Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

MonsterCloud's owner is charged with passing off purchased ransomware keys as proprietary decryption

MonsterCloud owner Zohar Pinhasi is charged with paying ransomware gangs over $8 million for keys while billing victims over $19 million. The charges turn on when the firm paid, so a recovery contract has to fix the order of steps and the source of any sample decryption.

The Watch · Security desk

How we use AISend a correction

What happened

  • Pinhasi faces one count of conspiracy to commit wire fraud and two of wire fraud over a scheme prosecutors say ran from June 2018 to June 2023.
  • He surrendered Wednesday, pleaded not guilty and was released on a $2 million bond, the U.S. Attorney's Office told BleepingComputer.
  • MonsterCloud, a Florida company, advertised tools and decryption techniques for recovering encrypted data without paying cybercriminals.
  • Prosecutors allege it had no such technology and instead paid ransomware operators for keys, then used those keys to restore customers' files.
  • The decrypted sample files MonsterCloud showed victims as "recovery proofs" came from the ransomware operations, the indictment alleges.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision MonsterCloud's contracts already allowed for paying attackers, so a buyer relying on paper needs terms on when payment can happen and who produced any sample decryption offered as proof.
  • cost On the indictment's headline figures, victims paid about $2.40 for every dollar that reached the gangs.
  • exposure Hundreds of U.S. and Canadian companies that hired MonsterCloud between 2018 and 2023 may have funded ransomware operators while believing they had avoided paying them.
  • precedent Nocella's office says it will pursue those who "cynically profit" from ransomware alongside the attackers, putting paid recovery intermediaries inside its stated scope.

The indictment acknowledges that some MonsterCloud contracts told customers the firm might communicate with or pay cybercriminals [7]. A customer who read one found a payment clause with a condition attached: the firm would contact attackers only if it could not decrypt the files by other means [7]. Prosecutors claim that contact was usually the first step [8].

A victim could not test that condition with the sample files. A decrypted sample shows only that someone holds a working key, and prosecutors say that someone was the gang [12].

The indictment gives two worked examples of the spread between what reached the attackers and what the customer paid. In one, MonsterCloud allegedly paid a gang about $8,200 and billed the victim about $150,000 [10], roughly 18 times the ransom [20]. In the other it allegedly paid about $236,000 and billed about $380,000 [11], a difference of $144,000 [21].

"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella Jr. said [9]. A federal grand jury in the Eastern District of New York returned the indictment on September 23 [2]. If convicted, Pinhasi faces up to 20 years in prison [14].

The allegations match public reporting from 2019. ProPublica reported then that MonsterCloud sometimes paid ransomware operators while claiming to offer a solution other than paying the attackers [16]. Pinhasi disputed that the company had promised in advance it could decrypt files and denied misleading customers. He told ProPublica its methods varied by case and declined to disclose them [18]. Prosecutors say the scheme ran until June 2023 [3], four years after that reporting [23].

The ProPublica piece included a test. Security researcher Fabian Wosar told the outlet that he and another researcher built their own ransomware and approached recovery companies posing as victims, using ransom notes that carried email addresses the researchers controlled [17]. Offers to pay the ransom arrived at those addresses from anonymous senders, and Wosar traced them to firms including MonsterCloud and Proven Data [17]. The test and the indictment cover only the firms they name. Neither measures how common the practice is among recovery vendors.

What to watch

  • A response from Pinhasi's attorneys, Christopher Clark and Rodney Villazor, whom BleepingComputer has asked for comment.
  • Whether prosecutors charge the co-conspirators the indictment says worked with Pinhasi.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories