Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Negotiation Chat – lockbit3.0

Chat ID: Leaked2025-ClientID-36

You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat.

If your archive weighs more than 10 megabytes, please use our file sharing service.
http://lockbitfss2w7co3ij6am6wox4xcurtgwukunx3yubcoe5cbxiqakxqd.onion
http://lockbitfsvf75glg226he5inkfgtuoakt4vgfhd7nfgghx5kwz5zo3ad.onion
http://lockbitfskq2fxclyfrop5yizyxpzu65w7pphsgthawcyb4gd27x62id.onion
For security reasons we do not click on other links you send in chat.
Please wait for a reply, sometimes it takes several hours due to possible time zone differences.
2024-12-23 10:56:21
Gang Avatar
Victim Avatar
hello sir, can you help me what you need to decrypt my files?
2024-12-23 10:57:33
Victim Avatar
[redacted].pdf.usKv553SJ this is a sample file
2024-12-23 10:58:55
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat.

If your archive weighs more than 10 megabytes, please use our file sharing service.
http://lockbitfss2w7co3ij6am6wox4xcurtgwukunx3yubcoe5cbxiqakxqd.onion
http://lockbitfsvf75glg226he5inkfgtuoakt4vgfhd7nfgghx5kwz5zo3ad.onion
http://lockbitfskq2fxclyfrop5yizyxpzu65w7pphsgthawcyb4gd27x62id.onion
2024-12-23 11:31:23
Gang Avatar
Victim Avatar
2024-12-23 12:28:50
Victim Avatar
could you please how much it will cost to recover my files because we need to know the costs involved.
2024-12-23 13:10:53
wait, tech support will send your test files
2024-12-23 14:50:20
Gang Avatar
price decrypt 80k in bitcoin, for all hosts and files
2024-12-23 14:51:56
Gang Avatar
Victim Avatar
sir this amount is very high to be paid. We would like to work with you because it will take much time to recover our infrastructure. So some questions from our side
1. Can you please provide a generous discount so it\'s easier for us to consider your solution?
2. How fast the recovery process will take if we work with you ?
2024-12-23 15:47:11
we can\'t offer you a discount
2024-12-23 16:08:06
Gang Avatar
if you pay quickly and restore the infostructure on the same day
2024-12-23 16:12:12
Gang Avatar
I saw your financial report, our price is not big for you
2024-12-23 16:14:28
Gang Avatar
2024-12-23 16:16:24
Gang Avatar
Victim Avatar
Thank you for the file.
It\'s been a very hard year for our company, also as you know we are in Greece and since 2010 it\'s been very tough times for businesses. And the end of the year is always very hard financially with cashflows.

That\'s why i am asking for your understanding in price, so I can make an easier decision for my manager to decide.
Please if you can convince your own management to consider a generous discount it will help us in our decision with positive result.
From our side we want our files faster and without loses than the options we have now.
It seems that you can provide this service from the proof you sent.
It would be nice if we can find an agreement on a price we can pay so we can pay you.
Right now the amount you said is far beyond our real financial capability so we cannot consider this an option.
2024-12-23 16:38:16
ok, we can do a 20% discount
2024-12-23 16:46:36
Gang Avatar
Victim Avatar
First of all thank you for your understanding and the discount you provided.
I appreciate your help on this.
But still we are very far away from what we can really pay.
Still the amount you mentioned after the discount is very hard to find in cash.
We need to take some serious IT decisions tomorrow as most consultants advised us to format and start from latest offline files which will take several days.
So please if you can give us a more grounded financial proposal do so since the purpose here is to see if we can use your services.
2024-12-23 17:14:17
I don\'t care whether you pay me or not, there will be no more talk about discounts
2024-12-23 17:19:57
Gang Avatar
If you don\'t make a decision, the price will be 2x tomorrow.
2024-12-23 17:25:20
Gang Avatar
Victim Avatar
Please don\'t misunderstand the interest to find a way to pay you with insult. This was not my point. I respect you are talking with us right now and understanding our side. I just want to make it work for our company based on our limitations in cashflow in the end of the year. I know that you don\'t care about us. You attacked us after all. I understand that it\'s just business for you. Some pay, some don\'t. We want us to both benefit from this incident. We gain knowledge and you gain money. But we wanted to get an amount that we can be able to pay you realistically. We are not here to play either. Unfortunately if your purpose is to raise the price there is no point of discussing any more. Even if we find the correct amount we can pay, we will need at least 7 working days to pay you. Regulations are hard with this kind of transactions.
2024-12-23 17:29:26
the price will be 60k your decision to pay or not.
2024-12-23 17:35:39
Gang Avatar
Victim Avatar
Is there a way to recover 2-3 computers with 15k and get a partial service from your side? So we can see the quality of your service that is valid and then during next year purchase some more bundle of computers? I am just exploring options here to help our operations based on our cashflows.
2024-12-23 17:56:21
no, the decryptor will be available for all your files with the extension
2024-12-23 17:58:44
Gang Avatar
Victim Avatar
Hello sir, could you please accept the price of 30000$ before the end of the year so we can catch up with the processes to pay you in full for the full service you provide? It will take a lot of effort for us to return to normality so we can see this as a successful penetration test from your team and justify the expenses we need to pay to your work. Mention we need some days to manage to pay this huge amount of money so we need your understanding on this.
2024-12-24 16:32:59
you can pay 50k, but the offer will be available for a some days
if you can\'t pay on the weekend, I\'ll refund price.
2024-12-24 18:04:24
Gang Avatar
Victim Avatar
Please stay with me on this. Even if we find a way to work together, the amount is too big to find it these days. Last two years it\'s been very hard for us and it\'s the end of the year. We are trying to find whatever resources are available in cash and let you know. In the following two days we will have a better picture on our financials. We need at least 6-7 days to find 30k, we will need more to get more money to you. There is very limited cashflow in the end of the year which makes things very hard. Let me see what we can do and get back to you. I will try my best, because we want this to finish soon. There is big spending in the end of the year and limited cash receivable. Need more time to see what we can do for you.
2024-12-24 21:03:25
Victim Avatar
hello sir, can you please let us know how we can do the payment?
2024-12-27 10:16:45
hello, btc wallet: [redacted]
2024-12-27 12:54:26
Gang Avatar
Victim Avatar
We managed to gather this amount you requested. It\'s been very hard.

