By Raphael Satter
WASHINGTON (Reuters) – A week after the notorious Russia-based extortionist gang Conti was humbled when reams of data on its internal chats were published online, a second group – Trickbot – appears to have been hit by a leak as well.
Detailed information purportedly about this second ransomware gang has appeared online, experts said late on Thursday, more evidence that groups with alleged Russian ties have been targeted for exposure in recent days.
Identifying details of purported gang members spread by a Twitter account calling itself “TrickbotLeaks” began percolating across the web on Thursday.
The account was suspended and Reuters could not immediately verify the authenticity of the information, but experts said the details being published aligned with their understanding of the group.
“It overlaps – largely overlaps – with our research,” said Vitali Kremez, the chief executive of Florida-based cybersecurity firm AdvIntel.
Kremez, who says he is in touch with a Ukrainian researcher alleged to be responsible for the earlier leak of Conti correspondence, said the drumbeat of disclosures appeared to have been in one way or another triggered by the Russian invasion of Ukraine.
“All the gloves are off” in the Russian cybercriminal sphere, Kremez said.
(Reporting by Raphael Satter; Editing by Howard Goller)