MonsterCloud owner Zohar Pinhasi faces charges over alleged secret payments to ransomware attackers for decryption keys.
Pinhasi, 50, who also used the names “Zack Silver” and “Zack Green,” was indicted by a federal grand jury in the Eastern District of New York on September 23. He was arraigned in federal court in Brooklyn on Wednesday, surrendered to authorities, pleaded not guilty and was released on a $2 million bond.
What are prosecutors alleging?
Pinhasi owned and operated Florida-based MonsterCloud LLC, a ransomware remediation company that advertised tools and decryption techniques intended to help customers recover encrypted files without paying cybercriminals.
Prosecutors allege that Pinhasi and his co-conspirators did not have the proprietary decryption technology they promoted. Instead, they allegedly contacted ransomware operators, paid them for decryption keys and used those keys to restore customers’ files.
The indictment alleges the scheme operated from June 2018 through June 2023. Pinhasi faces one count of conspiracy to commit wire fraud and two counts of wire fraud.
How were customers allegedly charged?
According to prosecutors, MonsterCloud charged customers substantially more than the amounts allegedly paid to ransomware operators.
In one case cited in the indictment, Pinhasi allegedly paid a ransomware group about $8,200 and charged the victim approximately $150,000 for recovery. In another, prosecutors allege that about $236,000 was paid in ransom while the customer was charged approximately $380,000.
The indictment also alleges that some MonsterCloud contracts disclosed that the company could communicate with or pay cybercriminals. However, prosecutors say those contracts portrayed such contact as a step that would be taken only if MonsterCloud could not decrypt the files by other means.
Prosecutors allege that, in practice, communicating with and paying ransomware operators was often the company’s first step in obtaining decryption keys.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
What role did recovery proofs play?
Prosecutors allege that MonsterCloud used decrypted sample files as “recovery proofs” to persuade customers that it could restore their data. The indictment claims those files had actually been decrypted with keys obtained from ransomware operators.
Over the alleged course of the scheme, Pinhasi and his co-conspirators are accused of facilitating more than $8 million in ransom payments while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.
The allegations also echo concerns reported about MonsterCloud years earlier. A 2019 ProPublica investigation reported claims that the company sometimes paid ransomware operators while presenting its services as an alternative to paying attackers.
What did Pinhasi say previously?
During the earlier investigation, Pinhasi disputed the allegations. He denied that MonsterCloud had promised in advance that it could decrypt customers’ files and said its recovery methods varied from case to case.
He also declined to disclose the techniques used by the company, describing them as trade secrets.
The current federal case concerns alleged conduct between 2018 and 2023. The charges against Pinhasi remain allegations, and he is presumed innocent unless proven guilty in court.
If convicted, Pinhasi faces a maximum sentence of 20 years in prison.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics
