Episode Show Notes

							
			

JACK: [Music] There’s a kind of silence that follows a ransomware attack. Your throat gets dry, your chest gets a little heavy, and everything around you goes silent, especially when you see texts like this flash across your screen; ‘All of your files are currently encrypted. If you try to ignore us…’ CONTI: We’ve downloaded your data and are ready to publish it.

JACK: You don’t know who’s on the other side of that ransomware note or just how much damage they may cause if you don’t pay up. The most fearsome enemy is the one you can’t see. That silence, pulsating fear, can be deafening as it creeps across hospitals trying to treat patients or business owners trying to make payroll or teachers running a class full of kids.

CONTI: The time is almost over. We need your decision. If we don’t receive any reply to this message, we begin publishing your data. Conti is here to prevent any further damages.

JACK: For years there was a group that called themselves Conti, and they wreaked havoc across the internet.

CONTI: Conti is here to prevent any further damages.

JACK: Hackers operate behind a curtain, known mostly by the destruction they leave behind. We rarely hear or see them. They want to remain covered up in the shadows under the guise of codes and keystrokes. But what happens when that curtain gets yanked and suddenly their deepest, darkest secrets are exposed for the whole world to see? Not just their threats against us, but their arguments, their insecurities, and fears?

Intro: [Intro music] These are true stories from the dark side of the internet. I’m Jack Rhysider. This is Darknet Diaries.

JACK: When I think about the lifespan of a Russian cyber gang, there’s an image that comes to mind. It’s that Russian nesting doll. You know those wooden dolls that stack together? They stack inside each other. They start small and then they get bigger and bigger and bigger. Russian hackers kind of operate in the same way. One tiny group starts it. They’re at the center. Then they develop more and more layers around them. They get bigger and more influential and can rack up millions of dollars and leave a trail of destruction. These Russian cybercriminals seem to be untouchable by the Western authorities. The FBI and Europol can’t go into Russia to arrest them, but they can issue arrest warrants for them in case they trip up or fly somewhere outside of Russia. They might get arrested. But you might think that when the cybercriminal gets arrested, it’s all over, right? Well, not exactly. Like those nesting dolls, when a cyber gang forms an outer shell, it forms into something else, sometimes something even more sinister, and it keeps happening over and over until they’re splintering cells, each one learning from the other, each one working together.

That’s how I think about Conti, one of the most successful ransomware gangs in history. [Music] But before I get into Conti, let’s back up a bit and take a look at where they came from. Before them were other ransomware groups. There was the Dyre gang and there was TrickBot. A central person in both of those was a Russian crime boss who went by the name Bentley. Bentley was an entrepreneur at heart and found creative ways to launder his cybercrime profits. In order to securely access profits from cybercrime, this Bentley character created side hustles to launder his cybercrime profits. It’s a hard problem that hackers have to figure out all the time. How do you turn ransomware payments, stolen credit card data, or crypto into something you can buy without leaving a paper trail? It’s where the business of illegal hacking meets the real world. Bentley’s big idea was to use his proceeds from the Dyre ransomware gang to create a film production company. I guess his idea was that if he can make a film with dirty money and then that film makes actual money, then that money is clean.

GEOFF: They’re winding up with so much money that they needed some vehicle through which to wash the money.

JACK: That’s Geoff White. He’s a good friend of the show. He’s an investigative journalist out of London, and he’s been reporting on some of the world’s most prolific hackers from the US to North Korea to Russia, and he hosts the new BBC podcast on Conti called The Conti Files. Geoff says Bentley’s film production company was called the 25th Floor Film Company, housed in a skyscraper in Moscow. Now, this wasn’t just an idea of Bentley’s; they were making actual films.

GEOFF: Obviously they have to make some films, ‘cause if you’re gonna have a front company, it’s got to actually do some of the work that the front company is supposed to be doing. So, they thought, well, what films should we make?

JACK: They worked on some movies and television shows in Russia and surrounding countries, and they also produced action films with A-list American stars. Like, there was this movie called Exposed starring Keanu Reeves, which was made by them.

KEANU: Nobody’s talking, and I don’t blame them. He’s dead, he’s dead, she’s dead, but somebody knows something.

JACK: Bentley knew all the ins and out of the cybercrime underworld, and he had a film production company, and this made him start to think.

GEOFF: [Music] Hilariously, they decided they would make a film about a group of Russian computer hackers which was gonna be called Botnet. This film they were gonna make — when I spoke to the screenwriter guy called David Kaplan, who was recruited in Hollywood — some Russian guys came up to him at a party and suggested he might like to write this film. Then when he starts researching it, he went over to Russia to meet the film company not realizing that the very building the film company was based in was also the same building where the hackers were working on this malware. They described the plot to him and they sort of said, well, there’s gonna be this guy in charge. Gonna be some big, bald guy, and there’s gonna be this smart number-two guy, and then there’s gonna be a glamorous woman.

All these people were actually real characters, real people in the Dyre gang. You know, Bentley, the guy who went on to become Stern, who went on to run Conti, was gonna be one of the characters in the film, and apparently they had a plan that they were going to come across to Hollywood, and actually shop this around and try and get some funding for it. So, it’s just — I can never get over this. In order to launder the profits from cybercrime, they created a film company, and then were gonna use the film company to make a film about the same cybercrime they were using to make the profits to launder through the film company. It’s just — it’s genius in a way, evil genius.

JACK: A critical rule in the hacker underground is don’t dox yourself. It’s really rule number one. If you’re doing cybercrime, you’ve gotta use fake names, fake addresses, burner e-mails, burner phones. You can’t trust anyone you’re working with because if they know who you are and they get compromised, now suddenly you’re compromised, too. The best operators in the world are the ones you’ve never heard of. Silence is their shield. People in this world who can’t resist telling their stories are often the first to get caught. So, it’s wildly surprising that Bentley and even the people around him in the Dyre gang were thinking about making essentially a documentary about their ransomware gang. But in the end Bentley never reached his dreams of making his big break with this movie, Botnet. Those dreams came crashing down at the end of 2015.

