Troldesh Ransomware Hacker Agrees To Halve Fee After Negotiations

A security researchers was successfully able to barter with a hacker responsible for the ‘Troldesh’ ransomware, halving the initial fee demanded for the decryption of her computer

Natalia Kolesova, an anti-bot analyst at Check Point, was able to initiate contact with the Russian hacker responsible for Troldesh, aka Encoder.858 or Shade through an email address.

Negotiating Ransom

Essentially, once Troldesh infects a machine via spam email, it gives out an email address for the user to contact, as it encrypts all the user’s data and demands a ransom in exchange for decryption.

A typical ransomware page
A typical ransomware page

This direct communication between the hacker and the victim is very rare, as most hackers try to hide themselves and avoid any direct contact with the victim. But the Troldesh hacker gives out an email address so they can dictate a payment method.

“I was very interested to learn more about the ransom and tried to start a correspondence with the attackers,” blogged Check Point’s Kolesova. “After several minutes I received an answer with my next instructions.”

The hacker demanded a payment of €250 (£183) to decrypt all of the files on her computer. But Kolesova pleaded with the hackers to get a discount, saying she was Russian and that €250 was a month’s salary for her.

“To my great surprise, after a minute I got an answer from a real person who was open to discussion!” she blogged. The hacker then offered to accept 12,000 roubles, a discount of around 15 percent.

After Kolesova pleaded further, the hacker responded: “The best I can do is bargain.”

Kolesova took a break and began pleading the next day. “I ask you: please, return my data – this is almost all of my life for the last several years! I really don’t have much money to pay you! Be humane!!!”

In the end, the hacker agreed to a payment of 7,000 roubles, a 50 percent discount from the initial asking price.

“By the end of our correspondence, I managed to get a discount of 50 percent,” blogged Kolesova. “Perhaps if I had continued bargaining, I could have gotten an even bigger discount.”

Ongoing Problem

Ransomware is an ongoing problem for the security industry and end users around the world.

Last year for example, researchers discovered Android ransomware that encrypted the user’s content on their mobile device before demanding a ransom payment so the victim can regain access to their files.

Last month, Symantec revealed ransomware themed around the TV show ‘Breaking Bad’. That malware affected computers across Australia, and encrypted images, videos, documents, and more on the compromised computer. It demanded up to AU$1,000 ((£510 / $791) to decrypt those files.

What do you know about Internet security? Find out with our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Nvidia And Partners To Build $500 Billion Of AI Infrastructure In US

Nvidia to partner with TSMC, Foxconn, Wistron, Amkor and SPIL to build $500 billion (£377…

6 hours ago

China’s Rare Earth Export Restrictions Poses Threat To US Defence

American think tank warns about possible threat to US defence, after China imposes rare earth…

7 hours ago

China Names US Operatives For Alleged Cyberattacks

China is reportedly pursuing three alleged US NSA operatives, after cyberattacks on Chinese infrastructure

9 hours ago

ASML, Others Outline Impact Of Trump’s Tariffs

Chip making giant ASML mirrors other equipment makers, and outlines financial impact of Donald Trump's…

10 hours ago

AI in Cybersecurity: Double-Edged Sword or Game-Changer?

AI is transforming cybersecurity, offering faster defence and smarter attacks. Learn how businesses can harness…

13 hours ago

Google Sued In UK For Online Search Domination

Search engine giant being sued for £5 billion ($6.64 billion) damages over allegations for online…

13 hours ago