180: Conti
Oct 6, 2026 · 59m
Summary
This episode traces the evolution of the Conti ransomware gang from the Dyer and TrickBot groups, highlighting the bizarre story of a leader who laundered cybercrime profits through a film production company. Host Jack Rhysider discusses the devastating 2021 attack on Ireland’s healthcare system and the group’s double-extortion tactics, including a controversial leak involving the Saudi royal family. The narrative culminates in the internal chaos caused by the Russian invasion of Ukraine, which split the gang and led to a massive data breach that exposed their secrets and ultimately dismant…
Topics discussed
The silence and fear following a ransomware attack
Introduction to the Conti gang and their hidden nature
Sponsors: ThreatLocker and Maze
The difficulty of arresting Russian cybercriminals
Bentley's money laundering scheme via film production
The irony of making a movie about their own cybercrime
The danger of cybercriminals telling their own stories
Evolution from the Dyer gang to TrickBot to Conti
Recruiting Max, a Latvian programmer, into the gang
Max's hiring process and initial suspicion
Max realizes she is part of a cybercriminal enterprise
Max's justification for her junior role
Max's arrest in Miami as the first Conti takedown
The devastating Conti attack on Ireland's hospital network
Scale of the Irish hospital infection and lockdown
Public condemnation and disruption of pandemic services
Impact on patients, including a cancer treatment cancellation
The $20 million ransom demand and data theft
Negotiations and the threat of data publication
Buying time while attempting to decrypt data manually
The decision to hand over the decryption key
Theories on why Conti stopped the Irish attack
The Conti attack on Graff, the luxury jeweler
The invention of double-dip ransomware
Conti's mistake in leaking high-profile client data
Accidental doxxing of the Saudi royal family
Conti's public apology and retraction of the leak
Speculation on who threatened Conti to remove the data
Intimidation by state actors against the gang
Conti's internal fear and public apology
Conti's $180 million haul and rising risks
Sponsor: Doppel
The concept of infiltrating hacker groups
Alex Holden and Hold Security's infiltration of TrickBot
Gaining trust and secrets from TrickBot members
Exploiting poor security practices of members
Building relationships with Stern, the Conti boss
Analyzing hundreds of thousands of chat logs
Conti's corporate structure and budgeting
Internal rules and debates about targeting hospitals
Stern's refusal to approve hospital encryption
Loss of leadership and internal chaos in Conti
Stern's disappearance and member anxiety
The impact of the Russian invasion of Ukraine on Conti
Internal division and the official Conti statement
A Ukrainian member's motivation to fight back
Collaboration to obtain and plan to leak chat logs
Moral justification for the leak by the Ukrainian analyst
The creation of the AtContiLeaks Twitter account
Identity of the leaker and the initial data dumps
Content of the leaks and exposure of members
The unprecedented nature of hackers being hacked
Law enforcement impact and unmasking of operatives
The fracturing of Conti and public memes
The drama and intrigue of the leaked chat logs
The challenge of translating 70,000 Russian messages
Linguistic quirks in the Conti chat logs
The aftermath of the leaks and Conti's disbandment
Splintering of Conti affiliates into new groups
The Conti attack on Costa Rica's government
Disruption of Costa Rica's digital economy and pensions
Expansion of the Costa Rica attack to other departments
Other ransomware groups joining the Costa Rica attack
Persistence of Conti ransomware via affiliates
The end of Conti and the beginning of arrests
The unknown fate of most Conti members
Vitaly Kovalev (Stern) and his potential billionaire status
The challenge of laundering cybercrime profits
Links to Dubai and cryptocurrency operations
Guests, sponsor, and show credits
Listen ad-free on Castria