{"id":2494,"date":"2022-03-11T12:52:22","date_gmt":"2022-03-11T19:52:22","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2494"},"modified":"2022-03-11T12:52:26","modified_gmt":"2022-03-11T19:52:26","slug":"conti-ransomware-gang-hit-with-data-leak","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/11\/conti-ransomware-gang-hit-with-data-leak\/","title":{"rendered":"Conti Ransomware gang hit with data leak"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" data-src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/conti.png\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption><a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/conti.png\">https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/conti.png<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-left wp-block-paragraph\">Conti, a well-known ransomware organization, declared support for Russia when it attacked Ukraine on February 25. It turned out to be a terrible idea: a vast collection of the gang&#8217;s secrets was disclosed just days later. The data includes information on hacking activities, the gang&#8217;s Bitcoin wallets, and speculation on the future of cryptocurrency as a money-laundering tool. Experts in ransomware are already combing over the data to learn more about the group&#8217;s internal activities. The files were translated into English by security researchers. In their statement, the leaker said, &#8220;Glory to Ukraine.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"twitter-tweet\"><blockquote class=\"twitter-tweet\" data-lang=\"en\"><p lang=\"en\" dir=\"ltr\">Conti ransomware group previously put out a message siding with the Russian government. <br><br>Today a Conti member has begun leaking data with the message &quot;Fuck the Russian government, Glory to Ukraine!&quot;<br><br>You can download the leaked Conti data here: <a href=\"https:\/\/t.co\/BDzHQU5mgw\">https:\/\/t.co\/BDzHQU5mgw<\/a> <a href=\"https:\/\/t.co\/AL7BXnihza\">pic.twitter.com\/AL7BXnihza<\/a><\/p>&mdash; vx-underground (@vxunderground) <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1498060366445613056?ref_src=twsrc%5Etfw\">February 27, 2022<\/a><\/blockquote><\/div>\n<\/div><figcaption>  <\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The Conti ransomware dumps revealed exactly how profitable ransomware can be, with upwards of $2 billion placed in the group&#8217;s principal Bitcoin wallet in the previous two years. The disclosed data package contains about 400 files comprising tens of thousands of internal Conti group conversation logs in Russian. The files contain around a year&#8217;s worth of messages dating back to January 2021, almost six months after the group&#8217;s formation in mid-2020.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong><em>What is the Conti Ransomware?<\/em><\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In May of 2020, the Conti ransomware surfaced on the threat scene. It has several similarities to other ransomware families. Conti has evolved quickly since its discovery, and it&#8217;s notable for how quickly it encrypts and installs throughout a target system. Conti is a &#8220;double extortion&#8221; ransomware that takes and threatens to reveal data in addition to encrypting it. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Ryuk_(ransomware)\">Ryuk ransomware<\/a> that first appeared in 2018 was created by the same group. The group is known as Wizard Spider and is based in Saint Petersburg, Russia. According to experts, Conti is said to have links to Russian intelligence which allows affiliates to rent access to the company&#8217;s infrastructure in order to conduct attacks.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong><em>Previous thefts of Conti<\/em><\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Conti has been accused of launching ransomware attacks on scores of companies, like <a href=\"https:\/\/www.pcmag.com\/news\/shutterfly-hit-with-conti-ransomware\">Shutterfly<\/a>, as well as key infrastructures, such as emergency dispatch centers and first-responder networks. Conti took out the Irish healthcare system&#8217;s networks in May, prompting a state-wide suspension of IT systems that caused serious delays around the country and cost the government more than $100 million in recovery expenses.[5]<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><em><strong>Ransomware can be lucrative<\/strong><\/em><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware is still prevalent for one simple reason: it&#8217;s profitable. It&#8217;s beneficial not just for ransomware producers (who are only one part of the equation), but for the whole network of participants that make up the ransomware economy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conti received $180 million in extortion payments last year, more than any other criminal organization. Conti was able to do things that average investors couldn&#8217;t, such as manipulate the price of cryptocurrencies in one direction or the other, thanks to his money. Building a cryptocurrency platform and seeding it with ill-gotten bitcoin from phantom investors is another option.