Cyber Crime

Researchers were able to access the payment portal of the Conti gang

The Conti ransomware group has suffered a data breach that exposed its attack infrastructure and allowed researcher to access it.

Researchers at security firm Prodaft were able to identify the real IP address of one of the servers used by the Conti ransomware group and access the console for more than a month. The exposed server was hosting the payment portal used by the gang for ransom negotiation with he victims.

“The PTI team accessed Conti’s infrastructure and identified the real IP addresses of the servers in question.” reads the report published by the experts. “Our team detected a vulnerability in the recovery servers that Conti uses, and leveraged that vulnerability to discover the real IP addresses of the hidden service hosting the group’s recovery website”

The experts launched an investigation into the activity of the group with the intent of unmask the Conti affiliates, retailers, developers and servers.

The researchers were able to unmask the real IP address of Conti’s TOR hidden service and contirecovery.ws and 217.12.204.135. The latter is an IP address owned by Ukrainian web hosting company ITL LLC.

Prodaft researchers were able to compromise the server and monitor network traffic for incoming connections, including SSH connections used by Conti members to access the server.

However, the IP addresses associated with SSH connections belonged to Tor exit nodes used by Conti operators to hide their identity.

The experts were also able to determine the OS of the server behind the hidden service, a Debian distro with hostname ”dedic-cuprum-617836”. Experts speculate the numeric value in the hostname is an invoice number for the server, assigned by the hosting company ITLDC.

Linux version 4.9.0-16-amd64 (Debian 6.3.0-18deb9u1) #1 SMP Debian 4.9.272-2
(2021-07-19)
217.12.204.135 dedic-cuprum-617836.hosted-by-itldc.com dedic-cuprum-617836

The security firm shared its findings with law enforcement authorities.

The experts also shared the contents of htpasswd file of the subject host that can be used in future investigations on the Conti operations.

The PTI team was also able to discover multiple victim chat sessions and captured login credentials for MEGA accounts used while contacting the victims. Experts were able to discover the connecting IP addresses, dates, the purchase method, and the software used for accessing the file sharing and upload service.

After the publishing of the report, the Conti operators have taken their payment portal offline, MalwareHunterTeam researchers confirmed.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Cyclone)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Paraguay Suffered Data Breach: 7.4 Million Citizen Records Leaked on Dark Web

Resecurity researchers found 7.4 million records containing personally identifiable information (PII) of Paraguay citizens on…

13 hours ago

Apple confirmed that Messages app flaw was actively exploited in the wild<gwmw style="display: none; background-color: transparent;"></gwmw>

Apple confirmed that a security flaw in its Messages app was actively exploited in the…

20 hours ago

Trend Micro fixes critical bugs in Apex Central and TMEE PolicyServer

Trend Micro fixed multiple vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer…

24 hours ago

Paragon Graphite Spyware used a zero-day exploit to hack at least two journalists’ iPhones<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

Security researchers at Citizen Lab revealed that Paragon's Graphite spyware can hack fully updated iPhones…

1 day ago

SinoTrack GPS device flaws allow remote vehicle control and location tracking

Two vulnerabilities in SinoTrack GPS devices can allow remote vehicle control and location tracking by…

2 days ago