenue ~$1billion you have enough money to pay us.

2020-10-25 09:19:04
Avatar
Avatar

We have researched your group and your capabilities. However, your revenue numbers for our company are incorrect. Yes, everyone was hit with COVID, but my staff was forced to evacuate due to wildfires, and even after, we could barely breathe the air outside for weeks. We would ask that you consider $900,000.

2020-10-26 02:07:38

We don't think, that our estimates are incorrect. Your financial reports are somewhat more reliable, than your word here and now. And your proposal here is just from the textbooks - ten times less, than our initial demand. It seems, that you do not understand, how works our group. We don't ask $90 millions, to receive our demand of $9 millions. Evacuation of your staff due to the wildfires, and complain about breath is not worth 90% of the demand. For now, it does not worth even 5% of our demand, before we get some real proposal. So you should understand, that our team have plenty of projects running, and yours - just one from many. If we don't reach an agreement, we'll just shorten our profit. And on other hand, you would be ruined. That is much more serious threat, than the wildfires. We'll wait for your proposal. Sincerely, yours.

2020-10-26 11:53:59
Avatar
Avatar

Thank you for getting back to us so quickly. We can tell how professional you are. Please understand that the financial numbers you are looking at are in Indian rupees – NOT US dollars. That is a huge difference. Your current demand is just not something our company can afford. I am trying to convince my board to make a better offer to you and we are looking to make a deal with you for sure, but we need you to please work with us. There must be a lesser amount we can pay you.

2020-10-26 20:52:27

Of course, we too want to work with you. And of course, we can talk about a lesser amount. But to start to rapidly move in that direction, we want to see a good, respectful starting offer from you. Please understand, that sum of about 1 million is regarded as an insult by my bosses. So we look forward to continue our negotiations on more acceptable terms.

2020-10-26 21:41:42
Avatar
Avatar

Thank you for your consideration towards a lesser amount. Please let me discuss with the board of directors to understand what may be viable

2020-10-27 01:26:01

OK, lets see what you can offer. And JFYI - we know that your financial reports are in [redacted currency] and we know exchange rates. We have also have huge experience in that business and understanding how much your private data costs including sources of you software which could become public via github. Anyway both of us are business people and count money very well.

2020-10-27 13:33:01
Avatar
Avatar

We are trying to get together resources to make a better offer, we appreciate your patience.

2020-10-27 22:29:58
Avatar

We’ve discussed this with the board and our finance team. We can pay $1,746,800. Getting an extra $846,800 was not easy. It required the approval of all board members. It took time for us to convince all members. We believe it is a fair and reasonable offer and it will be very difficult to get any more for you.

2020-10-28 18:32:27

Thank you for your efforts, now I see, that we can start moving towards you. It is fair and reasonable FIRST offer, and I glad, that we have now a chance to successfully negotiate. We are ready to make a discount of 1 million US dollars, so your price is now $8'000'000. Of course, we understand, that your work here is not easy and requires efforts to convince your board members. But we are still far from agreement. Our estimates are still much higher, than your proposal. We hope, that you will give us better price. And since it is our mutual interest to speed up our negotiations as much, as we can - take more serious steps toward us. It would be much easier than for us to make steps to you in response.

2020-10-28 20:58:39
Avatar
Avatar

Thank you for your response and your willingness to negotiate with us. I got a lot of pushback trying to find more funds. We just found out our insurance does not cover this cost, so all money is coming from our reserves. We were already dealing with dwindling revenue and clients are not signing new contracts. This is very difficult. Please, $2,350,000 and we can get this done.

2020-10-29 15:55:57

We've discussed your proposal with team, and we are ready to make another discount. Understanding that you have some issues with signing new contracts, your price is now $7'500'000. Of course, we are ready to move on further, depending on your offers. Time is crucial here, so the more serious steps you will take in our direction, the faster we will get an agreement. We understand, that any downtime of your business is not in your interests, it is quite costly. Possible losses, however, are much more expensive. But in fact, your downtime is not in our interests too, I can assure you. We know, that you have insurance, reserves, and possibility of loans. Your overall reserve is quite better, than your proposal. Make better offer, and we will move on.

2020-10-30 11:26:06
Avatar
Avatar

Thank you for your response and your lower price. We appreciate how professional you are. I am going back to my board now, but the last request took a lot of time and effort. You said you have 500gb of our data. Is there proof you can give me that I can take to my board to help try to get more funds?

2020-10-30 16:53:40

2020-10-25: https://privatlab.com/s/v/[redacted] pass:[redacted] Thank you for keeping in touch. We've already sent you proofs. Private data (like SSN, DOB) of your staff, data of clients, their diagnoses and your top-management data, source codes of your projects are not enough? We perfectly understand, that you are following the tutorial, no offence by that. Staff data doesn't worth anything for you. But if you need some points for your board... You already have issues with your dwindling revenue and shortage of new contracts. But if we will just say for a moment, that there is an announcement on our news site (and the rest of the cartel news sites), that your company had lost private data of your US customers, and source codes of your clients... US part of the revenue will go to zero, just as number of possible new contracts. We've already done such things before, and our "customers" were forced to face the grim consequences. We think, that there is no point in efforts to display more proofs. Situation is perfectly clear and we're already in the middle of negotiations. Of course, we just want to make money, and not to destroy business of our clients. We hope, that your board have enough commerce sense to make right choices. We're waiting for another good offer and are ready to move towards you, if it is good enough.

