HT TECH wants to start sending you push notifications. Click allow to subscribe

Backing Russia against Ukraine cost one of the world's most successful ransomware groups dear

Ukraine war: One of the world's most successful ransomware groups is reeling from a massive dump of its own data after the cybercriminal gang aligned itself with Russia.

By: BLOOMBERG
Updated on: Aug 22 2022, 10:24 IST
Conti, a cybercriminal group based in Russia has itself become the target of brute force attacks from hackers. (Pixabay)

Ukraine war: One of the world's most successful ransomware groups is reeling from a massive dump of its own data after the cybercriminal gang aligned itself with Russia.

Conti, a cybercriminal group that researchers say is based in Russia, has extorted millions of dollars from U.S. and European companies in recent years. It provides affiliates around the world with malware that they deploy against victims in exchange for a cut of the ransom payments.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

The data leak, which lays bare unprecedented details of attack infrastructure, Bitcoin addresses, as well as internal conflicts and accusations, might never have occurred if the ransomware group Conti had chosen to stay apolitical, said Alex Holden, the chief information security officer for cybersecurity firm Hold Security LLC. 

“The main thing is that the gang itself contained a number of Ukrainians, it did not differentiate between its members,” Holden said. That changed last week after Russian forces attacked Ukraine, shelling military airbases, attacking checkpoints and killing at least 137 Ukrainian troops.

While the Russian ground invasion played out on television screens around the world, a cyber conflict has occurred in parallel. Hackers on both sides of the conflict launched brute force attacks known as distributed denial-of-service attacks to knock government websites offline. 

By the end of last week, Conti surprised many by firmly planting itself in Russian President Vladimir Putin’s camp, saying it would use “all possible resources to strike back at the critical infrastructures of an enemy.” The announcement caused a fissure within the group, cybersecurity analysts told Bloomberg News, which counts members from Russia and Eastern Europe among its members and affiliates.

“Most Russian-language underground forums don’t allow discussions related to political topics,” said Oleg Bondarenko, a senior director on the research team at Mandiant Inc. “All such threads are quickly deleted by administrators,” and some forums ban accounts that talk of targeting Russian-speaking countries, he said.

Conti issued a more muted announcement soon after its initial message, saying that while the group didn’t ally itself with any particular government, it would direct resources at “Western warmongers” and avenge any attempts to target critical infrastructure in Russia or any Russian-speaking region in the world.

“Ransomware is a global operation,” said Allan Liska, an intelligence analyst at Massachusetts-based cybersecurity firm Recorded Future Inc. “You may be based in Russia but you have to take into account all of the affiliates that are spread out all over the world right now, most likely, who are not fans of Russia. So you can’t take a stance like that and not expect there to be blowback.”

The blowback, he said, came in the form of chat logs and internal recriminations that dated back 13 months bleeding out into the public with the data leak. 

“I’ve found 150-plus Bitcoin wallets, there’s a whole lot of analysis to be done with that,” he said. The back-end infrastructure that Conti administrators or affiliates used during ransomware attacks were now out there “for governments or cybersecurity companies to start poking to find weaknesses.” While internal structures could be changed, “now we know what the back-end structure looks like, and we know what to scan for, what to look for when they move it,” he said.

Investigators have previously used financial data, such as cryptocurrency wallet addresses, to map ransomware hackers’ activities, and in some cases seizing extortion funds. Technical data gives security personnel clues on how to block potential Conti hacks in the future. 

Hold Security’s Alex Holden also described what he’d been able to see of the leak. “We see the financial operations, we see their aspirations, for example, they talk about building their own cryptocurrency, we see them fighting with each other,” he said. “One of them recently encrypted a hospital filled with cerebral palsy patients, and we see how they are trying to kick this person out for breaking their code.”

The identity of the leaker is not clear, though Holden suggested a Ukrainian cybersecurity researcher was behind the revelations. 

If the revelations lead to the end of Conti’s domination of the ransomware market, there are still many others standing by to fill that space.

LockBit, a cybercriminal gang that also traffics in ransomware-as-a-service to hackers, released a statement over the weekend listing some of the many nationalities it counts in its community. 

“For us, it is just business, and we are all apolitical,” the group said. “We are only interested in money for our harmless and useful work. We will never, under any circumstances, take part in cyber-attacks on critical infrastructures of any country in the world or engage in any international conflicts.”

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 01 Mar, 22:02 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
21% OFF
Samsung Galaxy Tab S8
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹54,999₹69,999
Buy now
38% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,790₹52,999
Buy now
28% OFF
Asus ROG Zephyrus M16 GU603ZM K8034WS Laptop
  • Off Black
  • 16 GB RAM
  • 512 GB SSD
₹81,990₹113,990
Buy now
25% OFF
Asus ROG Zephyrus G14 GA401QC HZ046TS Laptop
  • Eclipse Gray
  • 8 GB RAM
  • 1 TB SSD
₹100,900₹135,000
Buy now
14% OFF
Asus ROG Strix Scar 17 G733CX LL013WS Laptop
  • Off Black Stealth
  • 32 GB RAM
  • 2 TB SSD
₹236,990₹275,990
Buy now
NEXT ARTICLE BEGINS