Conti, also tracked in some vendor nomenclature as Blue Cronus, was a financially motivated cybercriminal organization associated with the broader Conti/TrickBot ecosystem. Following the 2022 leak of internal Conti communications, the organization was assessed to encompass or closely overlap with multiple established clusters and malware operations, including elements associated with TrickBot, Bazar, Anchor, Ryuk, Emotet, and later Black Basta-linked personnel. Reported sub-groups and affiliated designations include White Magician, White Onibi, White Taranis, and White Dev 115. The actor is known for ransomware operations and related intrusion activity, using malware delivery chains involving families such as Bumblebee and IcedID. Its intrusion tradecraft aligns with broader 2022 criminal ecosystem trends that emphasized phishing and malware-based initial access, use of archive and disk-image based payload delivery to evade macro restrictions, and execution methods involving DLL payloads and abuse of native Windows utilities. Post-compromise activity commonly relied on widely abused offensive frameworks such as Cobalt Strike, with strong emphasis on credential access, defense evasion, lateral movement, persistence, and data theft in support of extortion. Conti became one of the most prominent ransomware actors of its era and is widely associated with double-extortion operations combining network encryption with theft of victim data. The group operated as part of a mature cybercrime ecosystem that shared tooling, personnel, and infrastructure across malware delivery, access brokerage, and ransomware deployment. Its activity reflects an organized, profit-driven model centered on large-scale enterprise compromise, post-exploitation efficiency, and monetization through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.