GEOFF: Now, tragic end to the 25th Floor Film Company and indeed the Dyre gang. They actually got raided by the Russian authorities. We don’t know why. Clearly they fell foul of the Russian authorities somehow. [Music] Off the back of that, out of the ashes of that emerges a new group. Now, that group, initially called TrickBot, starts to morph as they use ransomware, and the ransomware strain that they use — ‘cause different types of ransomware — the ransomware strain they used was called Conti. So, eventually the Dyre gang becomes TrickBot, and eventually TrickBot is known as Conti, and from then on they’re just known as the Conti gang, ‘cause they’re using Conti ransomware to infect victims.

JACK: Now you’re starting to see these Russian nesting dolls stacking up one on top of each other, layers upon layers in the group. Within all these variations of hacking gangs, leaders like Bentley learned how to recruit other members of this growing empire.

GEOFF: It’s astonishingly astute and driven and organized group of people. As you say, recruiting was a key part of it. They were able to recruit people through Russian job-seeker sites. They were obviously very cagey about what the operation was. They would say, do you want to join in a fast-moving startup?

JACK: One of those early hires was a Latvian computer programmer who went by the name Max. Now, when I first heard that there’s a computer programmer in the Conti gang named Max, the first thought I had was, of course there is. Max is a very popular classic hacker handle. This guy’s probably watched too many hacker movies and he probably wears hoodies and has this computer that’s got LEDs inside the case and stuff. But actually, this Max is opposite of what I pictured. Max is chatty, middle-aged, and a woman from Latvia, a mom, even. Her actual name is Alavita. She spoke with a journalist and the BBC translated her responses.

MAX: A long time ago I graduated from Latvian State University.

JACK: Max grew up in the 1980s in Soviet Union and managed to pick up coding work in Russia. Max has a degree in applied mathematics and wanted more than anything to become a computer programmer. She got married, had kids, and moved all the way to a tiny country in South America.

MAX: There I continued to work with Russians, but it was all uncertain from one project to the next. I wanted more stability and didn’t want to work alone, just my client and I.

JACK: So, she’s looking for a job. Computer programming is what she always wanted to do. She comes across a talent boot camp for coders.

MAX: I attended this three-day webinar. Your CV kind of goes into circulation, and a potential employer can come across it and even reach out with some kind of invitation.

JACK: Max sends her resume, and someone responds to see if she wants to join their company. She didn’t ask a lot of questions about who this company was, and she didn’t get a lot of information because Max thought that’s just how it goes in the land of coders. As part of the job application, she was asked to take a test.

MAX: So, I said that I will take this test. It was quite complicated, but I solved everything and sent them a link so they could see the results. The week after, they write back to me, okay, you’ve passed the test. When can you start? I’m like, if you want, right today.

JACK: She gets the job and starts getting to know her coworkers. Everyone is remote. Now, remember, Max is living in South America, so it feels a bit isolating. [Music] There’s some water-cooler talk over Jabber messenger, but something feels off. None of her coworkers are using their actual names. Instead, they’re using strange nicknames like Professor or Snow White or Adelina, simple, random nicknames. Then there was one other thing; no one on the team wanted to do a video chat with her.

MAX: I asked if we wanted to Skype, but they said that they were just chatting. I like good jokes. That’s why I wrote ironically in the email. Ah, maybe you’re the kind of hackers you hear so much about. He answered me, no, we are not hackers.

JACK: But soon enough, she learned the truth. Her boss gives her a link to a page that had some wording on it. She’s told to use what was on the site as a template for other sites, and that’s all she knows. The page loads. She sees the gears turning, turning. Max stares at her screen. Scrolling text comes across it, and it starts to come into focus.

MAX: There was text. Your computer is infected, blah, blah, blah, so pay money.

JACK: It’s a template for a ransomware note. This was the first time Max realized she’s not just a computer programmer for some tech company. She’s a programmer for a cybercriminal enterprise, where at the center was Bentley, who had pieced it all together from the rubble of the 25th Floor Film Company. This is the moment where Max goes from being an innocent computer programmer to knowingly being part of an international cybercrime syndicate, which has to be some decision, right? Like, when you realize you’re infecting the world with ransomware, do you say, oh no, that’s against my ethics, or do you just shrug your shoulders and say, you know what? It’s good pay. Why not?

GEOFF: At that point she decides to stick with it. Actually, at that point she’s living very far away from home. She’s living actually in Suriname in South America. I think she felt like she was very far away from any risks, maybe, there. She felt she was just working — by this point she realized she’s working for a ransomware gang. But I think she felt quite insulated and also felt that her role was fairly puny within this. It’s a classic thing where — I think she justified it to herself of, well, you know, I’m not really doing any hacking; I’m just doing some coding for them.

JACK: [Music] Over the years Max became a bigger and bigger part of their ransomware operations. While her focus is web design and web development, investigators said because of her language skills, she was able to help write ransomware notes.

GEOFF: Now, Max wasn’t massively great at operational security because she ends up hosting some of the Conti ransomware code apparently on her own website in her own name — Alavita is her name — and had also done some YouTube videos at the time, so it was also identifiable from those. It could be that her security was rubbish or it could be that she just didn’t realize how at risk she was.

JACK: This was the early stages of the Conti ransomware group forming, and they had already began infecting systems and getting paid when somebody wanted the decryption key, which of course was starting to draw attention of the US authorities. They began investigating who’s behind Conti, which led them to Max. Soon they discovered her real name was Alavita. They found that she was living in South America. They found out that she actually overstayed her Visa while in South America. So, the US authorities worked with the local authorities there to find her and get them to fly her home to Russia because she overstayed her Visa. But they purposely put her on a flight to Miami to make her connection to Russia, and when she landed in Miami, she was arrested by US authorities.

