A hacking group called NB65 claims it is using modified versions of Conti's leaked ransomware to attack Russian entities, including the space agency Roscosmos
A hacking group used the Conti's leaked ransomware source code to create their own ransomware to use in cyberattacks against Russian organizations.
Context & Ripple Effects
Conti's leadership declared support for Russia's invasion, prompting a pro-Ukraine member to post 339 days' worth of internal chat logs — a leak that then exposed the group's full hierarchy and internal structure. The leak has now escalated from embarrassment to weaponization: NB65 claims it rebuilt working ransomware from Conti's leaked source code and is turning it on Russian targets themselves.
That inversion matters because Conti was one of the most productive ransomware brands in the world; its own tooling being redeployed against Roscosmos and broadcaster VGTRK shows how quickly a syndicate's core asset can escape its control once geopolitics splits its ranks.
First-order effects
- Russian organizations — with Roscosmos and VGTRK named by NB65 — now face attacks built from the very ransomware strain that made Conti's name, while Conti itself loses exclusive control of its most valuable technical asset.
Second-order effects
- Conti's operational collapse accelerates: within weeks of the leak, AdvIntel reported the group took its infrastructure offline and its leaders dispersed into smaller crews, trading a unified brand for fragmented continuity.
Third-order effects
- The pattern points to ransomware syndicates behaving like franchises whose source code, once leaked, seeds successor operations — as later seen with Black Basta, a suspected Conti offshoot that Elliptic and Corvus tied to at least $107M in bitcoin extortion since early 2022.
The trend: Geopolitical alignment is fracturing Russia-linked ransomware syndicates, and leaked source code is redistributing their attack capability across successor groups faster than law enforcement or branding can track.