Money Over Morals: A Business Analysis of Conti Ransomware
Ian W. Gray, Jack Cable, Benjamin Brown, Vlad Cuiujuclu, Damon McCoy

TL;DR
This paper provides an in-depth empirical analysis of the Conti ransomware group, revealing its business structure, profit mechanisms, and ransom payment flows, based on leaked chat data and blockchain analysis.
Contribution
It introduces novel methodologies for tracing ransom payments and publishes a dataset of Bitcoin addresses, significantly advancing ransomware economic analysis.
Findings
Identified over $80 million in ransom payments to Conti.
Constructed a detailed operational and profit model of Conti.
Published a dataset of Bitcoin addresses related to Conti.
Abstract
Ransomware operations have evolved from relatively unsophisticated threat actors into highly coordinated cybercrime syndicates that regularly extort millions of dollars in a single attack. Despite dominating headlines and crippling businesses across the globe, there is relatively little in-depth research into the modern structure and economics of ransomware operations. In this paper, we leverage leaked chat messages to provide an in-depth empirical analysis of Conti, one of the largest ransomware groups. By analyzing these chat messages, we construct a picture of Conti's operations as a highly-profitable business, from profit structures to employee recruitment and roles. We present novel methodologies to trace ransom payments, identifying over $80 million in likely ransom payments to Conti and its predecessor -- over five times as much as in previous public datasets. As part of our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Cybercrime and Law Enforcement Studies · Spam and Phishing Detection