This was the first person to go down in the Conti group. They were charging her with her involvement with TrickBot and Conti. At this point TrickBot was working closely with the Conti ransomware gang, and soon they would merge together. Conti was going to acquire TrickBot. Conti ransomware was becoming sort of a service where you could be an affiliate of theirs. You could use the Conti ransomware to infect a network somewhere, and then once infected, the Conti team would then take it from there, negotiating payment, handing over decryption keys, et cetera, and then the affiliate would get a cut of it. A few months after Max’s arrest, hackers using the Conti ransomware launched a devastating attack that put Conti on the map of the world stage. [Music] In the early days of the pandemic, someone burrowed their way deep into Ireland’s hospital network.

The initial intrusion happened when a hospital employee opened a phishing e-mail containing a malicious Microsoft Excel attachment. They clicked it, they opened it, they got infected. That was Patient Zero. Attackers got in and opened up a backdoor so they could stay in, and then they began making that infection spread. Dozens of infected machines became hundreds. One infected hospital became two, which quickly spread to ten. Thousands of machines were infected, and the infection kept spreading across clinics and offices and more hospitals. Thousands of machines were hit with this ransomware. In total, over 70,000 computers were infected at 4,000 locations, and over forty hospitals were infected within the Ireland hospital network. It just sat there quiet, waiting for the right moment to lock up all the computers.

GEOFF: I sometimes liken it to being a burglar, you know? You break into a house. It’s dark. You have no idea of the layout of the house. So, you just have to kind of keep opening doors, and you hope that the door you open isn’t the one into the bedroom where the people who are in the house are there with a gun. There is a long process of scoping it out. Of course, at any moment you might get caught. Your access might be revealed.

JACK: After weeks of lurking in the network shadows, the hackers struck.

REPORTER: Ireland’s health service describing this as a significant ransomware attack, the people asking how an attack like this could have happened in the first place.

SPEAKER: There’s no doubt it is a vicious and a callous act and will be condemned everywhere by decent people.

JACK: It was total pandemonium. Ireland’s healthcare system was hit with the most devastating ransomware attack they had ever seen by a Russian-based cybercrime gang called Conti. Every hospital in the Irish network felt Conti’s attack. To keep track of patient appointments and records, clinicians just had to use pen and paper like the old days. The attack disrupted Covid and blood work tests, all this as Ireland was in its third wave of the Covid pandemic, its longest lockdown yet.

GEOFF: This is the middle of a pandemic, and as you say, people in Ireland, they speak their minds, the Irish, and they absolutely hated this. Why would people attack a health service, and particularly during the middle of a pandemic?

JACK: Maternity wards and pediatric units were thrown into chaos.

GEOFF: This is basically an entire country’s hospital system being held to ransom in one go. Absolutely stunning.

JACK: It was unlike anything that they — well, actually, we have ever seen before. The information systems behind all these hospitals went into a tailspin, a total scramble.

GEOFF: Health services classically do not prioritize IT security because they’ve got lots of other things to prioritize, and they generally don’t think that they’re gonna be a target for hackers. They haven’t been, historically.

JACK: Those patients ended up paying a big price. One person who Geoff actually talked to who lived in Dublin went through a particularly awful cancer treatment, a brain cancer treatment. But when the cyberattack happened, she was getting ready for a highly-targeted cancer treatment involving lasers zapping the cancer in these precise spots. But with computers down, the doctors had to cancel her appointment, so she had to wait even longer to get her cancer irradiated. Stories like these began to flood through Ireland’s hospitals. It was pure chaos. Of course, the Conti group was messaging the hospital saying, [Music] there’s one thing that can make this stop; money.

Just about every hospital in the network got a ransomware note saying, “we have ransomwared your data. If you want to contact us and negotiate, here is the way you do it.” The hackers demanded $20 million to bring back up the hospitals’ computers. To make matters worse, the Conti gang said they had stolen over 700 gigabytes of data like patient and payroll records. They were saying, if you want us to delete it, you have to pay. Now imagine you’re the one in the Ireland health department that has to make the call on what to do next. You came into work and you found every screen in the building displaying the same ransomware message. Everyone’s files are encrypted. All the computers are down. Your backups are gone. People’s lives are literally on the line, and at the bottom, a countdown and a price. Ireland’s response?

GEOFF: No, we are not gonna pay a ransom. Forget it.

JACK: [Music] The executives for the Irish health service kept in contact with the Conti gang, though. I think they were negotiating the price down. But I also think they were just trying to buy some time so that they don’t publish the data yet. There was some back and forth between the two of them while the Ireland health system tried desperately to get their systems back up and running all on their own.

GEOFF: They’re desperately trying to work out how can we decrypt this data without paying the ransom? How could we get hospitals back on their feet? Which are the most important hospitals? You’re gonna make some hard decisions there, Jack. You know, is children’s health more important than older persons’ health? Do you prioritize cancer or do you prioritize other diseases? These are the kind of decisions they’re having to make. They’re literally life-or-death decisions about where you try and apply the help first.

There was a calculation apparently made at the rate they were able to decrypt the data, how long it would have taken to decrypt all of it without the ransomware key, the decryption key, and it was in years, one or two years, to unscramble it all. So, you’re facing these problems month after month, potentially year after year. So, the hackers kept going. Of course, at this point, frankly, you may as well — you scramble all the data; you’re kind of in for a penny, in for a pound, or in for several tens of millions, in this case. There was a period of several weeks where all of this was going on. The data was scrambled, hospitals were really struggling. The hospitals were getting by. The health professionals, they can get back some test results, but it’s a fraction of what they get, and they can continue treatment with some people.

JACK: But after weeks, the hacker had a surprising change of heart. Out of nowhere, without having paid the ransom, they gave the decryption key over to Ireland, and seemingly just left the hospital alone after that. It’s still a mystery as to why, but there are some running theories. One theory is that there’s a Russian embassy in Ireland, and it condemned the attack, even agreeing to support Ireland as it recovered. So, the hackers handed over the decryption key so hospitals could recover, but their attacks continued against other places in Ireland. They infected school districts, city government, and businesses. Their demands were always the same; pay up to decrypt your computers or else we release your data on the dark web.

CONTI: Just in case, if you try to ignore us, we’ve downloaded your data and are ready to publish it if you do not respond. So, it will be better for both sides if you contact us as soon as possible.

