BlackCat ransomware insider case diagram

No Margarine for Error: Land O’Lakes Man Pleads Guilty in BlackCat Case

Land O’Lakes man slips into BlackCat scheme as insider, pleads guilty.

A self-described ransomware negotiator is now facing federal charges after admitting he secretly collaborated with threat actors while working cases on behalf of victims.

Forty-one-year-old Angelo Martino, formerly of Land O’Lakes, has pleaded guilty to one count of conspiracy to obstruct, delay or affect commerce by extortion, according to the U.S. Department of Justice.

In plain English, Martino presented himself as a security consultant who could help companies negotiate ransomware payments. Prosecutors say that in reality, he was secretly sharing sensitive negotiating details with attackers, helping them extract larger payouts from his own clients.

“Beginning in April 2023, Martino abused his role at a U.S.-based cyber incident response company to assist BlackCat actors,” the DOJ said in announcing the plea.

“Working as a negotiator on behalf of five different ransomware victims, Martino provided BlackCat attackers with confidential information about the negotiating position and strategy of his company’s clients without the clients’ or his employer’s knowledge or permission.”

BlackCat Partner in Crime

BlackCat (also known as ALPHV) is a prolific ransomware-as-a-service (RaaS) gang that trances back to 2021. It quickly rose to prominence for its scale and technical sophistication, according to researchers at Microsoft and CrowdStrike.

The malware is known for the fact it’s written in Rust—a relatively uncommon choice that allows it to operate across multiple operating systems. BlackCat operators distribute the malware through an affiliate model in which core operators supply the tooling while partners execute attacks.

Analysts at Palo Alto Networks Unit 42 and Cisco Talos say the group relies heavily on “double extortion,” stealing sensitive data before encrypting systems and threatening public leaks to pressure payment. BlackCat targets include healthcare, energy and other critical sectors. Despite repeated law enforcement takedowns, researchers note the group has remains a nuisance and is known for rebranding and resurfacing after disruption.

He Was Supposed to Help Victims

The case goes further than a corrupt middleman. According to the DOJ, Martino also admitted to conspiring with U.S.-based individuals Ryan Goldberg and Kevin Martin to deploy BlackCat ransomware against victims between April and November 2023.

In at least one instance, prosecutors say the group extorted roughly $1.2 million in Bitcoin from a victim, then split proceeds among themselves and laundered the funds.

The Justice Department said Martino was paid by BlackCat affiliates for the inside information he provided during negotiations, effectively allowing attackers to adjust their demands in real time based on victim behavior.

The scheme underscores a less-discussed risk in ransomware response: the insider threat within trusted recovery and negotiation processes.

“He also conspired with other U.S. residents to launch attacks on victims across the country,” the DOJ said.

Federal officials framed the case as a reminder that ransomware threats are not exclusively overseas operations.

“For all the international aspects of cybercrime, the threat is also here in the United States,” said Brett Leatherman, according to the release.

Sometimes, the call really does come from inside the house.

Authorities say they have seized roughly $10 million in assets tied to Martino, including cryptocurrency, vehicles, and a fishing boat. He faces up to 20 years in prison at sentencing, scheduled for July 9.

Shaun Nichols headshot

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity

Total
0
Shares
Previous Article
Laundry matt with Euros being washed to illustrate Fintech Fraud article

Fintech Fraud: How Mule Accounts Are Made and Sold

Next Article
Vercel logo illustrating an update to a supply-chain attack

Vercel Updates Platform, Scopes Possible Wider Impact of Attack

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading