Skip to content

Conti

Conti is a prolific ransomware family and cybercrime operation that became one of the dominant ransomware threats of the early 2020s.

Profile source: Mallory opens in a new tab

Conti

Family profile

Conti is a prolific ransomware family and cybercrime operation that became one of the dominant ransomware threats of the early 2020s. It is primarily associated with Windows environments and is known for fast, multithreaded file encryption designed to disrupt enterprise networks at scale. Conti operators and affiliates commonly conducted full-network intrusions rather than opportunistic single-host attacks, with activity linked to broader criminal ecosystems that also overlapped with TrickBot and, historically, personnel associated with Ryuk. After Ryuk activity declined, many members transitioned into the Conti operation, helping it rapidly expand.

Conti was operated as a structured, enterprise-like ransomware program with documented procedures, training materials, internal management, and repeatable attack playbooks. Public leaks exposed the group’s internal organization, manuals, and source code, including Conti v2, which later influenced other ransomware actors and derivative families. Multiple later ransomware operations were reported to have built lockers or platforms from leaked Conti code.

The malware’s core purpose is file encryption for extortion, and the broader operation was associated with double-extortion tactics in which victims could face both encryption and pressure tied to stolen data. Conti became widely recognized not only for its technical impact but also for the scale and professionalism of its criminal organization. The group ultimately fragmented after major internal leaks in 2021 and 2022, with members and code lineage dispersing into successor and splinter ransomware operations.

Capabilities

  • Extortion

Operational record

1
YARA rules
4
Ransom notes
32
Negotiations
3
Leak sites
0 available

Credential Theft

  • Mimikatz
  • ProcDump
  • Router Scan
  • SharpChrome

Defense Evasion

  • GMER
  • PCHunter

Discovery Enum

  • AdFind
  • Bloodhound
  • PowerView
  • Seatbelt
  • ShareFinder
  • SharpView
  • SoftPerfect NetScan

Exfiltration

  • Dropfiles
  • MEGA
  • Qaz[.]im
  • RClone
  • Sendspace
  • WinSCP

LOLBAS

  • BITSAdmin
  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC

Offsec

  • Cobalt Strike
  • Metasploit
  • Meterpreter
  • PowerShell Empire
  • PowerSploit
  • Rubeus

RMM Tools

  • AnyDesk
  • Atera
  • Splashtop

Reported operators

Threat actors

21 named in public reporting
Devman

Devman, a ransomware operator believed to be based in Russia and utilizing code derived from the leaked Conti source.

DragonForce

The sample analyzed in this report was identified as DragonForce ransomware developed based on Conti ransomware.

Conti

A longtime former member of Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, pleaded guilty ... The defendant and his conspirators used the Conti ransomware to terrorize people and businesses in the United States and around the world, causing millions of dollars in damage.

Silent Ransom Group

Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.

SRG

Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.

WIZARD SPIDER

The crypto-locking malware first emerged around the middle of 2018 and seemed to have its heyday largely in 2019, before rebranding as Conti around May 2020, and appearing to merge with TrickBot - aka Wizard Spider - by the end of 2021.

Karakurt

Emsisoft threat analyst Brett Callow previously told The Record that the group has been active since the middle of 2021 and is believed to be a spin-off of the Conti ransomware group. Several other security companies ... have released reports this year showing concrete ties between the infrastructure used by Conti and Karakurt.

DEV-0230

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

DEV-0506

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

DEV-0216

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

Trickbot

The State Department on Thursday announced a $10 million reward for information related to five specific individuals associated with the Conti ransomware group.

Russian Spider

Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...

NC1878

Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...

Lockean

Looking at the indicators of compromise in the report, Valery Marchive of LegMagIT found several IP addresses related to Conti ransomware, indicating Lockean’s affiliation to additional RaaS operations and targeting of businesses in other regions.

Nitrogen

The group started using stolen code from Conti in 2024 to build its own custom attack tools to hit Windows and VMware server environments.

Tramp

Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.

