Conti was a major Russian-linked ransomware syndicate active in the early 2020s and widely regarded as one of the most prolific cybercriminal operations of its period. The group operated a mature ransomware-as-a-service and affiliate-driven model with structured internal management, documented procedures, training materials, salary-based roles, and a clear chain of command. Leaked internal chats and manuals exposed an enterprise-like organization whose operators repeatedly followed established playbooks rather than improvising, and also highlighted operational overlap with the earlier Ryuk ecosystem. Many Ryuk participants later moved into the Conti operation. Conti conducted financially motivated intrusions against businesses, hospitals, government entities, and other organizations worldwide, with especially significant impact in the United States. The group is associated with attacks across multiple sectors, including healthcare, government and public sector, and broad commercial targets. Conti became known for large-scale ransomware deployment combined with data theft and extortion pressure through a public leak site. Its operations helped define the modern double-extortion model later reused by numerous successor and spinoff groups. The syndicate has been linked to the broader Russian cybercrime ecosystem and to clusters such as Wizard Spider and TrickBot. Public sanctions and investigative reporting have identified Russian national Vitaly Nikolayevich Kovalev, also known by aliases including Bentley, Bergen, Alex Konor, Benny, Ben, and Stern, as a leader within Conti. In 2022, the group publicly declared support for the Russian government during the invasion of Ukraine, after which internal fractures and leaks contributed to its collapse and reorganization. Conti’s tradecraft included initial access through phishing, exploitation of exposed remote services and unpatched vulnerabilities, extensive reconnaissance, credential theft, lateral movement, and coordinated ransomware deployment at scale. The group and its operators were associated with repeatable attack sequences, use of administrative tooling and batch-driven procedures, and post-compromise actions aligned with mature extortion operations. Conti also influenced later ransomware families and crews; multiple later operations and offshoots have been described as deriving personnel, code lineage, or operational practices from Conti.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as historical comparison for leak-site cross-posting behavior.
Referenced as the earlier cybercrime syndicate from which BlackSuit and Royal were described as spinoffs.
Referenced as a threat actor/ransomware operation that DevMan claimed to have worked with previously.
Prolific ransomware group in the early 2020s responsible for numerous attacks across business, healthcare, and government sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.