Credential Theft
- Mimikatz
- ProcDump
- Router Scan
- SharpChrome
Conti is a prolific ransomware family and cybercrime operation that became one of the dominant ransomware threats of the early 2020s.
Profile source: Mallory opens in a new tabConti
Conti is a prolific ransomware family and cybercrime operation that became one of the dominant ransomware threats of the early 2020s. It is primarily associated with Windows environments and is known for fast, multithreaded file encryption designed to disrupt enterprise networks at scale. Conti operators and affiliates commonly conducted full-network intrusions rather than opportunistic single-host attacks, with activity linked to broader criminal ecosystems that also overlapped with TrickBot and, historically, personnel associated with Ryuk. After Ryuk activity declined, many members transitioned into the Conti operation, helping it rapidly expand.
Conti was operated as a structured, enterprise-like ransomware program with documented procedures, training materials, internal management, and repeatable attack playbooks. Public leaks exposed the group’s internal organization, manuals, and source code, including Conti v2, which later influenced other ransomware actors and derivative families. Multiple later ransomware operations were reported to have built lockers or platforms from leaked Conti code.
The malware’s core purpose is file encryption for extortion, and the broader operation was associated with double-extortion tactics in which victims could face both encryption and pressure tied to stolen data. Conti became widely recognized not only for its technical impact but also for the scale and professionalism of its criminal organization. The group ultimately fragmented after major internal leaks in 2021 and 2022, with members and code lineage dispersing into successor and splinter ransomware operations.
Reported operators
Devman, a ransomware operator believed to be based in Russia and utilizing code derived from the leaked Conti source.
The sample analyzed in this report was identified as DragonForce ransomware developed based on Conti ransomware.
A longtime former member of Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, pleaded guilty ... The defendant and his conspirators used the Conti ransomware to terrorize people and businesses in the United States and around the world, causing millions of dollars in damage.
Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.
Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.
The crypto-locking malware first emerged around the middle of 2018 and seemed to have its heyday largely in 2019, before rebranding as Conti around May 2020, and appearing to merge with TrickBot - aka Wizard Spider - by the end of 2021.
Emsisoft threat analyst Brett Callow previously told The Record that the group has been active since the middle of 2021 and is believed to be a spin-off of the Conti ransomware group. Several other security companies ... have released reports this year showing concrete ties between the infrastructure used by Conti and Karakurt.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
The State Department on Thursday announced a $10 million reward for information related to five specific individuals associated with the Conti ransomware group.
Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...
Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...
Looking at the indicators of compromise in the report, Valery Marchive of LegMagIT found several IP addresses related to Conti ransomware, indicating Lockean’s affiliation to additional RaaS operations and targeting of businesses in other regions.
The group started using stolen code from Conti in 2024 to build its own custom attack tools to hit Windows and VMware server environments.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.
"...FIN7... known to collaborate with the Conti, REvil, Maze, Egregor, and BlackBasta ransomware gangs..."
Conti was a prolific ransomware strain for a few years... Conti responded by announcing its closure in May, but soon after, much of the Conti team split up into smaller groups and continued their activity.
The following analytic detects the execution of suspicious command-line arguments commonly associated with Conti ransomware, specifically targeting local drives and network shares for encryption.
...multiple overlaps with Conti ransomware.
Exploited software
MITRE ATT&CK
Reporting
Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.
The European Union imposed sanctions on eight individuals accused of participating in Russian-linked cyberattacks and cybercrime, targeting figures tied to Conti, TrickBot, Wizard Spider, LockBit, EvilCorp, BlackBasta, the Lumma infostealer, and the pro-Russian Cyber Army of Russia Reborn. Those named include alleged Conti leader Vitaly Nikolayevich Kovalev, bulletproof hosting operator Alexander Volosovik, two operators associated with Lumma, two members linked to Cyber Army of Russia Reborn, and two alleged members of GRU Unit 29155. The sanctions were issued amid broader Western attribution of Russian state and criminal cyber activity, including disruptive operations against Ukraine and its supporters and espionage and sabotage campaigns linked to the GRU. UK government reporting has profiled Russian military intelligence cyber and hybrid operations, including activity attributed to Unit 29155, while the EU action also cites links to the WhisperGate campaign and follows French accusations of Russian cyber espionage. The measures underscore continued efforts to publicly identify and financially isolate operators supporting both state-directed and criminal cyber operations.
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.