0%
BACK TO OVERVIEW

Why Some Ransomware Extortionists Are Friendlier Than Your IT Help Desk – And other Curiosities of Ransomware “Customer Communication"

Why Some Ransomware Extortionists Are Friendlier Than Your IT Help Desk –  And other Curiosities of Ransomware “Customer Communication"

The morning goes by uneventfully. An employee steps away from their desk for lunch and closes their laptop. Half an hour later, when they come back, their heart sinks: every file on the desktop is gone, no documents, no spreadsheets, just empty space. Suddenly a window they've never seen before pops up.

Incoming message
PUBG Ransomware
"Your files, images, musics, documents are Encrypted! Your files is encrypted by PUBG Ransomware! But don't worry! It is not hard to unlock it. I don't want money! Just play PUBG 1Hours!"

What sounds like a bad joke is a real case: the so-called PUBG ransomware actually encrypted its victims' files back in 2018. Instead of money, the attackers simply demanded that victims play a popular video game for a set amount of time, after which the data was automatically released again.

A curious one-off, sure. But it points to something fundamental: ransomware groups depend on negotiation.

What ransomware is, and how the extortion has escalated

Ransomware is a type of malicious software, or malware, that restricts or completely blocks access to data and systems. Such a program either locks down access to the entire system, or it specifically encrypts user data.

Over the past few years, this simple basic idea has grown into a tiered extortion model:

Stage 1
Single Extortion
Classic encryption
The traditional model: data and systems are encrypted to extort money for their release. Authorities advise against paying, yet many victims do, which only reinforces the trend.
Stage 2
Double Extortion
A response to backups
A reaction to victims increasingly relying on backups. Attackers steal sensitive data (such as customer or financial records) before encrypting anything, then extort money for two things at once: decryption, and preventing publication.
Stage 3
Triple Extortion
Maximum pressure
The highest level of escalation: criminals additionally extort third parties, such as the victim's customers or suppliers, threaten DDoS attacks, or reach out directly to the media to maximize pressure to pay.

The business model behind it: Ransomware-as-a-Service (RaaS)

Ransomware-as-a-Service is a cybercriminal business model in which developers sell or lease their malicious code to so-called "affiliates." These affiliates use the ready-made code to launch their own attacks. Anyone who outsources the technical development work to a RaaS provider needs almost no expertise of their own and can still get into cybercrime quickly.

20 %
of all cybercrime incidents involve ransomware
3
escalation stages of extortion

When extortionists sound like a support team

At first glance, extortion in cyberspace looks purely destructive. But real negotiation chats often reveal surprisingly organized processes. Many groups behave like a service provider, complete with their own support teams and a noticeably deliberate way of handling the victim.

Disclaimer: Out of respect for the victims of cyberattacks, all of the chats below have been anonymized, unless the victim in question has already been named publicly by the attackers themselves or in the media.

Excessive friendliness

Despite their criminal intent, many actors maintain a deliberately professional, sometimes exaggeratedly friendly tone, aimed at defusing the victim's panic. Their greetings mirror those of an ordinary software helpdesk, while also trying to build trust in the "payment and decryption process."

Babuk Support
"Hello! Technical support is happy to assist you."

Technical support for Bitcoin and Tor

Not every company is familiar with crypto exchanges or the Tor network. So groups offer step-by-step guides or chat-based technical support, in case victims simply don't know how to buy Bitcoin or use Tor.

Cloak Support
"So that YOU can quickly regain control of your data without further losses on YOUR part, please follow the suggested procedure exactly: [...] Stay calm and be patient — someone will definitely respond and help you recover your data."

Security advice after payment

Particularly bizarre: some groups treat their own hack, ironically, as a consulting service rendered. After payment, they hand over a detailed list of IT security shortcomings. For a moment, the extortionists slip into the role of a consulting firm.

Akira
"After spending several weeks investigating your network, we were able to identify several vulnerabilities that we strongly recommend addressing:
  1. None of your employees should open suspicious emails or links, download files, let alone run them on their computer.
  2. Use strong passwords and change them as often as possible (at least 1–2 times a month). Passwords should not be identical or reused across different systems.
  3. Set up two-factor authentication (2FA) wherever possible.
  4. Use the latest versions of operating systems, as these are less vulnerable to attacks.
  5. Update all software versions.
  6. Deploy antivirus solutions and traffic-monitoring tools.
  7. Set up a jump host for your VPN. Use credentials for it that are separate from your domain credentials.
  8. Use backup software with cloud storage that supports a token key.
  9. Train your employees on internet security precautions as often as possible.
The weakest point is the human factor and the carelessness of your employees, system administrators, and so on. We wish you security, peace of mind, and much success for the future."

