Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Conti was hiring: the ransomware crew’s entrance exam

Ransomnews Research TeamBy Ransomnews Research TeamSeptember 17, 2026No Comments12 Mins Read13 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Ransomnews cover: Conti was hiring, showing the group's affiliate entrance exam questions in a terminal panel
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

In May 2025 Germany’s federal police named Vitaly Nikolaevich Kovalev, a Russian born in 1988, as “Stern,” the man they say founded the Trickbot group and stood over the Conti and Ryuk ransomware operations. Kovalev does not appear in the crime-forum archives we hold, and neither does the handle “Stern.” The operation he is accused of running does. This is Conti’s recruitment desk, as it worked in private messages on the RAMP forum between November 2021 and May 2022.

What we found, and what we did not

We keep offline copies of the private-message databases of five Russian-language crime forums, RAMP among them. RAMP is the board that filled the gap after the older forums banned ransomware advertising in 2021, so it is where the ransomware crews went to hire. We searched all five archives for Kovalev, for “Stern,” and for “Trickbot.” None of them is there. We say that plainly, because on this subject the honest result is more useful than a forced one, and because we got the reverse test wrong once before and would rather show the working.

What the RAMP archive does hold is 41 private conversations run by a single account that recruited for Conti. It is a hiring desk: an advert, a standard set of questions, a queue of applicants, and a date on which it closed. A handle is not a person, so we treat this account as one that recruited under the Conti name rather than as anyone in particular. Its questions line up closely with Conti’s documented methods, which is the main reason we are satisfied it was the real recruitment channel and not someone trading on the brand.

Who is Vitaly Kovalev, and who is “Stern”?

Kovalev is the person German investigators place at the top of one of the most productive ransomware operations of the past decade. The BKA’s Interpol notice describes him as the founder of the Trickbot group, also tracked as Wizard Spider, and says he controlled both the Ryuk and the Conti ransomware gangs, with members seeking his approval before they acted. The United States and the United Kingdom had already sanctioned him in February 2023, alongside six other Trickbot members, and the US Secret Service lists him as wanted for bank fraud committed between 2009 and 2010, under the aliases “Bentley,” “Bergen” and “Alex Konor.”

The tie between the “Stern” handle and Kovalev is Germany’s, and it is recent. The 2023 US action named him under “Bentley” and “Ben,” and for years analysts were not sure whether Bentley and Stern were even the same man. What matters for this article is the shape the German case gives the organisation. The BKA calls it a group that “works in an organized and hierarchically structured manner and is project and profit-oriented.” That is the top of the business. The RAMP messages are the floor of it.

How Conti recruited on RAMP

One account, which we will refer to by its forum handle, ran 41 private conversations with 37 different RAMP members between November 2021 and the spring of 2022. The thread titles read like a careers inbox: “pentest,” “pentest work,” “affiliate program,” “I am interested in a partnership,” “Conti affiliate,” and, flatly, “corporation.” One advertised the terms on the tin: “Conti’s Elite Team Looking For Pentesters & Accesses 80/20.” The recruiter worked both directions. Applicants came to it, and it went out to access brokers who had posted on the board, opening with a line we saw more than once: “This is the Conti team. We saw your recent post. We would like to talk about possible cooperation.”

Replies from the Conti recruiter, by month 17 Nov 2021 13 Dec 2021 3 Jan 2022 0 Feb 2022 2 Mar 2022 7 Apr 2022 3 May 2022 45 replies from the recruiter account (RAMP user 114), Nov 2021 to May 2022. Source: RAMP private-message archive.

It was a narrow channel, not a mass call. Of the 567 RAMP members who ever sent a private message in our copy of the database, 37 reached this desk, and ten of those were sent the full written test. The rest were turned away, told to make contact on an encrypted messenger, or simply never answered.

How narrow the Conti hiring desk was on RAMP RAMP members who sent private messages the whole board 567 Messaged the Conti recruiter inbound applicants and outbound approaches 37 Were sent the written entrance exam the shortlist 10 Distinct handles, Nov 2021 to Mar 2023. Handle matches only. Source: RAMP PM archive.

