Skip to content

Quantum

Quantum is a Windows ransomware family associated with the post-Conti cybercrime ecosystem.

Profile source: Mallory opens in a new tab

Quantum

Family profile

Quantum is a Windows ransomware family associated with the post-Conti cybercrime ecosystem. It emerged as one of the successor brands used by actors linked to Conti after that syndicate fragmented in 2022, and it is widely reported to have later rebranded into Royal and subsequently BlackSuit. Quantum has been referenced alongside other Conti-derived or affiliated operations in financially motivated intrusions targeting enterprises and critical-sector organizations.

Observed Quantum intrusions follow a conventional big-game ransomware pattern centered on enterprise compromise, lateral movement, data theft, and domain-wide encryption. In documented cases, operators conducted multi-day hands-on-keyboard activity after initial access, used post-exploitation tooling such as Cobalt Strike, leveraged remote administration software for command and control, exfiltrated victim data, and then deployed the ransomware broadly across the environment. Remote execution and propagation have been observed via administrative mechanisms such as WMI and PsExec, consistent with mass deployment across Windows domains.

Quantum has been linked to intrusion chains in which initial access was obtained through phishing-delivered malware, including Emotet, and to broader ransomware ecosystems that also relied on loaders such as Qakbot and BumbleBee. Reporting also places Quantum among ransomware brands used by financially motivated actors such as Vanilla Tempest, and among strains connected through transactions and personnel overlap to senior TrickBot and Conti figures. The family has also been cited in discussions of re-extortion behavior among ransomware operations targeting mid-market and larger enterprises.

At high confidence, Quantum should be understood as a Conti-lineage ransomware brand used in double-extortion-style enterprise attacks against Windows environments, with capabilities including data exfiltration, lateral movement, post-exploitation activity, and impact through large-scale encryption.

Capabilities

  • Exfiltration
  • Lateral Movement
  • Post Exploitation

Operational record

1
YARA rules
2
Leak sites
0 available

Credential Theft

  • Mimikatz
  • ProcDump

Discovery Enum

  • AdFind

Exfiltration

  • MEGA
  • RClone

LOLBAS

  • PsExec
  • WMIC

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk
  • Atera
  • RSAT
  • Splashtop

Reported operators

Threat actors

2 named in public reporting
Conti

Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.

Stern

...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.

MITRE ATT&CK

Quantum in ATT&CK

5 distinct techniques

Reporting

Research mentioning Quantum

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

Jul 14
Cyber Security News

US Treasury Sanctions VPN Service that Helped Ransomware Actors to Attack Organizations

Jul 14
The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.