You already paid the criminals. Then a helper arrived with a decryptor, a serious voice, and an invoice that treated your panic as a product SKU. Zohar Pinhasi, SecurityWeek reports, was buying working ransomware keys and charging victims far more for remediation, with fake decryption tools covering an $11 million markup. If your cybersecurity plan treats the person holding the decryptor as a teammate, you just invited the second attacker into the war room.

The decryptor was a billing costume
The work is almost elegant in how little invention it needs. Pay the crew. Receive a key that actually opens files. Wrap it in software that looks like threat-protection research. Hand the victim a binary and a number with a lot of commas. They think they bought expertise. You sold them a reseller seat with the people who encrypted their disks.
You know the hour this lands. Banners on screens. Legal asking if paying is faster than restoring. Someone on the call says they have a decryptor. That sentence ends thinking. Boards hear “tool.” Engineers hear “maybe we sleep.” Procurement hears “approved vendor” because the alternative is admitting the backups were a slide, not a restore test.
A real key can live inside a fake product. That’s the part that should make you angry. The decryptor didn’t have to beat cryptography. It had to survive a screen share. Once the files open, nobody asks whether the GUI was a costume sewn around a purchase you could have made with fewer mystery binaries and a smaller wire.
Expect this to miss the firewall and last week’s brute-force noise on VPN. The access path is the incident channel itself. Threat detection that stops at malware hashes will bless a recovery utility because files decrypt and the ticket turns green. Green tickets are how markups hide.
Watch the tells. Pressure to run their binary as admin on production. Refusal to hand over raw key material you can test on a copy. A decryptor that phones home. A fee that tracks “urgency” more than hours. A vendor who wants to handle the criminal payment “for you,” then sell you the same key at retail. That’s arbitrage on your worst hour.
Hire help under the same controls you’d give a pentester with production access: supervised, scoped, logged, and unable to become the new source of truth for what happened. If they argue those terms slow the recovery, that’s data. People who own a working key can wait an hour for a sandbox. People who own a narrative cannot.
That wallet extension is a collection step
Same costume, smaller storefront. Researchers found 16 malicious Firefox extensions posing as Rabby and OKX wallet portals, desktop utilities, and browser tools. During import they intercept recovery phrases and private keys, then try to ship those secrets out. You thought you were restoring access. The add-on treated your paste as a pickup.

Helper economy, browser edition. Decryptor. Wallet portal. “Official” looking add-on. The UI is the exploit, and the victim performs the last mile because the prompt looks like work they already meant to do. You don’t need a zero-day when the user will type the crown jewels into a form that says Import.
Finance laptops with sideloaded extensions are a gift. Brute-force against a seed phrase is a cartoon. Stealing it at import is quiet. Your threat detection may never see a spray. It may see a successful HTTPS post from a browser you allowlisted last quarter because someone in treasury needed a helper. Cyber security on those machines is an extension policy, not a hope that the add-on store did your job.
If a tool’s only job is to hold keys, treat it like a domain controller. Pin the publisher. Block sideload. Ban wallet helpers that are not on a written allowlist. The ransomware recovery binary and the fake OKX panel are cousins. Both show up when you are desperate to get something back.
Cybersecurity after the banner is untrusted code
Treat recovery the way you treat unknown binaries, because that’s what it is. Defense in depth does not pause for a vendor on a video call. Incident response starts before anyone plugs in a decryptor, and it keeps going after files open. Security hardening here is boring on purpose: isolate, hash, test, rotate, hunt.
Do this in the room, not in a retrospective:
- Isolate encrypted hosts and snapshot them before any third-party binary runs.
- Hash every “decryptor,” sandbox it, and demand the raw key so you can test on a copy you control.
- Independently confirm the leak site, actor name, and decryptor lineage; do not take the vendor’s attribution as fact.
- Freeze identity providers and rotate secrets the ransomware could have stolen, including backups and cloud keys.
- Hunt for new local admins, services, scheduled tasks, and odd egress planted during “remediation.”
- Lock browsers to an extension allowlist on any machine that holds keys, seed phrases, or privileged passwords.
- Pre-negotiate IR so payment rails, tooling, and evidence handling have dual control before anyone is crying.
- Keep immutable backups a recovery vendor cannot reach from the domain, and tabletop the no-pay restore until “we have a decryptor” is a claim you can reject.
Put helpers in a lab VLAN, not on a domain admin jump. Watch cleanup egress the same way you watch breach egress. If their tool needs the internet to “license” decryption, you are not looking at a key. You are looking at a callback. Make the no-pay path real enough that a markup shop has nothing to sell.
The first patient count is a comfort object

Oracle Health’s tally is now nearly 20 million people, far above the counts that showed up in earlier filings and patient notifications. First numbers are comfort objects. They make the letter finite. They make the war room look finished. Then a vendor system you didn’t inventory appears, or a clinic that was “out of scope,” and the number moves.
This sits next to the fake decryptor. Early certainty is for sale. A recovery vendor will sell you closed. A notification letter will sell you a headcount. Keep the investigation open until the evidence stops changing, not until someone wants the lights off. Scope identity stores, connected clinics, backup catalogs, and every processor that synced a copy. If you brief leadership on a number before that work is done, you are briefing a press release.
Press releases are how $11 million markups and 20-million-record surprises get a head start. You don’t owe anyone a tidy story on day three. You owe them a scoped incident, a vendor you can fire, and a restore you can prove.
Sources
- Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
- 16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
- Oracle Health Data Breach Tally Climbs to Nearly 20 Million
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
