The Rise and Fall of the Trickbot and Conti Empires

Alex Holden

BSides NYC 2023 (0x04) · Day 1 · Talk - Other

Overview

In a captivating presentation at BSides NYC, Alex Holden, CEO of Hold Security, unveiled the intricate, often turbulent, history of two of the most notorious cybercriminal organizations of the past decade: Trickbot and Conti. This talk provided an unprecedented look behind the curtain of these ransomware empires, detailing their evolution from initial infection vectors to multi-million dollar operations, their internal power struggles, and their eventual, dramatic collapse. Leveraging years of deep-seated threat intelligence, including unique access to their internal communications and infrastructure, Holden offered a rare glimpse into the minds and methodologies of the adversaries.

Watch on YouTube

Visual summary for The Rise and Fall of the Trickbot and Conti Empires by Alex Holden
Visual summary for The Rise and Fall of the Trickbot and Conti Empires by Alex Holden

Key moments

  1. 0:00 Introduction: Trickbot, Conti, and threat intelligence
  2. 2:15 Understanding Emotet, Trickbot, and Conti's evolution
  3. 4:00 Infiltrating the cybercrime gang via social engineering
  4. 5:45 Criminal motivation: Trickbot's high profitability
  5. 6:45 Strategy: Operating inside without committing crimes
  6. 8:00 First encounter: Vigo County Sheriff's Office attack

The Rise and Fall of the Trickbot and Conti Empires

Speakers: Alex Holden, CEO, Hold Security

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=PDgxd3u0bm4

Overview

In a captivating presentation at BSides NYC, Alex Holden, CEO of Hold Security, unveiled the intricate, often turbulent, history of two of the most notorious cybercriminal organizations of the past decade: Trickbot and Conti. This talk provided an unprecedented look behind the curtain of these ransomware empires, detailing their evolution from initial infection vectors to multi-million dollar operations, their internal power struggles, and their eventual, dramatic collapse. Leveraging years of deep-seated threat intelligence, including unique access to their internal communications and infrastructure, Holden offered a rare glimpse into the minds and methodologies of the adversaries.

The presentation underscored the critical role of human intelligence and social engineering in penetrating seemingly impenetrable criminal networks. Holden's team not only observed but actively influenced the operations of these gangs, shedding light on their technical prowess, their surprising vulnerabilities, and the profound impact of geopolitical events like the war in Ukraine. This narrative is not merely a recounting of past events but a vital case study for understanding the dynamic nature of cybercrime and the innovative approaches required to combat it effectively.

The insights shared by Holden are invaluable for security professionals, law enforcement, and policymakers striving to comprehend, prevent, and respond to sophisticated cyber threats. By meticulously detailing the strategies employed to infiltrate and dismantle these groups, the talk offers actionable intelligence and a renewed appreciation for the complex interplay of technology, human psychology, and global events in the ongoing fight against cybercrime.

Background

▶ Watch: Introduction: Trickbot, Conti, and threat intelligence (0:00)

The narrative of Trickbot and Conti is one of evolution, consolidation, and adaptation within the cybercriminal underworld. It began with Emotet, primarily a delivery mechanism for vast phishing campaigns, sending hundreds of thousands of emails daily to infect victims. This initial foothold was then leveraged by the Trickbot empire, a sophisticated botnet focused on data harvesting and moving infected systems to the next stage of monetization: ransomware. Initially, Ryuk ransomware was the payload of choice. However, as Ryuk became more detectable and less effective, the same underlying criminal group transitioned to Conti, an emerging ransomware-as-a-service (RaaS) operation that eventually merged with Trickbot, forming a single, highly effective, and unfortunately, extremely profitable entity.

Hold Security's approach to understanding and countering these threats goes beyond traditional technical analysis. As articulated by Holden, effective threat intelligence is not merely about finding technical signals but deeply rooted in social engineering. It involves infiltrating the human networks of cybercriminals, understanding their motivations, observing their mistakes, and leveraging artificial intelligence models to detect and prevent crimes before human awareness. This methodology allowed Hold Security to gain unparalleled access, starting from the ground level of observing low-level credit card fraud operations and identifying shifts in criminal enterprises.

