Skip to main content
INFO Threat Intel #Ransomware#Data Breach#Fraud

MonsterCloud CEO Charged in Secret Ransomware Payment Scheme

3 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: organizations seeking incident response services faced financial fraud and deceptive recovery practices.
  • Affected systems: enterprise networks and client systems managed by MonsterCloud LLC between June 2018 and June 2023.
  • Remediation: organizations should thoroughly vet third-party incident response providers and verify their remediation methodologies.

Advertisement

Overview of the MonsterCloud Indictment

Federal prosecutors in the Eastern District of New York have charged Zohar Pinhasi, the owner and chief executive officer of the ransomware remediation firm MonsterCloud, with wire fraud and conspiracy. According to details published by BleepingComputer, Pinhasi allegedly operated a multi-year scheme from June 2018 to June 2023 where he falsely claimed to use proprietary technology to decrypt files for ransomware victims. Instead of utilizing in-house technical capabilities, prosecutors state that Pinhasi and his co-conspirators routinely contacted threat actors, paid them for decryption keys, and billed clients exorbitant fees while concealing these transactions.

The indictment details a stark financial discrepancy between the actual cost of obtaining decryption keys and the amounts billed to victims. In one specific incident cited by federal authorities, Pinhasi allegedly paid approximately $8,200 to a ransomware gang while invoicing the affected company $150,000. In another case, a ransom payment of roughly $236,000 preceded a customer charge of approximately $380,000. Over the course of the five-year operation, the scheme reportedly facilitated more than $8 million in ransom payments while extracting upwards of $19 million from organizations across the United States and Canada.

Technical Analysis and Investigation History

The allegations highlight ongoing integrity concerns within the incident response and ransomware recovery market. MonsterCloud frequently marketed its services by asserting it could restore encrypted environments without negotiating with or paying cybercriminals. When customers questioned recovery methods, representatives allegedly pointed to trade secrecy and utilized decrypted sample files obtained directly from the attackers to serve as “recovery proofs.”

Security researchers had previously identified similar practices involving the firm. A notable 2019 investigation by ProPublica detailed operations where independent researchers set up honeypot ransomware campaigns with attacker-controlled contact addresses. Security researcher Fabian Wosar observed that firms including MonsterCloud quickly reached out to these addresses to arrange ransom payments, contradicting public claims of proprietary decryption algorithms. Despite these historical warnings, the operation continued until the recent federal indictment, which carries a maximum sentence of 20 years in prison upon conviction.

Recommendations for Security Professionals

When evaluating third-party incident response partners, security teams and legal counsel must establish strict verification procedures. Prioritizing transparency and operational integrity helps ensure organizations do not fall victim to fraudulent remediation services.

  • Verify Provider Methodologies: Demand clear, verifiable documentation on how a remediation firm plans to restore systems without relying on undisclosed interactions with threat actors.
  • Conduct Due Diligence: Vet incident response vendors through established industry networks, peer recommendations, and independent security research before a crisis occurs.
  • Maintain Direct Oversight: Ensure internal legal and technical teams maintain visibility over any communications or negotiations conducted with external threat groups during an active incident.

Related: Cisco Talos Newsletter: Frustrating Adversaries and Security Updates, ShinyHunters Hacker Detained in Jordan, Cooperating With FBI

Advertisement

Advertisement