A code of honor of their own

Some extortion groups distinguish themselves from other criminals through a supposed moral code, in order to polish their own image. Off-limits areas are usually critical infrastructure such as healthcare, orphanages, or educational institutions, since attacking these puts lives at risk or generates massive public pressure.

Statement from CLOP Ransomware
CLOP
"We have never attacked hospitals, orphanages, nursing homes, or charitable foundations, and we will not do so."

CLOP also announced that, should it accidentally encrypt such an organization, it would provide a free decryptor. The same moral line surfaced when LockBit accidentally encrypted the systems of a hospital for sick children. The group publicly apologized and likewise offered a free decryptor for recovery.

Friendliness, support, and a code of honor are all part of the strategy. A victim who feels they're in good hands pays faster and negotiates less.

Containing ransomware: the kill chain as a roadmap

Prevention is best planned along the typical attack chain: from the initial compromise to incident response, there are six phases, each with concrete countermeasures.

Measure Target phase Core idea
Patch management Initial breach Exploited software vulnerabilities are among the three most common entry vectors used by ransomware groups.
Secured remote access Initial breach External access only via VPN, combined with two-factor authentication.
Email settings Initial breach Emails should be displayed as plain text rather than rendered as HTML, to avoid obfuscated links. In addition, execution of active content in HTML emails should be suppressed so that malicious scripts embedded in emails cannot run.
Program execution controls Initial breach Application whitelisting prevents unwanted software by only allowing approved programs to run.
Separate admin accounts Privilege escalation Privileged accounts reserved solely for administrative tasks, secured with their own 2FA.
Network segmentation Lateral movement Limits ransomware's reach to immediately adjacent systems, containing the damage. This relies on secure use of administrator accounts.
Active Directory hardening Lateral movement After the initial compromise, the central authentication and authorization service is usually the target. Making Active Directory harder to compromise can be guided by the IT-Grundschutz module APP2.2 Active Directory Domain Services.
Offline backups Encryption Physically or logically disconnected from the network after being created: the only reliable insurance against data loss.
Incident response plan Incident response Regularly rehearsed processes for responding to and restoring business-critical systems.

Pay or not? A dilemma with no clean answer

Preventive measures are worthwhile but offer no 100 percent protection against ransomware attacks. That's why it's crucial to be clear in advance about whether you'll even engage in negotiations with attackers, and whether you would pay a demanded ransom if it came to that.

Against negotiating
Why paying is problematic
Risk · Ecosystem · Reputation
×
No guarantee: even after payment, there's no guarantee that data will be fully restored, or that stolen data won't be sold anyway.
×
Funding crime: ransom money feeds directly into the business model and finances further attacks.
×
Repeat target: those who pay once are marked in the scene as a "good payer" and get attacked again more often.
For negotiating
Why people negotiate anyway
Buying time · Gathering evidence · Damage control
Buying time: while the back-and-forth plays out in chat, the IT team can try to restore systems from backups.
Gathering evidence: requesting decryption of individual test files to check whether the attackers can technically deliver at all.
Damage control: without backups and facing potential insolvency, companies often try to negotiate the demand down.

Without backups, and facing the threatened publication of sensitive customer data, a company's own reputation is also on the line: a massive breach of trust with customers that businesses rarely walk away from unscathed.

What the authorities recommend:

The FBI generally advises against paying ransom in a ransomware attack. Payment doesn't guarantee that data will be returned, and it encourages attackers to target further victims.

Europol: don't pay the ransom. A payment directly funds criminals and encourages them to continue their illegal activities.

The myth of the nice extortionist

The world of ransomware has long since evolved from flashy curiosities like the PUBG software into a billion-dollar shadow industry with its own corporate-style structures. Ransomware-as-a-Service shows how cybercriminals have adopted corporate structures to push victims, under extreme stress, toward paying quickly, while faking trust where none exists.

From an official standpoint, the question of whether to negotiate has a clear answer: don't pay. Every ransom paid funds the next wave of attacks and strengthens the criminal ecosystem. In practice, though, companies facing multi-extortion scenarios are often caught in a genuine dilemma, weighing the threat of data loss and reputational damage against their very survival. If negotiations are considered at all, they should never be entered into carelessly or treated as the primary option, but only as a tactical tool for gathering evidence and buying time.

The best protection against the "friendly" extortionist in the chat window remains uncompromising prevention: robust multi-factor authentication, airtight backup strategies, and regular employee training ensure that you never end up in a position of having to haggle with criminals over the price of your own data in the first place.

How well is your company prepared for a real-world scenario like ransomware and ransom extortion?

We find the security gaps in your software before criminals can use them as an entry point. Free initial consultation.

Request a consultation →