Analysis of leaked Conti files blows lid off ransomware gang
- Reference: 1646958630
- News link: https://www.theregister.co.uk/2022/03/11/conti_leaks_code/
- Source link:
Since then, infosec researchers around the globe have been [1]wading through this silo of intelligence, which reveals the inner workings of the criminal enterprise.
"I call this the Panama Papers of ransomware," Trellix's head of cyber investigations John Fokker [2]told The Record. Trellix is the cybersecurity company previously known as the combined McAfee Enterprise and FireEye.
Conti-nued
Although the ransomware crooks appeared to be dismantling their infrastructure after their internal files were stolen and leaked, Conti, like any number of horror-movie monsters, is still alive, according to the US government.
This week CISA, the FBI, the NSA, and the Secret Service posted a joint [3]advisory on Conti. "Conti cyber-threat actors remain active and reported Conti ransomware attacks against US and international organizations have risen to more than 1,000," the Feds said.
Uncle Sam urges organizations to review [4]its dossier on the gang, which includes technical information on how the miscreants gain initial access to networks plus indicators of compromise.
Conti, it should be said, has the ransomware business model down to a science. It extorted an estimated $180m last year, making it the most lucrative ransomware operation of 2021, according to the latest [5]Crypto Crime Report from security shop Chainanysis. As of late February, Conti's primary Bitcoin address contained more than $2bn in digital currency, according to a Rapid7 [6]report .
But, as with any business, it incurs significant expenses from paying employee salaries in BTC, and maintaining its infrastructure, according to data security biz Varonis.
[7]
"In addition to renting virtual private servers (VPS), favoring services that accept Bitcoin, the group most likely maintains VPN subscriptions to maintain a layer of anonymity when conducting their operations, as well as subscriptions to or purchases of various security products," it [8]wrote .
[9]
[10]
Other leaked documents provide insight into the ransomware gang's hirings and firings, according to [11]analysis by forensics firm BreachQuest. The security vendor provided a detailed Conti org chart that shows Stern, "the big boss," at the top with henchmen responsible for HR and recruitment, blogging and negotiating, training, and blockchain wrangling, plus teams underneath.
[12]Conti ransomware gang's source code leaked
[13]Alleged REvil suspect extradited and arraigned on ransomware spree charges
[14]Ukraine invasion: This may be the quiet before the cyber-storm, IT staff warned
[15]Ragnar ransomware gang hit 52 critical US orgs, says FBI
It turns out that even criminal operations are having difficulty hiring and keeping good staff these days. "Conti understands that the turnover ratio of workers is also very high due to the fact that they are running a criminal organization," BreachQuest wrote. "The Conti group has an HR/Recruiter that assists with the continual finding and recruitment of new candidates."
While Conti has been known for big game hunting — or focusing on high-value targets that will likely pay big bucks to get its encrypted data restored, or to prevent exfiltrated info from being publicly leaked — BreachQuest goes into detail about how Conti ensures that its processes pay off:
When the Conti group compromises Active Directory, they are looking for potentially interesting people like an admin, engineer, or someone in IT. Many companies think that backups are sufficient, but Conti hunts for backup servers to encrypt the backups as well as training manuals reveal that they know techniques to bypass backup storage vendors to make sure the backups are encrypted.
One of the instructions that stood out the most was a section titled "HOW AND WHAT INFO TO DOWNLOAD" that they state after raising the privileges to domain admin and invoke share finder, what Conti is interested in are financial documents, accounting, clients, projects, and much more.
CyberArk posted its own [16]analysis of the Conti leaks, and says the information can help organizations protect themselves. One of the data dumps included 12 git repositories of what's said to be internal Conti software.
"Upon quick inspection of these repositories, most of the code appears to be open-source software that is used by the Conti group," the analysis said. "For instance, [17]yii2 or [18]Kohana is used as part of (what seems to be) the admin panel. The code is mostly written in PHP and is managed by [19]Composer , with the exception of one repository of a tool written in Go." ®
Get our [20]Tech Resources
[1] https://blog.malwarebytes.com/threat-intelligence/2022/03/the-conti-ransomware-leaks/
[2] https://therecord.media/conti-leaks-the-panama-papers-of-ransomware/
[3] https://www.cisa.gov/uscert/ncas/current-activity/2022/03/09/updated-conti-ransomware
[4] https://www.cisa.gov/uscert/ncas/alerts/aa21-265a
[5] https://go.chainalysis.com/rs/503-FAP-074/images/Crypto-Crime-Report-2022.pdf
[6] https://www.rapid7.com/blog/post/2022/03/01/conti-ransomware-group-internal-chats-leaked-over-russia-ukraine-conflict/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YirXdoRKGtB@ItTa2AqdyAAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.varonis.com/blog/contileaks
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YirXdoRKGtB@ItTa2AqdyAAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YirXdoRKGtB@ItTa2AqdyAAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.breachquest.com/conti-leaks-insight-into-a-ransomware-unicorn/
[12] https://www.theregister.com/2022/03/02/conti-source-code-leaked/
[13] https://www.theregister.com/2022/03/10/revil_suspect_ukrainian_arraigned_us_court/
[14] https://www.theregister.com/2022/03/09/ukraine_russia_cyberattacks/
[15] https://www.theregister.com/2022/03/09/fbi_says_ragnar_locker_ransomware/
[16] https://www.cyberark.com/resources/threat-research-blog/conti-group-leaked
[17] https://github.com/yiisoft/yii2
[18] https://kohanaframework.org/
[19] https://getcomposer.org/
[20] https://whitepapers.theregister.com/
Will people learn?
Like most cyber crooks, if businesses kept their kit patched, Conti would be out of luck.
Re: Will people learn?
You have to cut them some slack. You can harden your stuff to be as secure & resilient as possible, but it amounts to SFA if the underlying OS is so full of security issues that you've built your castle on quicksand.
I feel the urge to embed the Youtube video clip of the Monty Python father explaining to his son about having built multiple castles on the same bit of land, the first two sinking into the swamp, but that this third/current one will surely last.
Yes enterprise customers have more options than mere consumer customers, but there's only so much you can do to plug all the holes while MS seems to take great delight in racing around the bottom of the boat with a nuclear-powered ice pick...
Check out Brian Krebs excellent multi-part discussion on Conti
https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/
He's been a fierce opponent (and target) of these criminal groups.
Mostly operating from Russia but sometimes masquerading as being Ukranian ops. (Can't imagine why this would be so.)