The entrance exam

At the centre of the operation was a written technical test. When an applicant asked to join, the recruiter answered with a templated note and a numbered questionnaire. The note read: “Good afternoon, and many thanks for your interest in Conti. Apologies for the long wait; because of the volume of candidates, we wanted to gather the applications and reply to everyone at once.” Then the questions. Translated from the Russian, they were:

CONTI // AFFILIATE ENTRANCE EXAM
  1. You have a shell or RDP session. What are your first five commands?
  2. Describe, step by step, how you establish persistence on a network. Cover each method in order, privilege escalation, ways to evade virtualization and antivirus, ways to delete backups, and ways to copy the data out.
  3. You need to dump the hashes from Active Directory, but you are an ordinary user with low privileges. Describe the escalation, step by step.
  4. Describe in detail how you obtain access to, and the addresses of, ESXi hosts.
  5. You need to find out whether an EDR is present on the network. What do you do, and how do you work out which EDR it is?
  6. The network runs Cylance, SentinelOne, CrowdStrike and Carbon Black. Set out how you would get past each one.
  7. You need to run a Kerberos script through Cobalt Strike. Write out the sequence of steps.
  8. How would you use the domain-controller flaws Zerologon or PetitPotam to escalate privileges?

None of that is generic. It names the specific endpoint products a real intrusion has to defeat, Cylance, SentinelOne, CrowdStrike and Carbon Black. It names the two domain-controller exploits, Zerologon and PetitPotam, that Conti’s own leaked playbooks leaned on. It assumes Cobalt Strike, it assumes VMware ESXi as a target for mass encryption, and it puts the two operational priorities of a ransomware attack, deleting the backups and stealing the data before you encrypt, into the marking scheme. This is the syllabus of the Conti attacker manuals that leaked in 2021, turned into an exam. It is why we read the account as a genuine Conti channel rather than a copycat.

The applicants talked like jobseekers with a history. One introduced himself by writing, “Previously worked with Conti and LockBit. Left Conti over a disagreement on political views,” a reference to the pro-Russia declaration that split the group in early 2022. Others led with a curriculum vitae of access: years in business email compromise, accesses “of various geos” ready to sort, corporate networks already in hand.

Free tool

How does your own site score?

Run the same forty passive checks against your own domain: TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

When the desk closed

The recruiter’s own replies thin out through the first half of 2022, from seventeen in November 2021 to a handful by the spring. The backdrop is familiar. Conti pledged support for the Russian government in late February 2022, and within days an insider leaked around 160,000 of its internal chat messages and its source code. In April it attacked the government of Costa Rica and drew a ten-million-dollar US bounty. By late May the Conti brand was being wound down and its infrastructure taken offline.

You can watch that happen on the desk. On 7 May 2022 a member asked whether the Elite Team was still taking people on. On 23 May the answer came back: “Sorry, we are closed.” It was the same two-word reply the account gave twice that month, and then it stopped answering at all. The applications did not stop. Members were still opening threads titled “Conti,” “corporation” and “Conti’s Elite Team Looking For Pentesters” as late as March 2023, knocking on a desk that had shut ten months earlier and getting no reply.

What the hiring desk tells us about Conti

The BKA’s phrase, “organized, hierarchically structured, project and profit-oriented,” is a description of a chain of command when you read it from the top. Read from the bottom, in these messages, it is a description of a company. There is a standing recruiter, a job advert with a revenue split, a written skills test with a marking scheme, and a backlog of candidates answered in batches because there were too many to handle one at a time. The section of the old forums that used to sell shells and accesses had become an initial access market, and Conti hired out of it the way a firm takes on contractors.

That is the part worth holding onto. The ransomware-as-a-service model is usually described in terms of malware and payment splits. The recruitment side is just as industrial. Kovalev, if the German attribution holds, was the chief executive of the firm. The people sitting this exam were applying for a job in it, and were being marked on whether they could break into your network and delete your backups before you noticed.