[6]<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><em><strong>What\u2019s next?<\/strong><\/em><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Information security, state-sponsored hacking, ransomware, and malware have all been at the forefront of the Russia-Ukraine conflict, with hackers on both sides purportedly executing large-scale operations against their opponents&#8217; infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Experts are keeping a tight eye on both nations, fearful that a volatile situation involving one of the world&#8217;s most powerful hacking superpowers might spark a massive cyber fight that outlasts the physical clashes.<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong><em>What to do immediately (if you have been hit with Conti):<\/em><\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To lessen the chance of being hacked by Conti ransomware, network defenders should implement the following mitigations, according to CISA, FBI, and NSA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022 Set up network segmentation and traffic filtering.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022 Run a vulnerability scan and maintain your software up to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022 Disable any programmes that aren&#8217;t essential and implement controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2022 Keep user accounts safe.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/image-4.png\" alt=\"\" class=\"wp-image-2496 lazyload\" width=\"750\" height=\"574\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/image-4.png 940w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/image-4-300x230.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/image-4-768x588.png 768w\" data-sizes=\"(max-width: 750px) 100vw, 750px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 750px; --smush-placeholder-aspect-ratio: 750\/574;\" \/><figcaption><a href=\"https:\/\/blog.malwarebytes.com\/wpcontent\/uploads\/2021\/04\/conti_ransom_note.png\">https:\/\/blog.malwarebytes.com\/wpcontent\/uploads\/2021\/04\/conti_ransom_note.png<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\" \/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong><em>References <\/em><\/strong><\/h4>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li><a href=\"https:\/\/heimdalsecurity.com\/blog\/what-is-conti-ransomware\/\">What Is Conti Ransomware and Who Is Behind It? (heimdalsecurity.com)<\/a><\/li><li><a href=\"https:\/\/info.varonis.com\/hsfs\/hubfs\/fig1.png?width=1202&amp;name=fig1.png\">https:\/\/info.varonis.com\/hsfs\/hubfs\/fig1.png?width=1202&amp;name=fig1.png<\/a><\/li><li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Ryuk_(ransomware)\">Ryuk (ransomware) &#8211; Wikipedia<\/a><\/li><li><a href=\"https:\/\/www.pcmag.com\/news\/shutterfly-hit-with-conti-ransomware\">Shutterfly Hit With Conti Ransomware | PCMag<\/a><\/li><li><a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/irish-healthcare-system-requires-more-than-100-million-to-recover-from-the-conti-ransomware-attack\/\">Irish Healthcare System Requires More Than $100 Million To Recover From the Conti Ransomware Attack &#8211; CPO Magazine<\/a><\/li><li><a href=\"https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-iv-cryptocrime\/\">Conti Ransomware Group Diaries, Part IV: Cryptocrime \u2013 Krebs on Security<\/a><\/li><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa21-265a\">Conti Ransomware | CISA<\/a><\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Conti, a well-known ransomware organization, declared support for Russia when it attacked Ukraine on February 25. It turned out to be a terrible idea: a vast collection of the gang&#8217;s secrets was disclosed just days later. The data includes information on hacking activities, the gang&#8217;s Bitcoin wallets, and speculation on the future of cryptocurrency as &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/11\/conti-ransomware-gang-hit-with-data-leak\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Conti Ransomware gang hit with data leak&#8221;<\/span><\/a><\/p>\n","protected":false},"author":406,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[16,19,47,39,40],"class_list":["post-2494","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","tag-cpsc329","tag-privacy","tag-ransomware","tag-russia","tag-ukraine","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Amna Hassan","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/amna-hassan\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/406"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2494"}],"version-history":[{"count":7,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2494\/revisions"}],"predecessor-version":[{"id":2507,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2494\/revisions\/2507"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}