Technical Appendix for the Preparation of an Indictment
Identification of the Figure “Stanton” as Sergey Khitrov
(correlation analysis, technical activity, geolocation linkage)
I. Summary
During a technical investigation conducted using OSINT methods and correlation analysis, a substantiated connection was established between the Conti group member under the alias Stanton and Russian citizen Sergey Khitrov, born 31.01.1994. This connection is confirmed by:
- Correlation of Khitrov’s flight dates with Stanton’s activity in Conti’s internal communication channels (Rocket-Chat);
- Stanton’s involvement in the technical infrastructure of attacks (crypting, build machines, locker projects);
- Geographical coincidence of Khitrov’s presence (in the UAE) with peaks in group activity;
- The nature of Stanton’s work, typical for individuals with a high level of technical competence and access to Conti’s internal tools.
Confidence level in identification: High Identification method: Multifactor correlation (time, location, behavior, logic of involvement)
II. Technical Profile of Stanton
Functions:
- Stanton acted as a crypter, build machine operator, and technical integrator of malicious builds in Conti group projects.
Stanton’s activities by date (excerpts from internal Conti Jabber reports):
- 31.03.2021: Series of crypts (dll → dll, exe → exe, trick, locke) — total of 50 crypts.
- 25.05.2021: Work on build machine, 1 crypt (dll → exe).
- 01.06.2021 / 15.06.2021: Stanton inactive (physically absent, left UAE for Russia).
Projects involving Stanton:
- Project Zeus: build machine, lockers, shellcode.
- Project Leo: crypts, build machine, teams g5, g10, g11, g12, 25, 40, v01, v03.
- Lockers: often associated with Stanton’s builds.
- Cobalt and shellcode: crypt infrastructure where Stanton is listed as operator.
Interactions:
- Mentions alongside figures Hugo, Sam, Carrol, Nevil, Diego, Dane, indicating his integration into the group’s technical core.
III. Correlation with Sergey Khitrov’s Geodata and Flights
30.03.2021
- Khitrov arrived in Dubai (flight TK-402 from Pulkovo via Istanbul).
- The next day (31.03.2021) — Stanton appears in Conti’s report with 50 crypts (maximum for the period).
- Conclusion: The day after Khitrov’s arrival in the UAE, Stanton shows high activity.
22.05.2021 – 29.05.2021
- Khitrov again arrives in Dubai.
- 25.05.2021 — Stanton crypts on the build machine.
- 01.06.2021 and 15.06.2021 — Stanton “did not crypt” as noted in the report (Khitrov left the UAE).
- Conclusion: Stanton’s activity ceases after Khitrov’s departure.
10.10.2021
- Khitrov arrived in Sharjah, UAE (flight G9-956 from Moscow).
- Activity in Rocket.Chat:
- 06.10.2021 — Stanton posts a series of technical messages (anonymization, PGP, TOR).
- 11.10.2021 — appears in chat with the phrase “Pruvet” (Hi).
- 12.10.2021 — code discussions, questions to colleagues.
- Conclusion: Chat activity precedes Khitrov’s flight, indicating task coordination before the business trip.
February 2022
- Khitrov’s flights during the period: 20, 25, 27 February.
- 25.02.2022 — Stanton active in Rocket.Chat, discussing crypters and finances.
- Conclusion: Direct date match.
IV. Additional Matches
- Stanton mentioned in connection with groups managed by core operators (g5, g10, g19, g25, etc.).
- Use of a build machine assigned to Stanton over a long period, indicating stable access to infrastructure.
- Multiple overlaps in technical terminology between Stanton and Khitrov in chat discussions (anonymization, TOR structures, PGP encryption, DevOps approaches).
V. Conclusion (Based on Technical Data)
Analysis of Stanton’s activity in the Conti infrastructure, combined with data on the movements of citizen S.A. Khitrov, allows us to state:
- Stanton is the alias used by Sergey Khitrov to participate in the technical implementation of Conti cyberattacks.
- Khitrov provided crypting of malicious builds, maintenance of build machines, and support of malicious infrastructure.
- His trips to the UAE coincided with active phases of Conti attacks.
- Coordination with key group member Vladimir Kvitko (Professor) — joint flight to Dubai, UAE on 05.02.2021 (air transport) flight SU-524 from Moscow (Sheremetyevo Terminal D).
Degree of technical linkage proof: High Type of criminal role: Organizational-technical Participation status: Permanent member with access to internal systems and key projects
Appendices
Sample selection of messages from Conti chats mentioning Stanton
| 2021-03-31 19:43:37 | mango | stern | [stanton] 30.03.2021 1, dll->dll, bk, 4 2, exe->exe, bk, 8 3, dll->dll, koba dll, 16 4, exe->exe, locke exe, 8 5, dll->dll, trick dll, 6 6, dll->dll, trick exe, 8 Total: 50 [dane] 30.03.2021 1. dll->dll, rob 32, 2 2. dll->dll, rldr, 1 3. dll->dll, locker 64, 1 4. dll->dll, DF, 2 5. dll->dll, лоадеры/боты Лео 64, 25 6. dll->exe, dl2 64, 1 Total: 32 [elroy, basil] 30.03.2021 cleaning, development Total: 0 [allen] 30.03.2021 1, dll->dll, dll_r0, 1 2, dll->dll, exe_r1, 1 Total: 2 [hugo] 30.03.2021 1, dll->exe, generic(dl2_g5_256), 6 2, dll->exe, generic(rldr.g3.18), 2 3, dll->exe, generic(rldr.10.3), 1 4, exe->exe, generic(locker_64), 1 Total: 10 Total: 94 Crypts for yesterday |



Stylometry Cluster Analysis text samples from Sergey Khitrov's Instagram comments and text samples of the Conti Rocket-chat leaks
