Conti ransomware source code leaked by Ukrainian researcher

Ransomware
Image Credit: Shutterstock (Image credit: Shutterstock)

A Ukrainian researcher who recently leaked tens of thousands of chat messages belonging to the operators of the Conti ransomware, has now published the malware's source code.

Following the initial leak in which 60,000 messages were pushed online, the same researcher then leaked another 107,000 internal messages, and after that the source code for multiple Conti tools, including the group’s administration panel, the BazarBackdoor API, as well as the Conti ransomware encryptor, decryptor, and builder.

The latter three came in a password-protected archive, but was soon cracked by another researcher, providing everyone with free and easy access to Conti’s underbelly.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Conti's image taking a hit

While this doesn’t necessarily spell doom for Conti, it could result in the creation of additional ransomware groups, as the source code can now easily be adopted by other threat actors, modified a bit, and returned back to vulnerable endpoints.

Whether or not that will be the case, and what will that mean for Conti, remains to be seen. The media speculate the leak will be a major blow for the ransomware gang’s reputation, which could result in affiliates moving elsewhere.

The Russian invasion of Ukraine doesn’t seem to be paying off. Besides heavy sanctions and the country’s elimination from various international organizations and infrastructure, the backlash has also spilled into the cyber-realm.

Conti has found itself on thin ice in the internet’s underworld, as it announced siding with Russia and threatened retaliation against anyone who would assault the country’s digital infrastructure. As many of its affiliates seem to be of Ukrainian origin, it wasn’t long before Conti was forced into altering its stance and declaring “neutrality”. 

However, that doesn’t seem to have helped the group much, as the Ukrainian leakster continues to expose the group’s dirty laundry on the internet. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ransomware
Top ransomware gang's internal chat logs leaked online
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Cl0p ransomware group says it was behind Cleo attacks
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
Less than half of ransomware incidents end in payment - but you should still be on your guard
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
Latest in Security
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Latest in News
An Nvidia GeForce RTX 4060 on a table with its retail packaging
Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – and that it’ll run with only 8GB of video RAM
A close up of the limited edition vinyl turntable wrist watch from AndoAndoAndo
This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want one
A close up of Gemma sitting down in Severance season 2 episode 7
'I'm like Gemma, I'm in the dark': Severance star Dichen Lachman shares disappointing filming update for the popular Apple TV+ show's third season
OpenAI
OpenAI wants to help your business build its next generation of AI agents
The main character from Intergalactic: The Heretic Prophet performing a jump attack on a robot enemy.
Neil Druckmann reveals new details about Naughty Dog's Intergalactic: The Heretic Prophet, says it's 'a game about faith and religion' and wants players to be 'lost' and 'confused'
A close up of Captain America with Thor and Hulk in the background during the Assemble scene in Avengers: Endgame
'We will draw inspiration': Joe and Anthony Russo reveal which of Marvel's Secret Wars comic book series have influenced Avengers 5 and 6's plot