
REAL Ransomware Chat Logs
Source: YouTube · John Hammond · published Oct 9, 2024 · 27:58
This video reveals the actual negotiation process between ransomware victims and cyber criminals through real chat logs, showing how attackers demand payment, threaten data leaks, and sometimes even explain how they compromised the victim's systems 0:00.
Key Takeaways:
• Ransomware operators follow a pattern of encrypting files, leaving ransom notes with dark web contact information, and pressuring victims to pay while threatening to publish stolen data 0:02
• Negotiations involve significant haggling over ransom amounts, with examples showing demands dropping from $3 million to $1 million as operators pretend to make concessions 1:58
• Attackers research victims' financial information including bank statements and cyber insurance limits to tailor their ransom demands appropriately 9:52
• Some ransomware groups provide "customer service" style interactions, offering proof of data possession and decryption capability before payment to build trust 9:22
• In certain cases, criminals even provide security reports explaining how they breached the network, such as accessing through dark web-purchased credentials and Kerberoasting attacks 19:49
These negotiations demonstrate how ransomware has evolved into a business-like operation with customer service, negotiation tactics, and even reputational concerns among criminal groups 19:23.
Sources:
- 0:00 Introduction to ransomware attack process and negotiations
- 0:02 Explanation of how ransomware attacks unfold
- 1:58(https://www.youtube.com/wat
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
what actually happens when your company is hit with ransomware obviously all your computers are locked and your files are encrypted and you want to decrypt your data so you might find the read me. text file or the ransom note on your desktop or in any of the folders and if you open that to follow the instructions the Cyber criminals and ransomware operators typically tell you that hey your data is stolen and encrypted and if you want it back you need to contact them on this Tour darket website a onion URL and you see a a good many up there for their blog or their leak site and ultimately they have you chat with them go talk to the ransomware support The Operators that are willing to have literal instant message slide in your DMs conversations on any of these tour onion links now these are …