Visualizing Conti: Revealing the Business of Ransomware-as-a-Service through New Analytical Techniques episode artwork

EPISODE · Jun 1, 2025 · 27 MIN

Visualizing Conti: Revealing the Business of Ransomware-as-a-Service through New Analytical Techniques

from Cybercrimeology · host Estelle Ruellan

In this episode:How Estelle became involved in ransomware research between degreesThe scale and origin of the ContiLeaks datasetUsing machine learning and topic modelling to analyse criminal group communicationsWhat the internal chat data revealed about the organizational structure of ContiSurprising insights about roles, specializations, and tasking within a criminal enterpriseWhy making cybercrime research accessible through data visualization mattersAbout our guest:Estelle Ruellanhttps://www.linkedin.com/in/estelle-ruellan/Papers or resources mentioned in this episode:Ruellan, E., Paquet-Clouston, M., & Garcia, S. (2024).Conti Inc.: understanding the internal discussions of a large ransomware-as-a-service operator with machine learning. Crime Science, 13, 16. https://doi.org/10.1186/s40163-024-00212-yFlare Data Explorer – Explore cybercrime datasets visually:https://flare.io/flare-data-explorer/Other:Wikipedia – Conti (ransomware): https://en.wikipedia.org/wiki/Conti_(ransomware)Wikipedia – Topic model: https://en.wikipedia.org/wiki/Topic_model

What can leaked internal messages from a ransomware group reveal about how cybercrime operations really work? In this episode, Estelle Ruellan discusses the analysis of the tens of thousands of chat messages leaked from the Conti ransomware group she created with colleagues. They to mapped the internal roles and communication patterns of this group using natural language processing and Latent Dirichlet Allocation analysis to better understand this notorious ransomware-as-a-service outfits. We explore this interesting analysis method, what it uncovered, and howMs Ruellan’s quest to make cybercrime more understandable with data visualization.

NOW PLAYING

Visualizing Conti: Revealing the Business of Ransomware-as-a-Service through New Analytical Techniques

0:00 27:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Cybercrimeology?

This episode is 27 minutes long.

When was this Cybercrimeology episode published?

This episode was published on June 1, 2025.

What is this episode about?

In this episode:How Estelle became involved in ransomware research between degreesThe scale and origin of the ContiLeaks datasetUsing machine learning and topic modelling to analyse criminal group communicationsWhat the internal chat data revealed...

Can I download this Cybercrimeology episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!