KELA REPORT

Analysis of leaked Conti’s internal data

On February 27, 2022, as a response to the Conti ransomware gang’s support of the Russian invasion of Ukraine, a suspected Ukrainian researcher leaked internal conversations of its members.

Share:

KELA report cover: Analysis of leaked Conti’s internal data

Key Report Highlights:

  • How a loose crew that ran Ryuk, Conti and Maze as separate projects evolved into the modern Conti operation
  • Conti’s toolset: Trickbot, Emotet and BazarBackdoor for initial access, Diavol as a side project, Cobalt Strike and Mimikatz, and attempts to test CarbonBlack and Sophos products
  • How Conti bought network access from Initial Access Brokers, including RDPCorp’s 35% and 15% ransom-share terms
  • Nearly 100 victims discussed in the chats, half of them never published, with ransom demands of USD 800,000 to 8.3 million (1-3% of revenue)
  • Conti’s organizational structure of hackers, coders, testers, crypters, OSINT specialists, negotiators, IT and HR, with profiles and connection maps of the top 15 actors

Download the Report

Related Resources

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested