Skip to content

Conti

Conti is a targeted Windows ransomware family operated by the Conti cybercrime syndicate from 2020 until the operation’s 2022 decline and cessation.

Profile source: Mallory opens in a new tab

Conti

Family profile

Conti is a targeted Windows ransomware family operated by the Conti cybercrime syndicate from 2020 until the operation’s 2022 decline and cessation. It was used in double-extortion attacks: operators encrypted victim data while threatening to publish previously stolen information if payment was not made. The operation functioned through a structured affiliate-oriented model and reportedly relied heavily on initial-access brokers and existing post-compromise tooling. Conti activity targeted large organizations across sectors and was associated with intrusions involving exposed remote services, VPN weaknesses, server vulnerabilities, and access obtained through malware such as TrickBot and QakBot.

Conti encrypts local files, accessible network shares, and remote SMB-accessible resources. Its ransomware implementation uses multithreaded encryption, per-file ChaCha8 keys protected with an embedded RSA public key, and different encryption modes based on file type and size. It can enumerate nearby private-network hosts through ARP data, probe SMB availability, and encrypt reachable administrative shares; this behavior is remote file encryption rather than self-propagation. Conti also terminates applications locking targeted files through Windows Restart Manager and deletes volume shadow copies to impede recovery.

The malware employs layered in-memory execution using shellcode and reflective loading, encrypted strings and API resolution, anti-analysis logic, and execution controls intended for hands-on operator deployment. Conti operators conducted reconnaissance, credential access, privilege escalation, lateral movement using SMB and RDP, and data theft before ransomware deployment. Reported tooling included PowerShell, Cobalt Strike, Mimikatz, Kerberoasting, Zerologon-related techniques, and Microsoft Exchange remote-code-execution exploits. Data was commonly exfiltrated using cloud-storage and file-transfer tooling. Conti’s source code and internal materials were leaked in 2022, contributing to code reuse and derivative ransomware families.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
4
Ransom notes
32
Negotiations
3
Leak sites
1 available

Credential Theft

  • Mimikatz
  • ProcDump
  • Router Scan
  • SharpChrome

Defense Evasion

  • GMER
  • PCHunter

Discovery Enum

  • AdFind
  • Bloodhound
  • PowerView
  • Seatbelt
  • ShareFinder
  • SharpView
  • SoftPerfect NetScan

Exfiltration

  • Dropfiles
  • MEGA
  • Qaz[.]im
  • RClone
  • Sendspace
  • WinSCP

LOLBAS

  • BITSAdmin
  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC

Offsec

  • Cobalt Strike
  • Metasploit
  • Meterpreter
  • PowerShell Empire
  • PowerSploit
  • Rubeus

RMM Tools

  • AnyDesk
  • Atera
  • Splashtop

Reported operators

Threat actors

29 named in public reporting
Conti-affiliates

Een handleiding hoe een ransomware-aanval met data-exfiltratie uitgevoerd moet worden door Conti-affiliates is gelekt in 2021.

WIZARD SPIDER

...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.

TA551

Conti cyberthreat actors remain active and Conti ransomware attacks against U.S. and international organizations have risen to more than 1,000. Notable attack vectors include Trickbot and Cobalt Strike.

The Conti Group

The Conti Group is renowned for being a very successful Ransomware operator and the gang have terrorized businesses worldwide by encrypting their networks for a ransom and also threatening to leak data if not paid.

Water Goblin

Based on data from the leak sites of their operators, 35.8% of these attacks were attributed to LockBit, while 19% belonged to Conti and 9.6% to BlackCat.

Conti

We noticed that only certain affiliates have access to a Linux variant of the Conti ransomware, targeting ESXi systems.

Trickbot

The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... The researchers saw both Diavol and Conti ransomware payloads deployed on a network in the same ransomware attack in early June 2021.

lalartu

Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.

fin12

The group that runs Conti ransomware has a new trick up its sleeve: hiring some of the top staff responsible for having developed the venerable TrickBot malware.

