KELA REPORT
Analysis of leaked Conti’s internal data
On February 27, 2022, as a response to the Conti ransomware gang’s support of the Russian invasion of Ukraine, a suspected Ukrainian researcher leaked internal conversations of its members.
Share:

Key Report Highlights:
- How a loose crew that ran Ryuk, Conti and Maze as separate projects evolved into the modern Conti operation
- Conti’s toolset: Trickbot, Emotet and BazarBackdoor for initial access, Diavol as a side project, Cobalt Strike and Mimikatz, and attempts to test CarbonBlack and Sophos products
- How Conti bought network access from Initial Access Brokers, including RDPCorp’s 35% and 15% ransom-share terms
- Nearly 100 victims discussed in the chats, half of them never published, with ransom demands of USD 800,000 to 8.3 million (1-3% of revenue)
- Conti’s organizational structure of hackers, coders, testers, crypters, OSINT specialists, negotiators, IT and HR, with profiles and connection maps of the top 15 actors




