Skip to main content
Mallory
16 malware families

Conti

Also known asconti

Conti is a Russian government-linked ransomware-as-a-service (RaaS) operation and ransomware group widely associated with Russia-based actors. The group publicly declared support for the Russian government after the 2022 invasion of Ukraine, later softened its statement, and has been described in reporting as Russia-linked, with at least some actors assessed to be based in Russia. Conti was responsible for more than 400 attacks between spring 2020 and spring 2021, mostly against U.S. organizations, and by January 2022 had reportedly victimized more than 1,000 organizations with over $150 million in payouts. Reported targeting included U.S. healthcare and first-responder networks, Ireland’s Health Service Executive, hospitals in New Zealand, Costa Rican government agencies, and other U.S. public-sector entities. The group used double extortion, stealing data before encrypting systems and threatening to publish or sell exfiltrated data via its leak site and negotiation portals. Conti operated as a business-like RaaS ecosystem with core operators and affiliates. Leaked internal chats exposed organizational structure, bitcoin addresses, law-enforcement evasion, attack methods, and a toxic internal culture. Additional leaks exposed the source code for Conti’s administrative panel, BazarBackdoor API, TrickBot command-and-control source code, and the Conti ransomware encryptor, decryptor, and builder. The leaks followed the group’s pro-Russia stance and were a major operational and reputational blow. The group is linked in the content to Ryuk, Diavol, TrickBot, and BazarBackdoor/BUMBLEBEE-related activity, including overlap noted by Google TAG and Proofpoint. Conti members and affiliates later dispersed into or were linked to other operations including Black Basta, Royal, Quantum, Hive, ALPHV/BlackCat, and Karakurt. Black Basta is described as a successor to Conti from February 2022, and Royal is described as a direct successor composed in part of former Conti members. The group appears to have disbanded or taken much of its infrastructure offline in 2022 after the leaks and fallout from its political stance, though former members continued operating under other banners.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics37 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1595
Active Scanning
TA0042
Resource Development
2 techniques
T1584
Compromise Infrastructure
T1588
Obtain Capabilities
T1588.001
Malware
T1588.002
Tool
TA0001
Initial Access
3 techniques
T1078×2
Valid Accounts
T1190×2
Exploit Public-Facing Application
T1566×5
Phishing
T1566.001
Spearphishing Attachment
T1566.003
Spearphishing via Service
TA0002
Execution
2 techniques
T1047
Windows Management Instrumentation
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
2 techniques
T1078×2
Valid Accounts
T1505
Server Software Component
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
3 techniques
T1070×2
Indicator Removal
T1078×2
Valid Accounts
T1218
System Binary Proxy Execution
TA0112
Defense Impairment
1 technique
T1553
Subvert Trust Controls
T1553.002
Code Signing
TA0009
Collection
3 techniques
T1005×3
Data from Local System
T1074×2
Data Staged
T1213×2
Data from Information Repositories
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1090.003
Multi-hop Proxy
T1219×3
Remote Access Tools
T1573
Encrypted Channel
TA0010
Exfiltration
3 techniques
T1041×3
Exfiltration Over C2 Channel
T1537×4
Transfer Data to Cloud Account
T1567×3
Exfiltration Over Web Service
TA0040
Impact
4 techniques
T1486×35
Data Encrypted for Impact
T1490×2
Inhibit System Recovery
T1565
Data Manipulation
T1657×12
Financial Theft
IOCS

Observables

10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping34

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal16

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables10

Domains, IPs, and hashes tied to this actor, refreshed continuously.