Sandworm

What makes this more interesting, is that the hacking group created their ransomware using the leaked source code for the Conti Ransomware operation... Almost all antivirus vendors detect this sample on VirusTotal as Conti, and Intezer Analyze also determined it uses 66% of the same code as the usual Conti ransomware samples.

NB65

What makes this more interesting, is that the hacking group created their ransomware using the leaked source code for the Conti Ransomware operation... Almost all antivirus vendors detect this sample on VirusTotal as Conti, and Intezer Analyze also determined it uses 66% of the same code as the usual Conti ransomware samples.

Overdose

The group’s alias is “Overdose,” and they are the primary Platform-as-a-Service fraud group behind TrickBot campaigns, namely those that result in Conti and Ryuk ransomware.

Devman

Devman, a ransomware operator believed to be based in Russia and utilizing code derived from the leaked Conti source.

DragonForce

The sample analyzed in this report was identified as DragonForce ransomware developed based on Conti ransomware.

Silent Ransom Group

Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.

Karakurt

Emsisoft threat analyst Brett Callow previously told The Record that the group has been active since the middle of 2021 and is believed to be a spin-off of the Conti ransomware group. Several other security companies ... have released reports this year showing concrete ties between the infrastructure used by Conti and Karakurt.

DEV-0230

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

DEV-0506

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

DEV-0216

Based on our telemetry from 2021 and 2022, Conti has become one of the most deployed RaaS ecosystems, with multiple affiliates concurrently deploying their payload.

Russian Spider

Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...

NC1878

Garda sources said the force’s involvement would become a substantive criminal investigation when a profile of the malware, called Conti, and its likely origins had been compiled during the work to contain and reverse its spread. The Conti ransomware, or malware, first appeared in December 2019...

Lockean

Looking at the indicators of compromise in the report, Valery Marchive of LegMagIT found several IP addresses related to Conti ransomware, indicating Lockean’s affiliation to additional RaaS operations and targeting of businesses in other regions.

Nitrogen

The group started using stolen code from Conti in 2024 to build its own custom attack tools to hit Windows and VMware server environments.

Tramp

Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.

Bl00Dy

...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.

FIN7

"...FIN7... known to collaborate with the Conti, REvil, Maze, Egregor, and BlackBasta ransomware gangs..."

Stern

Conti was a prolific ransomware strain for a few years... Conti responded by announcing its closure in May, but soon after, much of the Conti team split up into smaller groups and continued their activity.

Scattered Spider

The following analytic detects the execution of suspicious command-line arguments commonly associated with Conti ransomware, specifically targeting local drives and network shares for encryption.

