A drawing of a man wearing a hat with red eyes.

I've Been Hacked

Certified Network & Cyber Security Engineers

It looks like a plain pink background with a gradient.

I've Been Hacked | Cyber Security Specialists Gold Coast | 24/7

1300 714 359

Members of the hacker gang may act in Russia’s interest, but their links to the FSB and Cozy Bear hackers appear ad hoc


For years, Russia’s cybercrime groups have acted with relative impunity. The Kremlin and local law enforcement have largely turned a blind eye to disruptive ransomware attacks as long as they didn’t target Russian companies. Despite direct pressure on Vladimir Putin to tackle ransomware groups, they’re still intimately tied to Russia’s interests. A recent leak from one of the most notorious such groups provides a glimpse into the nature of those ties—and just how tenuous they may be.


A cache of 60,000 leaked chat messages and files from the notorious Conti ransomware group provides glimpses of how the criminal gang is well connected within Russia. The documents, reviewed by WIRED and first published online at the end of February by an anonymous Ukrainian cybersecurity researcher who infiltrated the group, show how Conti operates on a daily basis and its crypto ambitions. They likely further reveal how Conti members have connections to the Federal Security Service (FSB) and an acute awareness of the operations of Russia's government-backed military hackers.


As the world was struggling to come to grips with the Covid-19 pandemic’s outbreak and early waves in July 2020, cybercriminals around the world turned their attention to the health crisis. On July 16 of that year, the governments of the UK, US, and Canada publicly called out Russia’s state-backed military hackers for trying to steal intellectual property related to the earliest vaccine candidates. The hacking group Cozy Bear, also known as Advanced Persistent Threat 29 (APT29), was attacking pharma businesses and universities using altered malware and known vulnerabilities, the three governments said.


“It seemed to us that we were being followed, as unfamiliar cars were standing in the yard, two bodies were sitting in the car.”

KAGAS, A CONTI MEMBER, IN A LEAKED CHAT

Days later, Conti’s leaders talked about Cozy Bear’s work and referenced its ransomware attacks. Stern, the CEO-like figure of Conti, and Professor, another senior gang member, talked about setting up a specific office for “government topics.” The details were first reported by WIRED in February but are also included in the wider Conti leaks. In the same conversation, Stern said they had someone “externally” who paid the group (although it is not stated what for) and discussed taking over targets from the source. “They want a lot about Covid at the moment,” Professor said to Stern. “The cozy bears are already working their way down the list.”


“They reference the setting up of some long-term project and seemingly throw out this idea that they [the external party] would help in the future,” says Kimberly Goody, director of cybercrime analysis at the security firm Mandiant. “We believe that's a reference to if law enforcement actions would be taken against them, that this external party may be able to help them with that.” Goody points out that the group also mentions Liteyny Avenue in St. Petersburg—the home to local FSB offices.


While evidence of Conti’s direct ties to the Russian government remains elusive, the gang’s activities continue to fall in line with national interests. “The impression from the leaked chats is that the leaders of Conti understood that they were allowed to operate as long as they followed unspoken guidelines from the Russian government,” says Allan Liska, an analyst for the security firm Recorded Future. “There appeared to have been at least some lines of communication between the Russian government and Conti leadership.”


THE CONTI FILES

The Workaday Life of the World’s Most Dangerous Ransomware Gang

BY MATT BURGESS


THE CONTI FILES

The Big, Baffling Crypto Dreams of a $180 Million Ransomware Gang

BY MATT BURGESS


In April 2021, Mango, a key Conti manager who helps organize the group, asked Professor: “Do we work on politics?” When the Professor asked for more information, Mango shared chat messages they had with one person using the handle JohnyBoy77—all the members of the gang use monikers to help hide their identities. The pair were discussing people who “work against the Russian Federation” and the potential interception of information about them. JohnyBoy77 asked whether the Conti members could access data of someone linked to Bellingcat, the open source investigative journalists who have exposed Russian hackers and secret networks of assassins.

In particular, JohnyBoy77 wanted information linked to Bellingcat’s investigation into the poisoning of Russian opposition leader Alexey Navalny. They asked about Bellingcat’s files on Navalny, referenced access to passwords of a Bellingcat member, and mentioned the FSB. In response to the Conti conversations, Bellingcat’s executive director, Christo Grozevm, tweeted that the group had previously received a tip that the FSB had been speaking with a cybercrime group about hacking its contributors. “I mean, are we patriots or what?” Mango asked Professor about the files. “Of course we are patriots,” they replied.



Russian patriotism is constant throughout the Conti group, which has many of its members based in the country. However, the group is international in its scope, has members in Ukraine and Belarus, and has links to members farther afield. Not all of the group agree with Russia’s invasion of Ukraine, and members have discussed the war. “With the globalization of these ransomware groups, just because Conti leadership aligned well with Russian politics does not mean that the affiliates felt the same way,” Liska says. In one series of conversations dating back to August 2021, Spoon and Mango chatted about their experiences in Crimea. Russia invaded Crimea and annexed the region from Ukraine in 2014, a move that Western leaders say they should have done more to stop. The area was beautiful, they said, but Spoon hadn’t visited for 10 years. “I'll have to go and check it out next year,” Spoon said. "Russian Crimea.”


By Cyber Security Consultant January 30, 2024
Cyber Security is become most needed services for all business and industries in 2024. Every business is concerned about Cyber Security. Security operations (SecOps) leaders face a multifaceted challenge: detecting elusive and novel threats using outdated tools, mitigating the risks posed by unexplored dark data, and managing the resource-intensive nature of staying ahead of evolving […]
A drawing of a man wearing a hat and a mask
By Myles Larden December 11, 2023
This is a subtitle for your new post
A person is holding a credit card in their hand.
By Myles Larden November 21, 2023
Credit Card Skimming on the Rise
By Cyber Security Consultant January 26, 2023
ABOUT CERTIFIED LEAD IMPLEMENTER TRAINING AND EXAMINATION FOR INFORMATION SECURITY MANAGEMENT SYSTEM ISO / IEC 27001 Learn and get certified as a professional in implementation of ISO 27001 standard through our self-paced E-learning interactive course which comprises of 4 modules. Upon completion of these modules, you can appear for an examination and get certified as […]
A thief is fishing for emails on two laptops with a fishing rod.
By ThioJo May 5, 2022
Ive been hacked explaining how to spot a fake email
A person is holding a cell phone with a camera attached to it.
By Whos the boss May 5, 2022
A man is standing in front of a sign that says new scams 2022.
By ThioJo May 5, 2022
A bunch of visa cards are laying on top of a 100 dollar bill
By Wired.com May 5, 2022
ABOUT 500 ECOMMERCE websites were recently found to be compromised by hackers who installed a credit card skimmer that surreptitiously stole sensitive data when visitors attempted to make a purchase.
A silhouette of two people looking at a tinder app on a cell phone.
By Guardian Australia May 5, 2022
Victims ‘financially and emotionally devastated’ by scammers who prey upon vulnerable, often older, people, bureau finds
A close up of a cell phone with the instagram app on the screen.
By Myles Larden May 3, 2022
Instagram's automated 'video selfie' support system leaves our clients with no options to get their account back.
More Posts
Share by: