Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • DOGE Nears 20-Day High, as TRON Also Surges – Market Updates Bitcoin News bitcoin news
  • Bitcoin Forms Bullish Pattern, Why Break Above $31.5K Is The Key bitcoin news
  • Bitcoin Bearish Signal: Whales Ramp Up Dumping bitcoin news
  • A New Android Banking Trojan Spotted in the Wild cyber security news
  • Russia’s Anti-Monopoly Agency Proposes Higher Electricity Rates for Home Crypto Miners – Mining Bitcoin News bitcoin news
  • Report Reveals Terra Holders Liquidated Their Holding When Crash Started bitcoin news
  • Why Terra’s Anchor Protocol Changed Earn Rate To 18% APY bitcoin news
  • Decentralized Autonomous Organization Statistics Show $10 Billion Is Held by DAO Treasuries – Technology Bitcoin News bitcoin news

Conti Ransomware Gang Shut Down After Splitting into Smaller Groups

Posted on May 24, 2022 By root


Conti Ransomware Gang

Even as the operators of Conti threatened to overthrow the Costa Rican government, the notorious cybercrime gang officially took down their infrastructure in favor of migrating their criminal activities to other ancillary operations, including Karakurt and BlackByte.

“From the negotiations site, chatrooms, messengers to servers and proxy hosts – the Conti brand, not the organization itself, is shutting down,” AdvIntel researchers Yelisey Bogusalvskiy and Vitali Kremez said in a report. “However, this does not mean that the threat actors themselves are retiring.”

The voluntary termination, with the exception of its name-and-shame blog, is said to have occurred on May 19, 2022, while an organizational rejig was happening simultaneously to ensure a smooth transition of the ransomware group’s members.

AdvIntel said Conti, which is also tracked under the moniker Gold Ulrick, orchestrated its own demise by utilizing information warfare techniques.

CyberSecurity

The disbanding also follows the group’s public allegiance to Russia in the country’s invasion of Ukraine, dealing a huge blow to its operations and provoking the leak of thousands of private chat logs as well as its toolset, making it a “toxic brand.”

The Conti team is believed to have been actively creating subdivisions for over two months. But in tandem, the group began taking steps to control the narrative, sending out “smoke signals” in an attempt to simulate the movements of an active group.

“The attack on Costa Rica indeed brought Conti into the spotlight and helped them to maintain the illusion of life for just a bit longer, while the real restructuring was taking place,” the researchers said.

“The only goal Conti had wanted to meet with this final attack was to use the platform as a tool of publicity, performing their own death and subsequent rebirth in the most plausible way it could have been conceived.”

Conti Ransomware Gang

The diversion tactics aside, Conti’s infiltration specialists are also said to have forged alliances with other well-known ransomware groups such as BlackCat, AvosLocker, Hive, and HelloKitty (aka FiveHands).

Additionally, the cybersecurity firm said it had seen internal communication alluding to the fact that Russian law enforcement agencies had been putting pressure on Conti to halt its activities in the wake of increased scrutiny and the high-profile nature of the attacks conducted by the criminal syndicate.

Conti’s affiliation with Russia has also had other unintended consequences, chief among them being its inability to extract ransom payments from victims in light of severe economic sanctions imposed by the West on the country.

CyberSecurity

That said, although the brand may cease to exist, the group has adopted what’s called a decentralized hierarchy that involves multiple subgroups with different motivations and business models ranging from data theft (Karakurt, BlackBasta, and BlackByte) to working as independent affiliates.

This is not the first time Gold Ulrick has revamped its inner workings. TrickBot, whose elite Overdose division spawned the creation of Ryuk and its successor Conti, has since been shut down and absorbed into the collective, turning TrickBot into a Conti subsidiary. It has also taken over BazarLoader and Emotet.

“The diversification of Conti’s criminal portfolio paired with its shockingly swift dissolution does bring into question whether their business model will be repeated among other groups,” AdvIntel noted last week.

“Ransomware Inc. is less like the gangs they are often called and much more like cartels as time goes on,” Sam Curry, chief security officer at Cybereason, said in a statement shared with The Hacker News.

“This means partner agreements, specialized roles, business-like R&D and marketing groups and so on. And because Conti is beginning to mirror the sorts of activities we see among legitimate companies, it’s no surprise they are changing.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Microsoft Warns of Web Skimmers Mimicking Google Analytics and Meta Pixel Code
Next Post: Malware Analysis: Trickbot

Related Posts

  • New Zimbra Email Vulnerability Could Let Attackers Steal Your Login Credentials cyber security news
  • Twitter’s New Owner Elon Musk Wants DMs to be End-to-End Encrypted like Signal cyber security news
  • 10 Most Prolific Banking Trojans Targeting Hundreds of Financial Apps with Over a Billion Users cyber security news
  • New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the Wild cyber security news
  • Microsoft Warns Rise in XorDdos Malware Targeting Linux Devices cyber security news
  • Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Mad Money’s Jim Cramer Says Crypto Immolation Shows the Fed’s Job to Tame Inflation Is Almost Complete – Markets and Prices Bitcoin News
  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News

Recent Comments

No comments to show.
  • NFT and Digital Asset Authentication Technology Launches on KuCoin June 30th bitcoin news
  • Music Fans Rejoice as YellowHeart Protocol Is Set to Launch on Bittrex Global Starting Block – Sponsored Bitcoin News bitcoin news
  • Bitcoin Continues To Slide But Displays Bullish Divergences On Charts bitcoin news
  • Ethereum Keeps Sliding Down, Will The Support Line of $1,100 Break? bitcoin news
  • Stratis (STRAX) Soars 200% From June Low On Sky Dream Mall Launch bitcoin news
  • Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware cyber security news
  • Robinhood Launching New Non-Custodial Web3 Crypto Wallet – Wallets Bitcoin News bitcoin news
  • Fidelity Plans Hiring Spree to Expand Crypto Services to Include Ethereum Trading and Custody – Finance Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme