Categories: Tech

Akamai analyzes data from the Conti ransomware gang

the gang of Conti ransomware shortly after the Russian invasion of Ukraine, it declared its support for the Kremlin. And after that statement, on February 27 the Twitter profile @contileaks started posting internal documents and group chats. Akamai Security examined the gang’s documentation of the Conti ransomwareanalyzing the group’s tools and techniques.

Akamai analyzes data from the Conti ransomware gang

Considered the successor of the Ryuk group, the Conti ransomware gang has a turnover of nearly 200 million dollars, obtained by hitting high-profile multinational companies. And according to Akamai’s analysis, Conti operates just as if it were a company. It has a CEO who hires new operators, who then follow a series of very precise manuals. Which gave Akamai the ability to analyze hackers’ modus operandi.

Conti often operates using double extortion attacks. This means ransomware not only encrypts data but steals it: in this way, even if the company has backups to restart, the hackers they threaten to sell private information to the highest bidders.

Akamai could see in the data published on Conti that hackers follow a precise timeline, publishing information based on how long the company takes to pay the ransom. Unfortunately for they did not find documentation or manuals relating to the initial access procedures. In fact, the guidelines explain how to extort, not how to enter.

Once defenses are breached, hackers reach tomorrow’s controller by stealing user credentials and information. They use encrypt, trojan e injector proprietari, while using external tools such as Cobalt Strike, Mimikatz e PSExec and others for lateral movement in the system. And to increase permissions by collecting credentials with an arsenal of tools developed by others.

Security experts can learn more about the tools used by the Conti ransomware gang directly on Akamai’s website.

Published by
Walker Ronnie

Recent Posts

150+ Monopoly Go Bonus Dice Links & Promo Codes 2024

In the world of mobile gaming, Monopoly GO is a popular game known for being…

7 hours ago

Monsters & Co. Work in progress: season 2 coming soon!

After the success of the first season, the animated series Monsters & Co Lavori in…

9 hours ago

Xiaomi is expanding the Redmi family? A mysterious Redmi 13 appears

Xiaomi could launch a new cheap smartphone: Redmi 13. The first rumors speak of a…

9 hours ago

Senna, the trailer of the series about the legendary Brazilian driver

The world of Formula 1 is always celebrated in every form of media possible. This…

13 hours ago

Vivo expands the X100 family: X100 Ultra and X100s are coming!

Vivo expands the X100 family: X100 Ultra and X100s are coming, here are the first…

13 hours ago

CORSAIR: new RS MAX Series fans with increased thickness of 30 mm

CORSAIR has further optimized the performance of PC fans with the RS MAX Series with…

16 hours ago