JACK: [Music] One of their targets in 2021 was this jewellery company called Graff. It’s in the UK and known as the jeweller of the stars. Its clients include Donald Trump, Oprah Winfrey, and David Beckham. But the client list is never revealed publicly by Graff. It’s actually super secret. They are extremely tight-lipped about who their clients are. But in 2021 Conti broke into the jewellery store digitally and stole a list of all of Graff’s clients. This, of course, made Graff panic, and they were extremely upset. The names and phone numbers of all their high-end customers has been stolen and in the hands of some cybercriminals? Forget about the computers being encrypted. The stolen data was more of a problem now. Conti wasn’t messing around. When Graff didn’t pay right away, they wanted to show them they were serious, so they took a chunk of this customer data and released it. 70,000 Graff documents hit the dark web.

GEOFF: The solution to ransomware was pretty easy; back up your data, ‘cause if it’s scrambled, you can just wipe the computer, reinstall the data from backup, and jog on and not pay the ransom. Of course the ransomware gangs saw that, saw it’s a threat to their business, which it was, and invented the idea of what they called double-dip ransomware.

JACK: Double-dip ransomware, essentially a cyber attack with two steps; steal sensitive corporate data before encrypting it. It gives the hackers more leverage. Conti demanded the jeweller pay tens of millions of dollars to decrypt its systems and to prevent more information from getting out on the dark web.

GEOFF: So, instead of just scrambling the data, we will steal a chunk of the data and then scramble the data. If the victim refuses to pay because they’ve got backups of their data, we can say, ha-ha, if you don’t pay, we will leak this sensitive data. It’s exactly what happened to Graff. So, with Conti, it wasn’t the full leak. It would have been a few hundred pages, maybe, of data, but in there would have been the data of very high-profile clients. My guess is that Conti scanned the information and thought, oh, look, some famous people here. We’ll stick this online as a sort of threat to the Graff group and say, look, if you don’t pay the ransom, there’s gonna be more of this. But Conti didn’t look really carefully through the data they were leaking.

JACK: There was actually too much data for the Conti gang to analyze effectively. In the end, Graff did pay up. They paid $7.5 million in Bitcoin. They didn’t want the rest of their client list getting out, and they felt like this was the price they have to pay to keep their customers’ records secret. But how much can you even trust this Conti group to be good on their word when they say they’ll actually delete it? It must have been so maddening for Graff. But Conti’s successful jewellery heist may have been rushed, even sloppy. We all make mistakes when we’re rushing, and Conti is no different. Within the initial breach of customer data leaked on the dark web, Conti unwittingly shared details of purchases of high-profile members of society, and one of those was the Saudi royal family. That’s right, Conti doxxed the Saudi royal family.

GEOFF: [Music] And that did not go down well, it seems, among the Saudi royal family. There are people around the world who you want to offend and people who you really, really don’t, and the Saudis are probably very much the latter category.

JACK: After the UK’s Daily Mail reported on this heist, the Conti gang must have been contacted by someone or threatened or something serious happened, because Conti published an apology, something you never see from cybercriminals.

CONTI: We found that our sample data was not properly reviewed before being uploaded to the blog. Conti guarantees that any information pertaining to the members of Saudi Arabia, UAE, and Qatar families will be deleted without any exposure and review. Our team apologizes to his royal highness Prince Mohammed bin Salman, and any other members of the royal family whose names were mentioned in the publication for any inconvenience.

JACK: Conti said it removed the documents from Graff that had initially leaked online and claimed none of the stolen data was sold on auctions or offered as samples or revealed in any other capacity to any third party.

CONTI: Conti guarantees to implement a more rigid data-review process for any future operations.

JACK: Wow, that’s really unusual that they retracted their leak. My head starts to go to, okay, somebody was — somebody had enough wealth and influence to be able to say, okay, let’s find out who these people were and go and personally threaten them.

GEOFF: Yes, yes. There was an expert we interviewed for the podcast, a intelligence expert. His assessment of this was that the kinds of wealth you’re talking about and the kinds of people involved in those leaks — you’re talking about the top strata of the world’s richest, most powerful people. They have a cadre of people around them who look after their security and look after their interests. Those people are very good at their jobs and will make it absolutely clear to a gang like Conti; you have done this. There are going to be consequences for you. We have ways of finding you, and if we find you, you’re in a lot of trouble and potentially a lot of danger. So, there would have been an intimidation of Conti to say, take this data down or else. You’re not playing here with low players. You’re playing with serious people.

Now, as I say, we do not — no, we’re not privy to those e-mails because they would have been sent and received by the security teams behind these powerful people. But as I say, the proof of the pudding is in the eating. We know that Conti issued an apology and we know within internal conversations within Conti that they absolutely freaked out when this happened and were very worried. In fact, one of the quotes in the Conti gang was, they’ll find you and you’re gone. So, we know that Conti wrote internally. We know that publicly they were apologizing. If you join the dots, it does really look like somebody got to Conti and said, take it down or else.

JACK: [Music] Wow, that’s really surprising to me. I imagine these ransomware groups to be always getting threats from people, right? Just like, I will find you and I will take your children or dog or something. They just like watching the world burn. So, it’s just a surprise to see them be threatened in such a way, be scared in some way, that they issue an apology and redact their leak. They must have been really spooked. They were on such a roll, too. In 2021 alone, they collected over $180 million from their ransomware operations. But I guess Conti was getting their first taste of flying too close to the sun. We’re gonna take a quick ad break here, but stay with us because when we come back, these nesting dolls are gonna come apart in the most dramatic way possible.

Imagine this; two Russian hackers are having a conversation. One of them is planning a major attack against, I don’t know, a hospital, let’s say, and the other is in disguise posing as a Russian hacker, and he’s really trying to thwart that attack. The conversations are happening over a dark web forum or on Jabber or Rocket.Chat. Sure, conversations with a Russian hacker might start light, like talking about fishing or visiting Saint Petersburg’s art museums. But then they’ll take a turn, shifting to actual criminal secrets. Just imagine if you could get a hacker to be vulnerable when their guard is down. [Music] What kind of intel could you get about targets or methodologies for attack? Could you turn them away from cybercrime?

