Ransomware recovery CEO charged over secret ransom payments
by Lawrence Abrams · BleepingComputerThe owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.
Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn.
He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud in connection with an alleged ransomware decryption scheme that prosecutors say ran from June 2018 to June 2023.
The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond.
According to the indictment, Pinhasi owned and operated MonsterCloud LLC, a Florida-based ransomware remediation company that advertised tools and decryption techniques for recovering encrypted data without paying cybercriminals.
Prosecutors allege that Pinhasi and his co-conspirators had no such proprietary decryption technology and instead contacted ransomware operators, paid them for decryption keys, and then used those keys to restore customers' files.
The indictment acknowledges that some MonsterCloud contracts disclosed that the company might communicate with or pay cybercriminals. However, those contracts allegedly stated that MonsterCloud would contact attackers only if it could not decrypt a customer's files by other means.
Prosecutors claim that dealing with cybercriminals was usually MonsterCloud’s first step in obtaining decryption keys and recovering files.
"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” U.S. Attorney Joseph Nocella Jr. said.
"Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity."
MonsterCloud allegedly charged customers far more than the ransoms it paid.
In one ransomware recovery incident cited in the indictment, Pinhasi allegedly paid a ransomware gang about $8,200 and charged the victim approximately $150,000. In another, prosecutors say he paid approximately $236,000 and charged the customer about $380,000.
The indictment also alleges that MonsterCloud used decrypted sample files as "recovery proofs" to convince victims it could restore their data, even though those decrypted samples came from the ransomware operations.
Over the course of the alleged scheme, prosecutors say Pinhasi and his co-conspirators facilitated more than $8 million in ransom payments while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.
If convicted, Pinhasi faces up to 20 years in prison.
BleepingComputer contacted Pinhasi's attorneys, Christopher Clark and Rodney Villazor, for comment on the allegations and will update the story if we receive a response.
Similar concerns raised in 2019
A 2019 ProPublica investigation reported similar concerns about MonsterCloud, including that the company sometimes paid ransomware operators while claiming to offer a solution other than paying the attackers.
As part of that investigation, security researcher Fabian Wosar told ProPublica that he and another researcher created their own ransomware and approached several recovery companies while posing as victims.
The researchers provided the recovery firms with ransom notes containing email addresses they controlled for the fake ransomware gang. According to Wosar, those attacker-controlled accounts soon received anonymous messages offering to pay the ransom.
"Soon, the email accounts that he'd set up for the imaginary attacker began receiving emails from anonymous addresses offering to pay the ransom," ProPublica reported, citing Wosar. "He traced the requests to the data recovery firms, including MonsterCloud and Proven Data."
ProPublica reported that MonsterCloud had claimed it could recover the encrypted files without telling the supposed victim that it planned to pay the attacker.
Pinhasi disputed that MonsterCloud had promised in advance it could decrypt the files and denied misleading customers.
He also told ProPublica that MonsterCloud's recovery methods varied by case and declined to disclose them, describing the techniques as a "trade secret."
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.