UPDATED 22:14 EST / MARCH 10 2022

SECURITY

Leaked correspondence and files expose infamous Conti ransomware gang

An unknown member of the infamous Conti ransomware gang has been leaking internal documentation about the gang after it came out in support of Russia’s invasion of Ukraine.

The leaks started in late February in the days following the Russian invasion, with the leaker making it very clear that he or she was doing so because in support of Ukraine. Conti first emerged in 2020 and has quickly become one of the most prolific ransomware groups. It’s believed to have extorted $180 million from victims.

Previous Conti victims include Ireland’s health serviceAdvantech Co. Ltd., voice-over-internet-protocol hardware and software maker Sangoma Technologies Corp., hospitals in Florida and Texas, Tesla Inc. and Apple Inc. supplier Delta Electronics Inc. in January and kitchenware maker Meyer Corp. U.S. in February.

Dubbed the “Panama Papers of ransomware” by John Fokker, the head of investigations at Trellix, the leaked material offers a rare insight into the workings and activities of a major ransomware gang. Files leaked include chat logs, infrastructure and the economics of how the gang operates. Notably, some of the correspondence shows that Conti has links to the Kremlin and the Russian government.

As detailed Wednesday by researchers by BreachQuest Inc., the leaks show Conti to be a multilayered organization that operates like a company that hires and even fire contractors and salaried employees alike. That analysis includes a detailed Conti organization chart that shows the various people involved in the gang, starting from Stern, “the big boss” at the top of the group.

Apparently, hiring for a criminal ransomware gang isn’t that easy, despite the large amounts of money involved.

“Conti understands that the turnover ratio of workers is also very high due to the fact that they are running a criminal organization,” the BreachQuest researchers noted. “The Conti group has an HR/Recruiter that assists with the continual finding and recruitment of new candidates.”

Conti’s overhead costs were also detailed, as well as what they call “Project Blockchain,” an effort to create its own “altcoin” or form of cryptocurrency. Also detailed were operation details, such as how Conti compromises sites, escalates attacks and receives payment and the various tools used by the gang to spy on and compromise victims.

“The leaks reveal Conti’s arsenal and their mindset,” the researchers at BreachQuest said. They added that they “believe that many offspring or splinter ransomware groups will appear as this level of knowledge and insight that has never before been shared.”

Image: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.