ALEX: We find fascinating things on the dark web. We engage with the bad guys. We get inside of not only their systems but inside their heads.

JACK: This is Alex Holden. He’s a Ukrainian cyber-security researcher now living in the US, and he runs a company called Hold Security based in Milwaukee. Years ago, him and his team of analysts began infiltrating members of TrickBot, which would go on to get acquired by Conti. Alex and his team talked with TrickBot members pretending to be black hat hackers, trying to gain their trust. They weren’t buying or selling anything, ‘cause that is illegal, but they were on a top-secret mission to make connections. That’s what Alex does with ransomware gangs, nation-state threat actors, or hacktivist movements.

ALEX: You would be surprised, but the bad guys on the dark web, all of them need to talk to somebody. They need a friend. We create this friend environment for them to start spilling their deepest and darkest secrets.

JACK: So, they’re getting some of TrickBot’s deepest and darkest secrets through its members. They even applied for jobs at TrickBot and tried to move up the chain, and they developed relationships with the members to learn more and maybe even turn them good.

ALEX: We also meddled with some of their perceptions, opinions, even building paranoia for some of them, saying that law enforcement is coming for you.

JACK: After a while of chumming it up with TrickBot, Alex caught a big break.

ALEX: So, one guy part of TrickBot decided to give his girlfriend as a present access to TrickBot. So, this is not like presents that guys give to their girlfriends. But he gave access so she can go shopping. So, he showed how to find credit cards, how to take virtual machines and stuff like that, and through a folly of errors — because we had visibility into her communications. She did not believe in encryption or good passwords, things like that. She basically disclosed all of it. So, that was one of the main vantage points for a while. But over time we start looking at this and say, okay, he has access to a Jabber server, because this girl was given an account and the password was 123456. That’s what the admin gave her. But his password just had like an “A” at the end, after 123456.

JACK: Alex’s team whittled their way into TrickBot’s infrastructure, scraping chat logs and eventually cloning the network, and while continuing to make connections with some of the big players in the TrickBot echelon.

ALEX: You’ll build friendship with some of the people, including Stern.

JACK: Ah, yes, Stern. Remember I told you about that guy Bentley before? He was the one who ran the Dyre ransomware gang and then he started the 25th Floor Film Company, and then he started the TrickBot ransomware gang, which morphed into the Conti ransomware gang? Well, when it morphed into Conti, he morphed from Bentley to Stern. But at the time, we didn’t know who this Stern guy was. We only knew that he was one of the nesting dolls at the center of Conti.

ALEX: At some point Stern wants to build his own crypto-mining platform. There was conversation, like thirty, forty pages of conversation about that. But this is the idea, is to sway it from cybercrime to a social angle.

JACK: [Music] Trying to limit Stern’s damage, there are a lot of moving parts here, a lot of sleepless nights where Alex and his team was glued to chat logs, reading chat forums. They watched TrickBot starting in 2019 and continued as TrickBot got acquired by Conti two years later. His team obtained hundreds of thousands of messages. They curated the data, they read through it, and published summaries of the data. What they saw was a criminal enterprise a lot more organized than any of them even imagined.

ALEX: TrickBot was run by Stern as a company. It was not run as a gang. I’m very used to corporate America. It doesn’t look like that right now, but the company that they run, they had different departments. They had physical offices. They had lunches. They talked to each other. They were sympathetic to employees like Alavita, who got in trouble.

JACK: Alavita is the TrickBot member I told you about earlier who was arrested. She went by Max, remember?

ALEX: They even said that they are allocating $25 million in the first eight months of 2021, I believe, to improve their infrastructure. Not every company can afford that much of expension. They did. So, it was budgeting. It was accounting. It was everything.

JACK: Alex’s team also got insight into attacks that were still in the planning stages, attacks against schools, city governments, and hospitals. Here’s one Conti member named Target writing about going after healthcare.

TARGET: We got on a video call with them. They offered eighteen Bitcoin. Their turnover is $30 million. Heh, let them pay millions. Tomorrow we’ll make a move that’ll make the whole leadership go, “Please, miss, don’t do it”. They got used to little old chats and messages over there. Eighteen Bitcoin, heh. Tomorrow the whole office will rob them. Let them die.

JACK: Despite this being criminal activity, there are still certain rules that criminal hackers have. Ask enough people in the ransomware underground, and you’ll hear that there are certain targets that are just off limits, like hospitals. After the Russian hacking group LockBit targeted a children’s hospital in Canada in 2023, it publicly apologized and turned over the decryption key. It didn’t know it was a hospital. In the Conti chat logs, you can see internal disagreements about the ethics of going after healthcare. For example, one Conti member asks the Conti boss, Stern, if he signed off on encrypting the hospital’s data. Stern responds with…

STERN: I usually don’t approve encryptions.

CONTI MEMBER: If you didn’t approve it, I will hand the decryptor to that clinic. We agreed not to touch the medical center, remember?

JACK: This Conti member who was pushing back against going after hospitals messages Stern complaining about their coworker, someone who goes by the name Dollar.

CONTI MEMBER: Let’s get Dollar out of the game. He’s a total idiot. Back then he screwed me over, claiming he had an agreement with you to mess with the hospital, and now he targeted the hospital again. That’s disrespectful. I told him twice that we don’t touch the medical sector.

JACK: [Music] At this point Conti’s members and affiliates were in the hundreds, and as it grew it became more challenging to control hacking operations. So, it’s no surprise you’d get these internal riffs about who to attack. To make matters worse, Conti was without leadership. The boss, Stern, drifted away from the chat logs. He was just not present very much anymore. My theory is that when you start a new and upcoming cybercrime group, it’s exciting. It’s fun. But then when things start turning into just handling customer support issues all day long, leaders often lose interest. One of his deputies, someone who went by the name Mingo, got growingly frustrated about this.

