Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Negotiation Chat — Nightspire

Negotiation chats provided by Valéry Marchive and Julien Mousqueton.

Chat ID: 20250418

Victim
Hello. We received your note. Are you available to discuss recovery options?
2025-04-18
Hi. Yes, online 24/7. Price for full decryptor, master key + data deletion guarantee: 1 BTC.
Gang
We already exfiltrated 120 GB of your sensitive data. Payment within 5 days or publish starts.
Gang
Victim
1 BTC is impossible for us. We're a small-size manufacturing company. What's your realistic lowest offer?
We know your revenue from leaked docs — last year ~$1M. 1 BTC is only 10% — very fair.
Gang
But ok, show seriousness. Best we can do now: 0.8 BTC if paid in 72 hours.After that price increases 20% every 48 hours.
Gang
Victim
Still way too high. We consulted internally — board approved max budget 0.1 BTC for this incident.
Victim
We can pay that quickly if you prove decryption works. Can you decrypt 5 sample files first?
0.1? Too low, we reject. But we accept test decryption to build trust.Send up to 5 files (max 10MB each, different types/folders). After we return them decrypted, we talk serious discount.
Gang
Victim
Ok, uploading now:1. [redacted].nspire2. [redacted].nspire3. [redacted].nspire4. [redacted].nspire5. [redacted]_2024.nspire
Wait a mins.
Gang
https://gofile.io/[redacted]
Gang
Here are your 5 decrypted files. All perfect, no corruption.Now, with proof given — special price for fast deal: 0.75 BTC.Pay in 48 hours, we stop leak timer and send tool immediately after confirm.
Gang
Victim
Thank you for the test — files open fine.But that amount is still double what we can realistically do.We can counter at 0.2BTC. That's our absolute max, including recovery costs.
Victim
If you accept, we start BTC purchase today.
0.2? No, that's insulting after seeing your revenue docs.We can meet you at 0.7 BTC. Final offer for today only.We have buyers interested in your data already — automotive industry competitors.
Gang
Victim
We understand pressure, but bankruptcy isn't an option.How about 0.3? We can wire equivalent BTC within 24-36 hours.Also, can you provide more proof? Maybe decrypt one more critical file from a different server?
Ok, send one more file for second proof. Max 10MB.
Gang
After that — if you pay 0.6 BTC in 24 hours we close deal.No more haggling after this.
Gang
Victim
Uploading one more: [redacted].nspir
Got it. Decrypting... Returned decrypted.Everything checks out. Final price locked: 0.6 BTC.
Gang
Wallet: bc1[redacted]You have 24 hours.
Gang
Victim
We pushed board hard — they approved up to 0.5 BTC max.We pay immediately (within 12 hours).
Ok, 0.5 BTC accepted. You must pay in 12 hours. After that price increases 20% everyday.Send BTC to above wallet.Notify tx id here when sent.
Gang
Victim
Agreed on 0.5 BTC. Converting funds now.Will take ~8-10 hours for full amount.Please confirm timer paused.
Timer paused during negotiation/payment window. But if no tx by 12 hours total — resumes.Keep us updated.
Gang
Victim
Tx initiated. Hash: https://mempool.space/tx/[redacted]
Victim
Should confirm soon.
Good. https://gofile.io/[redacted]
Gang
You can find help.txt on our 7z file.
Gang
Victim
Downloaded and tested on test VM — decrypts sample perfectly.Starting on production servers now. Will update progress.
Good. We monitor chat for next 72 hours if needed.After full recovery confirmed by you — we permanently delete all data.
Gang
Victim
Decryption complete.
Victim
All critical systems back online. Thank you for the support.
Excellent. Data deletion has been completed on our side.
Gang
Logs wiped, no backups kept.
Gang
Victim
Understood. Closing this channel.
Victim
Thanks again.