Choose your location

Latest
Congress will continues its stir until CEC resigns: Hooda Mount Anak Krakatau Eruptions Intensify, Alert Level Raised to 'Watch' Artemis-II astronauts saw mysterious island of light on the Moon as they flew close $1,000,000,000,000: Cost of serving the debt storm in developing countries INDIA Bloc Protest Live: Fresh FIR against Rahul Gandhi, Priyanka over alleged assault, obstruction during stir Northern Ireland Assembly - Urgent Question on the First Minister on BBC Parliament: full details and when it's on

Feds Say Ransomware Expert’s Miracle Cure Was Just Paying the Hackers

Zohar Pinhasi spent years telling ransomware victims his Florida company could get their files back without paying the attackers. But federal prosecutors now say Pinhasi’s firm simply paid the ransoms on...

Gizmodo @kyletorpey

Zohar Pinhasi spent years telling ransomware victims his Florida company could get their files back without paying the attackers. But federal prosecutors now say Pinhasi’s firm simply paid the ransoms on behalf of victims at marked-up prices. Pinhasi, 50, a U.S. and Israeli national from Hollywood, Florida, was arraigned Wednesday in federal court in Brooklyn on two counts of wire fraud and one count of conspiracy to commit wire fraud.

He owns MonsterCloud LLC, which the charging document calls a purported ransomware remediation company. Each count carries a maximum of 20 years. FBI Assistant Director in Charge James C.

Barnacle Jr., who leads the bureau’s New York field office, said, “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center.” Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond, the U.S.

Attorney’s Office told BleepingComputer . How the MonsterCloud Ransomware Remediation Business Allegedly Worked The indictment says the MonsterCloud website claimed “our team specializes in helping businesses recover their data without succumbing to ransom demands,” and that the firm did it with “advanced decryption techniques and cutting-edge technology” and “proprietary tools.” Paying a ransom, the site warned, would not guarantee any data would be recovered, might invite another attack, and reward illegal behavior.

Multiple businesses hired MonsterCloud specifically because they did not want to pay a cybercriminal and would not have authorized a payment, prosecutors allege. Many of them came in through the Contact Us form on the website, which the indictment treats as evidence they had read the firm’s marketing pitch.

The companies were often struggling to operate or suffering financial losses because ransomware had locked them out of their files. Hundreds of them, in the United States and Canada, eventually paid the firm. Prosecutors say neither Pinhasi nor the employees and contractors they describe as co-conspirators had a specialized decryptor.

Instead, Pinhasi set the prices and handled ransom payment negotiations with the attackers. After a controller took the intake, MonsterCloud quoted an analysis phase, typically $2,500 to $10,000, with a money-back guarantee. Next, the client handed over the details of their case, usually with two encrypted sample files.

Continue reading

Watch a short ad to unlock the full article

The rest stays locked if you skip or close the ad early.

Article text via FreeNewsAPI. Rights remain with Gizmodo.

Read on publisher site → Opens Gizmodo in a new tab

More in India