MonsterCloud CEO Disguised Ransom Payments as Proprietary Tool, Say Prosecutors
A ransomware service that offered clients an extortion-free shortcut to unlocking their files was too good to be true, say U.S. federal prosecutors who say the secret behind Florida-based MonsterCloud was actually succumbing to hacker demands and paying a ransom to attackers, at victims’ expense.
See Also: A Prescriptive Guide to Cryptographic Compliance, Audit Readiness, and Post- Quantum Resilience
MonsterCloud owner Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” falsely claimed he had a proprietary “recovery tool,” prosecutors said. But from June 2018 through June 2023, instead of delivering this “principled alternative to paying off ransomware attackers,” the company directly negotiated with ransomware groups to obtain a decryptor, fraudulently charging customers a premium for doing so, said the U.S. Department of Justice.
A federal grand jury on Sept. 23 returned an indictment charging Pinhasi with two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a maximum penalty of 20 years in prison.
Pinhasi, a U.S. and Israeli national, appeared in a New York federal courtroom Wednesday, where he pleaded not guilty to the charges in the indictment and was released on a $2 million bond. The prosecution and defense told the court on Wednesday that they’re currently discussing a plea deal.
Investigators say he paid ransomware groups $8 million in ransoms to recover data on behalf of hundreds of clients in the United States and Canada, charging those victims $19 million, and in many cases never telling his firm’s clients that it paid a ransom.
“This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help,” said Assistant Director James C. Barnacle Jr. of the FBI.
Prosecutors said the company typically employed use of a two-phase approach. In the initial “analysis” phase, the company would typically charge a victim between $2,500 to $10,000 to demonstrate that they could recover the data. According to court documents, MonsterCloud did this by submitting a sample file or two from a victim’s system to the ransomware group that encrypted it in the first place, and receiving back a decrypted version.
Ransomware groups typically offer such “recovery proofs” for free in the initial stages of a negotiation, as an incentive to a victim to pay the ransom and recover much more of their data.
If a client chose to continue, in the second phase of an engagement, to provide “full” ransom recovery, prosecutors said MonsterCloud would typically quote the victim a price of up to two times – or more – of whatever amount they’d already negotiated with the ransomware group for a decryptor.
According to court documents, Pinhasi’s company in August 2023 paid a $8,200 ransom to a ransomware group and charged the victim $150,000 for data recovery, and in an October 2021 case, paid a ransom of $236,000 and billed the client $380,000. “Pinhasi typically did not disclose to MonsterCloud’s clients that ransom payments had been made or the difference between MonsterCloud’s fees and the ransom payment,” according to the indictment.
In fact, prosecutors said MonsterCloud often pledged to not pay criminals. “Multiple clients engaged MonsterCloud specifically because those clients did not want to pay a cybercriminal and would not have authorized any payment to a cybercriminal,” according to court documents.
Some of the company’s contracts did say it might contact a ransomware group directly, but “only once all possible means of directly decrypting a client’s files have been exhausted,” according to court documents. But prosecutors said contacting the ransomware group was typically MonsterCloud’s first step in any client engagement, followed by obtaining free proof of decryption and then paying a ransom.
The FBI and U.S. Cybersecurity and Infrastructure Security Agency continue to urge ransomware victims to never pay a ransom.
Click Here For The Original Source.
