Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Conti ransomware source code leaks
  • Malware

Conti ransomware source code leaks

Do Son March 24, 2022 2 minutes read
Conti ransomware source code
Add Daily CyberSecurity as a preferred source on Google

Conti, a notorious ransomware gang, has over the past two years attacked multiple multinational companies around the world while encrypting data and stealing data, threatening those companies with data backups to pay ransoms or leak confidential data.

Members of this ransomware gang are located in Russia or countries surrounding Russia, and Conti claimed support for Russian military operations when Russia marched into Ukraine.

Later, someone published the data of Conti’s internal chat server on the Internet. These data include daily communication between Conti members, and some data supporting the server were also stolen.

Image: bleepingcomputer

Previously, there were rumors that the data was leaked because of internal strife within Conti because of whether they supported or opposed Russia. This is purely a rumor, in fact, the data leak was a Ukrainian security researcher who infiltrated Conti to steal data and sabotage it.

Now that the second wave of sabotage has begun, the researcher released the source code of the Conti ransomware. The Conti gang encrypted the ransomware source code and placed it on the server. The researchers did not have the password, so they could not decrypt it. However, after the data was released, other security personnel had successfully cracked the encrypted password and made the Conti source code public.

This is absolutely good news for security companies, as security companies can study the operation process of this type of ransomware through the source code, and can also look for potential weaknesses to make decryption tools.

BleepingComputer, a website that focuses on security information, has compiled and verified the source code and verified that the code is valid, and core files such as cryptor.exe, cryptor_dll.dll, and decryptor.exe can be successfully created.

Unfortunately, while security companies can study these codes, other ransomware gangs can also use them to develop other ransomware.

Related coverage

  • Vultur Android Malware Spreads Its Wings, Poses Serious Threat to Mobile Users
  • ValleyRAT Campaign Leverages Shellcode and Social Engineering to Target Chinese Speakers
  • Operation Magnus Dismantles RedLine and META Infostealer Networks
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Conti ransomware source code

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-73807CVSS 9.8
    The mySCADA myPRO Manager command API does not properly enforce authentication for...
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing...
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller...
  • CVE-2026-61560CVSS 9.8
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version...
  • CVE-2026-73437CVSS 9.6
    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP)...
  • CVE-2026-61559CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version...
  • CVE-2026-91939CVSS 9.8
    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without...
  • CVE-2026-61568CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to...
  • CVE-2026-66887CVSS 9.6
    The affected products are missing authorization on state-changing CGIs and session checks...
  • CVE-2026-66890CVSS 9.6
    The affected products use hard-coded credentials, which could allow remote access to...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.