Skip to content

Ransomware

Extortion with cryptographic settlement

Ransomware groups demand BTC or Monero while threatening data publication—investigation focuses on payment tracing and attribution support.

Ransomware crypto angle

Organizations or individuals pay ransoms to receive decryptors or suppress leaks.

Payments are structured to obfuscate cash-out through mixers and exchanges.

Campaign flow

  1. 01

    Intrusion

    Initial access via phishing or exposed RDP.

  2. 02

    Deployment

    Encrypt files and exfiltrate data.

  3. 03

    Negotiation

    Tor portals provide payment instructions and timers.

Caution

  • Paying does not guarantee decryption or deletion
  • Secondary extortion after payment
  • Sanctions risks depending on actor group

Payment flows

BTC addresses often single-use; cash-out within days.

  • — Mixer usage common
  • — OTC brokers in high-value cases
  • — Monero hops reduce visibility

Evidence

  • Ransom note files
  • Payment TXIDs
  • Negotiation chat logs
  • IOC from IR firms

Investigation

01

Payment tracing

Follow ransom TX to services.

02

Infrastructure

Correlate leak site hosting with other campaigns.

Now

  • 01Engage incident response and legal counsel
  • 02Preserve logs before remediation wipes evidence
  • 03Report to authorities—do not pay without professional guidance

Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.

Frequently asked questions

Should we pay the ransom?

A policy decision with legal and ethical implications—we provide tracing, not payment advice.

Discuss ransomware payment tracing

Enterprise engagements require authorized contacts.