MINGO: You constantly give me the impression that you don’t care. You need to be online more often and in some situations be a bit tougher for disciplinary purposes.

JACK: Then by January 2022, researcher Alex Holden says Stern left Conti without a trace. The chat logs just show Conti falling into chaos after that.

CONTI MEMBER 2: Listen, Stern has gone missing.

CONTI MEMBER 3: No, he’s not missing. He’ll show up soon.

CONTI MEMBER 2: Everyone’s looking for him.

JACK: With the boss gone, people started getting worried if anyone was gonna get paid. Members weren’t quite panicking yet, but it felt like the ground was becoming unstable within Conti. Then to everyone’s surprise, a full-blown war erupted.

REPORTER: [Music] It was unprovoked, but this is what Russian president Vladimir Putin unleashed on Ukraine. As the sun came up this morning, a missile striking an industrial park in Western Ukraine. A helicopter assault on an airport outside of Kiev. Close, intense fighting, and there are civilian casualties.

JACK: [Music] Little did we know that Russia invading Ukraine was going to send a shock wave through Conti. Many of the members were glued to the news.

CONTI MEMBER 4: I hope that Kiev will be ours by evening.

JACK: But not everyone in Conti was rooting for Russia. Many of Conti members were from Ukraine. The war split a lot of families because some families were living in both Ukraine and Russia, and suddenly they were at war with each other. The war completely split the Conti pack, with some of its operators really unhappy about this invasion.

CONTI MEMBER 5: Friends, brothers, are there any Ukrainians besides me? Madness. Support me, brothers.

JACK: I mean, I’m just thinking about — how can you be thick as thieves with someone and go rob the world of millions of dollars, doing cybercrime together, and then suddenly go to war with the very people in your own group? Members were torn about what to do.

CONTI MEMBER 6: Talking to you directly. Your posts are painful for the members of our team.

JACK: Emotions and tension started flaring up in the group chat. Half the Conti gang were saying, Kiev by dawn, and the other half were saying, slava Ukraine. Eventually Conti as an organization took a stand, releasing a statement for the world to see.

CONTI: The Conti team is officially announcing full support of the Russian government. If anybody decides to organize a cyberattack or any war activities against Russia, we are going to use all our possible resources to strike back at the critical infrastructures of an enemy.

JACK: When that message showed up on computer screens across the world, there was someone who took this note very seriously. He was an IT specialist from Ukraine, and this message consumed him with anger.

CONTI LEAKER: I cannot shoot anything, but I can fight with a keyboard and mouse.

JACK: In an interview at the time, he told CNN he was prepared to cut deep into Conti where it hurt. We had someone voice his responses.

CONTI LEAKER: It’s my country. If the Ukrainian government provides me weapons, okay, I’ll go fight. But I am better at typing.

JACK: [Music] This Ukrainian IT specialist had a plan. He wanted to do a data breach on the Conti ransomware gang itself. He thought if he could get into their internal communications, download all their chat logs, see what their network consists of, look at their member information, he could expose them in a very devastating way. He started working with Alex Holden and others to try to obtain the Conti chat logs. He was grabbing the chat logs while other members of the team were reading through them and providing summaries. These messages were private in the Conti network. They were never meant to be released. But he was determined to expose them, to ruin Conti. He came to Alex and told him what his plan was.

ALEX: He talked to me ahead of time. We talked about how to do this properly, and it turned out the way it did. I had no control over it. I did tell him that he needs to think about it, but from a legal perspective it was not our data. From more perspective, I’m also from Ukraine, and I completely understand him and his actions. You have to understand that in the first days of the Russian invasion into Ukraine, Conti stated that they fully support the cause of Putin. My friend as a Ukrainian, Ukrainian citizen, Ukrainian national, felt that this is his way not to pick up a weapon and defend his homeland, but something to do bigger against the aggression from Russians.

JACK: Then about a week after the invasion, the Ukrainian analyst had infiltrated Conti deep enough and gathered enough incriminating data that he thought it was time to start leaking the data. He created a Twitter account called @contileaks, which it’s very ironic to breach and expose a company who’s in the very business of breaching and exposing companies, right? [Music] Here’s what the first tweet said.

CONTI LEAKER: Greetings. Here is a friendly heads up that the Conti gang has just lost all their shit. Please know this is true.

JACK: Now, there’s been speculation from researchers and journalists that the leaker may have been a disgruntled former Conti member. The truth is we aren’t exactly sure who the leaker is. But Alex Holden says he knows. He says the Conti leaker is a computer specialist who at the time of the leaks was a consultant for his company, and continues to live in Ukraine today. Regardless of who he is, he released the holy grail for cyber-security analysts, researchers, and journalists who were studying this gang.

CONTI LEAKER: The contents of the first dump contain the chat communications current as of today and going to the past of the Conti ransomware gang. We promise it is very interesting. There are more dumps coming. Stay tuned. Thank you for your support. Glory to Ukraine.

JACK: Over several data dumps there were tens of thousands of internal messages released. There were conversations about planning attacks, names of members, pictures of members, and details about the organization structure of Conti, which was surprisingly hiding in plain sight. But there were also nuggets that were meant to strike deep into Conti where it hurt, like the cryptocurrency accounts used to steal millions of dollars in ransomware payments or discussions about going after journalists reporting on the poisoning of the Russian opposition leader, Alexei Navalny. Alex Holden says before the logs were released, there was information excluded for safety reasons. But he says nothing was altered.

ALEX: My goal in cyber-threat intelligence is to help victims and help victims as effectively as possible. So, he did what he did, and he changed the world. We change the world one victim at a time. He did something bigger.

JACK: Because in this situation, Conti was a victim of a data breach, so this whole thing is flipped on its ear. I don’t think we’ve ever seen a data breach like this before where the hackers got hacked.

ALEX: I don’t think it was the right thing to do. Conti shattered in many different groups, and the members became part of many other ransomware groups that start multiplying the crime, and losing visibility actually increased the number of victims.