Exploited software

Vulnerabilities linked to Conti

59 CVEs
CVE-2020-1472 Zerologon CVE-2021-34527 PrintNightmare Windows Print Spooler Remote Code Execution CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2018-13374 Improper Access Control in Fortinet FortiOS and FortiADC LDAP Connectivity Test CVE-2018-13379 FortiOS and FortiProxy SSL VPN Pre-Authentication Path Traversal CVE-2021-34523 Microsoft Exchange Server PowerShell Backend Elevation of Privilege CVE-2021-31207 Microsoft Exchange Server Mailbox Export Arbitrary File Write CVE-2021-44228 Log4Shell CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution in Microsoft Windows CVE-2021-26855 Microsoft Exchange Server Pre-Authentication SSRF (ProxyLogon) CVE-2019-14598 Improper Authentication in Intel CSME (CVE-2019-14598) CVE-2018-12190 Privilege Escalation in Intel CSME and TXE via Insufficient Input Validation CVE-2018-3628 Buffer Overflow in Intel AMT HTTP Handler (CVE-2018-3628) CVE-2020-8752 Out-of-bounds Write in Intel AMT and Intel ISM IPv6 Subsystem CVE-2020-12297 Privilege Escalation in Intel CSME Driver Installer for Windows CVE-2019-11105 Privilege Escalation and Information Disclosure in Intel CSME (CVE-2019-11105) CVE-2020-0586 Privilege Escalation and DoS in Intel SPS Improper Initialization CVE-2017-5705 Buffer Overflow in Intel ME Firmware (CVE-2017-5705) CVE-2019-0096 Out-of-bounds Write in Intel AMT CVE-2019-11106 Insufficient Session Validation in Intel CSME and TXE CVE-2020-8744 Improper Initialization in Intel CSME, TXE, and SPS CVE-2020-8760 Integer Overflow in Intel AMT Privilege Escalation CVE-2019-11110 Authentication Bypass in Intel CSME and TXE CVE-2019-11104 Privilege Escalation in Intel MEInfo and TXE CVE-2019-11108 Insufficient Input Validation in Intel CSME (CVE-2019-11108) CVE-2020-8703 Privilege Escalation in Intel CSME via Improper Buffer Restrictions CVE-2020-12303 Use After Free in Intel CSME/TXE DAL Subsystem CVE-2020-0533 Weak Hash Function in Intel CSME CVE-2020-8757 Out-of-bounds Read in Intel AMT CVE-2019-0086 Insufficient Access Control in Intel CSME and TXE Dynamic Application Loader CVE-2018-12196 Arbitrary Code Execution in Intel AMT via Insufficient Input Validation CVE-2019-11103 Privilege Escalation in Intel CSME Firmware Update Software CVE-2018-12200 Privilege Escalation in Intel Capability Licensing Service <1.50.638.1 CVE-2020-0542 Improper Buffer Restrictions in Intel CSME (CVE-2020-0542) CVE-2019-0091 Code Injection in Intel CSME/TXE Installer CVE-2020-0541 Out-of-bounds Write in Intel CSME CVE-2019-11088 Privilege Escalation in Intel AMT via Insufficient Input Validation CVE-2019-0153 Buffer Overflow in Intel CSME 12.x CVE-2019-0169 Heap Overflow in Intel CSME and TXE CVE-2019-11087 Insufficient Input Validation in Intel CSME and TXE CVE-2020-0595 Use-After-Free in Intel AMT and Intel ISM IPv6 Subsystem CVE-2020-0594 Out-of-bounds read in Intel AMT and Intel ISM IPv6 subsystem CVE-2018-3627 Arbitrary Code Execution in Intel Converged Security Management Engine 11.x CVE-2020-8758 Improper Buffer Restrictions in Intel AMT/ISM Network Subsystem CVE-2019-11132 XSS in Intel AMT Web Interface (CVE-2019-11132) CVE-2020-8756 Privilege Escalation in Intel CSME (Improper Input Validation) CVE-2018-3616 Bleichenbacher-style Side Channel in Intel AMT TLS CVE-2020-12354 Privilege Escalation via Incorrect Default Permissions in Intel AMT SDK Installer CVE-2019-11097 Privilege Escalation via Improper Directory Permissions in Intel Management Engine Consumer Driver Installer CVE-2019-11131 Privilege Escalation in Intel AMT (CVE-2019-11131) CVE-2017-5712 Buffer Overflow in Intel AMT (CVE-2017-5712) CVE-2018-3657 Buffer Overflow in Intel AMT (CSME firmware <12.0.5) CVE-2019-11147 Privilege Escalation in Intel MEInfo and TXEInfo Hardware Abstraction Driver CVE-2019-11107 Privilege Escalation in Intel AMT (pre-12.0.45) CVE-2018-3643 Information Disclosure and Potential Code Execution in Intel CSME/Server Platform Services CVE-2018-12147 Privilege Escalation in Intel HECI Subsystem (CSME/SPS/TXE) CVE-2017-5711 Buffer Overflow in Intel AMT (CVE-2017-5711) CVE-2025-24472 Fortinet FortiOS and FortiProxy CSF Proxy Authentication Bypass CVE-2024-55591 FortiOS and FortiProxy Node.js WebSocket Authentication Bypass