Method, and what we are not publishing

The source is an offline copy of the RAMP forum’s private-message database, split into one file per author and decoded from the original dump. The figures come straight from it: 41 conversations, 37 counterparties, ten questionnaires sent, 45 messages from the recruiter account between 15 November 2021 and 23 May 2022. We publish the recruiter’s questionnaire because it is a recruitment document, and we describe the account as a Conti hiring identity because that is how it presented itself. We are not publishing the handles of the applicants, who have not been charged with anything, nor the Tox and Jabber contact identifiers that appear in the threads, nor anything from the forum’s member tables.

We also checked, and then set aside, a coincidence that would have made a better headline than it deserves. The 2009-era carding forum Verified, whose database we also hold, contains an account under the handle “bentley,” one of Kovalev’s documented aliases, active in the same years as his charged bank fraud. A shared handle on a common word is not evidence, we have no way to tie the two together, and we are not going to dress it up as though we could. As with our Exploit.in and Verified archive work, a handle match shows a channel, not a person.

Frequently asked questions

Who is Vitaly Kovalev?

Vitaly Nikolaevich Kovalev is a Russian national, born in 1988, whom Germany’s federal police identified in May 2025 as “Stern,” the founder of the Trickbot group and the figure at the top of the Conti and Ryuk ransomware operations. The United States and United Kingdom sanctioned him in February 2023, and the US Secret Service lists him as wanted for bank fraud committed in 2009 and 2010.

Is Kovalev named in these forum archives?

No. We searched five crime-forum private-message archives for Kovalev, for “Stern” and for “Trickbot,” and none appears. The material described here is a Conti recruitment account on the RAMP forum, which is a channel operated under the Conti name, not a named individual.

What was in Conti’s recruitment test?

An eight-question written exam sent to applicants. It covered first actions on a compromised host, network persistence, privilege escalation, dumping Active Directory hashes, reaching VMware ESXi hosts, identifying and bypassing named EDR products such as CrowdStrike and SentinelOne, running Kerberos attacks through Cobalt Strike, and using the Zerologon and PetitPotam domain-controller exploits.

How do you know it was really Conti and not an impostor?

The questionnaire matches the Conti attacker playbooks that leaked in 2021, down to the specific exploits, tooling and defensive products. That alignment, and the account’s consistent use of the Conti brand across 41 conversations, is why we read it as a genuine recruitment channel. It remains a handle-based judgement, not proof of identity.

When did the recruitment stop?

The account’s replies fell away through early 2022 and ended in May 2022, as the Conti brand was wound down after the February 2022 chat leaks and the attack on Costa Rica. Its last recorded reply, on 23 May 2022, was “Sorry, we are closed.” Applicants kept opening Conti recruitment threads until March 2023 without response.

What does this reveal about how ransomware groups operate?

That the recruitment side is as industrial as the malware. Conti ran a standing hiring desk with a job advert, a revenue split, a written skills test and a backlog of applicants answered in batches. It hired penetration testers and access brokers out of the forum economy much as a company takes on contractors.

Sources and further reading

  • United States Secret Service, Most Wanted: Vitaly Nikolayevich Kovalev, listing his aliases and the 2009 to 2010 bank-fraud charges.
  • BleepingComputer, “Germany doxxes Conti ransomware and TrickBot ring leader”, on the BKA’s May 2025 identification of “Stern” as Kovalev.
  • CoinDesk, “Russian Cybercrime Gang Trickbot Sanctioned by US, UK”, February 2023.
  • Related reading on Ransomnews: the threat-group catalogue, our Exploit.in and Verified forum-archive analyses, and the live ransomware victim feed.
  • Figures are computed from an offline copy of the RAMP forum private-message database. The recruitment account’s questionnaire is quoted from that copy and translated from the Russian.

This analysis is part of the Ransomnews cybercrime desk’s work on the underground economy. Handle matches are stated as handle matches. No applicant to this recruitment account is identified, and no individual is named beyond the aliases already published by law enforcement.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleExploit.in: inside a Russian hacker forum, 2005 to 2008
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Exploit.in: inside a Russian hacker forum, 2005 to 2008

September 17, 2026

Telegram 120M leak: we counted 63M, most from 2020

September 8, 2026

Condé Nast: 32.8M user records for sale, sample verified

September 7, 2026

Comments are closed.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,600 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.