Credential Theft
- Mimikatz
- ProcDump
- Router Scan
- SharpChrome
Conti is a targeted Windows ransomware family operated by the Conti cybercrime syndicate from 2020 until the operation’s 2022 decline and cessation.
Profile source: Mallory opens in a new tabConti
Conti is a targeted Windows ransomware family operated by the Conti cybercrime syndicate from 2020 until the operation’s 2022 decline and cessation. It was used in double-extortion attacks: operators encrypted victim data while threatening to publish previously stolen information if payment was not made. The operation functioned through a structured affiliate-oriented model and reportedly relied heavily on initial-access brokers and existing post-compromise tooling. Conti activity targeted large organizations across sectors and was associated with intrusions involving exposed remote services, VPN weaknesses, server vulnerabilities, and access obtained through malware such as TrickBot and QakBot.
Conti encrypts local files, accessible network shares, and remote SMB-accessible resources. Its ransomware implementation uses multithreaded encryption, per-file ChaCha8 keys protected with an embedded RSA public key, and different encryption modes based on file type and size. It can enumerate nearby private-network hosts through ARP data, probe SMB availability, and encrypt reachable administrative shares; this behavior is remote file encryption rather than self-propagation. Conti also terminates applications locking targeted files through Windows Restart Manager and deletes volume shadow copies to impede recovery.
The malware employs layered in-memory execution using shellcode and reflective loading, encrypted strings and API resolution, anti-analysis logic, and execution controls intended for hands-on operator deployment. Conti operators conducted reconnaissance, credential access, privilege escalation, lateral movement using SMB and RDP, and data theft before ransomware deployment. Reported tooling included PowerShell, Cobalt Strike, Mimikatz, Kerberoasting, Zerologon-related techniques, and Microsoft Exchange remote-code-execution exploits. Data was commonly exfiltrated using cloud-storage and file-transfer tooling. Conti’s source code and internal materials were leaked in 2022, contributing to code reuse and derivative ransomware families.
Reported operators
Een handleiding hoe een ransomware-aanval met data-exfiltratie uitgevoerd moet worden door Conti-affiliates is gelekt in 2021.
...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.
Conti cyberthreat actors remain active and Conti ransomware attacks against U.S. and international organizations have risen to more than 1,000. Notable attack vectors include Trickbot and Cobalt Strike.
The Conti Group is renowned for being a very successful Ransomware operator and the gang have terrorized businesses worldwide by encrypting their networks for a ransom and also threatening to leak data if not paid.
Based on data from the leak sites of their operators, 35.8% of these attacks were attributed to LockBit, while 19% belonged to Conti and 9.6% to BlackCat.
We noticed that only certain affiliates have access to a Linux variant of the Conti ransomware, targeting ESXi systems.
The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... The researchers saw both Diavol and Conti ransomware payloads deployed on a network in the same ransomware attack in early June 2021.
Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.
The group that runs Conti ransomware has a new trick up its sleeve: hiring some of the top staff responsible for having developed the venerable TrickBot malware.
What makes this more interesting, is that the hacking group created their ransomware using the leaked source code for the Conti Ransomware operation... Almost all antivirus vendors detect this sample on VirusTotal as Conti, and Intezer Analyze also determined it uses 66% of the same code as the usual Conti ransomware samples.
What makes this more interesting, is that the hacking group created their ransomware using the leaked source code for the Conti Ransomware operation... Almost all antivirus vendors detect this sample on VirusTotal as Conti, and Intezer Analyze also determined it uses 66% of the same code as the usual Conti ransomware samples.
The group’s alias is “Overdose,” and they are the primary Platform-as-a-Service fraud group behind TrickBot campaigns, namely those that result in Conti and Ryuk ransomware.
Devman, a ransomware operator believed to be based in Russia and utilizing code derived from the leaked Conti source.
The sample analyzed in this report was identified as DragonForce ransomware developed based on Conti ransomware.
Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.
Emsisoft threat analyst Brett Callow previously told The Record that the group has been active since the middle of 2021 and is believed to be a spin-off of the Conti ransomware group. Several other security companies ... have released reports this year showing concrete ties between the infrastructure used by Conti and Karakurt.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.
Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...
Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...
Looking at the indicators of compromise in the report, Valery Marchive of LegMagIT found several IP addresses related to Conti ransomware, indicating Lockean’s affiliation to additional RaaS operations and targeting of businesses in other regions.
The group started using stolen code from Conti in 2024 to build its own custom attack tools to hit Windows and VMware server environments.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.
"...FIN7... known to collaborate with the Conti, REvil, Maze, Egregor, and BlackBasta ransomware gangs..."
Conti was a prolific ransomware strain for a few years... Conti responded by announcing its closure in May, but soon after, much of the Conti team split up into smaller groups and continued their activity.
The following analytic detects the execution of suspicious command-line arguments commonly associated with Conti ransomware, specifically targeting local drives and network shares for encryption.
...multiple overlaps with Conti ransomware.
Exploited software
MITRE ATT&CK
Reporting
Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.
The European Union imposed sanctions on eight individuals accused of participating in Russian-linked cyberattacks and cybercrime, targeting figures tied to Conti, TrickBot, Wizard Spider, LockBit, EvilCorp, BlackBasta, the Lumma infostealer, and the pro-Russian Cyber Army of Russia Reborn. Those named include alleged Conti leader Vitaly Nikolayevich Kovalev, bulletproof hosting operator Alexander Volosovik, two operators associated with Lumma, two members linked to Cyber Army of Russia Reborn, and two alleged members of GRU Unit 29155. The sanctions were issued amid broader Western attribution of Russian state and criminal cyber activity, including disruptive operations against Ukraine and its supporters and espionage and sabotage campaigns linked to the GRU. UK government reporting has profiled Russian military intelligence cyber and hybrid operations, including activity attributed to Unit 29155, while the EU action also cites links to the WhisperGate campaign and follows French accusations of Russian cyber espionage. The measures underscore continued efforts to publicly identify and financially isolate operators supporting both state-directed and criminal cyber operations.
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.