/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Leaked chat logs reveal the internal structure and hierarchy of the Conti ransomware group, which some experts believe is a rebrand of the Ryuk ransomware gang

Brian Krebs / Krebs on Security :

Krebs on Security Brian Krebs

Context & Ripple Effects

The Krebs analysis is the forensic deep-dive that follows the leak of 339 days of Conti's internal chat logs, posted by a pro-Ukraine member after the gang's leaders declared support for Russia. Where the initial dump was raw material, Krebs' reporting maps what the logs actually show: a structured organization with a defined hierarchy — and evidence feeding the long-standing hypothesis that Conti is a rebrand of the Ryuk gang.

The timing matters because the leak landed while Conti was still operationally active, extorting targets like Costa Rica with a doubled $20M demand. An earlier researcher sting that exposed ransomware operators' payout structures showed how much damage visibility into a gang's internals can do; this leak hands defenders far more.

First-order effects

  • Security researchers and law enforcement gain an unprecedented map of Conti's command structure, affiliate relationships, and decision-making — the raw material for attribution work aimed at named individuals rather than just the brand.
  • The Ryuk-rebrand question moves from speculation toward testable claim, since the logs let analysts compare Conti's internal language, tooling, and payout habits against what is known about Ryuk.

Second-order effects

  • Conti's own leaked codebase gets turned against it: NB65 claims to be running modified versions of the leaked ransomware against Russian entities including Roscosmos, converting the gang's tooling into a weapon for its adversaries.
  • Victims and negotiators gain leverage — as with the earlier exposure of ransom payout structures and cash-out schemes, documented internal norms let targeted organizations and insurers calibrate whether and how to engage.

Third-order effects

  • If the pattern holds, ransomware 'brands' prove to be disposable shells: AdvIntel later reported Conti taking its infrastructure offline with leaders dispersing into smaller groups, suggesting leaks plus geopolitical overexposure accelerate fragmentation rather than killing the underlying talent pool.
  • Geopolitical alignment emerges as an operational liability for cybercriminal enterprises — declaring a side in a war gave insiders both motive and cover to detonate the group from within, a risk model other gangs must now price in.

The trend: Ransomware-as-a-service operations are proving structurally fragile: internal leaks and political positioning now dissolve major brands like Conti into dispersed successor groups faster than law enforcement ever did.

Discussion

  • @samilaiho Sami Laiho on x
    This is so amazing https://krebsonsecurity.com/ ...
  • @briankrebs @briankrebs on x
    Spent past 2 days reading 14 months worth of leaked chats from the Conti ransomware group (so you don't have to). Today's Part I focuses on the group's internal efforts to evade actions by law enforcement & intel agencies. This is a bottomless gold mine. https://krebsonsecurity.c…
  • @briankrebs @briankrebs on x
    These chats reveal the remarkable fact that Conti has the resources - dozens of employees - to be able to pivot from a single opportunistically infected PC to a ransomware attack in a 9-5 workday, if they really want to. Shows the enormous pressure put on incident response teams
  • @briankrebs @briankrebs on x
    In Part II of this series on the leaked chats from the Conti ransomware gang, we explore what it's like to work for Conti, as described by the employees themselves. Conti's shifting organizational structure, wracked by high attrition, is fascinating. https://krebsonsecurity.com/ …
  • @nicoleperlroth @nicoleperlroth on x
    Leaks from Conti ransomware group show even they think Putin is “out of his f-ng mind.” https://twitter.com/...