Leaked internal communications from the Conti ransomware operation exposed one of the clearest views yet into a major cybercrime enterprise run like a legitimate technology company. Material published beginning on 27 February 2022 after Conti publicly backed Russia included tens of thousands of Jabber messages, source code, infrastructure details, operational guidance, and translated archives shared through public repositories. The leaks showed Conti had structured management, HR, developers, testers, recruiters, support staff, payroll, and defined working practices, with some reporting describing roughly 150 members and others documenting more than 160,000 messages among nearly 500 actors tied to Conti and related operations. Researchers said the disclosures revealed a mature ransomware-as-a-service and double-extortion business that had already become one of the most damaging strains globally, with the FBI previously linking Conti to more than 1,000 victims and over $150 million in victim payments by early 2022.
The leaked chats also mapped Conti’s wider ecosystem, showing overlap with TrickBot, BazarLoader, Ryuk, LockBit, Maze, Ragnar Locker, Emotet, IcedID, Buer, Amadey, and other malware operations, while indicating the group often avoided Russian and Chinese targets and may have had links to Russian state interests. Analysts said the disclosures uncovered victim-selection methods, attack infrastructure, salaries, and collaboration patterns, while also creating a proliferation risk by giving other criminals access to Conti tradecraft and code. Despite the exposure, reporting indicated the group continued operations, adapted its tooling and intrusion methods, and may have influenced or re-emerged through later activity such as Monti, underscoring that the leak disrupted secrecy more than it ended the threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
44 events from the most recent confirmed update back to the earliest known activity.
On May 19, 2022, the admin panel of Conti's official website shut down, marking a visible contraction of the gang's public infrastructure after the leaks.
In May 2022, the U.S. State Department's Rewards for Justice program announced rewards of up to $10 million for information on specific Conti members including Professor, Reshaev, Tramp, Dandis, and Target.
In the first four days of April 2022, the Conti leak site added 11 victims, reinforcing Secureworks' assessment that the group remained highly active.
In April 2022, a LockBit 2.0 representative said on an underground forum that they had been in contact with Conti representatives, mainly due to interest in using TrickBot.
In a March 31, 2022 RAMP forum post, a persona identified as 'Jordan Conti' said the group continued operating, claimed a 50% payment rate, and asserted the public leak site listed only non-paying victims.
On March 16, 2022, Silent Push reported that the February 27 Conti leaks exposed source code, infrastructure, and operational guidance that could help both defenders and aspiring ransomware operators.
By March 16, 2022, a GitHub repository aggregating Google- and DeepL-translated Conti leak materials and helper scripts had been published.
On March 10, 2022, the GitHub repository's 'Conti IOC.txt' file was updated in commit 80e830f by user 'whichbuffer.'
On March 8, 2022, a GitHub repository containing Conti indicators of compromise, TTPs, tool lists, and vulnerabilities was initialized and populated with multiple uploaded files.
By 2022-03-07, researchers said Conti had already recovered from the late-February leaks, migrated exposed infrastructure, posted new extortion-site dumps, and completed two new data breaches at U.S.-based companies. Observers also reported renewed phishing, command-and-control, and attempted breach activity after a brief slowdown.
A third batch of Conti leak materials was referenced in a ContiLeaks tweet dated March 2, 2022, including Jabber logs.
In March 2022, the number of victims posted on Conti's leak site rose to the second-highest monthly total since January 2021, indicating the leaks did not significantly disrupt operations.
In March 2022, a Ukrainian researcher affiliated with or working for Conti leaked hundreds of files and more than 60,000 internal messages, exposing the gang's operations, tools, and costs; Conti source code was also leaked publicly that month.
A second batch of Conti leak materials was referenced in a ContiLeaks tweet dated February 28, 2022, including JSON archives for multiple days of data.
A first batch of shared Conti leak materials was referenced in a ContiLeaks tweet dated February 27, 2022 and mirrored in a translation repository.
On February 27, 2022, the @ContiLeaks Twitter account was created and began leaking Conti communications and internal materials online.
Conti publicly expressed support for the Russian administration early in the Russia-Ukraine crisis, a move that multiple sources say triggered retaliatory leaks from a Ukrainian insider or researcher.
