
DOGE-Trolling Ransomware Hackers Demand $1 Trillion
Update, April 24, 2025: This story, originally published April 23, has been updated with information from a new FBI ransomware report following the latest DOGE attackers' trillion-dollar ransom demand.
The same criminal group behind the DOGE Big Balls ransomware attack has just upped the ante. A newly updated ransom note is now using Elon Musk and DOGE references with a demand for, are you sitting down, one trillion dollars from victims.
Although there is no doubt that ransomware threats should be taken very seriously, what with a massive surge in ransomware attacks this year, new password-cracking tools being employed to gain initial access, and some very concerning political moves by big names in the extortion-racket industry, not all the players take themselves seriously it would seem.
The ransomware group behind the recent DOGE Big Balls threat, using a variant of existing malware known as FOG, and trying to pin responsibility for the attacks on a well-known member of the Department of Government Efficiency team, has just updated its ransom note. As detailed in an April 21 security report by researchers Nathaniel Morales and Sarah Pearl Camiling at Trend Micro, the ransomware now appears to have started trolling DOGE and Elon Musk mercilessly. In reference to the now-infamous Musk demand for federal workers to email DOGE what they had achieved, leaving them fearing for their jobs if they did not comply, the ransom note has been altered to read:
'Give me five bullet points on what you accomplished for work last week or you owe me a TRILLION dollars.'
In an April 23 FBI internet crime report, B. Chad Yarbrough, the FBI
operations director for criminal and cyber, confirmed that ransomware is 'the most pervasive threat to critical infrastructure' and played an increasingly important role in the $16.6 billion cost of cybercrime to individuals and organizations in the U.S. across 2024. Interestingly, the FBI report said that the FOG ransomware threat, a variant of which has been used in the DOGE Big Balls attacks, was the most reported of new ransomware attacks during 2024. The bureau's Internet Crime Complaint Center provides this information to field offices to help the FBI 'identify new ransomware variants, discover the enterprises the threat actors are targeting, and determine whether critical infrastructure is being targeted,' the FBI said.
'The most alarming thing about the FBI's IC3 report is that its numbers are just the tip of the formidable iceberg of organized cybercrime,' Dr Ilia Kolochenko, CEO at ImmuniWeb, said. Warning that a 'growing number' of U.S. organizations prefer to silently settle with ransomware groups that carry a strong reputation for keeping attacks and data confidential following payment, Kolochenko said that it's likely we will see this option continue to be taken. 'In all cases,' Kolochenko advised, 'the final decision to pay or not to pay should be brainstormed with cybercrime experts and lawyers having experience in such matters. Otherwise, you are running a sprint on thin ice.' In the case of the DOGE attacks, maybe less consideration is required when the demand is for a trillion dollars.
'The ransomware payload embedded in the samples has been verified as FOG ransomware,' the Trend Micro report warned, 'an active ransomware family targeting both individuals and organizations.' As such, it's imperative that you do not think that just because the attackers might act like clowns, the threat itself isn't serious.
Indeed, the ransomware demand itself is all business. 'We are the ones who encrypted your data and also copied some of it to our internal resource,' the attackers state. They then advise the victim that the sooner they are contacted, the sooner they can get everything resolved, offering instructions on using a Tor browser to get the next steps.