The initial infiltration was serendipitous, beginning with the observation that some credit card fraudsters were abandoning their profitable businesses between 2017 and 2018. Investigation revealed that these individuals were being recruited by Emotet and Trickbot, which offered significantly higher profits, sometimes $100,000 overnight from a single ransomware attack. Hold Security analysts, skilled in social engineering, managed to gain introductions into the Trickbot gang. The strategy for maintaining access without committing crimes was simple yet ingenious: "talk big but do nothing." By feigning busyness with other "bad things" or claiming infrastructure takedowns by law enforcement, they avoided active participation while gathering critical intelligence. This allowed them to operate in an observer role, building trust and connections that would prove instrumental in their long-term monitoring of the group. An early encounter involved the Vigo County Sheriff's Office in Indiana, which was infected by Trickbot in May 2019. Despite Hold Security's repeated warnings to the sheriff's office and through third parties, the warnings were ignored, and two months later, the office paid the ransom, highlighting the challenges of proactive defense even with advanced intelligence.

Key Findings

▶ Watch: Infiltrating the cybercrime gang via social engineering (4:00)

Holden's presentation revealed several pivotal findings about the operational tactics, vulnerabilities, and eventual downfall of the Trickbot and Conti empires:

Unconventional Infiltration Techniques:

The most striking example of infiltration involved a cybercriminal who, in a bizarre act, granted his girlfriend access to Trickbot infrastructure to purchase personal items with stolen funds. This individual, lacking any understanding of Operational Security (OpSec), frequently asked questions, shared screenshots of internal systems, and eventually provided login credentials to her virtual machine to Hold Security's personas. This access, initially used for trivial purchases like car squeegees and toenail fungus remedies, became a crucial early-stage access point, providing lists of abused devices and insights into the gang's financial operations.

This led to an even more significant breakthrough: the girlfriend was introduced to the gang's Jabber server, their primary communication platform. The Jabber administrator, in an astonishing display of poor OpSec, visually guided her through the login process, revealing incredibly simple passwords like "cat" and "password1." This blunder granted Hold Security admin rights to the Jabber server, providing them with "most if not all communications" from 2019 until the final days of the Conti gang.

The "Conti Leaks" – A Proactive Intelligence Advantage:

While the public became aware of the Conti Leaks around February 27, 2022, Hold Security had unique access to this data as an "exclusive product" streaming daily through the Jabber servers. This allowed them to read communications in real-time, anticipate attacks, and even influence outcomes. Holden noted that many planned attacks discussed in the chats "didn't pan out" due to their proactive work. This real-time intelligence enabled them to "manipulate the bad guys into disclosing more information" by having an inside track.

Sophisticated Operations and the "Crime of Honor":

The gangs demonstrated high levels of operational sophistication. Emotet managed complex phishing campaigns with daily statistics, adapting email templates and payloads based on infection and click rates. Ransomware negotiations initially relied on over 10,000 unique ProtonMail accounts, managed by just two dedicated cybercriminals using scripts.

A fascinating cultural insight was the concept of a "crime of honor" among Russian cybercriminals. They maintained brutal honesty with their victims, whom they called "customers." If a victim paid, they would always receive their decryption keys and would not be extorted again. This adherence to promises, even in a criminal context, was crucial for their business model, as it built trust that encouraged victims to pay. This principle was so deeply ingrained that a Ryuk boss deemed a bug preventing the decryption of very large files (over 1TB) as "bad news" because it broke their "promise to decrypt," leading to a prompt software fix.

US Cyber Command and Microsoft Interventions (2020):

In late August 2020, U.S. Cyber Command launched its first public offensive operation against Trickbot, polluting its panels with over 2.7 million false entries from various subnets. Simultaneously, Microsoft initiated legal takedowns of Trickbot's Command and Control (C2) infrastructure globally. However, these actions only "wounded the beast." Within hours, angry Trickbot operators (Stern, Mango) partnered with a Russian data broker named "aggressor" to load Trickbot agents onto over 100,000 devices in a matter of days. The full ransomware operation resumed within two weeks.

Retaliation and Hospital Attacks (October 2020):

Angered by the takedowns, Trickbot operators, as observed on October 26, 2020, boasted access to 428 U.S. hospitals, medical systems, and clinics, explicitly targeting these as retaliation. Through a collective effort with organizations like Mandiant and law enforcement, Hold Security believes they prevented over half of these intended attacks, though some major hospitals were unfortunately impacted during the COVID-19 pandemic.

