Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
MonsterCloud owner Zohar Pinhasi was charged with wire fraud for marking up ransomware payments by about $11 million.
Zohar Pinhasi, 50, owner of US company MonsterCloud and also known as Zack Silver and Zack Green, appeared in a New York court on wire fraud and wire fraud conspiracy charges. Prosecutors say he told ransomware victims his firm could restore data with proprietary decryption tools without paying attackers. Instead he allegedly paid the ransomware operators for keys and charged clients a large markup. Across the scheme he allegedly paid more than $8 million in ransoms and charged clients more than $19 million, including one case of about $8,200 paid and about $150,000 billed.
- Zohar Pinhasi, owner of MonsterCloud, faces wire fraud and conspiracy charges.
- He allegedly paid ransomware groups, then billed victims much higher fees.
- One case: about $8,200 paid to attackers and $150,000 charged to the client.
- Overall he allegedly paid over $8 million and billed clients over $19 million.
Full article284 words · extracted from securityweek.com · click to collapse
The owner of a US company was charged with defrauding clients through a ransomware remediation scheme.
Zohar Pinhasi, 50, the owner of MonsterCloud, a US and Israeli national also known as ‘Zack Silver’ and ‘Zack Green’, appeared in a New York court to face wire fraud charges.
According to the indictment, Pinhasi claimed that MonsterCloud could help organizations that fell victim to ransomware to recover their data without paying the attackers.
While cautioning ransomware victims not to pay the attackers, Pinhasi allegedly falsely claimed his company could decrypt ransomware.
Pinhasi allegedly claimed that MonsterCloud was using proprietary tools and advanced decryption techniques to recover encrypted data without paying the attackers.
Instead, he contacted the ransomware groups that hacked his clients, paid ransoms to obtain the decryption keys, and then charged the victim organizations a fee when using the decryption key to restore the data.
Advertisement. Scroll to continue reading.
In one instance, he made a ransom payment of approximately $8,200 to a ransomware affiliate, and then charged the client approximately $150,000.
Throughout the scheme, he allegedly paid over $8 million in ransoms and charged his clients over $19 million.
Pinhasi was charged with wire fraud and wire fraud conspiracy and could be sentenced to tens of years in prison.
“The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” Assistant Attorney General A. Tysen Duva said.
Related: Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
Related: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
Related: Alleged ShinyHunters Leader Arrested in Jordan
Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/