The DOGE references are not the only trolling in the updated ransom note, there's also a 'Don't snitch now' warning. This could be in response to the ransomware informer platform that I have previously reported on. The humor — I guess that's what it is an attempt at — continues with a warning from the attackers that they have 'grabbed your trilatitude and trilongitude (the most accurate) coordinates of where you live,' in order to prove that they are lying. Not lying and not funny, but not to be ignored either. Report any such attacks to the FBI here.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CNN
17 minutes ago
- CNN
‘Tesla Takedown' protestors have a new target: Elon Musk's Tesla Diner
For months, protesters have gathered outside Tesla showrooms in response to Elon Musk's role in reducing US government spending as part of the Department of Government Efficiency. This weekend, protesters in Los Angeles found a new destination: Musk's new 24-hour Tesla Diner in the Hollywood area. Musk had touted the concept of an 'old school drive-in, roller skates & rock restaurant' in 2018. Since opening on Monday, the retro-futuristic diner with electric vehicle-charging stations has had long lines of customers who are served burgers in Cybertruck-designed boxes. One customer posted to YouTube that he waited 11 hours for the restaurant to open. But Joel Lava, who has helped organize 'Tesla Takedown' demonstrations and has spearheaded protests at the diner, believes that protests could continue throughout the summer and that the buzz around the new restaurant will soon die down. '(Customers are) waiting 11 hours so they can have Tesla-brand burgers and fries,' Lava told CNN. 'This is the world's most renowned anti-trans advocate who just opened a diner in West Hollywood. The community is not very supportive of Elon.' Lava estimates as many as 75 demonstrators joined the diner protest on Saturday. He said organizers began planning protests for this weekend after the diner abruptly opened on Monday. 'Our main message is Tesla funds fascism. Elon Musk, via DOGE, has destroyed our government agencies and people's jobs, and people are dying around the world because of him,' Lava said. Tesla did not immediately respond to CNN's request for comment. Lava said protest attendance for Tesla Takedown events peaked at the end of March, but has 'been going strong.' Protests outside of Tesla showrooms across the United States have remained a weekly staple in many cities, with 40 protests planned on the 'Tesla Takedown' website for the weekend. 'We've already been successful in tarnishing the Tesla brand,' he said. During last week's second-quarter earnings call, Musk highlighted Tesla's future — not its gloomy present-day — by reaffirming ambitious plans for the company's robotaxi service and mass production of its humanoid robot, Optimus, which was serving popcorn at Musk's diner. Tesla's auto revenue fell 16% from April to June and overall revenue was down 12%, according to its earnings report. Sales of its best-selling Model Y and Model 3 fell 12% compared with a year ago, while sales of its more expensive models, including the Cybertruck, plunged 52%. Shares of Tesla (TSLA) were down more than 4% last week, closing at $316.06 on Friday, after falling 9% on Thursday. Since peaking at $479.86 on December 17, Tesla shares have plunged 34%. CNN's Chris Isidore contributed to this report.


CNN
18 minutes ago
- CNN
‘Tesla Takedown' protestors have a new target: Elon Musk's Tesla Diner
Food & drink Corporate newsFacebookTweetLink Follow For months, protesters have gathered outside Tesla showrooms in response to Elon Musk's role in reducing US government spending as part of the Department of Government Efficiency. This weekend, protesters in Los Angeles found a new destination: Musk's new 24-hour Tesla Diner in the Hollywood area. Musk had touted the concept of an 'old school drive-in, roller skates & rock restaurant' in 2018. Since opening on Monday, the retro-futuristic diner with electric vehicle-charging stations has had long lines of customers who are served burgers in Cybertruck-designed boxes. One customer posted to YouTube that he waited 11 hours for the restaurant to open. But Joel Lava, who has helped organize 'Tesla Takedown' demonstrations and has spearheaded protests at the diner, believes that protests could continue throughout the summer and that the buzz around the new restaurant will soon die down. '(Customers are) waiting 11 hours so they can have Tesla-brand burgers and fries,' Lava told CNN. 'This is the world's most renowned anti-trans advocate who just opened a diner in West Hollywood. The community is not very supportive of Elon.' Lava estimates as many as 75 demonstrators joined the diner protest on Saturday. He said organizers began planning protests for this weekend after the diner abruptly opened on Monday. 'Our main message is Tesla funds fascism. Elon Musk, via DOGE, has destroyed our government agencies and people's jobs, and people are dying around the world because of him,' Lava said. Tesla did not immediately respond to CNN's request for comment. Lava said protest attendance for Tesla Takedown events peaked at the end of March, but has 'been going strong.' Protests outside of Tesla showrooms across the United States have remained a weekly staple in many cities, with 40 protests planned on the 'Tesla Takedown' website for the weekend. 'We've already been successful in tarnishing the Tesla brand,' he said. During last week's second-quarter earnings call, Musk highlighted Tesla's future — not its gloomy present-day — by reaffirming ambitious plans for the company's robotaxi service and mass production of its humanoid robot, Optimus, which was serving popcorn at Musk's diner. Tesla's auto revenue fell 16% from April to June and overall revenue was down 12%, according to its earnings report. Sales of its best-selling Model Y and Model 3 fell 12% compared with a year ago, while sales of its more expensive models, including the Cybertruck, plunged 52%. Shares of Tesla (TSLA) were down more than 4% last week, closing at $316.06 on Friday, after falling 9% on Thursday. Since peaking at $479.86 on December 17, Tesla shares have plunged 34%. CNN's Chris Isidore contributed to this report.


Business Insider
an hour ago
- Business Insider
Tesla receives shareholder proposals related to xAI investment, Reuters says
Tesla (TSLA) has received several shareholder proposals related to its plan to invest in CEO Elon Musk's xAI, Reuters reports. Elevate Your Investing Strategy: Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence. Published first on TheFly – the ultimate source for real-time, market-moving breaking financial news. Try Now>>