Within hours of Sophos Rapid Response beginning its engagement early on December 3, 2021, the Conti group launched its attack against the same healthcare provider.
On December 3, 2021, employees found Karma ransom notes set as wallpaper on about 20 workstations and servers; the note claimed data was stolen but not encrypted because the victim was in healthcare.
On December 1 and 2, 2021, the Karma group exfiltrated 52 GB of archived files from the Canadian healthcare provider to Mega cloud storage.
On November 30, 2021, an attacker connected to 104[.]168.44.130 and launched batch scripts that installed Cobalt Strike beacons across email servers, domain controllers, and other systems.
Between November 29 and November 30, 2021, logs showed repeated failed connections to internal servers, followed by successful use of the created Administrator account to access another server.
On November 11, 2021, a second ProxyShell intrusion against the Canadian healthcare provider installed a web shell on the Exchange IIS instance.
In November 2021, two high-level Conti managers discussed a partnership with LockBit 2.0 and later clarified the arrangement in leaked conversations.
In November 2021, the Conti leak site reached a peak of 95 listed victims, the highest monthly total cited by Secureworks for 2021.
On October 22, 2021, a Conti representative posted on a Russian-language hacking forum criticizing the reported U.S. compromise of REvil's systems.
On September 27, 2021, Conti's OSINT team leader discussed updating the group's ransom note by copying part of the Ragnar Locker ransom note.
On August 10, 2021, attackers exploited ProxyShell vulnerabilities on a Canadian healthcare provider's Exchange server, creating an administrative account and establishing access later used in ransomware activity.
IBM X-Force reported in October 2021 that ITG23 had partnered with TA551/Shathak around July 2021 to distribute TrickBot and BazarBackdoor, which later enabled Conti deployments.
As of July 1, 2021, the Bitcoin address shown in the leaked payroll message had received 2.31 BTC, worth about $80,000 at the time.
A June 29, 2021 message from 'Mango' to 'Stern' described a biweekly salary breakdown for an 81-person operation, illustrating the scale of the group's payroll structure.
On 2021-05-20, the FBI issued Alert CP-000147-MW warning that Conti had hit at least 16 U.S. healthcare and first responder networks in the prior year and more than 400 organizations worldwide.
Leaked chats suggested Netwalker affiliates may have integrated with Conti after Netwalker takedown and arrest activity in early 2021.
In October 2020, leaked internal chats showed a Conti manager using the handle Target discussing attacks on U.S. clinics. The conversation provided early evidence from inside the group of interest in healthcare-sector targeting.
From September to October 2020, Conti-Ryuk attacks targeted organizations including Sopra Steria, Steelcase, Merieux NutriSciences, and Northern Trust, allegedly generating 1.5 million in ransom payments.
On August 26, 2020, two actors discussed compensation and recruitment issues related to the Ryuk team, further linking Conti leadership to Ryuk operations.
Leaked chats indicated that Conti started collaborating with Ryuk around August 2020, reinforcing links between the two ransomware operations.
On July 17, 2020, Conti's head developer said the group changed its cryptographic algorithm from AES-256 to ChaCha20 to improve encryption speed.
On July 16, 2020, two Conti-linked actors discussed using money earned from Ryuk ransomware campaigns to pay rent and other expenses.
On July 8, 2020, a top Conti developer told a senior manager that a Maze ransomware developer had provided access to Maze's administrative panel.
In July 2020, leaked chats showed Conti actors discussing Maze taking a percentage of proceeds and obtaining a Maze ransomware build for analysis, indicating an early Conti-Maze connection.
On June 23, 2020, a senior Conti manager discussed a reported slowdown in Ryuk activity and said Ryuk operations would soon return to normal.
Conti was first seen in early 2020 and began operating as a ransomware-as-a-service strain tied to the Wizard Spider/GOLD ULRICK ecosystem.
Within 48 hours before publication, Conti updated recent victim listings to advertise the sale of access to hacked organizations and their network data rather than only leaking stolen files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourceintel471.com
Open sourceintel471.com
Open sourceintel471.com
Open sourcecyberscoop.com
Open sourcekrebsonsecurity.com
Open sourceicij.org
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.