A Ukrainian researcher continues to cause trouble for the Conti ransomware gang, publishing more internal conversations, as well as the ransomware's source code.
See also: Nvidia confirms data breach after cyberattack

The notorious ransomware group Conti released a statement last week saying it was siding with Russia in its invasion of Ukraine. Shortly after, it released another statement saying the group was not aligned with any government and condemned the war. However, a Ukrainian researcher who has been secretly spying on the hackers’ operations was apparently upset by these statements and decided to expose the group’s data.
On Sunday, the Ukrainian researcher leaked 393 JSON files containing over 60,000 internal messages, taken from the group's private XMPP chat server.
These conversations took place between January 21, 2021 and February 27, 2022 and contained important information, such as bitcoin addresses, attack information, etc.
On Monday, the researcher continued to expose more Conti data. Specifically, he leaked another 148 JSON files containing 107,000 internal messages from June 2020, around the time the Conti ransomware gang began operating

The researcher also leaked the source code for the gang's administrative panel, the BazarBackdoor API, screenshots from storage servers, and much more.
See also: TeaBot trojan “resurfaces” on the Play Store and targets users around the world
However, what caught the eye was a password-protected file containing the source code for the Conti ransomware encryptor, decryptor, and builder.
While the Ukrainian researcher who leaked the data did not share the password publicly, another researcher soon cracked it, giving everyone access to the Conti ransomware source code.
Although the leak helps the investigation, the availability of this code has its drawbacks.
When the source code for HiddenTear (for “educational purposes”) and Babuk ransomware, threat actors quickly began harvesting the code to launch their own malicious operations. The same is expected to happen now.
See also: Microsoft: Ukraine was attacked by FoxBlade malware before the invasion
The leaks of internal messages and source code were certainly a significant blow to the team and its reputation. Many affiliates may leave the team and go elsewhere. It remains to be seen whether this incident will actually have any significant impact on the gang.
Source: Bleeping Computer
