Dr. Ransomware
TL;DRVenezuelan cardiologist Moses Luis Zagala Gonzales, known online as Asclepius, was accused by US prosecutors of creating ransomware tools Thanos and Jigsaw v2, and licensing them to cybercriminal affiliates.
The story of the case against Moises Luis Zagala Gonzalez — a cybercriminal polymath, or international fall guy. This is part one of a two episode investigation from The Ransomware Files miniseries.
Follow The Ransomware Files wherever you listen to podcasts. https://anchor.fm/ransomwarefiles + https://twitter.com/ransomwarefiles
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: How did you get on to this story?
Speaker 2: Well, the Department of Justice released a press release, announcing this criminal complaint. It was interesting, not only for, like, the content, which is a cardiologist in Venezuela who's accused of coding ransomware, but also the length of the press release. It was just really, really long. And I was like, okay. Well, I gotta go to this document, read this, and just started reading this criminal complaint, which just read, like, something otherworldly even in the ransomware world. And I was just thinking like, I've gotta find this guy.
Speaker 1: The FBI cyber most wanted list is longer than I was expecting. Right now, there are 113 names on that list. 113 people who the FBI would most like to talk to. And you start scrolling through this grid of faces and you're gonna start to see some patterns. A good chunk of the people on the FBI cyber most wanted list are in military uniforms, wanted for alleged involvement in state sponsored hacks.
Speaker 3: But out
Speaker 1: of those 113 faces, one of them sticks out. Because only one person on the FBI cybercrime most wanted list is wearing a crisp white doctor's coat. He is, from what I can tell, the third oldest person on the list. He is 55 years old at time of recording. His name is doctor Moses Luis Zagala Gonzales, and he is either a cardiologist moonlighting as a cybercriminal polymath or the fall guy for a decades long cyber criminal operation.
Speaker 2: If he is who they say he is, I don't think his family really has any idea. They probably just thought Moses is in the backyard shed doing his computer stuff. Right? That's probably what they knew.
Speaker 1: Jeremy Kirk, who makes the excellent podcast miniseries, The Ransomware Files, started pulling on this thread a few months ago, trying to answer this question. Who is this Venezuelan cardiologist who the American government alleges is the architect of some of the world's most dangerous ransomware tools? So rather than asking Jeremy to answer all of the questions he already answers on that show, The Ransomware Files, we are proud to bring you that episode. The first part of his two part piece on the story of Moses Luis Zagala Gonzales. The Ransomware Files episode 10, doctor ransomware, here on Hacked.
Speaker 2: In the late nineteen nineties, there was an elite crew of hackers who specialized in what's called reverse engineering. They called themselves High Cracking University. They took pride in taking apart software binaries, which are executable programs that you'd install on a computer. They take the software apart or crack it as they say. They were amongst the best in the world at reverse engineering Windows applications. And while you can crack software with the aim of just not having to pay for it, they weren't into it for that. They were in it for intellectual sport. And one among their ranks was an expert reverse engineer who went by the name Asclepius. He was smart and he was one of the highest ranking members of the group. And while many hackers eventually move on to other things, get different jobs or their skills fade, Asclepius stayed around. The nickname from the late nineteen nineties pops up on malware forums in the February and beyond. And in May 2022, US prosecutors accused Asclepius of creating file encrypting ransomware. Ransomware is now a billion dollar cybercriminal industry. Attackers break into networks, encrypt all of the files, and demand a ransom to supply the decryption key. It's devastating high-tech crime.
Speaker 4: It's completely unpredictable, and when it strikes, it's debilitating. At at best, it shuts down corporate operations for a period, but at worst, it can destroy an
Speaker 2: institution. Much, but, of course, not all ransomware activity has a nexus to Eastern Europe and Russia, and it usually involves younger people in their twenties or thirties. That general profile is in part what made the US government's announcement so intriguing. They allege that E Scalpius' in real life name is Moses Luis Zagala Gonzales. He's a 55 year old cardiologist living in Ciudad Bolivar. It's a city in Southeastern Venezuela that struggles with constant power outages, water supply issues, and often protests. Prosecutors claim Moses is a multitasking doctor who designed two ransomware tools and trained attackers on how to use them. You could say they're essentially accusing him of being doctor ransomware. The accusation is so far out of the normal bounds. Could someone be a cardiologist and a ransomware developer?