Bl00Dy

...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.

FIN7

"...FIN7... known to collaborate with the Conti, REvil, Maze, Egregor, and BlackBasta ransomware gangs..."

Stern

Conti was a prolific ransomware strain for a few years... Conti responded by announcing its closure in May, but soon after, much of the Conti team split up into smaller groups and continued their activity.

Scattered Spider

The following analytic detects the execution of suspicious command-line arguments commonly associated with Conti ransomware, specifically targeting local drives and network shares for encryption.

Exploited software

Vulnerabilities linked to Conti

2 CVEs

MITRE ATT&CK

Conti in ATT&CK

60 distinct techniques

Techniques

60 techniques
T1210 Exploitation of Remote Services T1059.001 PowerShell T1562 Impair Defenses T1135 Network Share Discovery T1570 Lateral Tool Transfer T1046 Network Service Discovery T1490 Inhibit System Recovery T1566 Phishing T1078 Valid Accounts T1021 Remote Services T1486 Data Encrypted for Impact T1489 Service Stop T1105 Ingress Tool Transfer T1005 Data from Local System T1083 File and Directory Discovery T1016 System Network Configuration Discovery T1140 Deobfuscate/Decode Files or Information T1588.001 Malware T1567.002 Exfiltration to Cloud Storage T1041 Exfiltration Over C2 Channel T1027 Obfuscated Files or Information T1567 Exfiltration Over Web Service T1537 Transfer Data to Cloud Account T1057 Process Discovery T1059.003 Windows Command Shell T1657 Financial Theft T1565 Data Manipulation T1021.001 Remote Desktop Protocol T1074 Data Staged T1071 Application Layer Protocol T1204.002 Malicious File T1608.006 SEO Poisoning T1189 Drive-by Compromise T1204 User Execution T1566.001 Spearphishing Attachment T1190 Exploit Public-Facing Application T1213 Data from Information Repositories T1018 Remote System Discovery T1222 File and Directory Permissions Modification T1529 System Shutdown/Reboot T1218.010 Regsvr32 T1485 Data Destruction T1055.001 Dynamic-link Library Injection T1021.002 SMB/Windows Admin Shares T1049 System Network Connections Discovery T1106 Native API T1080 Taint Shared Content T1078.002 Valid Accounts: Domain Accounts T1047 Windows Management Instrumentation T1136.002 Create Account: Domain Account T1547.001 Boot or Logon Autostart Execution: Registry Run Keys T1068 Exploitation for Privilege Escalation T1218.011 Signed Binary Proxy Execution: Rundll32 T1562.001 Disable or Modify Tools T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1482 Domain Trust Discovery T1560.001 Archive Collected Data: Archive via Utility T1071.001 Application Layer Protocol: Web Protocols T1219 Remote Access Software

Reporting

Research mentioning Conti

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

Jul 20
Zdnet

Qui sont les pirates russes visés par les nouvelles sanctions eur ...

The European Union imposed sanctions on eight individuals accused of participating in Russian-linked cyberattacks and cybercrime, targeting figures tied to Conti, TrickBot, Wizard Spider, LockBit, EvilCorp, BlackBasta, the Lumma infostealer, and the pro-Russian Cyber Army of Russia Reborn. Those named include alleged Conti leader Vitaly Nikolayevich Kovalev, bulletproof hosting operator Alexander Volosovik, two operators associated with Lumma, two members linked to Cyber Army of Russia Reborn, and two alleged members of GRU Unit 29155. The sanctions were issued amid broader Western attribution of Russian state and criminal cyber activity, including disruptive operations against Ukraine and its supporters and espionage and sabotage campaigns linked to the GRU. UK government reporting has profiled Russian military intelligence cyber and hybrid operations, including activity attributed to Unit 29155, while the EU action also cites links to the WhisperGate campaign and follows French accusations of Russian cyber espionage. The measures underscore continued efforts to publicly identify and financially isolate operators supporting both state-directed and criminal cyber operations.

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.