A pro-Ukraine actor leaked Conti Ransomware V3.0 source code, a compiled locker, and a decryptor, exposing the inner workings of one of the most active Russian-speaking ransomware operations. Researchers reviewing the leak said the code was functional and tied it to a broader stream of disclosures that also revealed Conti’s internal chats, tools, training materials, and administrative panels. Technical analysis of the leaked conti_v3.sln project showed API hashing and anti-hooking for evasion, multithreaded encryption, use of CryptGenRandom, RSA, and the ChaCha stream cipher, plus logic for full or partial encryption based on file type and size, including special handling for databases and virtual machine files.
The leak gave defenders unusually detailed visibility into a group that had already evolved from Ryuk-linked operations and adopted double extortion through its Conti.News leak site, where stolen data was published to pressure victims. Separate reporting also documented active Conti affiliates using tools such as Cobalt Strike and PsExec against U.S. organizations, while independent researchers published unpacking work for Conti samples using FireEye’s Speakeasy emulation framework to dump unpacked payloads from memory and repair imports. Together, the disclosures increased defensive insight into Conti’s malware and operations, while also raising the risk that other threat actors could reuse the leaked code and techniques.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On March 20, 2022, the pro-Ukraine researcher ContiLeaks uploaded the source code for Conti Ransomware V3.0 to VirusTotal along with a compiled locker and decryptor. The leak continued a broader campaign exposing Conti's internal tools, chats, and infrastructure after the group's public support for Russia.
Technical analysis published in March 2022 examined the leaked Conti codebase, including the conti_v3.sln project, API hashing, anti-hooking, multithreaded encryption, and use of ChaCha and RSA. The analysis framed the leak as a significant exposure of Conti's locker and decryptor internals.
A previously leaked older Conti ransomware source code version was described as having source files last modified on January 25, 2021. Later reporting used this date to distinguish the older codebase from the newer V3 leak.
By August 2020 reporting, researchers said TrickBot-linked operators had stopped broadly deploying Ryuk since July 2020 and were deploying Conti instead. Conti also launched its Conti.News data leak site, listing 26 victims and formalizing its double-extortion model.
Threatpost reported that eSentire had published a report on a newly identified Conti affiliate that used Cobalt Strike and PsExec in attacks against seven U.S. companies across multiple sectors between 2021 and 2022. The report included accounts, IP addresses, domains, and ProtonMail addresses tied to the affiliate.
A GitHub repository published an automatic unpacker for a specific Conti sample using FireEye's Speakeasy framework. The author documented halting execution at the first VirtualProtect call, dumping the unpacked PE from memory, and attempting to repair its import table, while noting the method was not fully reliable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
fireeye.com
Open sourcecocomelonc.github.io
Open sourcethreatpost.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.