JACK: Alex Holden says even though he wouldn’t have publicly released the logs, the disclosure changed the Conti gang in profound ways.

ALEX: How many TrickBot and Conti operatives have been unmasked since? How many of them were indicted? How many of them are on wanted lists for us, from a law enforcement perspective?

JACK: [Music] I remember when these leaks came out. It was quite a moment if you were on Twitter at the time. We all got our popcorn out and we were just watching this cyber-gang unravel in real time. The nesting dolls just kept opening one after another, and we had no idea how many would just keep opening. It was just wild to see one open after another. People were being exposed left and right. There were pictures of the Conti gang going around. Soon there were memes about the members. Like, surprisingly, there was a half-dozen women who were members of the Conti gang. So, you’d see posts like, these are the women of the Conti ransomware gang. Lots of photos were shown of just them driving in cars, eating lunches, passports, photos of them.

Many of them were looking like they were part of the world of luxury. It felt like the lid of this shadowy, dark underworld just blew off in an instant. It was such a rare glimpse into one of the most successful ransomware groups of all time. Twitter was having a field day. This wasn’t your typical white paper write-up on some ransomware group. This had drama. This had intrigue. This had dirt on scandals. I even posted a meme which said, ‘Infosec: we know drama’. Just reading through the chat logs, you see all kinds of infighting. You can tell that something catastrophic is going to happen soon. A lot of us were just sitting back in our chairs like, wow, Season 1 of this show is amazing. Investigative reporter Geoff White grabbed a front-row seat.

GEOFF: When this came out, I think there was all this stuff about cyberattacks around Ukraine, just trying to keep abreast of all of that. Then these Conti leaks come out. It’s 70,000 messages, Jack. It was an absolute nightmare. They’re all in Russian. They’re in Cyrillic characters. They’re in hacker slang, so you could try and start translating them. Then immediately afterwards you get this second huge dump of information that’s even more messages.

JACK: You read 47,000 of these messages?

GEOFF: Yes, yes. Yeah, I did.

JACK: Amazing.

GEOFF: The thing about the leaks is it’s thousands of messages. They’re all in Russian. They’re all in Cyrillic characters. Obviously you’re thinking — a lot of your listeners will be thinking, well, stick them in one of these LLMs. Let the AI do the work. LLMs do not deal well with Cyrillic alphabet. So, there’s loads of mistranslations. So, one of the things they keep talking about in their leaks is the cue balls. Who’s got the cue balls? Like snooker or pool or, you know. I couldn’t understand this, and then I realized that if you take the Russian translation of Bitcoin, which is Bitkoin — but the N at the end, because it’s in Cyrillic, looks a bit like a V. So, the translation engines translate it as ‘bitkov’, which in Russian is ‘cue ball’. Bitkov, cue ball.

So, whenever they’re talking about the cue balls, it means they’re talking about Bitcoin. So, immediately you start to kind of understand there’s a code almost in the translations. The other thing they kept talking about was the toad, as in the reptile. Well, why is the toad slow, and I’ve got problems with the toad. I couldn’t understand why they kept talking about the toad. It turns out this was — the software they were using to communicate was Jabber, which in Russian is ‘zhaba’. ‘Zhaba’ translates as toad. So, they keep talking about the toad, and you realize they’re talking about the Jabber thing being slow. [Music] So, as you’re reading through these messages, you have to go through them by eye, I think, one by one, because only then you get the hang of what is actually being discussed.

JACK: Okay, so after the leaks came out and we start to see the inner workings of how this Conti ransomware gang is operating, do they skitter? Do they run away? Do they hide, shut up shop, or what happens to them?

GEOFF: So, in terms of what happened next to Conti, we know that the gang apparently disbanded, and we know that there was talk in the chats of, well, it’s coming to an end. Just go off and rest for a little while. We’ll regroup. People who track these things are pretty sure that various affiliates with Conti just became affiliates for other gangs. There’s some suggestion that Conti members set up other ransomware groups. There’s crossovers with code and so on. So, the thing splinters and it fractures. But there’s this amazing moment where they decide — someone somewhere within Conti decides they’re gonna go for one last big takedown and they’re just gonna do an absolute showstopper, and that’s when they decide they’re gonna hit an entire country. They’re gonna hit the government of Costa Rica.

REPORTER 2: Late today we learned that Costa Rica has declared a state of emergency after a ransomware attack. Sounds very…

REPORTER 3: [spanish]

SPEAKER 2: I was very terrified for us. Over thirty government organizations were compromised by that campaign. Like, we didn’t know what to do.

REPORTER 2: …and exposed citizens’ personal information. So, it’s not clear how they’re gonna resolve…

JACK: Yeah, Costa Rica declared they’re at war with Conti. How about that? Nobody was expecting this as the next step from Conti, especially after they just got exposed. About two dozen different government organizations were targeted, and many sectors came to a screeching halt. This was a big deal for Costa Rica. The first thing that was hit was Costa Rica’s treasury. One of the big ramifications of that was importing and exporting of goods, and all that’s run digitally. So, that just collapsed, and they had to go back to pen and paper. But Costa Rica was not ready for that. A large chunk of the country’s money just got cut off because imports, exports just grinded to a halt. There were also disruptions with paying salaries and pensions for government workers.

GEOFF: In the end, the sort of solution they came up with was anybody who got a pension last month gets another pension this month. You know, just pay people again and hope we sort it out later. So, they did manage to get around that.

JACK: There was also political consequences. This attack happened right in between a change of presidential administrations, and it fed into the whole campaign against the existing government. Like, of course they’re incompetent; they couldn’t stop this cyberattack.

GEOFF: It sort of fed into this sense of a country that was kind of on the edge. As the government started looking at this and refused to pay Conti, Conti upped the ante and attacked more parts of the government, more government departments. I think the science and technology department got attacked, and in the end there was various local government websites that got taken down. As I said, you got this pylon effect where other gangs and other cyber-criminals started to get involved. The Conti government was, in the end, fighting fires, and there were probably in the dozens of attacks, some much bigger like the treasury and so on, some much smaller in terms of local government institutions. But it really was pandemonium. It happened at this time the transfer in government when Costa Rica was particularly vulnerable.

