Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump


A mystery whistleblower calling himself GangExposed has exposed key figures behind the Conti and Trickbot ransomware crews, publishing a trove of internal files and naming names.

The leaks include thousands of chat logs, personal videos, and ransom negotiations tied to some of the most notorious cyber-extortion gangs —believed to have raked in billions from companies, hospitals, and individuals worldwide. It’s part of his “fight against an organized society of criminals known worldwide,” GangExposed told The Register via Signal chat. He claims that he’s not interested in the $10 million bounty that the Feds have put up for information about one key Conti leader that he’s already named, as well as a second that he says will soon be identified on Telegram.

Read more…
Source: The Register News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Albabat ransomware

    January 26, 2024

    Albabat, also known as White Bat, is a financially motivated ransomware variant written in Rust that identifies and encrypts files important to the user and demands a ransom to release them. It first appeared in November 2023 with the variant Version 0.1.0. Version 0.3.0 was released in late December, followed by version 0.3.3 in mid-January 2024. ...

  • UK councils remain downed by cyberattack

    January 26, 2024

    Three local councils in the United Kingdom continue to experience disruption to their online services, a week after confirming a cyberattack had knocked some systems offline. The councils for Canterbury, Dover, and Thanet — all of which are based in the U.K. county of Kent and have a combined population of almost 500,000 residents — said ...

  • Kansas City Area Transit Authority hit by ransom cyber-attack, affecting communications

    January 26, 2024

    The Kansas City Area Transit Authority announced this week that is was hit by a ransom cyber-attack. The incident was reported on Tuesday, Jan. 23. KCATA said all service is operating, including fixed-route buss, Freedom and Freedom-On-Demand paratransit service. KCATA said at this time regional RideKC call centers can’t receive calls or can any KCATA landline. Read ...

  • Malicious ads for restricted messaging applications target Chinese users

    January 25, 2024

    An ongoing campaign of malicious ads has been targeting Chinese-speaking users with lures for popular messaging applications such as Telegram or LINE with the intent of dropping malware. Interestingly, software like Telegram is heavily restricted and was previously banned in China. Many Google services, including Google search, are also either restricted or heavily censored in mainland ...

  • Billion-dollar financial giant EquiLend hit by cyberattack

    January 25, 2024

    EquiLend, a global financial technology, data and analytics firm, suffered a cyberattack – possibly ransomware – that forced parts of its digital infrastructure offline. In a press release, EquiLend said that on January 22, 2024, its technicians identified a “technical issue that placed portions of our system offline.” Following an investigation, the company identified a cybersecurity ...

  • Another Phobos Ransomware Variant Launches Attack – FAUST

    January 25, 2024

    The Phobos ransomware family is a notorious group of malicious software designed to encrypt files on a victim’s computer. It emerged in 2019 and has since been involved in numerous cyber attacks. This ransomware typically appends encrypted files with a unique extension and demands a ransom payment in cryptocurrency for the decryption key. FortiGuard Labs has ...