Please let us know if you accept the following.
When we pay 50.000$ USD to this wallet [redacted] you will keep your promise to:
1. Give us a tool to decrypt all our files in ESXi and all computers affected and we will decrypt today
2. Provide technical support from your side in case something doesn\'t work
3. Promise you will never attack us in the future
4. Help us understand how we can prevent such incidents again in the future and explain how you managed to get in our infrastructure along with technical details.

When we have your replies and confirmation for the above we proceed in the payment.
2024-12-27 13:08:42
1. there will be no problems with the decryptor,for esxi and all windows files
2. you will need to disable your av and just run the .exe decryptor
3. it could be someone else
4. you know your pass P@ssw0rd
2024-12-27 13:18:22
Gang Avatar
Victim Avatar
if we pay in the next hour when we will get decryptor?
2024-12-27 13:20:28
i make a request to tech support, it can take from an hour to five hours
2024-12-27 13:24:37
Gang Avatar
Victim Avatar
shall we sent 10$ just you to confirm and then send the rest 49990 ?
2024-12-27 13:26:16
ok
2024-12-27 13:27:13
Gang Avatar
Victim Avatar
https://mempool.space/tx/[redacted] can you confirm you received this ?
2024-12-27 13:31:24
yes 0.00010389
2024-12-27 13:34:48
Gang Avatar
Victim Avatar
bitcoin seller sais you got the money. Please confirm
https://mempool.space/tx/[redacted]
2024-12-27 14:12:01
is ok, thank you
2024-12-27 14:19:47
Gang Avatar
wait pls, tech support will drop decryptor here
2024-12-27 14:24:03
Gang Avatar
Victim Avatar
ok
2024-12-27 14:24:15
2024-12-27 14:27:31
Gang Avatar
Victim Avatar
this is not decryptor
2024-12-27 14:32:37
yes, decryptor we wait
2024-12-27 14:37:36
Gang Avatar
2024-12-27 15:49:34
Gang Avatar
Victim Avatar
What about esxi ?
2024-12-27 15:55:19
Give me readme file from esxi
2024-12-27 15:55:52
Gang Avatar
Victim Avatar
ok give me 5 minutes
2024-12-27 15:57:26
Victim Avatar
2024-12-27 16:18:02
Victim Avatar
the VMDK files cannot be decrypter with the .exe decryptor. could you please send decryptor for VMDK in ESxi based on the txt file i sent you 15 minutes ago ?
2024-12-27 16:30:50
yes
2024-12-27 16:31:33
Gang Avatar
wait 5 minutes
2024-12-27 16:31:38
Gang Avatar
2024-12-27 16:36:55
Gang Avatar
Victim Avatar
is there a way to decrypt VMDK files on windows? i have a copy of them and the windows decryptor doesn\'t work with them
2024-12-27 16:40:14
only linux
2024-12-27 16:40:31
Gang Avatar
Victim Avatar
please provide command line instructions to run linux
2024-12-27 16:42:05
Victim Avatar
1. Could you please tell me which commands to run on ESXi step by step in order to decrypt all files?
2. Is there a chance that something goes wrong when i execute this decrypt_ESXI_X64 command on ESXi? Do i lose all the VMDK files in the server?
2024-12-27 16:55:40