Speaker 5: So some people reply to the message saying, oh my god. This makes no sense because, you know, he was my teacher or, you know, he was my professor at college, and he was my or he was my doctor. And, one guy was like, absolutely, I'm sure he's not guilty. You know, I'm sure he's not the guy you're looking for. So, yeah, I mean, people are pretty shocked.
Speaker 2: This incredible story will stretch across two episodes. We're gonna explore who is Moses Zagalla and why The US authorities think he's a ransomware mastermind. We'll also see what he and his family have to say about the allegations. This is the Ransomware Files. I'm Jeremy Kirk. In this podcast miniseries, I'm exploring the impact of ransomware, one of the greatest crime waves to ever hit the Internet. Schools, hospitals, and companies have fallen victim to cybercriminals encrypting their data and demanding payment. But IT pros are fighting back, and they have stories of resilience and fortitude. Everyone knows the FBI's most wanted list, but there's also a most wanted list for people accused of cybercrimes. There's a new entry on that list, Moses Seagala. His wanted poster has three photographs of him, and the one in the middle stands out. He has a bald head, an earnest smile, and is wearing a doctor's white overcoat. He's even got a stethoscope around his neck. Why is this guy on this list? Well, when someone is accused of a crime in The United States, the documents are published for anyone to see. Those include indictments, criminal complaints, transcripts, and more. You can learn an incredible amount about an ongoing case. In the case of Moses Luis Zagala Gonzalez, and I'm just gonna call him Moses for short, what's available is a 20 page affidavit written by an FBI special agent. The document details some of the evidence that the US government alleges against him. Now I wanna be clear here that the allegations made by the US government have not been tested in court. As they say on American TV, but it's true, Moses is innocent until proven guilty. If he were to travel to The United States or was extradited there, he would be entitled to respond to the accusations against him. That would occur in the course of a trial, either by a jury or by a judge. No part of this podcast should be taken as implicating his guilt. The FBI's affidavit is dense and intensely interesting. It's written by Chris Clark who identifies himself as a special agent focused on cybercrime, financial crime, and money laundering. It's full of details about Moses' alleged hacker past, the long trail that led to the current accusations, and startling errors in operational security. Alexander Meindlin is the assistant US attorney for the Eastern District Of New York, which is the federal court where Moses would face trial. Alexander will prosecute the case.
Speaker 4: Moses Seagala is a cardiologist in his mid fifties who lives in Ciudad Bolivar in Venezuela. In addition to being a cardiologist, he as charged in the government's complaint, he also designs, sells, and rents and licenses out ransomware. He's accused essentially of conspiring with users of his ransomware to carry out ransomware attacks on on victim networks. So he's created, well, he created a series of malicious tools, but as relevant to us, the tools, mostly are, a tool called Thanos and a tool called Jigsaw version two. And the the conduct that, he's charged with is, knowingly arranging with cyber criminals, to help them use his tools, in return either for a licensing fee or for a share of the profits. And in fact, he's he's charged with, being himself at the head of a group of ransomware attackers, who use his use his software as as affiliates in return for a for a licensing fee.
Speaker 2: To get to where this criminal case is today, we have to start in the past. In fact, all the way back to the late nineteen nineties, in the early years of the commercial Internet. Who is or was Asclepius? Well, he's actually been around for a long time. Everyone is familiar with his staff or rod. The staff has a serpent entwined around it, and it's a symbol that's incorporated into that of many medical organizations around the world. Asclepius was quite active in that high cracking university group. Surprisingly, there's quite a bit about the group still floating around on the Internet even today. They were master reverse engineers solving big, tough problems. They were also big on sharing the knowledge with others and pushing that knowledge forward. It was called a university after all. And to them, it wasn't just dissecting software. It was an art. Asclepius was one of the highest ranking members of the group. The person behind the nickname was sharp, highly technical, and wrote in fluent, beautiful English with only the occasional grammatical error. His presence was so valued within the group that in 1998, he was trusted with one of High Cracking University's annual challenges. It was called the strainer. It was a series of four reverse engineering challenges. Those who solved the challenges would be admitted to High Cracking University. And instead of saying money or a prize, those who solved the strainer in innovative ways were allowed to put a plus sign in front of their nickname. That was the sign of honor that indicated to others they were now part of this elite group. In late nineteen ninety eight, after that year's strainer had been completed and the winner selected, Asclepius congratulated those who solved the challenges. Asclepius writes,
Speaker 6: Welcome to the PlusHCU. I know you're already elite crackers. You've gained your admission to our university. From this day, we will share cracking knowledge, constituting the most valuable and unique feedback between the best crackers in the scenario. You can now proudly wear the plus sign before your names.
