Darknet Diaries EP 180: Inside Conti - The Rise and Fall of a Devastating Ransomware Empire
This episode provides an extensive investigation into Conti, one of the most successful and devastating ransomware operations in history. The story traces the evolution of Russian cybercrime groups through multiple iterations, like Russian nesting dolls stacking inside each other. Before Conti existed, there was the Dyre gang led by a crime boss named Bentley. When Russian authorities raided Dyre in 2015, the operation morphed into TrickBot, which eventually became known as Conti. Bentley himself transformed into a new identity called Stern and continued leading operations. These groups operated with remarkable sophistication, even creating a film production company called the 25th Floor Film Company to launder their cybercrime profits. Bizarrely, they planned to produce a movie called Botnet about their own hacking operations, featuring characters based on actual gang members. The episode details how Conti recruited members through legitimate job-seeking websites in Russia, presenting themselves as a fast-moving startup. One key recruit was a Latvian programmer named Max, whose real name is Alavita. She was a middle-aged mother with a degree in applied mathematics who unknowingly joined the operation after passing a coding test. When she discovered she was working for a ransomware gang after being shown a ransomware note template, she chose to continue working with them. Max eventually became involved in writing ransomware notes and web development for the group. Her poor operational security led to her arrest when she landed in Miami for a connecting flight, making her the first Conti member to be apprehended by US authorities. Conti's most devastating attack targeted Ireland's entire healthcare system in 2021, during the height of the COVID-19 pandemic. Over 70,000 computers across 4,000 locations and forty hospitals were infected with ransomware. The attack caused total chaos, forcing hospitals to revert to pen and paper for patient records and appointments. Cancer treatments were delayed, maternity wards were disrupted, and the entire country's medical infrastructure was thrown into crisis. Conti demanded twenty million dollars for decryption. Ireland refused to pay, and after weeks of struggle, Conti surprisingly provided the decryption key without payment, possibly due to pressure from the Russian embassy in Ireland. However, this demonstrated Conti's evolution to double-dip ransomware, where they both encrypted systems and stole sensitive data, giving them leverage even if victims had backups. Another significant Conti operation targeted Graff, a luxury jeweler whose clients included celebrities and royalty. Conti stole customer data and began leaking it when Graff didn't immediately pay. However, the leaked data inadvertently included purchase records of the Saudi royal family. This mistake led to what appears to have been serious threats against Conti from powerful security teams protecting these high-profile individuals. In an unprecedented move for a cybercrime group, Conti issued a public apology specifically to Prince Mohammed bin Salman and other royal family members, promising to delete the data and implement better review processes. Internal chat logs showed Conti members were genuinely frightened, with one member writing that the Saudis would find them and they would be gone. Graff ultimately paid 7.5 million dollars in Bitcoin. The episode reveals how cybersecurity researcher Alex Holden and his team at Hold Security infiltrated Conti by posing as hackers and building relationships with members over years. They gained access to Conti's Jabber server and cloned their network, obtaining hundreds of thousands of internal messages. This provided unprecedented insight into how Conti operated like a legitimate corporation with departments, budgets, physical offices, and even allocated twenty-five million dollars for infrastructure improvements in 2021. The chat logs also revealed internal ethical debates, with some members refusing to attack hospitals while others, like a member named Dollar, ignored these boundaries. When Russia invaded Ukraine in February 2022, Conti publicly declared full support for the Russian government, which enraged a Ukrainian IT specialist who had access to their systems. This Ukrainian analyst, working with Alex Holden, executed a massive data breach against Conti itself, creating the Twitter account contileaks and releasing tens of thousands of internal messages, member photos, cryptocurrency accounts, and organizational details. The leaks exposed the gang's structure, revealed member identities, and created chaos within the organization. The timing was particularly devastating because Conti's membership was split between Russians and Ukrainians, and the war had already created internal tensions. The leaks included everything from attack planning discussions to personal photos of members living luxurious lifestyles. The cybersecurity community watched in real-time as one of the world's most successful ransomware operations unraveled publicly. While Alex Holden expressed concerns that the leaks caused Conti to splinter into multiple smaller groups that became harder to track, the disclosure led to numerous indictments and fundamentally changed how law enforcement understood ransomware operations. After the leaks, Conti attempted one final major attack against the entire government of Costa Rica before the organization disbanded, with members scattering to join or form other ransomware groups.