back

by zorked·5y ago·view on hn ↗
I negotiated for a friend in a small ransomware case. They paid $2k. Yes, reputation is important, I did some research to check whether others had successfully negotiated. If you get a reputation for not delivering nobody will negotiate with you. Likewise if you have a good reputation the amount of money people are willing to risk on getting their data back goes up, and that's good for business. It's also a reason why the ransomware was very clearly branded.

It's criminal but the principles of business still apply.

1 comments
I may been a bit glib in my original post, but is there actually a website where ransomware gangs reputation are tracked?
In our case I googled the email address that was left in every folder and read forums on how their users dealt with it. We negotiated $2k to $400.

My company bought a small business and it happened next day. A hole in RDP that was simply open to the internets. No backups, no failover, just a regular business, you know. Partially my fault, as this thing should have been evaluated/fixed before the deal. Convincing the owners that it wasn't me (I just got an administrative password) was a separate fun.

Seems like it was an inside job if it happened the same day.
Unlikely, all things considered. With default port RDP on the internet it is just a matter of time, and then of a coincidence.
For $400 or even $2000? That's an awfully small payout for an enormous legal risk.
Yes, but multiply the ransom by multiple small, low ransom targets, as is commonly the case with groups taking a more diversified approach of targeting many small companies in the same attack type, partly depending on such small ransom demands to individually not even be reported to investigating authorities, and getting at least a partial ROI. This opposed to making a huge single demand from one large company that almost certainly causes your ransom attempt to trigger a police investigation and the not small chance of the company simply deciding not to pay, leaving you with 0 for that particular effort.
What about if it had happened 2 days later? or 3?

What's the magic number to make you think that it was/wasn't an inside job?

Even if there isn't, you can still probably copy and paste part of the ransomware message into Google and find stories of other people that interacted with them.