Speaker 2: What's remarkable about Asclepius is his emphasis on education. He was meticulous, polite, and held very high standards when it came to judging what participants submitted. He cared about the craft and not just the endpoint of cracking software, but how one got there. To be a reverse engineer capable of solving Asclepius' challenges, you needed to know Windows and software engineering really well. That included analyzing assembly language, system memory manipulation, anti debugging techniques, and tangling with encryption systems. Those skills could certainly be ported to other types of software development, maybe even ransomware. As Alexander said, the US government claims Moses developed Jigsaw version two, which was a standalone ransomware program. They also claimed he developed Thanos, which is what's called a ransomware builder. A ransomware builder is an application that actually creates new variants of ransomware that can be deployed on a victim's network. Lindsey Kaye is an expert malware analyst and senior director with the computer security firm Recorded Future. She coauthored a report on Thanos that was released in June 2020. I asked Lindsay what she thought about the code's quality. I want to make a note here as well about Lindsay's response. When chatting about Thanos, we often refer to its developer using the pronoun he inadvertently. That's not intended to mean the developer is Moses. Again, that is an accusation that is being made by the US government. So after taking a look at this code, would the person who designed Thanos likely be able to get a job as a software programmer? Or, I guess, to, to put it another way, how good was this evil code?
Speaker 7: This thing that he built, and if he built it on his own, there's at least some software engineering skill set and principles there. So at least kind of at a basic level, yeah, he could probably be a software engineer. It's really hard to kinda tell if just he wrote this or he didn't kind of start with another skeleton of code or he didn't get a lot of examples off the Internet. Because, you know, right now, there's we've access to so much available that it's like, could he have taken a bunch of pieces and just knew enough to cobble them together versus did he write all of the code on his own? So it's a little hard to say there, but clearly, he is not incompetent in the ability to put together code and make it work.
Speaker 2: There's yet another Greek mythology theme running here as well. The name Thanos may be derived from a destructive Marvel comic character who originated from a moon of Saturn. It also might be derived from Thanatos, a figure in Greek mythology associated with death. Moses is accused of actually licensing the Thanos client itself to customers. They're called affiliates in ransomware parlance, kind of similar to affiliate marketing. Lindsay explains that isn't quite the usual way it works in the ransomware business.
Speaker 7: Generally, how a ransomware as a service program will work is once you gain access to the affiliate panel, the ones that don't you don't kind of get the builder yourself, you would log on, access that, pick all the configuration options. So for things like Black Matter and Alpha, kinda more recently, if you've heard of those, that's an example there. You pick all your configuration options, you hit build, and then out comes the build for you. So you don't have it on your own machine to build it, but you do obtain those builds, which theoretically are unique and built to your kind of custom affiliate configurations.
Speaker 2: To put it another way, you just order up your ransomware malware like the way, say, you would order a pair of sunglasses online. Tick the things you want in the checkboxes, polarized, gray tint, and away you go. There were more than 40 configuration options in Thanos, but what Moses is accused of selling is not only the sunglasses, but also the machine that makes the sunglasses, which in this example is the ransomware builder. Thanos was easy to use, which was appealing to those less technical cyber criminals since it didn't use the command line. Command line applications don't have the graphical user interfaces or GUIs, which is how most of us use software. To make command line applications run, you have to know the right commands and enter those into the command line. There's no easy drop down menus. And, of course, they're inherently more difficult to use if you don't know the commands. Here's Lindsay again.
Speaker 7: People aren't necessarily going to want to buy a builder that is all command line, especially if they're getting into ransomware and they're not already super technically competent. Right? So if they're not able to kind of understand how to use those things, they want that nice GUI that's easy to use, easy to understand, pick which features you want, really configure it that way.
