Zeon is a Russian-language ransomware group that emerged from the 2022 fragmentation of the Conti cybercrime syndicate. It is consistently described as one of the successor subgroups formed after Conti’s shutdown, alongside Black Basta and Quantum, within the broader post-Conti ransomware ecosystem. Zeon has been referenced as operating Rust-based ransomware, reflecting a wider trend among ransomware developers toward Rust for cross-platform support and more complex binaries. Reporting also places Zeon within the interconnected cluster of former Conti and TrickBot-linked operators that repeatedly rebrand, share personnel, and overlap with other ransomware and extortion operations. Zeon’s lineage ties it to a mature Russian-speaking cybercrime environment associated with large-scale ransomware, data theft, and extortion activity. Although detailed public reporting on Zeon’s standalone victimology and internal structure remains limited, high-confidence reporting links the group to former Conti members and to the broader operational patterns of that ecosystem, including encrypting malware deployment and extortion-oriented intrusions. Zeon is also cited in timelines and infrastructure analyses involving other post-Conti groups, reinforcing its role as part of the successor landscape that followed Conti’s collapse.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the successor groups formed by former Conti members after Conti disbanded.
Named as one of the ransomware groups that former Conti members reportedly splintered into after Conti shut down.
One of the named subgroups formed by former Conti members after Conti disbanded.
Named as a rebranded subgroup emerging from the Conti ecosystem after Conti’s 2022 disbandment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.