Analysis of ransomware techniques
We will start with the most significant and pivotal leak of Conti’s source code, then we will analyze the source code of Hello Kitty Ransomware.
Conti
What is Conti ransomware? ContiLocker is ransomware that was created by the Conti Ransomware Gang, a criminal organization that operates in Russia and is believed to have connections with Russian security agencies. Additionally, RaaS is a business model utilized by Conti.
The Conti ransomware source code leak, named ContiLeaks, was released by a Ukrainian security researcher in retaliation for the cybercriminals’ support of Russia during the invasion of Ukraine in February 2022.
ContiLeaks source code structure looks like the following:
Figure 16.1 – ContiLeaks conti_v3 source code structure
As we can see, the most recent updated date appears to be January 25, 2021.
A Visual Studio solution (containing conti_v3.sln
) is indicated in the...