Speaker 2: Thanos was brilliantly simple. It had a text box in the GUI where you could write a customized ransom note. You could also add your own creepy menacing graphic. It had a bunch of features too that were designed to ensure its own success by thwarting security or analysis tools used by researchers. For example, it could kill processes affiliated with traffic analysis tools such as Wireshark and Firesheep. It had capabilities to avoid running in virtual machines. Virtual machines are often used by malware analysts to safely look at dangerous applications. Malware creators know this happens, so they often code their malware to look for signs that this may be happening and just stop running. Asclepius also put a unique feature into Thanos that wasn't in a lot of other types of ransomware. It was called RIP Lace or replace. So in November 2019, a security company called Niatron discovered a technique that could allow ransomware to slide past security products. Those products are designed to closely watch changes to files and then stop any actions that appear to be malicious. But the replace technique allowed for the modification and encryption of the Windows file system in a way that endpoint protection products missed. Just two months after Niatron released its findings, the feature had been wrapped into Thanos. On one of the forums where Thanos was sold, a person going by the nickname Nosiphoros, which is one of the nicknames the US government claims Moses used, touted the technique as an advantage of using Thanos. It showed that whomever developed Thanos was keeping up with new research to make more resilient ransomware. Recorded Futures said Thanos was the first ransomware family to advertise the use of the replace technique.
Speaker 7: So I think one of the most significant and kind of interesting aspects of this is that we talk a lot about kind of what threat actors have access to on the dark web, but this is something that, you know, researchers are putting out. So it's very interesting to see somebody now taking research that we as security researchers are putting out and then implementing it. I think this is just a great example that really underscores that idea. So they have access to the same things that we do. So how are we detecting them? Sort of what are we looking for? What are the indicators that are interesting to us, and here's just a really great example of that in in practice.
Speaker 2: Thanos spawned many ransomware variants. Those variants, you can think of them as kind of like the children of Thanos, went by names like Prometheus, Heron, Spook, Hackbit, and Midas. They ended up infecting businesses and organizations around the world in Peru, Mexico, Canada, Chile, Brazil, Italy, and France. There was even a report that an Iranian state sponsored hacking group that's nicknamed Muddy Water had used Thanos. The justice department complaint even alleges that Moses boasted about that use of Thanos on one forum. All of that activity raised alarms. Many computer security companies, including Palo Alto Networks, Zscaler, IBM Security X Force, all wrote analysis of Thanos since it appeared to have notable uptake by cybercriminals. Asclepius was a quite active developer. On one forum, the person wrote to customers assuring them that, quote, I have been developing malware for many years and update my products on a daily basis. Asclepius regularly posted updates on improvements and changes to Thanos. Software developers usually publish what's called a change log, which is kind of like a running list of modifications and improvements to the software. On the 12/01/2019, Asclepius writes
Speaker 6: Code to cripple several antivirus products. Code to erase shadow copies created by third party products.
Speaker 2: Shadow copies are a type of backups, and ransomware actors will often try to erase those backups to make it more likely that victims will have to pay them for a key. On 12/14/2019, Asclepius noted some more improvements.
Speaker 6: Encryption speed significantly improved. Only a few minutes needed to encrypt a full hard drive.
Speaker 2: These improvements to Thanos obviously took time. Could a person conceivably balance a career in cardiology with malware development? Thomas Holt is a professor in the School of Criminal Justice at Michigan State University. He researches computer hacking and malware and the behavior of those who use the Internet for crime, I asked him about the seemingly contradictory premises that the US Department of Justice has outlined.
Speaker 8: The real trick in my mind is the fact that for a profession like cardiology where you would expect that that involves long hours, tremendous focus, to have the free time after that to be able to be a competent hacker who's developing tools that people are using, that to me is the real odd, standout in all of the in all of the, events described.
Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations, but boy does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 9: No one goes to Hank's for spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.
Speaker 10: If you've got an insurance question, you could talk to your nana, but she'd probably just tell you how she insured her couch from stains by covering it with plastic. Or you could talk to your local GEICO agent. They'll give you a different kind of warm and fuzzy with personalized assistance for all your insurance needs, like how you could be saving on your policies. So let your nana cover her couch in plastic and let a local GEICO agent help cover you, but not in plastic. To find a GEICO agent near you, visit geico.com/local.
