Conti was a major financially motivated ransomware and double-extortion operation active from 2020 until its 2022 dissolution. Also referred to as the Conti gang, Conti Group, and Conti ransomware group, it operated as a structured cybercrime enterprise using affiliates and initial-access brokers, with business-like recruiting, performance management, victim research, negotiation, and data-management functions. Conti targeted large organizations, including government, health care, and education entities, and assessed victim revenue, liquidity, cyber-insurance coverage, and executive contacts to calibrate ransom demands and extortion pressure. Conti intrusions used compromised remote access, exposed services, server vulnerabilities, and access associated with malware ecosystems including TrickBot, BazarLoader, QakBot, and Emotet. Operators conducted reconnaissance, credential theft, privilege escalation, and rapid lateral movement, particularly through SMB and RDP. Known tradecraft included PowerShell, Cobalt Strike, Mimikatz, Kerberoasting, Zerologon, Microsoft Exchange exploitation, UAC-bypass methods, NTDS credential-database theft, and native Windows utilities. The ransomware used layered in-memory execution and reflective loading, API and string obfuscation, anti-analysis logic, multithreaded encryption, service disruption, remote encryption of accessible network shares, and deletion of volume shadow copies to inhibit recovery. Conti combined encryption with theft and threatened publication of victim data through a leak site. It prioritized sensitive documents and email data for extortion and used cloud-storage services and Rclone for exfiltration. The group was associated with the Karakurt data-extortion operation, characterized as Conti's extortion arm before Conti ceased operations. Former Conti members have also been reported in later ransomware operations including Royal. Conti source code was leaked in 2022 following internal conflict related to the group's support for Russia's invasion of Ukraine; the leaked code subsequently influenced other ransomware families.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Microsoft announced the existence of CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, and with their powers combined, they are ProxyShell. These vulnerabilities... leverage pre-auth path confusion for ACL bypass, elevation of privilege on the Exchange PowerShell backend, and post-auth arbitrary file writes to install a web shell onto the compromised system. | Pre-Auth Path Confusion ACL Bypass (CVE-2021-34473)
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
Conti has been particularly quick to adopt the latest vulnerability SMB and RDP exploits, such as PrintNightmare.
They check for the “PrintNightmare” vulnerability (CVE-2021-34527) in Windows Print spooler service, EternalBlue vulnerability (CVE-2017-0144) in Microsoft Windows Server Message Block, and the “Zerologon” vulnerability (CVE-2020-1472) in Microsoft Active Directory Domain Controller.
2 more CVEs tied to this actor tracked in Mallory.
208 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the apparent codebase source from which Gunra's ransomware was derived after Conti's source code leak.
Ransomware operation that closely partnered with and later effectively absorbed TrickBot talent and access capabilities, using that access to breach victim networks, gain administrative control, steal data, and deploy ransomware with double-extortion tactics.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Referenced as a major ransomware operation whose leaked source code reshaped the ransomware ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.