Darknet Diaries Darknet Diaries

180: Conti

Oct 6, 2026 · 59m

Summary

This episode traces the evolution of the Conti ransomware gang from the Dyer and TrickBot groups, highlighting the bizarre story of a leader who laundered cybercrime profits through a film production company. Host Jack Rhysider discusses the devastating 2021 attack on Ireland’s healthcare system and the group’s double-extortion tactics, including a controversial leak involving the Saudi royal family. The narrative culminates in the internal chaos caused by the Russian invasion of Ukraine, which split the gang and led to a massive data breach that exposed their secrets and ultimately dismant…

Topics discussed

The silence and fear following a ransomware attack Introduction to the Conti gang and their hidden nature Sponsors: ThreatLocker and Maze The difficulty of arresting Russian cybercriminals Bentley's money laundering scheme via film production The irony of making a movie about their own cybercrime The danger of cybercriminals telling their own stories Evolution from the Dyer gang to TrickBot to Conti Recruiting Max, a Latvian programmer, into the gang Max's hiring process and initial suspicion Max realizes she is part of a cybercriminal enterprise Max's justification for her junior role Max's arrest in Miami as the first Conti takedown The devastating Conti attack on Ireland's hospital network Scale of the Irish hospital infection and lockdown Public condemnation and disruption of pandemic services Impact on patients, including a cancer treatment cancellation The $20 million ransom demand and data theft Negotiations and the threat of data publication Buying time while attempting to decrypt data manually The decision to hand over the decryption key Theories on why Conti stopped the Irish attack The Conti attack on Graff, the luxury jeweler The invention of double-dip ransomware Conti's mistake in leaking high-profile client data Accidental doxxing of the Saudi royal family Conti's public apology and retraction of the leak Speculation on who threatened Conti to remove the data Intimidation by state actors against the gang Conti's internal fear and public apology Conti's $180 million haul and rising risks Sponsor: Doppel The concept of infiltrating hacker groups Alex Holden and Hold Security's infiltration of TrickBot Gaining trust and secrets from TrickBot members Exploiting poor security practices of members Building relationships with Stern, the Conti boss Analyzing hundreds of thousands of chat logs Conti's corporate structure and budgeting Internal rules and debates about targeting hospitals Stern's refusal to approve hospital encryption Loss of leadership and internal chaos in Conti Stern's disappearance and member anxiety The impact of the Russian invasion of Ukraine on Conti Internal division and the official Conti statement A Ukrainian member's motivation to fight back Collaboration to obtain and plan to leak chat logs Moral justification for the leak by the Ukrainian analyst The creation of the AtContiLeaks Twitter account Identity of the leaker and the initial data dumps Content of the leaks and exposure of members The unprecedented nature of hackers being hacked Law enforcement impact and unmasking of operatives The fracturing of Conti and public memes The drama and intrigue of the leaked chat logs The challenge of translating 70,000 Russian messages Linguistic quirks in the Conti chat logs The aftermath of the leaks and Conti's disbandment Splintering of Conti affiliates into new groups The Conti attack on Costa Rica's government Disruption of Costa Rica's digital economy and pensions Expansion of the Costa Rica attack to other departments Other ransomware groups joining the Costa Rica attack Persistence of Conti ransomware via affiliates The end of Conti and the beginning of arrests The unknown fate of most Conti members Vitaly Kovalev (Stern) and his potential billionaire status The challenge of laundering cybercrime profits Links to Dubai and cryptocurrency operations Guests, sponsor, and show credits
Listen ad-free on Castria