
LEAKED Russian Hackers Internal Chats
Source: YouTube · John Hammond · published Mar 12, 2025 · 24:04
The leaked internal chat logs of the Black Bosta ransomware group expose a highly structured, hierarchical operation with clear roles and infrastructure, offering critical threat intelligence for defenders. 0:34
Key Takeaways:
• Black Bosta operated as a business with defined roles—sales, infrastructure, and negotiations—led by a ring leader known as GG (possibly Oleg Nefedov) 2:57.
• The group used a structured chat system with internal team members identified by usernames (e.g., GG, YY, NN) and affiliates marked by two-letter suffixes (e.g., Lapa, N3) 3:30.
• They relied on legitimate hosting providers via resellers like VPS.co.t to host C2 infrastructure, using bulletproof hosting to avoid takedowns 17:01.
• Chat logs reveal active development and sharing of attack tools, including EDR bypass techniques ("silencer") and Cobalt Strike usage 10:01.
• Their dark web presence is inactive since early 2025, with no new attacks reported, suggesting internal disruption or organizational change 1:18.
The leak provides a rare, detailed view of a ransomware-as-a-service operation, revealing both its organizational sophistication and exploitable vulnerabilities. 23:52
Sources:
- 0:34 Overview of the Black Bosta chat leak (Sept 18, 2023 – Sept 28, 2024).
- 2:57 Organization structure, leadership, and team roles.
- 3:30 Internal team and affiliate identification.
- [17:01](https://www.youtube.com/watch?v=cH7BYWbtsfI&t
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
on February 20th 2025 the cyber security industry and cyber threat intelligence Community received a lovely gift a group of Russian hackers and ransomware operators had their internal chat logs leaked and made public on the open internet this was The Black bosta ransomware Gang one individual another thread actor presumably called exploit Whispers released a file on Telegram and then eventually I think uploaded to Mega or whatever but that included all of the black bosters groups chat messages from September 18th 2023 to September 28th 2024 so about a year of their internal comms apparently this individual exploit Whispers believe that black bosta crossed the line when they targeted Russian Banks and black bosta is a ransomware as a service group they came to life in April 2022 and they ha…