Conti was a prolific Russian-speaking ransomware operation active primarily from 2020 until its public collapse in 2022. It is widely associated with the broader TrickBot and Wizard Spider cybercrime ecosystem and is considered one of the most consequential ransomware groups of its period. Conti conducted large-scale double-extortion campaigns, stealing data and encrypting victim networks to pressure payment, and targeted more than 1,000 organizations worldwide across healthcare, government, education, and private-sector industries. The FBI estimated the operation had generated at least $150 million in ransom payments by early 2022. Conti operated with a mature, enterprise-like structure that included developers, administrators, negotiators, operators, and affiliates. The group used a broad intrusion lifecycle typical of top-tier ransomware crews: exploitation of internet-facing systems, use of compromised credentials, phishing and loader malware, privilege escalation, credential theft, lateral movement, remote execution, backup destruction, and mass encryption. Public reporting and government advisories have linked Conti to the use of tools and techniques such as PsExec for ransomware propagation, and the group has been associated with malware and access tooling in the TrickBot ecosystem, including relationships to Ryuk-era operators and related loader infrastructure. Conti is also notable for its role in the evolution of the modern ransomware landscape. Many Ryuk members later joined Conti, and after Conti’s 2022 implosion, former members and affiliates were widely assessed to have dispersed into successor or related operations. Reporting has repeatedly linked ex-Conti personnel or tradecraft to groups including Black Basta, Akira, Royal, BlackSuit, 3AM, and Silent Ransom Group, among others. Some later ransomware families also showed code or procedural similarities to Conti, including Linux and ESXi-focused development paths. The group’s downfall followed its public declaration of support for the Russian government after the 2022 invasion of Ukraine, which triggered major internal leaks. Those leaks exposed internal chats, operational procedures, and organizational details, providing rare visibility into ransomware business practices and accelerating the fragmentation of the group. Although Conti ceased operating under its original name in 2022, its personnel, tooling lineage, and operational playbooks continued to influence subsequent ransomware and extortion activity. Known aliases and naming overlap in public reporting are limited; the operation is most commonly referred to simply as Conti. It is best understood as both a distinct ransomware brand and a central node in a wider Russian-speaking cybercriminal network whose members reappeared across multiple post-2022 extortion groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the subject of a podcast series examining leaked internal chats from the Conti ransomware group, revealing members discussing their criminal operations and internal communications.
Named as one of the ransomware groups that exploited Log4Shell in incident response cases.
Referenced as a later ransomware operation joined by many former Ryuk members.
Now-defunct ransomware operation whose shutdown is associated in the report with the 2022 decline in confirmed ransomware attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.