Emotet Takedown and Internal Intrigue (January 2021):

Law enforcement efforts led to the takedown of Emotet in January 2021. A critical piece of evidence was found on one of their servers: a src.tar.gz file containing extensive infrastructure details, accidentally left by an operator named Dima. This leak led to Dima being abandoned by his superiors. This period also saw the rise of "Taker," a highly paranoid but technically skilled hacker who, after being fed paranoia by Hold Security, proved his capabilities by hacking Emotet servers himself. Stern, the Trickbot leader, capitalized on this internal struggle, placing Taker in charge of Emotet's infrastructure and pushing out the former leader.

The Case of Alavita/Max – A Developer's Downfall:

A C++ developer, identified as Alavita (using the alias Max), was recruited by Trickbot in 2019 via a legitimate job site, earning only $1,500 per month. Her complete lack of OpSec was her undoing: she used her real name initially, constantly revealed her gender and location through her writing style, and most crucially, infected herself with a Trickbot agent on Christmas Eve 2019. She even used her personal development domain (.nl) to deliver Trickbot payloads. Arrested in Florida in February 2021, her case highlighted the exploitation of even legitimate developers. Despite her importance to the gang (developing code for ransomware like Enigma, a planned Ryuk successor), Trickbot leaders abandoned her when legal fees for her defense reached $120,000, even after initially exposing their own family members' addresses while trying to find lawyers.

Conti's Pre-War Expansion and Collapse:

In 2021, Conti underwent a massive expansion, operating with two physical offices in Moscow, spending 2 billion rubles ($25 million USD) between April and August on infrastructure, and attempting to hire over 200 developers and pen testers. They even tried to buy a major Russian dark web forum for $10 million, believing themselves "completely above the law."

However, this ambition was short-lived. Weeks before the February 2022 war in Ukraine and the public Conti Leaks, many Trickbot and Emotet actors publicly quit, sensing that operations were "getting too hot." When Russia invaded Ukraine, Conti controversially issued a statement supporting the Russian government. This decision was met with internal dissent, as many members "absolutely hated Russia." A "brave Ukrainian" cyber security researcher, motivated by the war, then disclosed years of internal Jabber chatter and source code, creating the devastating Conti Leaks. This act, seen as a "cyber weapon," exposed identities, internal conflicts, and operational details, dealing a "deadly blow" from which the gang never recovered. While Conti continued for several months under new branding, their criminal activity significantly diminished, and members eventually migrated to other groups like BlackCat/ALPHAV.

Technical Deep Dive

▶ Watch: Criminal motivation: Trickbot's high profitability (5:45)

The operational complexity of the Trickbot and Conti empires was built on a foundation of interconnected components, each meticulously managed to maximize illicit gains. The initial infection vector, Emotet, was a masterclass in persistent phishing. Its operators maintained sophisticated management panels that tracked daily email campaigns, monitoring infection rates and click rates. If these metrics dropped, they would rapidly adapt, changing email templates and modifying payloads to bypass detection. This agile approach underscored their commitment to maintaining a broad initial attack surface.

Once a system was infected, Trickbot acted as a versatile botnet and data harvester. It was designed to exfiltrate sensitive information, including credentials, financial data, and system configurations, which would then be leveraged for further attacks. The choice of ransomware payload evolved over time. Initially, Ryuk ransomware was deployed, but its increasing detectability led to a pivot to Conti. The transition wasn't merely a rebranding; it involved significant development efforts. Alavita, the ill-fated developer, worked on Enigma, a planned successor to Ryuk, highlighting the continuous software development cycle within these criminal enterprises. The leakage of Enigma's source code, however, prevented its widespread adoption and pushed the gang fully towards Conti.

Conti's operations themselves were highly structured. For ransomware negotiations, the gang initially relied on a vast network of over 10,000 unique ProtonMail accounts. These were not manually managed; scripts were employed to aggregate incoming messages, with a dedicated team of just two cybercriminals responsible for monitoring and responding. Each ransomware incident was assigned a unique negotiation account (e.g., T2-245), demonstrating an attempt at systematic management, even if the sheer volume often overwhelmed their capacity. Later, the gang developed specialized ransomware negotiation panels, streamlining the interaction with victims.

