A hacking group appears to have used the source code of the Conti ransomware to create its own ransomware and use it in cyberattacks against organizations in Russia. The Conti source code was leaked a while ago by a Ukrainian researcher.
Almost daily we hear about ransomware attacks targeting companies and encrypting data. However, we rarely hear about Russia being the target of such attacks.
See also: Microsoft: Prevented attacks against Ukraine by removing domains of Russian APT28

Now it appears that a hacking group known as NB65 is now targeting Russian organizations with ransomware attacks. The group is breaching Russian entities, stealing their data and leaking it online, warning that the attacks are due to the Russian invasion of Ukraine.
Russian entities said to have been attacked by NB65 include document management operator Tensor, the Russian space agency Roscosmos , and VGTRK, Russia's state television and radio broadcaster.
The attack on VGTRK was particularly significant as it is said to have resulted in the theft of 786.2 GB of data. This includes 900,000 emails and 4,000 files, which were published on the website DDoS Secrets.
Since late March, hackers NB65 have started targeting Russian organizations with ransomware attacks. Most interestingly, however, the hacking group created its ransomware using the source code of the Conti Ransomware, which was created by Russian hackers who forbid their members from attacking entities in Russia.
The source code and internal conversations of the Conti gang were leaked, following a statement by the group that it was on Russia's side in relation to the attack on Ukraine. Following this, a Ukrainian security researcher leaked 170,000 internal messages and the source code.
A sample of NB65's modified Conti ransomware executable was uploaded to VirusTotal, allowing us to get a glimpse of how it works.
See also: Meta malware: Malicious emails distribute new info-stealer

Almost all antivirus vendors detect this sample on VirusTotal as Conti, and Intezer Analyze confirmed that it uses 66% of the same code as common Conti ransomware samples.
According to BleepingComputer, when encrypting files, the ransomware will append the .NB65 to the files.
The ransomware also creates ransom notes named R3ADM3.txt across the encrypted device, with the threat actors blaming Vladimir Putin and the invasion of Ukraine for the attack.
“We are watching very closely. Your President should not have committed war crimes. If you are looking for someone to blame for your current situation, look no further than Vladimir Putin,” reads the ransom note left by the hacking group NB65 to its victims in Russia.
According to BleepingComputer, the ransomware is based on Conti's source code, but has been modified for each victim so that available decryption tools do not work.
See also: Android banking malware remotely takes control of devices

The hacking group stressed that attacks against organizations in Russia will stop when hostilities in Ukraine cease.
“We will not be hitting targets outside of Russia. Groups like Conti and Sandworm, along with other Russian APTs, have been hitting the West with ransomware for years… We realized it was time for them to deal with it themselves,” the hackers told BleepingComputer.
Source: www.bleepingcomputer.com
