Leaked Conti communications and ransomware source code exposed the Russian-speaking group’s internal operations after it declared support for Russia’s invasion of Ukraine in 2022. A Ukrainian cybersecurity researcher released 60,694 messages across 393 JSON files, which other researchers subsequently validated. ReliaQuest found a structured organization with persistent leadership, defined employment practices, and communications concentrated among a small number of users. Messaging dropped substantially on weekends and correlated with newly reported victims, but those patterns do not establish when attacks occurred; explanations for individual activity spikes remain speculative.
Tenable identified more than 30 vulnerabilities associated with Conti and its affiliates, with privilege-escalation flaws accounting for nearly three quarters of those disclosed in the communications. The group combined multiple initial-access methods with post-compromise techniques aimed at obtaining domain administrator privileges and encrypting systems across victim networks. Most listed vulnerabilities already had patches available, underscoring the need to address both internet-facing exposure and internal escalation paths. MITRE’s separate reporting identifies AdFind as an Active Directory reconnaissance utility used by numerous intrusion sets, including Wizard Spider, reinforcing the importance of monitoring directory enumeration alongside privilege escalation rather than relying on perimeter defenses alone.

See which actors are running it and whether you're in range.
15 events from the most recent confirmed update back to the earliest known activity.
BreachQuest published an analysis of the leaked communications identifying vulnerabilities that Conti appeared to use against organizations.
Later in March, the same researcher uploaded the source code for version three of Conti ransomware to VirusTotal.
At the start of March, the researcher released a password-protected archive containing an older version of Conti's ransomware source code.
A Ukrainian cybersecurity researcher, described by another source as an alleged Conti member, publicly leaked internal Conti conversations. The dataset contained 60,694 messages in 393 JSON files and allegedly originated from the backend of Conti's Jabber server.
Conti advertised for networkers, access providers, penetration testers, and individuals with access to corporate botnets.
Conti acknowledged an infrastructure attack. A representative claimed that no information about its systems or personnel was exposed and that all systems had been restored following a security audit.
An affiliate leaked Conti training materials and operational details, including alleged server IP addresses, an administrator's username and Jabber ID, and a Tor chat link. The leaker alleged that recruits received an insufficient share of ransom payments.
A cybercriminal forum user shared approximately 27 GB of Conti material, including red-teaming videos, tools, and malicious PowerShell scripts.
Conti attacked Ireland's Health Service Executive and demanded a $20 million ransom. The organization refused to pay.
Conti and its affiliates reportedly began exploiting CVE-2021-44228, known as Log4Shell, in attacks in late 2021.
Carbon Black researchers first discovered the Conti ransomware in 2020.
The password-protected archive was subsequently cracked, and its source-code contents were published online.
Other cybersecurity researchers subsequently confirmed the validity of the leaked internal communications.
Conti revised its statement supporting Russia to soften its rhetoric about retaliatory attacks.
Conti declared support for Russia's invasion of Ukraine and threatened retaliatory attacks against critical infrastructure belonging to organizations or nations conducting cyberattacks or war activities against Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
reliaquest.com
Open sourcetenable.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.