2020-10-30 21:26:38
Avatar
Avatar

Thank you for your willingness to negotiate and continue working with us. This is very difficult for me. I have never been under so much stress ever. Please, we are getting to the point where our finances are very pressured with the loss of business. Our board is eager to get this done and has approved up to $3,095,400, This a big increase and a very good offer to you. Can we please settle at this number?

2020-10-31 16:15:44

We've discussed your offer with team. As a token of respect for your efforts to move on our negotiations, our boss had approved huge discount of $2'500'000 to speed up our bargaining. Your fast responding made such terms real. So as we make serious step to you, your price is hold now at a point of $5'000'000. We think that as a fair offer in comparison to your possible losses. Let us be professionals and settle at this number. We look forward to your answer.

2020-10-31 23:21:01
Avatar
Avatar

First, thank you very much for being reasonable. I believe that we are very close here. I only have certain authority. Anything more will take more convincing and more time. If we could settle at $3,771,100 (the exact amount of everything that I have been able to locate for you), we can get you all the money or crypto as soon as tomorrow (Monday). (It is Sunday today). If you require more, I will need more time. Please can we make this a deal for $3,771,100?

2020-11-01 20:50:19

We see that we are very close to a deal. Lets make an additional discount and total amount will be $4,500,000.

2020-11-01 21:08:24
Avatar
Avatar

Thank you for being so reasonable. You have me at my very end. I have gotten every authority I can get. There is no more. I have $4,110,500 to pay you. This is a huge amount of money – much much more than I ever imagined when we began. Please confirm that for this amount, we will receive ALL decryption keys and your technical recommendations, a list of all our files you have taken, evidence from you that all our files you have taken are permanently deleted, and some kind of report from you explaining how you got into our system.

2020-11-02 19:01:23

We will provide you with a bitcoin wallet here in the chat. - Then you have to send 1 bitcoin to our wallet for verification only. After we confirm this transaction, you can send the entire amount. - After receiving the first confirmation about the blockchain, we will permanently delete Leak Publication and provide you with decryption software, usage guide and access to a file vault with all your data. We will also give you recommendations for improving security measures.

2020-11-02 20:33:41
Avatar

This is your bitcoin adress [redacted]

2020-11-02 21:54:54
Avatar

Please advise how to send the first part of the payment.

2020-11-02 21:57:20
Avatar
Avatar

Can you confirm that we are settled at $4,110,500?

2020-11-03 14:32:35

Yes, we are settled at this number.

2020-11-03 15:11:49
Avatar
Avatar

Thanks we are working on getting the funds transferred.

2020-11-03 20:42:40

how long do you need?

2020-11-03 20:54:54
Avatar
Avatar

At current market prices, the amount will be 298.5 bitcoin. Do you agree to that amount?

2020-11-03 22:07:45

Yes that's right

2020-11-03 22:27:05
Avatar

We see the first transaction and confirmation. It is OK to send full amount now.

2020-11-03 23:47:13
Avatar
Avatar

Ok. Sent payment.

2020-11-04 00:12:06

Yes we see a transaction. After getting confirmations you will receive unlocker immediatly.

2020-11-04 00:14:13
Avatar

Gentlemen, we have received your payment. To unlock your systems, we send you an executable file. For correct operation, please disable all antiviruses, including windows defender, and then run it on all blocked machines. A little later, the swami will be contacted by our technical specialist who will provide a log tree and give advice.

2020-11-04 00:32:24
Avatar

You link for unlocker: unlocker.zip

2020-11-04 00:34:18
Avatar

Here is a Mega cloud account of your private data: [redacted]@protonmail.com [redacted]

2020-11-04 00:39:20
Avatar

You can safely remove data and download a file tree. If you need any support - please note us, we will help you with everything.

2020-11-04 00:40:56
Avatar
Avatar

Thank you for working with us. We received the tool and the link. When do you think you will be ready to deliver the log tree and give us advice? We would like to take your offer to support us.

2020-11-04 21:45:13

With the message above, you have gained access to your file tree.I repeat, go to mega.nz use login [redacted]@protonmail.com and password [redacted] then safety delete your date. A little later, you will receive a report on how the attack occurred and recommendations for protection. Please be patient.

2020-11-04 22:20:43
Avatar

Have you unlocked your files? Have you successfully opened mega.nz account? Do you need any other help? We will delete this chat forever soon.

2020-11-06 23:22:06
Avatar
Avatar

Please confirm that you did not publish or keep any copies of our data. Also, you said you would tell us how you got into our system. How did you breach us?

2020-11-07 22:46:02

Of course, we confirm, that we will not publish, or keep any copies of your data. For the breach report please wait for our tech team, they will answer you in 1-2 days.

2020-11-08 11:39:43
Avatar

This information is provided by Valéry Marchive