勒索信文件 : BLACKOUT_NOTE.pdf
BLACKOUT_NOTE Dear ***, unfortunately, you’re out of luck - your local network is encrypted, and confidential information has been uploaded to external servers. Please read the text below carefully and consider all possible scenarios. If you are a technical specialist without the necessary credentials, please provide this file unmodified to company management. (!) Do not convey the basic essence in words, this will interfere with the understanding of the situation and can decide the fate of the entire company. What Happened You have fallen victim to an attack by an organized hacker group. We spent a significant amount of time inside your local network - reading your emails, accessing internal files, and compromising multiple workstations and servers. This was not an automated attack. Encryption We have encrypted the majority of your critical infrastructure and destroyed all accessible backups. Without our assistance, you will not be able to recover the encrypted files - this will severely disrupt your business operations. About decrypting the files Encryption Details Your files have been encrypted using RSA-2048 asymmetric encryption. Without the private key which is exclusively in our possession and was never stored on your network - recovery is impossible. Beware of Scammers Many fraudulent actors claim to offer decryption services. Do not waste your time or money - they cannot help you. Proof of Decryption When you contact us, we will decrypt several sample files that you provide us for free, proving that: 1. Decryption is possible. 2. We hold the only valid key. You can provide absolutely any encrypted file, we could not download your entire network, so we cannot take it from our copies. ANY INTERACTIONS WITH THE FILES MAY CAUSE THEM TO BECOME CORRUPTED, WE CAN'T HELP YOU WITH THEM AFTER THAT, MAKE BACKUPS IF YOU WANT TO EXPERIMENT WITH THEM. For *** We were on your network for a couple of months, it was extremely difficult to move deeper, you have good password management, especially for Linux hosts, but everything became easier after capturing a couple of jumpservers. We are sure that most of the backups were deleted, ordinary workstations of which a couple of thousand were not backed up in any way, most of the tape media were damaged and recovery from them is impossible. Not all, but a large proportion of Linux hosts are also in poor condition. In general, corporate processes are frozen for an indefinite period, which is why you are already losing a lot of money. Stolen sensitive data Second Critical Point: We have copied significant amounts of your sensitive data to our servers and will publish everything unless we reach an agreement. The immediate consequences include: Severe reputational damage Operational risks from leaked source code containing security vulnerabilities Exposure of customer databases (including names, email addresses, and passwords) Vulnerability to follow-up attacks as other threat actors exploit the leaked data For *** You have an incredibly huge network, of course we couldn’t copy even a couple percent of the files from it, but we tried to take the most valuable. oa.***.com Source files, deployment .war files and of course the dump of the oracle database from ***, it is large, some garbage tables were truncated. ***File Encryption System It was critical to take this with you otherwise many of the files would be unusable. We took the server and client sources (from the workstation of one of the admins, it seems ***, although he is generally evil, we never penetrated ***), installers and of course a database dump with cryptographic keys for decryption (***). We have not done this, but we are confident that with this data posible decrypt any of your CDG files. *** peoplesoft Here was the data of all your employees, more than *** records, their addresses, numbers, personal emails, and many had identification documents. There is also a lot of interesting information about the company’s assets. This system is some kind of IT hell, but we found the complete database - ***. *** dump, also without a couple of garbage tables. *** customer management system *** database dump, .war application file, part of the attached files. There are data on contracts, information about other companies, etc. In theory, your competitors might like it. pan.***.com We did not have full admin access to this system, although we tried very hard, the admin definitely received a couple of notifications on his phone. However, we were able to gain full access to many important shares. We copied *** files from DepartmentShare, office documents, photos, spreadsheets, documentation, etc. Our Offer We offer the following: Full decryption tool - Complete recovery of all your encrypted files Complete data deletion - Permanent removal of all stolen files from our servers, with guarantee that no copies were shared with third parties Non-attack guarantee - We will not target your organization in the future Optional security report - Detailed breakdown of our infiltration method and security recommendations to prevent future breaches Price: *** This is *** of your annual revenue, you will definitely lose more without dialogue with us. Possible scenarios and risks The possible scenarios are globally 2: You agree to our deal. We understand that there is a risk that we will not fulfill our obligations after payment. We can take a logical approach to this issue. We offer you to decrypt some files for free, so we have a decryptor, to pass it to you is just to send an exe file, even easier than decrypting your test files, we have no reason not to do it after payment, on the contrary otherwise we will lose reputation, not only ours, but the whole sphere, you can search for such cases almost never happened. Also we can not delete your files, it also has little sense, we want from you hundreds of times more money than you can get from these files. We may try to attack you again, but we hope that you will make a conclusion from this situation and will better protect your network and even if not, most likely you just will not pay a second time, why should we waste our efforts. You're not accepting our deal. You can contact cybercriminalization companies, your government services, ask for a tax deferral, you may be able to protect your network, you may be able to put some EDR for a lot of money, but the underlying problem will not go away, your files will remain encrypted, and important information will be publicly available. There is also the risk of repeated attacks, we may realize that you don't want to cooperate and slam the door very loudly. How to contact us We have our own portal on the Tor network. Visit our site on the Tor network: You will need to download the Tor Browser. *** Our portal URL: *** Then you can log into your personal account, there will be more information and chat with support. Your COMPANY_ID for login: *** If you have problems with Tor, you can write to us directly in TOX Chat: *** ToxID: *** In tox, the dialog connection works directly without servers, try to keep the application always running. We are unlikely to respond instantly, but we will respond within 24 hours, stay tuned. Deadlines If you enter into dialogue, we will freeze all timers for the duration of the negotiations. *** We will make a post about your company (without the ability to download your files), the specialized media will notice this and you will have additional problems. It would be best to write before this time if you want to cooperate. In your case, things get complicated by the fact that you have stocks trading on the American exchange (***), and the publication of the news will definitely affect them. *** We will publish all your data. Further negotiations are impossible. We are waiting for dialogue.