Skip to content

Monti

Monti is a ransomware family that emerged in 2022 and is widely assessed to be closely related to Conti, either as a rebrand by former Conti operators or as a new variant built from the Conti source code leaked that year.

Profile source: Mallory opens in a new tab

Monti

Family profile

Monti is a ransomware family that emerged in 2022 and is widely assessed to be closely related to Conti, either as a rebrand by former Conti operators or as a new variant built from the Conti source code leaked that year. It has been described as a Conti doppelganger because it closely mirrors Conti tradecraft and tooling, and code analysis has identified strong similarity between Monti and Conti, including a very similar entry point.

Monti is associated with the broader post-Conti fragmentation of the ransomware ecosystem, in which affiliates and developers moved between brands after Conti’s operational decline. Reporting has linked Monti to activity by actors with prior Conti affiliations, and it has appeared alongside other major ransomware strains in enterprise-targeting intrusion sets.

Monti has been observed targeting Linux environments, including VMware ESXi systems, reflecting the broader shift of ransomware operators toward hypervisors and server infrastructure where a single compromise can disrupt many hosted workloads. In Linux-focused deployments, ransomware of this class typically emphasizes file encryption over complex modular functionality, often relying on external scripts, command-line parameters, webshells, or legitimate administration tools during the intrusion. Monti has been noted to generate a characteristic encryption log during execution.

High-confidence reporting supports classifying Monti as ransomware. Its operational context is consistent with enterprise extortion campaigns against organizational infrastructure rather than consumer-focused malware activity. Available information does not establish a single exclusive delivery mechanism for Monti itself, but it appears in an ecosystem where Linux and ESXi ransomware intrusions commonly begin through exploitation of exposed services, deployment of webshells, use of stolen SSH credentials, or brute-force access against internet-facing systems.

Capabilities

  • Extortion

Operational record

1
YARA rules
2
Ransom notes
2
Leak sites
0 available

Credential Theft

  • Mimikatz
  • Veeam-Get-Creds

Defense Evasion

  • Avast Anti-Rootkit driver
  • GMER

Discovery Enum

  • SoftPerfect NetScan

Exfiltration

  • MEGA
  • PSCP
  • WinSCP

RMM Tools

  • Action1
  • AnyDesk

MITRE ATT&CK

Monti in ATT&CK

6 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.