Speaker 11: This episode is brought to you by Nespresso. Being the best version of yourself is an everyday journey, and it begins in the morning by taking a moment to ground yourself. With the new Nespresso Vertuo Up coffee machine, morning routines become rituals. Just one gentle press. And coffee brews, unfolding into whatever you need today. Bold or delicate, iced or hot, familiar or new. Press to explore. Every coffee, a new world. New virtual up. Shop now at nespresso.com.
Speaker 2: Software development isn't easy, however, and neither is cryptography. Mistakes by ransomware developers have sometimes allowed security researchers to unlock the files of victims. They're considered small wins in a fight where the ransomware actors usually have the upper hand, and researchers found mistakes in Thanos. The mistakes would probably irritate a meticulous precise person like Asclepius. As mentioned before, Thanos had a variety of selectable options. One of those options was to use a static password to create an AES symmetric key that would be used to encrypt files on a victim system. That static password was used along with what's called a SALT to generate the encryption key. Salt in cryptography terms refers to a random value. So the password and the salt were used together to create the AES encryption key. But the problem is that the static password was actually left in the ransomware client itself, which meant it was recoverable. Lindsay explains.
Speaker 7: If it's baked into the file and a reverse engineer looks at it, now they just have to figure out what the salt is. So if the defender gets the ransomware and they're able to figure out what that symmetric key is, then they can decrypt the files.
Speaker 2: IBM's X Force team also spotted another error. It was a weakness in the key generation algorithm. They analyzed a variant called Prometheus that was generated by Thanos. Prometheus's problem was that when it created an encryption key, it failed to use a truly random value as the seed. So let's unpack what that means. In the process of creating an encryption key, Prometheus used a value called a seed. It's supposed to be a random number, and it may seem easy to pick a random number, but actually generating long random numbers is actually quite hard because creating those numbers often means starting with some value or other formula. To create a so called random number, Prometheus used the number of milliseconds that had elapsed since a particular computer had started. That was the seed value. That gave researchers a chance. Calculate the right seed value and the correct key to decrypt the files could be revealed. IBM was able to create a decryptor that ended up helping some victims. It doesn't mean that whomever designed Thanos was a poor developer. Lindsay says that cryptography is difficult to get right, but it meant a lucky break for some victims.
Speaker 7: A lot of really kind of what makes crypto good is that key. So if you're able to guess that key, then the crypto is not really going to protect what you think it is. Other threat actors seem to make some mistakes there. So while that's good for defenders, it's not something that I would necessarily bank on.
Speaker 2: Since US prosecutors announced their case against Moses, I've been trying various ways to get in touch with him. That's involved contacting old Jabber Chat nicknames and email addresses linked with some of the nicknames in the criminal complaint. I found a lot of material online, in fact, reams of it. And to be honest, I don't think I've uncovered everything affiliated with the nicknames, particularly Asclepius. The nickname seems to pop up again and again on forums associated with phone hacking tools, software modification, and malware. I needed to find Moses and see if he'd answer some questions. What's his relationship with computers? Why would The United States think he's a ransomware mastermind? How did he end up becoming a cardiologist? And, of course, what's his response to the allegations? None of the chat handles or email addresses in the forum posts I found got me closer to Moses, but I had another idea. The criminal complaint had a Gmail address associated with Moses's alleged PayPal account. I remembered that on PayPal, you could also send a note along with money. So I sent $13.37 in US dollars, plus a note that asked if whomever received it could get in touch. Some of you listening are probably already smiling at the amount. The number 1337 is numerical shorthand for l e e t or leet. Now leet is an abbreviation for the word elite. In hacker speak, one three three seven became the numerical representation of that compliment. I hope somebody would recognize the amount and maybe have a chuckle and hopefully reach out. But, unfortunately, no one responded, probably because the FBI now controls the account. I really just needed to find somebody on the ground in Venezuela.
Speaker 5: When I read the criminal complaint, I was like, woah. You know, like, I was picturing this, evil genius, and it's actually just like a genius.
Speaker 2: That's Anna Vanessa Herrero. She's a top notch journalist based in Caracas who's reported for the New York Times and the Washington Post. She's been tracking down Moses, his family, his friends, and even his patients.
Speaker 5: What I can see here, is that people are like, woah. What just happened? He cannot be the guy. So everyone I've been reading that's been tweeting or tweeted about this, they were all very surprised.