The internal communications backbone for both Trickbot and Conti was a Jabber server. This platform facilitated real-time discussions among gang members, coordination of attacks, and sharing of intelligence. The critical vulnerability here was the appalling OpSec of the administrators, who, as detailed by Holden, used laughably simple passwords like "cat" and "password1." This lapse allowed Hold Security to gain deep, sustained access to their internal chatter, providing invaluable insights into their plans, frustrations, and methodologies. Beyond Jabber, the gangs also extensively used Cobalt Strike servers for lateral movement within compromised corporate networks, a common tool for post-exploitation activities in both legitimate penetration testing and malicious operations.

The technical infrastructure also faced direct attacks. U.S. Cyber Command launched an offensive that polluted Trickbot's data panels with 2.7 million false entries, disrupting their intelligence gathering. Microsoft simultaneously targeted C2 components with legal takedowns, aiming to cripple their operational infrastructure. While these actions caused temporary disruption, the gangs demonstrated resilience, quickly shifting to new infrastructure and leveraging external data brokers like "aggressor" to rebuild their botnet capabilities, sometimes infecting over 100,000 devices in days. The accidental leak of src.tar.gz files on Emotet servers by an operator named Dima further exposed their internal workings, providing law enforcement with critical intelligence about their infrastructure.

Ultimately, the technical deep dive reveals a paradox: while these groups operated with sophisticated tools and a highly structured approach to crime, their human element often introduced critical vulnerabilities through poor OpSec, internal conflicts, and an underestimation of their adversaries' capabilities.

Demo / Proof of Concept

▶ Watch: Strategy: Operating inside without committing crimes (6:45)

While Alex Holden's talk did not feature a live, interactive demo or a dedicated proof-of-concept demonstration of a specific exploit, he presented compelling visual evidence directly from the cybercriminal operations. This included numerous screenshots of the gangs' internal management panels, such as Trickbot's botnet control interface showing lists of infected devices and their details. He also displayed authentic chat logs from the Jabber server, illustrating actual conversations between gang members, including the negotiation instructions and the "crime of honor" discussion regarding the Ryuk bug. These visual aids served as powerful corroboration of Hold Security's deep access and extensive intelligence gathering, effectively demonstrating the inner workings of these groups without needing a live technical execution.

Defensive Implications

▶ Watch: First encounter: Vigo County Sheriff's Office attack (8:00)

The insights gleaned from the rise and fall of the Trickbot and Conti empires offer profound defensive implications for organizations and law enforcement alike.

  1. Prioritize Human-Centric Threat Intelligence: The core lesson is the indispensable value of human intelligence (HUMINT) and social engineering in cybersecurity. Relying solely on technical signals is insufficient. Defenders must cultivate capabilities to understand adversary motivations, internal dynamics, and communication channels. This means investing in analysts with strong social engineering skills and supporting research that penetrates the human layer of cybercrime.
  1. Bolster Operational Security (OpSec) Practices: The downfall of these gangs was frequently precipitated by their own abysmal OpSec. While this directly benefits intelligence gatherers, it also serves as a stark reminder for legitimate organizations. Every employee, from executives to junior staff, must adhere to stringent OpSec protocols, including strong, unique passwords, multi-factor authentication, and vigilance against phishing. The Alavita case highlights that even skilled developers can be caught due to simple OpSec failures, emphasizing the need for continuous training and awareness.
  1. Enhance Collaboration Between Public and Private Sectors: The successful prevention of many hospital attacks and the eventual takedown of Emotet were direct results of unprecedented collaboration between Hold Security, Mandiant, U.S. Secret Service, FBI, and other international law enforcement agencies. This multi-stakeholder approach, combining private sector intelligence with public sector authority, is crucial for disrupting large-scale cybercriminal operations. Organizations should actively participate in information-sharing initiatives and establish clear communication channels with law enforcement.
  1. Proactive Monitoring and Early Warning Systems: Hold Security's ability to monitor Trickbot panels and Jabber chats in real-time allowed for proactive intervention. Defenders need robust monitoring solutions that can detect anomalous network activity, indicators of compromise (IOCs), and unusual data exfiltration attempts. Understanding adversary Tactics, Techniques, and Procedures (TTPs) from intelligence sources enables the creation of more effective detection rules and alerts.
  1. Understand Adversary Psychology and Business Models: The "crime of honor" concept among Russian ransomware gangs provides critical insight into their operational integrity. While not condoning their actions, understanding their perceived "honesty" can inform negotiation strategies for victims. Knowing their "breaking points" and how they value their reputation for delivering decryption keys can be leveraged. However, legal complexities, such as accessing compromised ProtonMail accounts, remain a significant challenge.
  1. Be Prepared for Retaliation and Adaptability: The immediate and aggressive retaliation by Trickbot against U.S. hospitals after government takedowns underscores that offensive actions against cybercriminals can provoke a backlash. Defenders must anticipate and prepare for heightened attack volumes and targeted campaigns following major disruptions or geopolitical events. Adversaries are highly adaptable, quickly re-tooling, re-branding, and rebuilding infrastructure, necessitating continuous vigilance and flexible defensive strategies.
  1. Scrutinize Supply Chains and Recruitment: The recruitment of Alavita via a legitimate job site highlights a potential vulnerability in the hiring process. Organizations must conduct thorough background checks and implement robust security awareness programs, recognizing that insider threats, whether intentional or unwitting, can originate from seemingly innocuous sources.

