Disgruntled ransomware affiliate leaks the Conti gang's technical manuals
Full article399 words · extracted from therecord.media · click to collapse
A disgruntled member of the Conti ransomware program has leaked today the manuals and technical guides used by the Conti gang to train affiliate members on how to access, move laterally, and escalate access inside a hacked company and then exfiltrate its data before encrypting files. Leaked on an underground cybercrime forum named XSS earlier today, the files were shared by an individual who appears to have had an issue with the low amount of money the Conti gang was paying them to breach corporate networks. In messages spammed across the forum, the individual shared screenshots of IP addresses where the Conti gang hosts Cobalt Strike command-and-control servers, which Conti affiliate members use to access hacked company networks.
https://twitter.com/pancak3lullz/status/1423324601346629635
In addition, the individual also published a RAR archive named "Мануали для работяг и софт.rar," which roughly translates to "Manuals for hard workers and software.rar." This archive contains 37 text files with instructions on how to use various hacking tools and even legitimate software during a network intrusion. For example, the leaked manuals contain guides on how to: Leaks from Ransomware-as-a-Service (RaaS) operations are extremely rare; however, the data shared today isn't anything that security researchers would describe as groundbreaking. The leaked files contain guides for basic offensive tactics and techniques that the Conti and other ransomware gangs have used during previous intrusions for years. However, the leak will help some security firms put together stronger defensive playbooks that they can recommend to their customers in order to improve their ability to detect Conti intrusions—now knowing exactly what operations Conti affiliates might execute.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/disgruntled-ransomware-affiliate-leaks-the-conti-gangs-technical-manuals