Quantum was a Russian-speaking cybercriminal ransomware and extortion operation active by 2022 and widely assessed as part of the post-Conti ecosystem. It is commonly referenced as Quantum, Quantum Group, or Quantum ransomware. Reporting consistently links it to former Conti members after Conti’s 2022 collapse, with Quantum later rebranding to Royal and subsequently to BlackSuit in 2024. Quantum conducted double-extortion intrusions, combining data theft with file encryption and then pressuring victims through leak-site publication. Victimology included healthcare and other enterprise targets, with publicly reported incidents including attacks against medical organizations and financial-sector entities. The group publicly exposed stolen data when victims did not meet extortion demands. The operation is associated with the broader Russian-language ransomware milieu that splintered after the Conti leaks. Multiple reports describe Quantum as one of several successor or affiliated brands that emerged from former Conti personnel alongside groups such as Black Basta and Zeon. Later reporting on Royal and BlackSuit places Quantum within a lineage of repeated rebranding rather than as an isolated standalone crew. Infrastructure and tradecraft overlaps have also been reported between Quantum and other ransomware operations. In particular, Play ransomware activity has been noted to share partial infrastructure characteristics with Quantum, including reported similarities in Cobalt Strike beacon watermarks seen in campaigns tied to botnet-delivered access. These overlaps suggest operational relationships or shared resources within the same criminal ecosystem, though the precise structure is not fully public. Overall, Quantum is best understood as a Conti-linked ransomware brand used during the fragmentation and reorganization of a major Russian-speaking cybercrime syndicate, employing double extortion against enterprise victims before transitioning into the Royal and later BlackSuit operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a Conti successor subgroup that rebranded first to Royal and later to BlackSuit.
Named as one of the ransomware groups that former Conti members reportedly splintered into after Conti shut down.
A subgroup formed from former Conti members that quickly rebranded to Royal and later to BlackSuit.
Named as a Conti-linked rebrand that subsequently rebranded to Royal and later to BlackSuit (2024).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.