In essence, defending against sophisticated ransomware groups requires a holistic strategy that integrates cutting-edge technical defenses with deep human intelligence, strong OpSec, and seamless collaboration across the cybersecurity ecosystem.

Key Takeaways

  • Cybercrime Evolves Through Consolidation: The journey from Emotet as a phishing vector to Trickbot as a botnet and Conti as a dominant ransomware operator, culminating in their merger, illustrates a clear trend of criminal organizations consolidating resources and expertise to maximize illicit gains.
  • Human Intelligence is Paramount: The talk emphasized that deep infiltration into cybercriminal groups relies heavily on social engineering and human intelligence gathering, providing insights that technical analysis alone cannot. This included exploiting poor OpSec and building trust with adversaries.
  • The "Crime of Honor" Drives Ransomware Success: Russian ransomware gangs, particularly Conti, operated on a strict code of conduct, promising and delivering decryption keys upon payment. This "brutal honesty" with victims (their "customers") was a core business principle that fostered trust and encouraged ransom payments.
  • Government Actions Can Have Unintended Consequences: While U.S. Cyber Command and Microsoft's offensive operations against Trickbot were significant, they initially only wounded the "beast," leading to a period of increased anger, rapid re-tooling, and retaliatory attacks, notably targeting over 400 U.S. hospitals.
  • Geopolitical Events and Insider Leaks Are Catalysts for Collapse: The war in Ukraine and the subsequent Conti Leaks, initiated by a "brave Ukrainian" researcher, were the decisive factors in the empire's downfall. This unprecedented disclosure of internal communications and source code, coupled with internal dissent over geopolitical stances, proved to be a "deadly blow" from which the gang never recovered.
  • Poor Operational Security (OpSec) Remains a Critical Vulnerability: Despite their technical sophistication, the downfall of many individuals within these gangs, and the groups themselves, was repeatedly linked to fundamental OpSec failures, such as using simple passwords, sharing sensitive information, and accidental self-infection.

About the Speaker(s)

Alex Holden is the CEO of Hold Security, a prominent cybersecurity firm specializing in threat intelligence and cybercrime investigations. With years of experience operating in the murky depths of the dark web, Holden and his team have gained unparalleled access to the inner workings of some of the most notorious cybercriminal organizations. His expertise lies in leveraging sophisticated social engineering techniques and deep analytical skills to infiltrate and monitor these groups, providing unique, real-time insights into their operations, motivations, and vulnerabilities. Holden is a leading voice in the cybersecurity community, known for his ability to bridge the gap between technical threat intelligence and actionable defensive strategies.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Holden is presenting primary-source intelligence on Trickbot/Conti that most researchers only read about secondhand — admin rights to the Jabber server, real-time Conti Leaks access before the public drop, and granular operational detail on the hospital retaliation campaign. This is a threat intel briefing judged on the quality of the operator perspective and the data behind the claims, and on both counts it delivers.

Heather Calloway (CISO) — SOLID

A genuinely rare intelligence window into how Trickbot and Conti operated, with compelling sourcing and real narrative payoff. But this is a war story, not a governance brief — the defensive implications are generic, and the talk doesn't tell a CISO or board what structurally changes because of what Holden knows.

→ Top-rated talks at BSides NYC 2023 (0x04)

All talks from BSides NYC 2023 (0x04)