JACK: The incoming president treated this like it was a national emergency, and like a wildfire, the vulnerability spread across government organizations. Some systems were infected through phishing e-mails while for others malware was just put right on them right from the internet, and something became clear; maybe this wasn’t just Conti.

GEOFF: As the attack went on, other cybercrime groups, other ransomware groups emerge and also started attacking Costa Rica. So, it was kind of a pylon. So, Conti were there, definitely, but the effects of the Conti gang got amplified as the attack unfolded over weeks in Costa Rica.

JACK: Yeah, and I don’t know if it matters or not, but we don’t know if it was the Conti ransomware gang that actually picked their targets or if it was their affiliates that picked the targets, or a mix of both.

GEOFF: Precisely. I mean, Conti had so many affiliates by this point, and those affiliates would of course all have had access to the encryption software, the ransomware software. So, even if the central core Conti group dissolved, it strikes me as possible certainly technically that somebody could have retained that encryption software. If they’re an affiliate and good at getting into a network and infecting a network, there’s no reason why they couldn’t have used the Conti ransomware without the core Conti gang being aware of it, approving it, or even still being in existence. This could have been an entirely single-affiliate-led job, I think. From my technical understanding, that’s certainly possible.

JACK: Another possibility Geoff says is that this was a former member of Conti that was just flexing their muscles, saying, hey, I came from Conti and I did the Costa Rica attack. Imagine what else I can do. We know for sure that Costa Rica got hit by Conti ransomware, but that was the last incident we ever saw of the Conti ransomware, because after that, arrests started happening. Certain low-level members of Conti and TrickBot were getting nabbed. Conti seemed to be done. Too much had been exposed. The war tore the members apart, and Stern, their leader, was still missing from daily operations. But the affiliates that were helping spread the Conti ransomware, many of them probably just joined other groups.

GEOFF: There were loads of other gangs recruiting. If you say, ‘Look, I was with the Conti gang. I managed to get a couple of high-profile targets. Can I work with your ransomware as an affiliate?’ , you’re likely to get a job elsewhere. In terms of the core Conti gang, we don’t know what happened with them. The suspicion is they went on and formed other groups.

JACK: The fact is, many of the Conti members who appeared in the logs, we don’t know who they really were or what happened to them. It’s because a lot of them used fake names and were based in Russia, so it’s just really hard to trace. But one high-ranking person within Conti we do know. It’s Stern, the TrickBot commander who was in charge when Conti absorbed TrickBot. German police and international prosecutors identified Stern as Vitaly Kovalev, a Russian national in his late thirties. The European Union, UK, and the US all sanctioned him, linking him back to TrickBot and Conti, a multinational response that essentially tries to freeze him off from the global economy. He’s gonna have a hard time using any service that changes his money into dollars or euros.

He likely can’t travel to any country that has an extradition treaty with the US. Vitaly allegedly racked in more than $300 million in ransomware payments, and that’s just his own personal cut of the proceeds. But given how long he’s been at it, Geoff White says it’s possible that he might be a cybercrime billionaire, which would be the first person to become a billionaire from cybercrime. Vitaly isn’t someone that you would look at and say, oh yeah, that’s a successful cybercrime boss right there. If you look him up online, you can see his face, and he doesn’t look suspicious. He doesn’t have a hood or coverings. He’s smiling, looking cheery. He’s the kind of person that if you were lost on the street, you would stop and ask for directions and say hello.

GEOFF: Frankly, you don’t look at pictures of Kovalev and think internet’s gangster number one. Now, I don’t know how many other of the people you’ve investigated, Jack, who you would think that about, but he really just doesn’t seem the type, which is odd for me to be saying as an investigative journalist. Normally I would look at people and go, yeah, I can see you doing this, but Kovalev somehow not. Of course, the big problem Vitaly Kovalev’s got, if indeed he is Stern and did run the Conti gang, is what to do with all that money. ‘Cause you’ll know — again, you’ve done stories in this. Bitcoin, if you’ve made money in Bitcoin, you’ve got a big problem in that it’s traceable. You know, the big problem I suspect now for members of the Conti gang is where to launder that money. Actually, what we turned up as part of the podcast was a sort of whole slew of kind of Middle-East based, often Dubai-based cryptocurrency-type operations that people were saying were linked to or seemed to have links to people at the Conti gang and some of the individuals behind that. Interestingly, sort of around the Ukraine war there was kind of a bit of an exodus of Russians towards Dubai and towards the Middle East.

JACK: Conti’s rise is both astonishing and tragic. It became the apex predator in the cybercrime world. Its tactics evolved, and that turned into a cash cow, and it became so big that it spawned a network of affiliates who went rogue and put targets on its back. Conti became so big and famous and scary until it became too large to last, a victim of its own success.

Outro: [Outro music] Thank you so much to my guests Alex Holden and Geoff White. Geoff actually has a multi-part podcast called The Conti Files by Cyber Hack, which goes into so much more detail about this Conti story. He interviews some really interesting people, and it’s worth listening to that. Hey, I just released a whole new podcast. It’s called LOW, and it is out and available for everyone to go listen to right now for free. Just search your favorite podcast player for LOW or go to thisislow.com to find it. This is a story that is so long and twisted that I felt deserved its own podcast. It stands on its own as something truly special. At least I think so.

The feedback I’ve gotten so far is that it is mind-blowing. It’ll make you think differently about your life, and a lot of people say it should absolutely be a movie. I’ve never put so much effort into a story before. It took like seven years for me to get this out, so go listen to LOW now. Thank you. This episode was created by me, Sir Loin, Jack Rhysider. The ping repeater himself, Sean Powers, is who wrote and produced this one. Our editor is the ransom werewolf, Tristan Ledger, mixing done by Proximity Sound, and our intro music is by the mysterious Breakmaster Cylinder. My ransomware negotiator quit on me last week. She said the job had too many demands. This is Darknet Diaries.

Transcription performed by LeahTranscribes