LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Group Profile Money Message

Money Message: Group Profile

Money Message emerged in March 2023 with a technically capable C++ ransomware and immediately demonstrated its reach with a high-profile breach of MSI — extracting firmware signing keys and source code alongside encrypted systems. The group operates without an affiliate programme, keeping operations tight and targeting selective high-value victims.

By Ransomware Tracker ·
Money MessageMSIransomwareC++firmwaresupply chainaviationAMES Airlinesdouble-extortion20232026
Threat Level
8/10
Sectors Targeted
technology
aviation
manufacturing
gaming
Ransomware Family
Money Message

Money Message first appeared in March 2023, and within weeks of its emergence it had breached MSI (Micro-Star International) — one of the world’s largest PC hardware manufacturers. That incident demonstrated both the group’s technical capability and its willingness to pursue victims whose data has value beyond ransomware payment: MSI’s stolen data included BIOS source code, private keys for Intel Boot Guard, and firmware signing certificates. The downstream supply chain implications of that leak extended well beyond the ransom itself.

Origins and Operating Model

Money Message does not operate as a ransomware-as-a-service platform. The group maintains its own encryptor and does not recruit external affiliates, keeping the operation smaller and operationally tighter than RaaS-based groups. Victim selection appears deliberate rather than opportunistic, with targets chosen for the value of their data or strategic significance rather than volume.

The group maintains a Tor-based leak site where victim data is published if ransom demands are not met. The site’s design and operation are professionally maintained compared to many newer groups.

Technical Profile

Encryptor: Money Message’s ransomware is written in C++. Researchers who analysed the binary found it uses symmetric encryption with per-file keys protected by an embedded public key — standard double-encryption architecture. The encryptor targets both Windows and Linux environments, with the Linux build specifically capable of affecting VMware ESXi hypervisors.

Encryption approach: The group uses a fast encryption model that prioritises the file header rather than encrypting entire files. This allows rapid encryption of large volumes of data — important for minimising detection window before all accessible files are rendered inaccessible. The approach is less thorough than full-file encryption but operationally faster.

Network shares: The encryptor enumerates and encrypts network shares in addition to local drives, which is significant in enterprise environments where shared storage holds high-value data.

No self-propagation: Unlike ransomware families that include worm capability, Money Message’s encryptor does not self-propagate. The group handles lateral movement through conventional means during the initial access phase, spreading manually before deploying the encryptor.

Ransom note: The group leaves a text-based ransom note referencing a .onion negotiation channel. Demands are communicated through that channel rather than through any automated portal.

Confirmed Incidents

MSI (March–April 2023)

The most consequential Money Message incident was the breach of Micro-Star International, disclosed in late March 2023. The group claimed access to approximately 1.5 TB of data, including MSI source code and, critically, private signing keys used for Intel Boot Guard and MSI’s own BIOS firmware signing.

Money Message demanded $4 million. MSI did not confirm payment. The group subsequently published the stolen data, which included:

  • BIOS source code for multiple MSI motherboard models
  • Private keys for Intel Boot Guard — a hardware-rooted trust mechanism that verifies firmware hasn’t been tampered with
  • MSI’s own firmware signing private keys

The publication of Boot Guard private keys had documented downstream security implications. Intel Boot Guard is designed to prevent installation of unsigned firmware; private key compromise undermines that guarantee for affected hardware. Intel and MSI issued guidance following the disclosure.

AMES Airlines (2023)

The group claimed a breach of AMES Airlines, a Philippine cargo and charter operator, with data published on its leak site. The aviation sector targeting reflects an interest in organisations with time-sensitive operational data where disruption pressure is high.

Additional Victims

Money Message has claimed victims across manufacturing, technology, and gaming sectors. The group maintains a relatively low cadence of publicly claimed victims compared to high-volume RaaS operations, consistent with an operational model focused on selective high-value targets.

Tactics, Techniques, and Procedures

Initial access: The group has used compromised credentials and exploitation of internet-facing services. Specific initial access brokers or consistent IAB relationships are not publicly documented.

Lateral movement: Standard enterprise credential abuse and network enumeration before encryptor deployment.

Data exfiltration: Exfiltration occurs before encryption, following the double-extortion pattern. Stolen data is staged on attacker infrastructure and used as leverage in parallel with the ransom demand.

Negotiation: The group communicates through a Tor-based chat interface. Known negotiation posture includes reduced demands where victims engage quickly, though the MSI public disclosure suggests the group will publish data when negotiations fail or demands aren’t met.

Assessment

Money Message occupies a distinct position: technically capable, operationally self-contained (no affiliate model), and willing to pursue targets whose data creates systemic supply chain risk beyond the immediate victim. The MSI incident established that the group understands and exploits the downstream value of manufacturing and technology company data — firmware signing keys have value in ways that a ransom payment does not capture.

For organisations in technology manufacturing, aviation, and the broader supply chain around hardware development: Money Message is a relevant threat actor to track, less for volume and more for the intent and capability to pursue high-leverage data targets.

// Related Intelligence
Group Profile

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Group Profile

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms

Group Profile

Gunra Ransomware: Conti-Derived RaaS Expands to Five Continents with Multi-Sector Targeting