Speaker 2: By all appearances, Moses is a respected person in the community. He appears to be married to a kidney doctor named Rosani. He's been working at a private clinic in Ciudad Bolivar. We managed to find some of his brothers. There's Guillermo, who's a dental specialist in Caracas, Carlos, who appears to specialize in forensics with the national police, and Gustavo, who's a lawyer in Miami. We started trying to contact them. When you look at a photo of Guillermo Zagala, he and Moses resemble one another. Anna reached out to Guillermo, and we chatted afterwards.
Speaker 5: So I need to tell you what happened today. I contacted Guillermo on Facebook.
Speaker 2: Oh, great. What what did he have to say?
Speaker 5: Well, I said that you and I were working on this and, he immediately attacked me.
Speaker 2: Next time on the ransomware files, doctor Ransomware part two. You really must believe that we are stupid or we don't have enough to eat. Do me the favor of bothering me more. I'm going to file a complaint for harassment. Wait. Wait. Wait. So so say that again. So she says that his email has been hacked and that somebody else is using his identity for all this stuff?
Speaker 4: One one detail that I think is relevant is that as as as stated in the complaint, that there there are CBP records, border protection records about Segala's entry into The US. The, the literal guy is linked to the literal email address through his physical passage across US borders.
Speaker 2: This episode of the Ransomware Files was written, researched, edited, and produced by me, Jeremy Kirk. It was also researched and reported by Anna Vanessa Herrero on the ground from Caracas. The production coordinator for the Ransomware Files series is Rashi Ramesh. The Ransomware Files theme song and other original music in this episode are by Chris Gilbert of Ordinary Weirdos Records, myself, and India Kirk. If you enjoyed this episode of the Ransomware Files, please share it and leave a review. It will help keep this project going. The series has its own Twitter handle at ransomware files, which tweets news and happenings about ransomware. I'm on Twitter at Jeremy underscore Kirk. If you would like to participate in this project or have an idea for it, please get in touch. The project is looking for other people, organizations, and companies that can share their unique experiences for the benefit of all until ransomware, hopefully, becomes a thing of the past.
Speaker 1: Thanks for listening everybody. Thank you to Jeremy Kirk for sharing this episode with us. If you wanna hear the second part of this series, I highly recommend it. It gets very very interesting. We recommend you give it a ransomware files subscription, and you can find the second half of the story right over there. Big old shout out to our new patrons on Patreon. That's patreon.com/hackedpodcast. A great way to support the show. Martin, thank you. Amina Kaplan, thank you. Milo Shala, thank you very much. Stephen Armstrong, sure do appreciate it. Renfield, thank you. Hope you enjoyed this, episode we shared with you. We'll back at you, two weeks from now with with a a Hacks original and with a hopefully an interview I'm very, very excited about. We'll catch you in the next one. Thanks for listening.
Speaker 3: Hey there. It's Wayfair here, where delivery and setup are as easy as a few taps on your phone. You're relaxing in an old hammock, scrolling Wayfair's app when you spot it, a brand new patio set. Next thing you know, Wayfair delivers it right to your patio and sets it up. Oh, you need a new grill too? Alright. Wayfair's got you covered. With Wayfair's room of choice delivery and fast expert set up on qualifying orders, life gets a little easier. Visit wayfair.com or the Wayfair app.
Speaker 11: Wayfair, every style, every home.
Speaker 12: Some follow the noise. Bloomberg follows the money. Because behind every headline is a bottom line. Whether it's the funds fueling AI or crypto's trillion dollar swings, there's a money side to every story. And when you see the money side, you understand what others miss. Get the money side of the story. Subscribe now at bloomberg.com.
Speaker 13: Ryan Reynolds here from Mid Mobile with a message for everyone paying big wireless way too much. Please, for the love of everything good in this world, stop. With Mint, you can get premium wireless for just $15 a month. Of course, if you enjoy overpaying, no judgments, but that's weird. Okay. One judgment. Anyway, give it a try at mintmobile.com/switch.
Speaker 14: Upfront payment of $45 per three month plan, equivalent to $15 per month required. Intro rate first three months only, then full price plan options available. Taxes and fees extra. See full terms at mintmobile.com.