HomeSecurityUkrainian researcher published the source code of Conti ransomware

Ukrainian researcher publishes Conti ransomware source code

A Ukrainian researcher continues to cause trouble for the Conti ransomware gang, publishing more internal conversations, as well as the ransomware's source code.

See also: Nvidia confirms data breach after cyberattack

Conti ransomware source code

The notorious ransomware group Conti released a statement last week saying it was siding with Russia in its invasion of Ukraine. Shortly after, it released another statement saying the group was not aligned with any government and condemned the war. However, a Ukrainian researcher who has been secretly spying on the hackers’ operations was apparently upset by these statements and decided to expose the group’s data.

On Sunday, the Ukrainian researcher leaked 393 JSON files containing over 60,000 internal messages, taken from the group's private XMPP chat server.

These conversations took place between January 21, 2021 and February 27, 2022 and contained important information, such as bitcoin addresses, attack information, etc.

On Monday, the researcher continued to expose more Conti data. Specifically, he leaked another 148 JSON files containing 107,000 internal messages from June 2020, around the time the Conti ransomware gang began operating

Ukrainian researcher publishes Conti ransomware source code

The researcher also leaked the source code for the gang's administrative panel, the BazarBackdoor API, screenshots from storage servers, and much more.

See also: TeaBot trojan “resurfaces” on the Play Store and targets users around the world

However, what caught the eye was a password-protected file containing the source code for the Conti ransomware encryptor, decryptor, and builder.

While the Ukrainian researcher who leaked the data did not share the password publicly, another researcher soon cracked it, giving everyone access to the Conti ransomware source code.

Although the leak helps the investigation, the availability of this code has its drawbacks.

When the source code for HiddenTear (for “educational purposes”) and Babuk ransomware, threat actors quickly began harvesting the code to launch their own malicious operations. The same is expected to happen now.

See also: Microsoft: Ukraine was attacked by FoxBlade malware before the invasion

The leaks of internal messages and source code were certainly a significant blow to the team and its reputation. Many affiliates may leave the team and go elsewhere. It remains to be seen whether this incident will actually have any significant impact on the gang.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS