MonsterCloud Owner Charged With Allegedly Defrauding Ransomware Victims
The owner of ransomware recovery company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying attackers for decryption tools while claiming to use proprietary technology to recover encrypted data.
Zohar Pignasi, 50, who is also known as “Zack Silver” and “Zack Green,” was indicted by a federal grand jury in the Eastern District of New York on September 23. He was arraigned Wednesday in federal court in Brooklyn.
Pignasi is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege that the ransomware decryption scheme operated from June 2018 through June 2023.
The U.S. Attorney’s Office told BleepingComputer that Pignasi turned himself in on Wednesday, pleaded not guilty and was released on $2 million bail.
Prosecutors allege MonsterCloud secretly paid ransomware gangs
According to the indictment, Pignasi owned and operated MonsterCloud LLC, a Florida-based ransomware remediation company that promoted tools and decryption techniques designed to recover encrypted data without paying cybercriminals.
Prosecutors allege that Pignasi and his co-conspirators did not have the proprietary decryption technology they claimed to use. Instead, they allegedly contacted ransomware operators, paid them for decryption keys and used those keys to restore customers’ files.
Some MonsterCloud contracts disclosed that the company might communicate with or pay cybercriminals. However, prosecutors allege that the contracts stated MonsterCloud would contact attackers only if it could not decrypt a customer’s files through other means.
According to prosecutors, MonsterCloud’s first step in obtaining decryption keys and recovering files was typically to negotiate with cybercriminals.
“As alleged in the indictment, the defendants re-victimized their clients while reaping huge profits for themselves by falsely claiming to decrypt the ransomware without paying the ransom,” U.S. Attorney Joseph Nocera Jr. said.
“Our office will vigorously prosecute ransomware attackers who prey on Americans around the world and those who cynically profit from their criminal activity.”
MonsterCloud allegedly charged victims millions for ransomware recovery
MonsterCloud allegedly charged customers substantially more than the ransom payments made to attackers.
In one ransomware recovery case cited in the indictment, Pignasi allegedly paid a ransomware gang approximately $8,200 and charged the victim approximately $150,000. In another case, prosecutors say he paid about $236,000 and billed a customer approximately $380,000.
The indictment also alleges that MonsterCloud used decrypted sample files as “recovery evidence” to convince victims that their data could be restored. Prosecutors say the samples may have been decrypted using keys obtained from a ransomware campaign.
During the alleged scheme, Pignasi and his co-conspirators allegedly facilitated more than $8 million in ransom payments and charged hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.
If convicted, Pignasi could face up to 20 years in prison.
BleepingComputer has contacted Pignasi’s attorneys, Christopher Clark and Rodney Villazor, for comment on the allegations. This article will be updated if they respond.
Similar concerns about MonsterCloud were reported in 2019
Similar concerns about MonsterCloud were reported in a 2019 ProPublica investigation. The report alleged that the company sometimes paid ransomware operators while claiming to offer recovery methods that did not involve paying attackers.
As part of the investigation, security researcher Fabian Wasser and another researcher created their own ransomware and approached several recovery companies while posing as victims.
The researchers provided a ransom note containing email addresses they controlled for the fake ransomware gang. According to Wasser, the accounts soon began receiving anonymous messages offering ransom payments.
“Soon, the email account he set up for the fictitious attacker began receiving emails from anonymous addresses offering ransom payments,” ProPublica reported, citing Wasser. “He tracked requests to data recovery companies such as MonsterCloud and Proven Data.”
ProPublica reported that MonsterCloud claimed it could recover encrypted files without telling alleged victims that it planned to pay the attackers.
Pignasi disputed that MonsterCloud promised in advance that it could decrypt files and denied misleading customers.
He also told ProPublica that MonsterCloud’s recovery methods varied from case to case. He declined to disclose the technology, describing it as a “trade secret.”
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



