Internal messages from the Trickbot ransomware gang during 2020 detail its structure, target choices, plans to open St. Petersburg offices, and more
WiredMatt Burgess
Context & Ripple Effects
The leaked 2020 chats land mid-arc in a long unraveling of Trickbot. After the joint Microsoft and US Cyber Command disruption left parts of the botnet still online in late 2020, Bitdefender observed the operators quietly rebuilding much of the operation by mid-2021 — resilience that made the group a standing target for researchers and governments alike.
What makes these messages valuable is that they come from inside rather than inference: they join a researcher's social-engineering coup that exposed the gang's ransom payout and cash-out schemes, and they precede Wired's monthslong investigation that unmasked a key member. The St. Petersburg office plan is the detail that reframes Trickbot less as an anonymous crew than as a company with hiring and real estate ambitions.
First-order effects
Law-enforcement and research teams working Trickbot gain primary-source material on its org chart, target-selection logic, and member habits — the same kind of internal detail that fed the later US-UK sanctions on eleven alleged members and DOJ indictments of nine alleged Trickbot and Conti figures.
Trickbot members identified or narrowed down by the messages face direct personal risk: exposure has historically converted into sanctions designations and sealed indictments for this group.
Second-order effects
Conti, whose members overlap with Trickbot in the DOJ indictments, inherits scrutiny of shared personnel — every new leak about one crew sharpens the picture of the other.
Ransomware crews watching Trickbot's paper trail have an incentive to harden communications discipline, raising the cost of the chat-leak and social-engineering methods that produced both this trove and the earlier payout-structure revelations.
Third-order effects
If the pattern holds — disruption attempts, then leaks, then sanctions and indictments — ransomware groups' corporate-style organization becomes their main attack surface: offices, payroll structures, and internal messaging give investigators durable handles even when botnet infrastructure is rebuilt.
The trajectory points toward ransomware being treated as a sanctions-and-indictment problem aimed at named individuals rather than purely a malware takedown problem, with attribution increasingly built on leaked internal records.
The trend: Ransomware syndicates that organized like companies are being dismantled through their own internal communications, as leaks convert into sanctions and indictments against named members.
Fascinating insight into the operations of one of the biggest ransomware groups. “You see, how fast, hospitals and centers reply,” Target, a key member of the Russia-linked malware gang, boasted in messages to one of their colleagues."Answers from the rest, [take] days." https://…
Ransomware is a organized crime issue complicated by the fact that hackers are conditioned to think American victims are wealthy & deserve to be extorted. “Fuck clinics in the usa this week...There's gonna be a panic.” This @mattburgess story goes there. https://www.wired.com/...
A leader of the Trickbot ransomware group in Russia, to a new member worried about getting caught: “Here it is guaranteed that no one will touch you” https://www.wired.com/...
This article by @mattburgess1 sheds some light on the severity of the threat from that campaign. The adversary was targeting hundreds of facilities and predicted their operations would cause a panic. 3/x https://www.wired.co.uk/... https://twitter.com/...
“The core members of the gang make reference to Kremlin-backed activities. Stern mentioned setting up an office “for government topics” in July 2020."" 👀 https://www.wired.com/...
“Trickbot doesn't seem to be targeting very specifically; I think what they have is numerous affiliates working with them, and whoever brings the most money is welcome to stay.” 📸: Katleho Seisa/Getty Images https://www.wired.com/... https://twitter.com/...
Absolutely fantastic article here from @mattburgess1 at @WIRED that looks at the organizational structure and operations of Trickbot. Love reading about the business side of cybercrime. https://www.wired.com/...
Eek, good piece @wired, but the exclusive framing is a little strange. I'd reported these messages before. @mattburgess1 https://www.wired.com/... https://twitter.com/...
WIRED was able to see hundreds of messages sent “between senior members” of the ransomware gang Trickbot. The messages portray hackers ramping up their operations and targeting hospitals that were struggling with responding effectively to Covid-19 https://www.wired.com/... https:…
Exclusive: WIRED has seen hundreds of internal messages sent between members of Trickbot, the notorious Russian ransomware gang. The exchanges detail the inner workings of the hacking group that targeted over 400 US hospitals. By @mattburgess1 https://www.wired.com/...
Really interesting and fairly insane look inside a prolific cybercrime gang. They have multiple offices, according to leaked chat logs, including one specifically being set up “for government topics.” https://twitter.com/...
New from me: documents from inside ransomware gang Trickbot reveal its ruthless attitude and ways of working. Internal messages from 2020 show its structure, how the group targeted 400 US hospitals, planned to open six offices in St Petersburg + more https://t.co/DFXtVSibrL 🧵