MITRE ATT&CK

Conti in ATT&CK

94 distinct techniques

Techniques

94 techniques
T1486 Data Encrypted for Impact T1046 Network Service Discovery T1622 Debugger Evasion T1490 Inhibit System Recovery T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1070 Indicator Removal T1135 Network Share Discovery T1021.002 SMB/Windows Admin Shares T1027 Obfuscated Files or Information T1140 Deobfuscate/Decode Files or Information T1057 Process Discovery T1657 Financial Theft T1083 File and Directory Discovery T1620 Reflective Code Loading T1489 Service Stop T1598.004 Spearphishing Voice T1105 Ingress Tool Transfer T1588.001 Malware T1071 Application Layer Protocol T1016 System Network Configuration Discovery T1049 System Network Connections Discovery T1055.001 Dynamic-link Library Injection T1080 Taint Shared Content T1106 Native API T1059.003 Windows Command Shell T1055 Process Injection T1018 Remote System Discovery T1562 Impair Defenses T1566 Phishing T1567.002 Exfiltration to Cloud Storage T1059 Command and Scripting Interpreter T1078 Valid Accounts T1003.001 LSASS Memory T1133 External Remote Services T1190 Exploit Public-Facing Application T1219 Remote Access Tools T1047 Windows Management Instrumentation T1573 Encrypted Channel T1537 Transfer Data to Cloud Account T1053.005 Scheduled Task T1590 Gather Victim Network Information T1203 Exploitation for Client Execution T1041 Exfiltration Over C2 Channel T1036 Masquerading T1529 System Shutdown/Reboot T1562.001 Disable or Modify Tools T1074 Data Staged T1053 Scheduled Task/Job T1570 Lateral Tool Transfer T1082 System Information Discovery T1059.001 PowerShell T1567 Exfiltration Over Web Service T1564.003 Hidden Window T1027.002 Software Packing T1005 Data from Local System T1069.001 Local Groups T1596 Search Open Technical Databases T1003.003 NTDS T1566.001 Spearphishing Attachment T1124 System Time Discovery T1003 OS Credential Dumping T1210 Exploitation of Remote Services T1595 Active Scanning T1129 Shared Modules T1021 Remote Services T1547.004 Winlogon Helper DLL T1518 Software Discovery T1027.007 Dynamic API Resolution T1485 Data Destruction T1059.004 Unix Shell T1021.001 Remote Desktop Protocol T1566.002 Spearphishing Link T1218.010 Regsvr32 T1071.004 DNS T1132 Data Encoding T1567.003 Exfiltration to Text Storage Sites T1048 Exfiltration Over Alternative Protocol T1583 Acquire Infrastructure T1565 Data Manipulation T1204.002 Malicious File T1608.006 SEO Poisoning T1189 Drive-by Compromise T1204 User Execution T1213 Data from Information Repositories T1222 File and Directory Permissions Modification T1078.002 Valid Accounts: Domain Accounts T1136.002 Create Account: Domain Account T1547.001 Boot or Logon Autostart Execution: Registry Run Keys T1068 Exploitation for Privilege Escalation T1218.011 Signed Binary Proxy Execution: Rundll32 T1482 Domain Trust Discovery T1560.001 Archive Collected Data: Archive via Utility T1071.001 Application Layer Protocol: Web Protocols

Reporting

Research mentioning Conti

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

Jul 20
Zdnet

Qui sont les pirates russes visés par les nouvelles sanctions eur ...

The European Union imposed sanctions on eight individuals accused of participating in Russian-linked cyberattacks and cybercrime, targeting figures tied to Conti, TrickBot, Wizard Spider, LockBit, EvilCorp, BlackBasta, the Lumma infostealer, and the pro-Russian Cyber Army of Russia Reborn. Those named include alleged Conti leader Vitaly Nikolayevich Kovalev, bulletproof hosting operator Alexander Volosovik, two operators associated with Lumma, two members linked to Cyber Army of Russia Reborn, and two alleged members of GRU Unit 29155. The sanctions were issued amid broader Western attribution of Russian state and criminal cyber activity, including disruptive operations against Ukraine and its supporters and espionage and sabotage campaigns linked to the GRU. UK government reporting has profiled Russian military intelligence cyber and hybrid operations, including activity attributed to Unit 29155, while the EU action also cites links to the WhisperGate campaign and follows French accusations of Russian cyber espionage. The measures underscore continued efforts to publicly identify and financially isolate operators supporting both state-directed and criminal cyber operations.

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.